Written evidence submitted by FTI Consulting LLP and Clifford Chance LLP
Introductions
FTI Consulting LLP
FTI Cybersecurity combines cutting-edge, intelligence-led capabilities around a trusted core of comprehensive offerings. We are a global leading provider of independent cyber and risk management advisory services with a core offering focused on cyber readiness, incident response, and complex investigations.
As an international company serving organisations across the globe, we build a safer future by helping businesses understand their own environments, harden their defences, rapidly and precisely hunt threats, holistically respond to crises, and recover operations and reputation after an incident. Our team has a unique ability to include sector and industry expertise alongside our cybersecurity capabilities. Our team, capable of deploying worldwide, consists of more than 450 dedicated cybersecurity experts, incident response consultants, developers, and data analysts with extensive investigative backgrounds, led by those with decades of experience at the highest levels of law enforcement, intelligence agencies, and global private sector institutions.
Every cybersecurity strategy, incident response plan, and investigation brings with it considerations beyond cyber. FTI Cybersecurity supports all needs and challenges related to cybersecurity, such as global investigations, forensic accounting and technology, data and analytics, data privacy and protection, crisis management and strategic communications, and anti-money laundering. We have comprehensive expertise spanning nearly every industry.
With our global team’s deep experience in law enforcement and government, we maintain relationships with the top global intelligence agencies, regulatory authorities, and private agencies to better support our clients in their prevention, response, and investigation of cyber threats and incidents.
Clifford Chance LLP
Clifford Chance is one of the world’s pre-eminent law firms, with significant depth and range of resources across five continents. We always strive to exceed the expectations of our clients, which include corporates from all the commercial and industrial sectors, the financial investor community, governments, regulators, trade bodies and not-for-profit organisations. We provide them with the highest quality advice and legal insight, which combines the Firm’s global standards with in-depth local expertise.
1) The extent and nature of the ransomware threat (including sources), modes of extortion, and how the threat could evolve in future:
The extent and nature of the ransomware threat is constantly shifting and has evolved over time. Whilst we have seen modes of ransomware-related extortion develop as the ransomware ecosystem has iterated and adapted in response to a variety of geopolitical and social factors, future threats related to this attack type could involve interference with data integrity as well as the continued elevation of the sophistry of current extortion techniques and a concentration on cloud service providers.
2) Levels and sources of vulnerability of UK organisations to ransomware, including operators of critical national infrastructure:
Critical national infrastructure (CNI) has long been a target of ransomware attacks, and this is likely to be no different when considered in the context of the UK’s 13 CNI sectors – regardless of the public and private nature of various elements of our CNI. Whilst levels of vulnerability will vary depending on the control suites in place across different organisations and the respective regulatory requirements that may mandate these measures, a general increased reliance on digitalisation in the wake of the pandemic and a recent rise in attacks on supply chains are examples of current sources of vulnerability.
3) The UK victim experience, including sources of support for prevention, detection and recovery, public-private partnerships, the role of the media, access to and availability of insurance cover, and regulatory requirements placed on ransomware victims:
It is important to note that analysis of the UK victim experience is somewhat hampered by the globally recognised issue of underreporting when it comes to ransomware attacks; a lack of reporting that can be motivated by reputational fears, or the perceived complexity and/or redundancy of reporting attacks to law enforcement. Recent years have also seen a significant hardening of the cyber insurance market, with a marked narrowing in agreed terms of coverage. In combination with the often-aggressive level of enforcement actions taken against victim organisations, the UK victim experience is one which is unsupported in some areas by governmental and/or regulatory bodies – leading ransomware targets to seek help and support from private organisations instead.
4) The effectiveness of the response to ransomware by Government, law enforcement agencies and other UK state actors, including key operational challenges and ministerial oversight:
It is notable that the general response to ransomware by Government, law enforcement agencies and other UK state actors has largely been restricted to advice regarding the non-payment of ransom requests and cybersecurity measures. The ethical and judicial basis of this approach is understandable, particularly so in light of international sanctions that may apply to certain threat actor groups. However, the historically sparse guidance and information regarding payments and their implications, large number of organisations involved in cybersecurity policy and regulation, and the lack of specialised cybersecurity knowledge within designated investigative bodies has often led to a lack of clarity for businesses and individuals.
5) Reforms that might enhance the UK’s resilience to ransomware, reduce the economic and societal damage that it causes, and/or support the law enforcement response; Lessons that could be learned from other countries’ approaches and responses to ransomware:
Building the UK’s resilience to ransomware has already proven itself to be an established national priority at government level. However, although current proposals for legislative reform place heavy emphasis on cyber risk management, there is little by way of reforms or formal programmes focused on streamlining information sharing and strategic development between the public and private sectors, despite the value of the knowledge that each has to impart to the other and the value of these strategic relationships in establishing dialogues around ransomware and resilience-building measures. The US’s approach to private sector engagement provides a robust example of how proactive communications and dynamic information sharing initiatives can inform effective, collaborative approaches to cyber threats.
The threat of ransomware – globally and in the UK – is real and established. However, the shifting dynamics of its nature and constantly moving parameters means that the extent and manifestation of this threat can, does and will vary at different points in time.
What is Ransomware, and How Does it Work?
At its highest level, ransomware is a form of malware[1] – malicious software – that is designed to deny an individual or an organisation access to their systems and/or data. In order for a ransomware attack to be successful, the malicious software has to gain initial access to a target victim’s system. This access – often referred to as the infection or attack vector – can be achieved by the threat actor in several ways. Three of the most common infection vectors are phishing emails (malicious communications that dupe a recipient into clicking a link and downloading malware onto their device), the exploitation of new or known vulnerabilities in systems or software, and the exploitation of services such as Remote Desktop Protocol (RDP), which can allow a threat actor to remotely connect to a network using guessed, leaked or stolen credentials before downloading, executing and spreading the malware of their choice prior to encrypting and/or exfiltrating data.
Whilst ransomware represents a single subset of a wide range of malware types, ransomware itself has many variants or “strains” – each of which possesses unique characteristics and functionalities. The number of ransomware strains in existence is significant: by way of example, of the 10.8 million malware incidents detected by Bitdefender in November 2021, 222 individual ransomware families were identified.[2] There are, however, some ransomware variants which are better known than others given the frequency of their use in high-profile attacks, recent examples of which are the eponymously-named strains LockBit 3.0, Conti, PYSA, Hive, BlackCat and ALPHV.
Why Focus on Ransomware?
Although ransomware is just one of many types of cyber attacks, it is certainly amongst the most widely scrutinised and discussed. For technical researchers and members of the cybersecurity profession, this is understandable: between the complex dynamics of ransomware groups and the continuous development of the ransomware strains themselves, there is much to be analysed. However, unlike other cyber attack types, ransomware as a form of attack is commonly reported in the mainstream press and is familiar to the general public; a fact that can be directly attributed to the extent and nature of the threat it poses and the fact that ransomware attacks often affect the wider population.
Ransomware is also unique due to the fact that the existential nature of the threat places many organisations in a position where the payment of a ransom is often the only meaningful route to recovery. In spite of the potential risks of sanctions breaches, terrorist financing, or funding of criminal activities, the catastrophic disruption caused by ransomware means that organisations are often left with little choice but to pay a ransom and hope for decryption. This is particularly acute in sectors where potential harm to the citizen is immediate and significant, such as healthcare, financial services, or utilities; sectors where any loss of service, even for a matter of hours, can have dire consequences for the wider public. The consequences and impacts of a ransomware attack can therefore be many and wide-reaching, including:
Given that ransomware is a single attack type with multi-faceted and layered consequences, the nature and extent of this threat is not to be underestimated.
Ransomware: A Brief History
Prior to this paper commenting on the present and future implications and sources of this threat, it is important to note that despite the recent extent to which ransomware has permeated the social consciousness and commanded the attention of the media, international governments, public bodies and private sector enterprises, bad actors holding computer systems and/or digital data access to ransom is not a purely contemporary phenomenon. In 1989, for example, the AIDS trojan – also referred to as the PC Cyborg virus – was distributed via floppy disk to targets in over 90 countries, demanding that victims sent $189 to an address in Panama before their system access was restored.[3] Despite the relatively crude nature of its operation, this event – acknowledged by many as one of the world’s earliest recorded ransomware attacks – set the evolution of this attack type into motion. Although the sophistry of computer systems and corresponding exploitation techniques developed at a steady pace over the ensuing two decades, ransomware did not manifest itself as a common threat during this time – potentially due to the difficulty of remaining anonymous whilst collecting extortion payments. However, with the emergence of cryptocurrencies such as Bitcoin in 2009, system exploitation and file encryption became synonymous with a significant monetary opportunity that carried little risk of the threat actors behind it being identified.
Over the next several years, eCrime[4] figures soared – and so did the number of ransomware types that were specifically developed to take advantage of this new era of digital exploitation. The figures tell their own story: whilst only 10,000 ransomware samples were identified in 2010, this number grew explosively to over 4 million by 2015 – a period that also saw the significant advancement of encryption algorithms such as 2048-bit RSA that was first leveraged to significant effect by CryptoLocker, one of the first significant ransomware variants, in 2013.[5] By 2015, ransomware had cemented itself as a credible threat to users of information systems, with the malware frontrunners of the day – TeslaCrypt, CTB-Locker, Scatter and Cryakl – revealing themselves as responsible for 79.2% of crypto-ransomware attacks experienced by users.[6]
In addition to the ransomware attacks of this period commanding relatively low ransoms in comparison to the seven-figure sums commonly demanded today from target global enterprises, the impact of the ransomware types listed above – although damaging to their immediate victims – was not felt on a global scale. However, the WannaCry and NotPetya ransomware attacks of May and June 2017 respectively quickly changed understandings of how malware could spread – and the extent of the operational and financial damage it was capable of wreaking. The WannaCry attack in particular had a significant impact on the UK’s National Health Service, costing the service an estimated £92m in lost output and restorative operations.[7] In addition to these attacks being significant for the global lateral movement they demonstrated ransomware being capable of, these were some of the earliest examples of nation-state mounted attacks. The WannaCry attack has been largely attributed to North Korea, with speculation around the country’s motivation for this action revolving around retaliation for sanctions imposed on them for nuclear activity.[8] The NotPetya campaign, on the other hand, has been linked to the Russian government’s Sandworm hacking group with the first – and potentially only intended victim – being Ukraine and its critical infrastructure.[9] With the occurrence of these two global events, ransomware was now not only a financially motivated crime – it was markedly dangerous weapon being used in political disputes.
Given the scale of the ransomware threat that had proven itself by this time, the emergence of Big Game Hunting (BGH) in 2018 came as little surprise to those who had been following ransomware’s journey. Whereas ransomware operators had previously attempted to infect large numbers of victim devices with the hope of receiving small payments from as many people as possible, the advanced capabilities of malware, spoofing techniques and phishing tactics during this period caused threat actor groups to shift their modus operandi to target fewer, bigger targets whose ransom payments would represent a significantly larger financial yield – a shift that continues to characterise the malware features and victim profiles observed in even the most recent ransomware attacks.
Ransomware: Where are We Now?
With Big Game Hunting having established itself on a global scale, ransomware attacks continued to grow in destructive impact and frequency – and were exacerbated by the start of the COVID-19 pandemic which, in forcing workforces online practically overnight, created new opportunities for the exploitation of remote connections. The figures speak for themselves, demonstrating that threat actors did indeed seize the opportunity to exploit the situation: corresponding with the start of the pandemic, 2020 saw an explosive rise in payments made by ransomware victims, with Chainalysis reporting that over $406 million worth of cryptocurrency was paid to attackers that year:
Source: Chainalysis
In addition to these figures marking 2020 as a standout year for ransomware, this period also saw the firm establishment and increased deployment of the “double extortion” ransomware technique. Whereas ransomware operators had previously denied their victims access to their files by encrypting them, cybercriminals now threatened to expose the stolen data on the Dark Web or on dedicated leak sites if no ransom was paid. Ransomware families which demonstrated this technique – evidence of the evolving tactics, techniques and procedures (TTPs) associated with threat actor activity – included Maze, Egregor, Sodinokibi and DoppelPaymer. It should be noted, too, that some ransomware operators have also adopted a “triple-extortion” approach where, in addition to the encryption and threat of data exposure, distributed denial-of-service (DDoS) attacks and communications with stakeholders are used to further pressure victim organisations into making ransom payments.[10]
Whilst considering the evolution of the TTPs associated with ransomware, we wish to highlight the considerable development of the business model associated with this attack type and the general broadening of the ransomware ecosystem that the past few years have seen. One of the most critical developments in this space has been the creation and widespread adoption of the Ransomware-as-a-Service (RaaS) model, a graphical depiction of which is below:
Source: Carnegie Mellon University Software Engineering Institute
As the diagram above demonstrates, RaaS models allow ransomware developers to offer “affiliates” – cybercriminals without the skill, time or resource to develop their own ransomware code – the opportunity to use their ransomware to attack an intended victim in return for an upfront payment or share of the attack profits. Once the affiliate receives the developer’s customer ransomware, they mount the phishing and/or credential exploitation attack to gain access to their victim’s system before encrypting and/or exfiltrating their data and sending the ransom demand. If the ransom is paid, a decryption key may be provided to the victim organisation and the attack profits (which may go through a form of laundering or redirection to evade detection) are shared between the affiliate and developer before the process begins again.
Given the huge sums that ransomware has commanded since 2020, it is not surprising that RaaS has come to represent big business in its own right. In addition to the RaaS landscape being competitive, with operators advertising their services on the Dark Web and running publicity operations, this business model is reflective of that adopted by many contemporary mainstream businesses. For example, RaaS operators are known to commonly offer their services on a monthly subscription basis and charge licensing fees. In addition, packages often include extras such exfiltrated data hosting, victim payment portals and victim communication capabilities alongside the malicious code the affiliate can use to launch a ransomware attack on their intended target/s.
RaaS operations are now commonplace, and have been linked to some of the most significant ransomware attacks of recent years. Carbon Spider, for example – an Eastern European criminal group who have been active since 2013 – introduced a RaaS affiliate program for their DarkSide ransomware in 2020 which was identified as having been used in the ransomware attack visited upon Colonial Pipeline in May 2021.[11] The wide availability of the RaaS model – and the success it has been seen to enjoy – significantly expands the parameters of the ransomware threat, not only through the amount of attacks that can be launched and the subsequently expanded reach of a range of malware strains, but through the significant sums of money generated by these operations; sums which have, and will likely continue to motivate developers and affiliates to seek more targets.
There is something ironic in the fact that as ransomware developers have created their own supply chains, ransomware attacks on global enterprises have significantly increased in the last two years. To many threat actors, supply chains represent an opportunity to take advantage of what may be poorly secured access points within the target business’s systems or impact several organisations through an attack on a single supplier. In addition to the widely-reported SolarWinds supply chain attack of 2020, a recent example of a supply chain attack was the REvil ransomware attack experienced by remote management software vendor Kaseya in July 2021. The impact of this attack was significant: in addition to a Swedish supermarket chain which used Kaseya’s software having to close 800 stores for close to a week, REvil claimed to have encrypted more than 1 million systems and demanded an initial $70 million payment for a universal decryptor. With supply chain risk management remaining an area that many large organizations have yet to confidently manage,[12] supply chains – and the businesses that rely on them – remain vulnerable to attacks of this kind.
Contemporary Threat Sources
Despite the huge number of ransomware groups that have been observed over the past decade and the impressive business organisation these groups have demonstrated themselves as being capable of building, it is notable that the lifespan of specific groups is not particularly long – a fact that can be attributed to the group rebrands that commonly occur, the splintering of existing groups, or law enforcement interventions. Whilst a history of specific threat actor groups is outside the scope of this paper, the following section provides brief summaries of the locations, operations and histories of three groups that have been heavily operational within 2022.
1) Conti
Conti ransomware is a tool widely believed to be operated by the Wizard Spider group. This Russia-based, financially motivated cybercrime group have proved to be one of the most adaptive and persistent threat groups in the online exploitation space and are known for their use of the double extortion technique. Conti ransomware, which is believed to have extorted $180 million from businesses in 2021,[13] is currently widely recognised as one of the world’s leading and highest-grossing ransomware threats.
Conti ransomware is thought to be the latest iteration of the group’s Ryuk ransomware, which was one of the first ransomware strains developed specifically to target large enterprise environments. Correspondingly, Conti ransomware has primarily been seen attacking large enterprises in North America and Europe, with over 400 confirmed corporate victims and evidence of ransom demands as high as $25 million. Whilst the ransomware has affected many industries, the healthcare sector in particular has been targeted by Conti with the group identified as the cybercriminals behind the May 2021 Health Service Executive (HSE) cyber attack in Ireland – the largest known attack against a health service computer system.[14]
Although it is standard practice for RaaS models to divide the proceeds of a ransomware attack between the affiliate and the ransomware provider, a recent CISA report has highlighted how Conti differs from other RaaS operations:
“While Conti is considered a ransomware-as-a-service (RaaS) model ransomware variant, there is variation in its structure that differentiates it from a typical affiliate model. It is likely that Conti developers pay the deployers of the ransomware a wage rather than a percentage of the proceeds used by affiliate cyber actors and receives a share of the proceeds from a successful attack.”[15]
Whilst the regular RaaS model outlined above is indicative of a more transactional relationship between the ransomware provider and the affiliate that deploys the malicious software, the CISA report highlights a model through which a deeper relationship is built between the Conti developers and their affiliates - affording the group a larger opportunity to recruit new members to its core team and operate with a broader global reach.
Although many members of the Conti gang are based in Russia, the operations of its affiliates have indicated a broad international scope. The invasion of Ukraine has been significant in its revealing of division within the group in many ways, particularly through the actions of a pro-Ukrainian researcher who infiltrated the group and gained access to Conti’s files and internal chat systems. On 28 February 2022, this researcher set up a Twitter account named @ContiLeaks and published over 60,000 chat messages sent between the group’s members – in addition to code associated with the ransomware and reams of internal Conti documents.
The chat leaks have significantly increased the intelligence available on the Conti gang, providing indications, for example, that there are between 60-100 members of the core team, with managers and a CEO-type figure in place.[16] This formal structural insight into the team’s operation is not hugely surprising; as has been evident for some time, the group operates much like any other large corporation with staggered shifts to ensure round-the-clock coverage, twice-monthly payroll schedules, onboarding processes for new recruits and – according to some reports – physical offices.[17]
For the past two decades or so, the Russian-speaking criminal underground has largely abided by an unwritten agreement that cybercrime gangs in the region don’t target victims in the Commonwealth of Independent States (CIS), the regional intergovernmental organisation in Eastern Europe that was formed following the dissolution of the Soviet Union in 1991.[18] However, Russia’s invasion of Ukraine has seen cracks form in a criminal society that has previously remained apolitical – united, in fact, by the common goal of successfully committing cybercrime leveraging cross-national teams. An initial pro-Russian statement published by the group has led to its demise, not only due to the internal division amongst members of the syndicate but due to declining payments from victims concerned about violating sanctions risks associated with Russian threat groups following its invasion of Ukraine. The growing toxicity of the brand saw Conti launching a final high-profile attack against the Costa Rican government in May 2022 before shutting down its operations the following month. However, despite no longer being united under the Conti name, research has suggested that the group remains active, operating through a new umbrella network of autonomous groups such as Karakurt, Black Basta and BlackByte.[19]
2) LockBit
LockBit is a well-known cybercrime syndicate whose operations were first observed in 2019. The group is widely known for operating a RaaS model, and for engaging in the double extortion techniques described above. Recent attack targets include French electric multinational Thales Group in January 2022, the French Ministry of Justice in January 2022 and the exfiltration of Bridgestone Americas data in February 2022.
LockBit ransomware has gone through several iterations and has shown itself to continually adapt to reflect trends in the ransomware landscape. LockBit’s initial targets notably excluded CIS countries and Russian systems, and included business within the US, the UK, Germany, France, India, China, India and the Ukraine.
Although LockBit 1.0 stood out as unique when it was first observed due to its ability to self-propagate, the group’s subsequent version of their ransomware – LockBit 2.0 – famously made use of tools native to Windows systems in order to better avoid detection. This period in LockBit’s history saw the group engage in double extortion, and actively seek insiders within target organisations to assist in mounting attacks.[20] Target enterprises included those within the healthcare, education and charity sectors.
In March 2022, LockBit rebranded to LockBit 3.0, which has also been referred to as LockBit Black. In addition to featuring enhanced encryption mechanisms, LockBit 3.0 also allows people to purchase stolen data directly from their dedicated leak site.
Given the group’s presence within Russian-speaking language forums, LockBit’s declaration of its neutrality in relation to Russia’s invasion of Ukraine was surprising to some. However, it has been theorised that in addition to using this neutrality on cybercrime forums to try to poach pro-Ukraine Conti loyalists, this declaration may have been due to LockBit’s desire to exploit a loophole in cybersecurity insurance relating to the “force majeure” policy that prevents insurers from covering the costs of a ransomware attack during active conflicts.[21]
3) ALPHV
ALPHV – also known as BlackCat or Noberus – were first observed as an active threat actor group in November 2021. In addition to employing a RaaS model, the organisation has come to be well-known for their use of the triple extortion tactic, in which – after sensitive data is exfiltrated and encrypted, threats of DDoS attacks are threatened to gain more leverage over their targets.
ALPHV’s string of recent successes and deployment of sophisticated TTPs has led security researchers to believe that the group was founded by an experienced member of a ransomware gang rather than a newcomer to the game; in fact, there have been claims that ALPHV represents a rebranding of BlackMatter, or intentional successor to REvil.[22]
ALPHV has been seen promoting their activities and recruiting members on Russian-speaking language forums, providing some clue as to their geographic base. The ransomware that they operate is distinct, having been developed using a programming language called Rust. Rust’s known fast performance and cross-platform capabilities have led to variants of this ransomware being observed across both Windows and Linux between December 2021 and January 2022.
ALPHV’s victims are typically large organisations from which significant ransoms can be demanded; recent reports suggest that their demands have ranged from $400,000 to $3 million in cryptocurrency. The group’s dedicated leak site names over twenty victim organisations, representing global geographies and multiple business sectors.
The Ransomware Threat: 2023 and Beyond
Although ransomware figures have dipped since reaching their most recent crescendo in 2021, the threat posed by ransomware on a global scale remains concrete. From both a technical and operational perspective, ransomware has proven itself to be incredibly iterative and adaptive and there is no doubt that its capabilities and the methodologies of its operators will continue to evolve.
Eastern Europe has previously been home to a significant number of ransomware groups, and this is unlikely to change in the next few years. However, there are a variety of factors that may see an increased concentration of activity coming out of Russia moving forward, including strong perceptions of state protection for cybercrime groups, support of Russia’s invasion of Ukraine and motivation for retaliatory action against Ukraine’s supporters, and fears of crackdowns and law enforcement actions by Europe and the US.
In addition to a potential increase on attacks on third party cloud providers in light of organisations’ increasing reliance on these services, the evolution of the ransomware threat may see a move from data encryption and exfiltration to data corruption; a tactic that would theoretically allow threat actors to cause significant reputational and operational chaos without the expense and difficulty of exfiltrating and hosting large amounts of stolen data. Data corruption attacks are not without precedent: in December 2020, for example, the European Medicines Agency (EMA) fell victim to a cyber attack after which stolen information regarding vaccines was published online – information which was found to have been manipulated prior to its public posting.[23] In addition to this type of attack being especially dangerous to organisations that incorporate machine learning into their products or services, attacks on data integrity have significant implications for the spread of disinformation in the context of elections and conflict – implications that may serve as an inducement for more attacks of this type to be mounted in the coming years.
The evolution of the global ransomware threat has demonstrated the breadth of the risk associated with this form of cybercrime through the ever-lengthening list of targets across all profile types who have fallen victim to it. Although the technical specifications of ransomware can be complex, the risk statement associated with its operation is simple: any organisation with a digital footprint that can be financially or reputationally exploited through the encryption and/or exposure of sensitive data is a potential target for ransomware threat actors – and the UK, where ransomware attacks reported to the Information Commissioner’s Office increased 100% from 326 in 2020 to 654 in 2021, is no exception.[24]
In many ways, UK patterns associated with ransomware have followed global trends. As recent research from Jumpsec shows, for example, the global ransomware peak noted in 2021 and the subsequent dip in 2022 has also been observed in the UK:
Source: Jumpsec – UK Ransomware Trends 2022
In keeping with a country that has been reported to suffer the third highest rate of ransomware attacks in the world,[25] it has also been noted that the exposure of significant system vulnerabilities over the past two years – which, predictably, lead to spikes in exploitative attacks – have seen the number of malware attacks on UK organisations rise alongside those experienced by victims globally: following breaking news of the PrintNightmare, Proxy/Shell, Log4j, Spring4shell and Follina vulnerabilities, for example, threat actor activity reported in the UK soared.[26]
The UK-specific data pertaining to ransomware, however, suggests that that are important distinctions to note in the country’s experience of this attack type over the past two years. Although recent research by NordLocker[27] has suggested that the top 5 industries affected by ransomware in the USA were Construction, Manufacturing, Transportation, Healthcare and Technology, the same report notes that in the UK, attacks on the Education and Business Services sectors represented the most affected industries – a conclusion further reinforced by Jumpsec’s data:
Source: Jumpsec – UK Ransomware Trends 2022
The UK has 13 national infrastructure sectors: Chemicals, Civil Nuclear, Communications, Defence, Emergency Services, Energy, Finance, Food, Government, Health, Space, Transport and Water. As the data above indicates, few of these sectors have been the focus of persistent targeting over the past 24 months. However, this is not to say that there have been no attempts on the UK’s critical national infrastructure (CNI) in recent times. In August of this year, for example, South Staffordshire Water announced that it had fallen victim to a ransomware attack in which the threat actors – later identified as the Cl0p ransomware group[28] – claimed to have been able to access the SCADA systems which controlled industrial processes at their water treatment plants; proving this by publishing leaked documents and screenshots of those SCADA systems to their leak site.[29] In addition to this incident raising levels of concern around the exploitation of Operational Technology (OT) systems on UK soil, the fact that the timing of this attack coincided with a period of drought in the UK provides a further indication that bad actors are taking advantage of socio-political moments of hardship to put extra payment pressure on victims.
The UK’s National Health Service – an indisputable element of the country’s critical national infrastructure – has also not been immune to the nefarious intentions of threat actor groups this year. In August, LockBit 3.0 was used to mount a ransomware attack against Advanced – a software supply business who not only support thousands of the NHS’s healthcare professionals with their solutions, but whose Adastra software works with 85% of NHS 111 services.[30] The attack, which exploited the Remote Desktop Protocol described in the opening section of this paper, caused the major outages of between five and seven key systems, with Advanced confirming in a statement that customer data was exfiltrated from two systems used to manage care homes and services.[31] The system outages were so severe that staff were taking care notes with pen and paper over a month after the attack was identified; a manual process which severely impacted patient care due to the lack of ability to communicate medical notes across systems and practices.[32]
When considered alongside examples such as the REvil Elexon Energy ransomware attack in May 2020,[33] the damage wrought upon the Ministry of Defence’s Defence Academy network in March 2021,[34] and the ransomware attack on the Police Federation of England and Wales in March 2019,[35] it is clear that attacks on the UK’s critical national infrastructure – although not persistent or sustained at present – represent a real, credible and tangible threat; a threat which, given ransomware’s increased prevalence in the private sector, is heightened by the largely private ownership of much of the UK’s CNI.
Much like our global counterparts, the attacks that have targeted elements of the UK’s national infrastructure bear the hallmarks of current ransomware trends – patterns around sources of vulnerability do not demonstrate radical difference across geographical bounds. Common sources of vulnerability to ransomware attacks and their effects include increasingly sophisticated phishing and spear-phishing attacks, business email compromises, supply chain attacks which leverage unprotected points of connection, a lack of privilege management and account protection allowing threat actors to move laterally within a network having gained initial entry, human error, the exploitation of Remote Desktop Protocol and a lack of patching on technologies such as firewalls. Given that Conti and Lockbit were found to be the most active ransomware gangs in the UK between January 2020 and July 2022, it becomes clear that the ransomware threat to the UK is posed by some of the world’s most sophisticated ransomware threat actors who are responsible for attacks at the cutting edge of the field. The vulnerability level of any organisation, including those within critical national infrastructure sectors, will therefore depend on how strong and defined their controls and processes are across areas such as patching, supply chain risk management, security awareness education, and network monitoring.
This is especially important given the ever-increasing digitalisation of the UK’s CNI operations and the increasing sophistication and automation of the technologies they rely upon. In addition to facing the challenges that many global organisations have encountered due to COVID-induced remote workforces and increasing dependencies on IoT devices, rollouts of new operational technologies will often increase the attack surface of the organisation. The ongoing digital revolution of the UK’s rail networks provide a good example of how elevated cybersecurity risk levels accompany technological advancement. The 2021 Williams-Shapps Plan for Rail pledges to create “a new brand and identity [to] mark the end of a quarter century of fragmentation” – a process of rebuilding that places technologies such as online payments at the heart of these efforts.[36] As noted in Tech UK, however, online payments are just the beginning. Amongst other things, this process of improvement will necessitate the leveraging of Big Data, cloud-based infrastructure, digital twins, passenger WiFi, CCTV and interconnected systems and networks to ensure a seamless delivery flow[37] – process elements that each carry elevated levels of cybersecurity risk, proven in part by the significant ransomware attack suffered by the IT systems belonging to Italian State Railways (FS) and its subsidiaries in March of this year that caused the suspension of all rail services and left FS unable to update passenger information screens at stations.[38] It is therefore critical that a secure-by-design approach is taken in the formulation, testing and eventual rollout of any digital transformation efforts, and that cybersecurity – a word that, notably, does not appear once in the Williams-Shapps plan – is considered from a strategic risk perspective to contain the attack surface as far as is possible.
It is also important to note that levels of vulnerability will vary depending on levels of preparedness that fall outside the realm of technical controls, too. Although recent research has shown that 70% of cyber leaders in UK CNI organisations believe that ransomware will significantly disrupt their operations in the coming year, 62% of those surveyed did not have decision-making processes in place to decide whether or not their organisations should make ransom payments[39] - pointing not only to a need for more robust internal policymaking within CNI structures, but an increased level of attention from senior leadership and the adoption of top-down, executive-driven cybersecurity strategies. Organisations within CNI sectors, however, are not the only bodies in the UK who would benefit from an increased focus on cybersecurity risk at the Executive and Board level. In addition to finding that only 13% of businesses routinely assessed their suppliers for cybersecurity risk, the Cyber Security Breaches Survey 2022 by the Department for Digital, Culture, Media & Sport (DCMS) notes that only 23% of UK businesses have a formal cybersecurity strategy in place – a finding which is reflective of the accompanying fact that only 50% of UK businesses update their senior team on their cybersecurity state and posture on a quarterly basis, with 16% of business never updating senior management on cybersecurity risks and actions.[40] Whilst these statistics point to a wider trend regarding the need for increased engagement with cybersecurity at executive level, the disruptive financial, operational and reputational potential of a successful attack on critical national infrastructure – attacks that have been seen in the UK and abroad – should further underscore the importance of preparedness in the policy and strategic spheres as well as the technical arena.
One of the main reasons that an analysis of the victim experience is difficult is that many organisations are reluctant to report ransomware incidents publicly. This may be due to concerns regarding reputation (such as a fear of public embarrassment) or because of threats made by the threat actor regarding the potential for data exposure if the ransom demanded is not paid. When ransomware incidents are reported, detailed information from the victim organisation is usually not made public. Furthermore, even in cases where the victim experience is reported, the information is incomplete or provided in a format that is not easily reviewable as the organisation is usually focused on its recovery from the attack and bringing systems back online and in some cases may be reluctant to share publicly any information due to the perceived risks of either or both regulatory enforcement action and follow-on civil litigation.
In some cases, the attackers may specifically target individuals or organisations which are less likely to report the incident. This may not be the primary driver of an attack; however, threat actors' focus on large targets inevitably means that professional and financial services and other regulated industries are targeted (particularly since highly developed industries often draw the most regulation).
An additional complexity is in the response or assistance provided by law enforcement during the reporting process. While the police generally respond to reports of an incident in a timely manner, meaningful assistance is usually provided only in the most serious cases, where additional resources are provided through organisations such as the NCA or NCSC rather than the relevant local police force. The majority of cases are therefore left to the generally opaque "criminal investigation" process. The broader context of ransomware is that attackers are often not based in the UK or the relevant jurisdiction, making it difficult for the police to investigate the perpetrators. Even within the jurisdiction, the technical nature of ransomware matters makes them difficult to investigate, requiring additional technical assistance from specialist forces or another agency.
Support is therefore most often privately obtained. The cost of mounting a response to a ransomware incident may in some cases be covered by a cyber insurance policy. Whilst traditional insurance coverage for business interruption and property liability has tended to cover cybersecurity matters, the market has been volatile, leading to many providers withdrawing their offerings and others tightening their underwriting standards. The market has seen significant price increases in the past three years, given the expanding attack surface, the proven danger of data exposure across the globe, the increasing sophistication of cyber attacks, and cyber attacks that have been mounted as part of broader geopolitical conflicts. The insurance market has had to address the increasing utilisation and dependence on information technology and digital devices, which reflect the growth of the likelihood and severity of threats from malicious actors. Increasing diligence standards in insurance provision mean that coverage is increasingly limited to organisations that are already relatively sophisticated in their security posture.
The Information Commissioner (supported by the Information Commissioner's Office, or ICO) is the regulator tasked with enforcing UK data protection law, including in relation to personal data breaches. It does not have jurisdiction other than when personal data is involved. Organisations suffering a ransomware attack involving personal data are required by law to notify the Information Commissioner "without undue delay, and where feasible, not later than 72 hours after having become aware" of a personal data breach unless it is "unlikely to result in a risk to the rights and freedoms of natural persons". This is a low reporting threshold and consequently the ICO receives a large volume of data breach notifications, including many involving ransomware. It has historically been the ICO's general position to consider organisations suffering ransomware attacks as victims, but in more recent times, the ICO has undertaken enforcement action against companies which the ICO considers as having failed to implement adequate information security controls. Given the fact that the ICO has investigatory and enforcement powers, this may account for some organisations being less willing to engage proactively with the ICO. In our experience, there is limited support provided to organisations in the context of making a notification to the ICO.
Despite the ICO exercising its powers of financial penalty, there is an argument to say that an aggressive regulator is not the best way forward as information sharing will be stymied by this approach. The focus ought to be on dialogue at multiple levels, and the lack of cybersecurity education available to the wider public weakens the case for aggressive enforcement if mistakes are made.
Finally, we note that threat actors to date have operated on the basis of "big game" hunting. That is to say, targeting organisations that are likely to pay a ransom, for reasons of reputational damage or financial loss (e.g., from operational disruption). In very few cases are the individuals whose data is involved in a ransomware incident targeted, as it requires significant investment of time and effort to monetise specific personal data from an incident.
The payment of a ransom in the context of cybersecurity is a contentious issue that relates to longstanding arguments around ransom payments more generally, such as in the context of terrorism and piracy. As noted above, however, making a payment may be the only viable means through which victims may regain access to their systems and data within a tolerable period. Making payment also creates a clear financial incentive for the threat actor to release data and assist with systems recovery, with a broader incentive to heed its promise to do so lest future payments are refused.
From the perspective of government officials, the main objection is usually that payment of a ransom encourages the continuation of illicit and illegal activity. The vicious cycle is self-perpetuating, with ransom payments going towards funding criminal activity and developing ever more sophisticated tools to target a broader spectrum of potential victims.
In the UK, there has been little governmental support or co-ordination outside of general sentiments indicating that ransoms should not be paid, such as the joint letter between ICO and NCSC to Law Society of 8 July 2022, and as discussed in the National Cyber Strategy. Victim organisations, whilst recognising these general sentiments, will inevitably consider whether a ransom should be paid depending on the circumstances of each attack, balancing the risks and benefits of such an approach. In some cases (such as the ransomware attack on the City of Baltimore in 2019), the City refused to pay a ransom demanded of $76,280, despite the cost of recovering its systems and operations standing at an estimated $18 million.
The lack of firm and detailed guidance regarding ransomware payments leads to a lack of clarity for industry players and the public. It is unclear if and to what extent governmental bodies have considered the myriad of potential consequences that might arise from a refusal to pay a ransom. If guidance regarding a range of options in a ransomware scenario were to be in place, this would represent a key component of a risk-based framework for regulation. One example of a typical risk-based framework for regulation is that associated with Health and Safety. The Health and Safety Executive is extremely active in producing guidance on almost every aspect of Health and Safety on a regular basis. This mature regulatory framework for governance of the risk-based approach to Health and Safety is yet to develop in cybersecurity.
Part of the issue may relate to the disparate number of organisations involved in cybersecurity regulation:
While this is an issue not unique to cybersecurity (e.g., the Care Quality Commission regulating quality and safety of care in the context of Health and Safety), the large number of departments and bodies with overlapping functions and powers can hinder effective governance. The level of government and strategic oversight in the area is often unclear and, beyond published policy positions as to cyber strategy, there appears to be limited ministerial oversight and direction.
However, we note that even where centralised cyber services exist, the resources they are afforded are often constrained. For example, Action Fraud serves as a one-stop shop for criminal reporting for cybercrime, including ransomware incidents. However, in our experience, the responding or allocated force is usually unfamiliar with cyber incidents and ransomware, and/or takes a significant amount of time to investigate an incident. Often this results in a parallel notification to the NCSC to seek expert input, yet in many such cases the NCSC is not resourced to respond adequately to incidents occurring outside of CNI and/or lacks the sector-specific expertise necessary when working with specialist firms.
We note that none of the public sector organisations listed above focus on providing support to organisations. This includes:
Building the UK’s resilience to ransomware has already proven itself to be an established national priority at government level. Between the 2022 National Cyber Strategy’s commitment to make to make the UK a leading responsible and democratic cyber power by 2030, regular and sustained investments in the NCSC and the 2020 creation and continued development of the National Cyber Force,[42] it is clear that understandings around the need for increasingly comprehensive and collaborative cross-departmental and cross-body processes to proactively counter cyber threats in the UK are widely held by people with the resources and power to deliver significant action in this space.
Given the heightened risks associated with supply chains, for example, current plans for reform that include a focus on managing third party risk such as those outlined in DCMS’s Proposal for legislation to improve the UK’s cyber resilience[43] – largely recognised as the UK’s answer to the EU’s Digital Operational Resilience Act (DORA) – are positive steps forward that will have significant implications for the bolstering of the UK’s resilience to ransomware. Furthermore, the proposed legislation’s focus on tackling the skills shortage within the cybersecurity profession and ensuring the professional standards of those currently supporting the field will markedly improve the quality, knowledge and experience of the country’s cybersecurity workforce – measures that will certainly help build the UK’s resilience to a range of cyber threats. Taken together with the July 2022 discussion paper issued by the PRA, FCA and the Bank of England following the publication of the Financial Services and Markets Bill 2022-23, attempts at harmonising cybersecurity standards and reporting requirements in critical sectors such as Financial Services are clearly legislative priorities.
However, although current proposals for legislative reform place heavy emphasis on cyber risk management – an emphasis that, given the current threat landscape, is well-placed – there is little by way of reforms or formal programmes focused on streamlining information sharing and strategic development between the public and private sectors, despite the value of the knowledge that each has to impart to the other – and it is here that lessons could be learned from other countries’ approaches and responses to ransomware.
The United States’ approach to public-private partnerships is particularly illuminating in the context of a discussion of this kind. Much like the UK’s CNI model, a large portion of the US’s CNI is privately owned and operated. Acknowledging that “partnerships between the public and private sectors that foster integrated, collaborative engagement and interaction are essential to maintaining critical infrastructure security and resilience”,[44] the Cybersecurity and Infrastructure Security Agency (CISA) have created formal partnerships to share critical threat information, inform risk mitigation strategies and share other vital information and resources. These partnerships are structured via the 2013 National Infrastructure Protection Plan (NIPP)[45]which establishes the mechanism for collaboration between private sector owners, operators and government agencies and the requirements for partnerships between the federal government, critical infrastructure owners and operators, and state, local, tribal and territorial (SLTT) government entities. The NIPP, in turn, is supported by the Critical Infrastructure Partnership Advisory Council (CIPAC)[46] which provides a forum in which the government and private sector entities, organised as coordinating councils, can jointly engage in a broad spectrum of activities to support and roll out critical infrastructure security and resilience efforts.
The US has a number of information sharing tools and platforms available to support critical infrastructure sectors including the Homeland Security Information Network – Critical Infrastructure,[47] the CISA Gateway,[48] the National Infrastructure Coordinating Center (NICC),[49] the National Risk Management Center (NRMC),[50] the Protected Critical Infrastructure Information Programme[51] and widely-available Protective Security Advisors (PSAs).[52] In addition, the Critical Infrastructure Threat Information Sharing Framework is a formal resource designed to guide public and private critical infrastructure owners and operators receive and report threat information.[53] Whilst this is an extremely broad set of mechanisms that may not be totally suitable for the UK, the concept of a framework that is explicitly intended to foster, nurture and make actionable a relationship between government and private sector organisations that has cyber resilience and risk mitigation at its heart has import for resilience-building efforts on our home soil.
This paper acknowledges, of course, that the UK’s National Cyber Security Centre operates the CNI Hub which is set up to provide advice and guidance across CNI sectors through the deployment of initiatives such as the CISP information sharing platform, participation in working groups, official assurance schemes, and the Industry 100 (i100) programme. Based on the respective experiences of the parties submitting this evidence, however, the key difference between the US and the UK’s offerings in this space appears to lie in both the depth of engagement between the private sector and governmental organisations and the proactivity of governmental bodies in communicating with the full breadth of the private sector – both of which have significant implications in the context of ransomware responses and the building of resilient futures.
The proactive nature of US federal bodies’ engagement with the private sector manifests itself in many forms, including CISA’s regular invitations to private sector organisations to informational calls which provide detail about newly-discovered vulnerabilities and mitigation strategies, the widespread issuing of CISA Alerts regarding new exploits, and the frequent publishing of joint advisories with the FBI who regularly assist with providing intelligence around Threat Actor groups to a range of cross-sector organisations and provide post-incident support. Although the NCSC, for example, offers a wealth of information and guidance regarding threats and responses to incidents, it seems that it is largely the responsibility of private organisations to seek it out as and when it is required. In addition, there are currently marked differences in the NCSC’s depth of engagement across sectors. For example, the NCSC is well integrated with Financial Sector CNI and engages actively within important information sharing and incident response initiatives such as the Financial Sector Cyber Collaboration Centre (FSCCC). Although this initiative is fully supported by the NCSC, it is private sector led, struggles for depth beyond CNI, and is non-existent in other critical sectors across the UK where no such mechanisms for coordination and collaboration exist. Furthermore, cross sector engagement remains an issue and the NCSC might be expected to be doing more in this space given the pervasive nature of the threat and the critical interdependencies that exist.
The authors of this paper recognise that adequately resourcing and empowering an organisation like the NCSC to act in a proactive capacity is difficult and is a process that may require time. However, there is strategic precedent demonstrated by bodies such as the UK’s Fire Services that can be instructive in modelling the kind of proactivity and public engagement that would both raise awareness of cyber threats and encourage deeper and more frequent public and enterprise engagement with the organisations tasked with tackling them. In addition to the public service announcements and fire safety education campaigns broadcast over a wide range of media channels, fire safety demonstrations and leaflets are regularly delivered to business across the UK, many fire stations are open for visits from the public, and fire service personnel enter people’s homes to fit smoke detectors as a free service. Whilst the parallels will not be exact, reforms that would see organisations like the NCSC increasingly empowered and resourced to establish and implement proactive engagement strategies across UK business and the wider public would hugely expand the organisation’s impact and ability to collaboratively build resilience to a range of cyber threats.
The UK has already demonstrated a proven commitment to responding the cyber threats – and ransomware in particular – through the policy reforms described above, the creation of bodies such as the NCSC and the NCF and, indeed, inquiries such as the one this paper is responding to. These initiatives have already made a significant difference to the amount of information available regarding the scale and scope of the country’s threat landscape, and focused work to standardise cyber-specific processes and implement the increasingly proactive engagement measures between the public and private sectors suggested by this paper will only serve to further strengthen response and resilience efforts.
20 December 2022
[1] Malware is any type of software which is designed to disrupt the operations of a computer, server, endpoint, device or network, leak private information, gain unauthorised access to information or systems, restrict access to data or interfere with a device’s security or privacy.
[2] Bitdefender: “Threat Debrief: December 2021” (https://businessinsights.bitdefender.com/bitdefender-threat-debrief-december-2021)
[3] SDX Central: “Case Study – AIDS Trojan Ransomware” (https://www.sdxcentral.com/security/definitions/what-is-ransomware/case-study-aids-trojan-ransomware/)
[4] eCrime is a broad category of online criminal activity, encompassing all kinds of cybercrime.
[5] Crowdstrike: “History of Ransomware” (https://www.crowdstrike.com/cybersecurity-101/ransomware/history-of-ransomware/)
[6] Digital Guardian: “A History of Ransomware Attacks – The Biggest and Worst Ransomware Attacks of All Time” (https://digitalguardian.com/blog/history-ransomware-attacks-biggest-and-worst-ransomware-attacks-all-time#3)
[7] National Health Executive: “WannaCry cyber-attack cost the NHS £92m after 19,000 appointments were cancelled” (https://www.nationalhealthexecutive.com/articles/wannacry-cyber-attack-cost-nhs-ps92m-after-19000-appointments-were-cancelled)
[8] Virsec: “It’s Official – North Korea is Behind WannaCry” (https://www.virsec.com/blog/its-official-north-korea-is-behind-wannacry)
[9] Wired: “The Untold Story of NotPetya, the Most Devastating Cyberattack in History” (https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/)
[10] Trend Micro: “Ransomware Double Extortion and Beyond: REvil, Clop, and Conti” (https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/ransomware-double-extortion-and-beyond-revil-clop-and-conti)
[11] For more details on this attack’s cause, details and aftermath, please see Reuters’ report: (https://www.reuters.com/business/colonial-pipeline-ceo-tells-senate-cyber-defenses-were-compromised-ahead-hack-2021-06-08/)
[12] According to the Department for Digital, Culture, Media and Sport (DCMS)’s 2022 Cyber Security Breaches Survey, only 13% of UK business assessed the risks posed by their immediate suppliers, with organisations saying that cybersecurity was not an important factor in the procurement process. The report can be found here: https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2022/cyber-security-breaches-survey-2022
[13] KnowB4: “Conti Ransomware Attacks Reap in $180 Million in 2021 as Average Ransomware Payments Rise by 34%” (https://blog.knowbe4.com/conti-ransomware-attacks-reap-in-180-million-in-2021-as-average-ransomware-payments-rise-by-34).
[14] On 14th May 2021, the Health Service Executive (HSE) of Ireland suffered a major ransomware attack delivered through malicious Conti software – activity that was attributed to Wizard Spider. This was the most significant attack on an Irish state agency in history, causing all of its IT systems nationwide to be shut down and resulting in the confidential medical information of over 500 people being published online.
[15] CISA Alert AA21-265A, updated 9 Mar 2022 (https://www.cisa.gov/uscert/ncas/alerts/aa21-265a)
[16] Wired: “The Workaday Life of the World’s Most Dangerous Ransomware Gang” (https://www.wired.com/story/conti-leaks-ransomware-work-life/)
[17] Checkpoint: “Leaks of Conti Ransomware Group Paint Picture of a Surprisingly Normal Tech Start-Up… Sort Of” (https://research.checkpoint.com/2022/leaks-of-conti-ransomware-group-paint-picture-of-a-surprisingly-normal-tech-start-up-sort-of/)
[18] Medium: “Inside the Conti leaks rattling the cybercrime underground” (https://readme.security/the-conti-leaks-first-rumble-of-the-ukraine-earthquake-thats-rattling-the-cybercrime-underground-7abb23b0fb04)
[19] Security Week: “Conti Ransomware Operation Shut Down After Brand Becomes Toxic” https://www.securityweek.com/conti-ransomware-operation-shut-down-after-brand-becomes-toxic#:~:text=Conti%20Ransomware%20Operation%20Shut%20Down%20After%20Brand%20Becomes%20Toxic,-By%20Eduard%20Kovacs&text=The%20Conti%20ransomware%20operation%20has,affiliation%20with%20the%20Russian%20government.
[20] Avertium: “An In-Depth Look at Ransomware Gang, LockBit 3.0” (https://www.avertium.com/resources/threat-reports/in-depth-look-at-ransomware-gang-lockbit-3.0#:~:text=LockBit%20originally%20targeted%20organizations%20within,losing%20access%20to%20their%20data)
[21] ITWorld Canada: “Russian Ransomware Attacks on Ukraine Faces Major Roadblocks” (https://www.itworldcanada.com/post/russian-ransomware-attacks-on-ukraine-faces-major-roadblocks)
[22] See https://www.varonis.com/blog/alphv-blackcat-ransomware for a comprehensive summary of ALPHV’s history, operations, IOCs, and traditional targets.
[23] Politico: “EU medicines agency says hackers manipulated leaked coronavirus vaccine data” (https://www.politico.eu/article/european-medicines-agency-ema-cyberattack-coronavirus-vaccine-data/)
[24] Insurance Times: “UK Ransomware Attacks Rise by 100% in 2021” (https://www.insurancetimes.co.uk/news/uk-ransomware-attacks-rise-by-100-in-2021-rpc/1440698.article)
[25] Computer Weekly: “UK suffers third highest number of ransomware attacks globally” (computerweekly.com/news/252525466/UK-suffers-third-highest-number-of-ransomware-attacks-globally)
[26] Jumpsec: “UK Ransomware Trends 2022” (https://www.jumpsec.com/uk-ransomware-trends-2022/)
[27] NordLocker: “Ransomware Statistics – Who is Targeted the Most?” (https://nordlocker.com/ransomware-attack-statistics/)
[28] Cl0p are thought to be a Russian-language cybercriminal group responsible for several high-profile ransomware attacks. The group are known for their use of the double extortion technique, with victims who refuse or fail to pay ransoms being named on ‘CL0P^_-LEAKS’ – the group’s Tor-hosted data leak site. Although the group had gone quiet for some time, 21 new victims were named to their data leak site in April 2022. However, there is speculation as to whether these were recent victims or part of a data dump of previously unpublished attacks as part of the group’s shutdown after such an extensive period of inactivity.
[29] IT Governance: “South Staffordshire Water Targeted by Cyber Attack” (https://www.itgovernance.co.uk/blog/south-staffordshire-water-targeted-by-cyber-attack)
[30] Digital Health: “Major outage of multiple health and care systems provided by Advanced” (https://www.digitalhealth.net/2022/08/advanced-major-outage/)
[31] Advanced: “Cyber Incident Summary” (https://www.digitalhealth.net/wp-content/uploads/2022/10/Advanced_Cyber-Incident-Summary.pdf)
[32] BBC News: “Advanced Cyber-Attack – NHS Doctors’ Paperwork Piles Up” (https://www.bbc.co.uk/news/technology-62725363)
[33] TechMonitor: “Internal Data Stolen, Leaked, in REvil Attack on Electricity Market’s Elexon” (https://techmonitor.ai/technology/cybersecurity/elexon-hack-ransomware-revil)
[34] IT Governance: “Cyber attack on UK Defence Academy causes “significant” damage” (itgovernance.co.uk/blog/cyber-attack-on-uk-defence-academy-causes-significant-damage)
[35] ZNet: “Police Federation Hit by Ransomware Attack” (https://www.zdnet.com/article/police-federation-hit-by-ransomware-attack/)
[36] Department for Transport: “Great British Railways – The Williams-Shapps Plan for Rail” (https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/994603/gbr-williams-shapps-plan-for-rail.pdf)
[37] Tech UK: “People, Data and Devices: The Digitalisation Journey of UK Rail Networks” (https://www.techuk.org/resource/people-data-and-devices-the-digitalisation-journey-of-uk-rail-networks-guest-blog-by-vyssion.html)
[38] International Rail Journal: “Italian railway IT system suffers major cyber-attack” (https://www.railjournal.com/infrastructure/italian-railway-it-system-suffers-major-cyber-attack/)
[39] Bridewell: “Cyber Security in Critical National Infrastructure Organisations – 2022” (https://www.bridewellconsulting.com/cyber-security-in-cni-organisations-2022)
[40] Department for Digital, Culture, Media & Sport: “Cyber Security Breaches Survey 2022” (https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2022/cyber-security-breaches-survey-2022#chapter-3-awareness-and-attitudes)
[41] National Cyber Security Centre: “Alert – Critical Risk to Unpatched Fortinet VPN Devices” (https://www.ncsc.gov.uk/news/critical-risk-unpatched-fortinet-vpn-devices)
[42] National Cyber Force Explainer: (https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1041113/Force_Explainer_20211213_FINAL__1_.pdf)
[43] Department for Digital, Culture, Media & Sport: “Proposal for legislation to improve the UK’s cyber resilience” (https://www.gov.uk/government/consultations/proposal-for-legislation-to-improve-the-uks-cyber-resilience/proposal-for-legislation-to-improve-the-uks-cyber-resilience#annex-b-consultation-questions)
[44] CISA: “Critical Infrastructure Sector Partnerships” (https://www.cisa.gov/critical-infrastructure-sector-partnerships)
[45] 2013 National Infrastructure Protection Plan (https://www.cisa.gov/sites/default/files/publications/national-infrastructure-protection-plan-2013-508.pdf)
[46] CISA: “Critical Infrastructure Partnership Advisory Council” (https://www.cisa.gov/critical-infrastructure-partnership-advisory-council)
[47] HSIN is the trusted network for homeland security mission operations to share Sensitive But Unclassified (SBU) information. The Critical Infrastructure community on HSIN (HSIN-CI) is the primary system through which private sector owners and operators, DHS, and other Federal, state, and local government agencies collaborate to protect the Nation’s critical infrastructure. HSIN-CI provides real-time collaboration tools including a virtual meeting space, document sharing, alerts, and instant messaging at no charge.
[48] The CISA Gateway serves as the single interface through which DHS partners can access a large range of integrated infrastructure protection tools and information to conduct comprehensive vulnerability assessments and risk analysis.
[49] The NICC is the 24/7 information coordination and sharing operations center that maintains situational and operational awareness, communication, and coordination among the critical infrastructure public and private stakeholders.
[50] NRMC evaluates the potential consequences of disruptions across the cyber-physical domain through an integrated analytical approach that implements deliverables required by Presidential Policy Directive 21 and Executive Order 13636.
[51] The PCII Program works with government organizations and the private sector to protect critical infrastructure information needed for effective incident management, as well as steady-state operations and preparedness.
[52] PSAs are security subject matter experts strategically deployed across the United States to protect the Nation’s critical infrastructure by providing state, local, tribal, territorial, and private sector partners access to DHS risk-mitigation tools, products, and services and by supporting officials responsible for planning and leading major events. In addition, PSAs support response and recovery efforts to all-hazard incidents through field-level coordination and information sharing.
[53] Department of Homeland Security: “Critical Infrastructure Threat Information Sharing Framework” (https://www.cisa.gov/sites/default/files/publications/ci-threat-information-sharing-framework-508.pdf)