The National Cyber Security Center (NCSC) and Information Commissioner’s Office (ICO) warn that keeping cyber incidents quiet increases the chances of other attacks and makes everyone less safe.
In a rare joint blog post, today, authorities from both countries worked together to debunk some of the common myths about incident reporting and break the cycle of cybercrime.
They argued that every incident that goes unreported is a missed opportunity to learn from it and strengthen protections for all organizations. If it was a ransomware attack, they warned that paying the extortionists would encourage them to continue the attack.
“Imagine coming home from work and your house has been burglarized. and continue working as if nothing happened,” the blog post said.
“Next week, your neighbors will also be robbed, but they won’t mention it, so you may not know about it. It’s because you didn’t realize the windows weren’t locked yet, and it’s easy for them to break in again.”
Incident Report Details: Security Incidents Reported to the FCA to Surge 52% in 2021
NCSC and ICO list six common misconceptions about incident reporting.
- Hiding an attack means all will be well
- Reporting to the authorities increases the likelihood that the incident will become public
- Pay the ransom and the case will be solved
- No need to pay ransom if your organization has good offline backups
- Organizations do not need to report to ICO if there is no evidence of data theft
- Organizations will be fined if data is compromised
The NCSC explained that it never actively releases incident information or shares it with regulators without the consent of victims groups. The ICO added that it would not disclose the details of the incident beyond confirming whether the incident was reported.
The NCSC told the organization that offline backups do not reduce the risk of data theft from a double-extortion ransomware attack, and that victims can claim their data has been stolen, even if there is no evidence that the data was stolen. “We should start with an assumption,” he cautioned.
The ICO also struggled to point out that while online blackmailers may claim that all violations are fined, the reality is quite different.
“As an impartial and proportional regulator, the ICO understands that helping organizations improve their data protection practices is also the best way to protect people’s data,” he said. “If serious, coordinated, or negligent conduct is found that endangers people’s information, law enforcement action may be an option. But this is not a comprehensive approach.”