Public Sector Focus

11.12.17

Public sector cyber security needs to fight back

Getting security wrong during the transition from paper to digital could mean a loss of public confidence in new services, argues Graeme Stewart, director of public sector at Fortinet UK&I.

From ransomware attacks against the NHS, to cyber-attacks on parliamentary email accounts, it’s safe to say that it’s been a bad year for cyber security in the public sector. Technology may be one of the UK’s fastest-growing industries, but the public sector is still faced with risks that arise during the transition from paper to digital.

Public sector organisations across every service stand to lose valuable data which is vulnerable to criminals. This can range from high-value research from universities to patient records and even sensitive information shared by government officials. So why is the public sector struggling to prevent cyber-attacks?

Budget constraints are universal across all public sector services, and IT managers are increasingly finding themselves tasked to do more with less. As a result, basic security hygiene has always been an Achilles heel for public sector organisations. The most high-profile example of this is the recent WannaCry attack, which crippled the NHS and was able to spread due to a failure to patch a known exploit. Security is unfortunately not seen as an enabler to business operations, so even basic security practices can fall by the wayside. Fostering a culture of security amongst employees at every level is key to putting a stop to preventable cyber-attacks and must be factored into any cyber security program. This means encouraging employees to update systems regularly and to be wary of suspicious emails and links.

The rapid transition from paper to digital means that the public sector is also faced with a widening cyber security skills gap, with industry estimates suggesting that there could be up to three million unfilled jobs in the cyber security industry by 2021.

The issue is compounded by few graduates with the necessary skills. The government has started to take action with initiatives such as the Cyber Schools Programme, which aims to provide young people aged 14-18 with cyber skills by 2021. A complete overhaul in how cyber security talent is developed should play a key part in defending the public sector from cyber-attacks.

Another issue holding back public sector cyber security efforts is that many organisations see cyber security spend as an unnecessary cost of business, with minimal ROI. This is a damaging misconception, especially for public sector organisations looking to minimise costs. When you consider that a medical record is worth 10 times as much as a credit card number on the black market, it’s no surprise that research shows 34.4% of all breaches worldwide are hitting the healthcare industry. There is a cost associated with breaches but, aside from the financial impact, breaches can bring about lawsuits and regulatory penalties and compromise not only patient data but patient care. As we saw with WannaCry, when malware prevents NHS staff from accessing systems, the ability to deliver care is affected.

With research from Vanson Bourne showing that the NHS alone is projected to save £15m a year by investing in cyber security, it should be viewed as an enabler to allow operations to not only become more agile, but to also save money. In order to unlock the potential of digitisation, public sector organisations must prioritise cyber security, which will in turn improve quality of patient care and levels of patient trust.

Whilst the UK government has pledged to bolster the public sector’s cyber security systems with a £21m investment, it is pivotal that escalating issues such as the skills gap, legacy systems and employee education are addressed. At a time when public sector budgets are already being cut, getting security wrong during the transition from paper to digital could mean a loss of public confidence in new services. Not only this, but with the introduction of the General Data Protection Regulation in May 2018, public sector bodies must ensure that they avoid fines. However, loss of public confidence in services could be much more damaging in the long term. It’s vital that organisations prioritise educating employees about the dangers of phishing and social engineering.

FOR MORE INFORMATION
W: www.fortinet.com

Comments

There are no comments. Why not be the first?

Add your comment

public sector executive tv

more videos >

latest public sector news

Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

19/08/2020Leeds’ Clean Air Zone Plans Suspended for the foreseeable future

Leeds City Council have today (August 19) announced that their plans for a Clean Air Zone within the city may not have to go ahead due to lower e... more >
Apprenticeships on the rise across London boroughs

19/08/2020Apprenticeships on the rise across London boroughs

According to recent statistics by London Councils, apprenticeships directly created by London boroughs are up 14% on the previous  year. ... more >
Colleges set to receive £200m in Funding

19/08/2020Colleges set to receive £200m in Funding

Over 180 colleges are set to receive a share of £200m, in order to repair and refurbish buildings and campuses. The funding makes up p... more >

editor's comment

25/10/2017Take a moment to celebrate

Devolution, restructuring and widespread service reform: from a journalist’s perspective, it’s never been a more exciting time to report on the public sector. That’s why I could not be more thrilled to be taking over the reins at PSE at this key juncture. There could not be a feature that more perfectly encapsulates this... read more >

last word

Prevention: Investing for the future

Prevention: Investing for the future

Rob Whiteman, CEO at the Chartered Institute of Public Finance (CIPFA), discusses the benefits of long-term preventative investment. Rising demand, reducing resource – this has been th... more > more last word articles >

the raven's daily blog

Cleaner, greener, safer media: Increased ROI, decreased carbon

23/06/2020Cleaner, greener, safer media: Increased ROI, decreased carbon

Evolution is crucial in any business and Public Sector Executive is no different. Long before Covid-19 even became a thought in the back of our minds, the team at PSE were looking at innovative ways to deliver its content to our audience in a more dynamic and responsive manner. We’re conscious to take the time to both prot... more >
read more blog posts from 'the raven' >

comment

Peter Kyle MP: It’s time to say thank you this Public Service Day

21/06/2019Peter Kyle MP: It’s time to say thank you this Public Service Day

Taking time to say thank you is one of the hidden pillars of a society. Being on the receiving end of some “thanks” can make communit... more >
How community-led initiatives can help save the housing shortage

19/06/2019How community-led initiatives can help save the housing shortage

Tom Chance, director at the National Community Land Trust Network, argues that community-led initiatives are a productive way of helping to solve... more >
Aberdeen's green transport fleet attracting international attention

19/06/2019Aberdeen's green transport fleet attracting international attention

Aberdeen City Council’s hydrogen spokesperson, councillor Philip Bell, highlights the Granite City’s determination to play a leading ... more >
A fifth of public sector workers have never received a thank you from the people they serve

13/06/2019A fifth of public sector workers have never received a thank you from the people they serve

A fifth of the country’s public sector workers say they have NEVER received a ‘thank you’ for doing their job as Public Service... more >

interviews

Artificial intelligence: the devil is in the data

17/12/2018Artificial intelligence: the devil is in the data

It’s no secret that the public sector and its service providers need to invest in technology to help make better use of their resources. Bu... more >
Digital innovation in the public sector: The future is now

17/12/2018Digital innovation in the public sector: The future is now

One of the public sector’s key technology partners has recently welcomed a new member to its team. Matt Spencer, O2’s head of public ... more >
New Dorset Councils CEO on the creation of a new unitary: ‘This is going to be the right decision for Dorset’

05/11/2018New Dorset Councils CEO on the creation of a new unitary: ‘This is going to be the right decision for Dorset’

The new chief executive of one of the new unitary authorities in Dorset has outlined his approach to culture and work with employees, arguing tha... more >
Keeping the momentum of the Northern Powerhouse

15/10/2018Keeping the momentum of the Northern Powerhouse

On 6 September, the biggest decision-makers of the north joined forces to celebrate and debate how to drive innovation and improvement through th... more >