16 February 2023

How local councils can bolster cyber resiliency

How local councils can bolster cyber resiliency image
Image: Rick Jones is CEO and co-founder of DigitalXRAID.

Local councils are at serious risk of cyberattacks. Providing essential services across the country, councils have experienced rising numbers of breaches as increasing digitalisation has expanded the attack surface available for exploitation by bad actors. In fact, UK councils suffered 10,000 attempted cyberattacks every day in the first half of 2022.

The attack on Gloucester Council in December 2021 is a prime example of how much damage can be inflicted by a successful cyberattack and the long-lasting impact of the disruption caused – systems still weren’t fully operational eight months later. The good news, however, is that improving cybersecurity and mitigating against attacks does not have to be complex nor costly. But what is key for councils is to fully engage in the process and go beyond minimum requirements where possible.

Establishing the essentials

As vital public bodies, local councils are under particular pressure to demonstrate the strength of their cybersecurity via a regular, legally required IT Health Check (ITHC), as set out by the National Cyber Security Centre (NCSC). A full ITHC is a crucial part of a security strategy as it reviews and provides assurance over the security of key infrastructure systems and services. However, there is a tendency for the process to be treated like a tick-box exercise.

Local councils often lack sufficient in-house cybersecurity expertise and operate on extremely tight budgets, meaning it can be difficult to dedicate the time and resources necessary to go beyond the ITHC and adopt best practice across the organisation. However, there are a number of measures that can help strengthen councils’ cybersecurity strategies and ensure more holistic protection.

For Wiltshire Council, this meant engaging with a new testing partner that was part of the CHECK scheme. Choosing to work with an experienced third party helps councils identify areas to include in the ITHC to exceed the NCSC guidelines and improve on results from previous years. This was a key aim for Wiltshire, as a forward-thinking and innovative council with a vision to build stronger communities with core values that underpin what it does daily.

Both internal and external testing was conducted to evaluate Wiltshire Council’s IT posture and understand any potential security gaps. Working closely with their security partner throughout the scoping process meant Wiltshire received advice on what should be included in the ITHC on top of the NCSC’s guidelines, going beyond the basics. The council was made aware of what testing was being actioned at each stage of the process, understood what next steps were being taken, and received clear and detailed reporting to outline any vulnerabilities identified.

As a result, Wiltshire Council received approval from the Cabinet Office with no issues or checks needed. Greater detail in their report provided the council with a deeper understanding of any risk exposure, while the IT department was able to set out a remediation plan to address gaps identified.

Proactive protection

In addition to ITHCs, there are numerous proactive measures local councils can implement to further bolster their security posture. Considering a recent report found that phishing attacks are the biggest threat to UK councils, with 75% stating it was the most common threat vector attempted against them, adopting a ‘security-first’ mindset across the whole organisation is crucial. Often non-security personnel can fall into the trap of thinking security isn’t their responsibility. And yet, one staff member clicking one malicious link in a phishing email can be all it takes to launch a successful cyberattack. Councils should therefore be considering regular phishing training and simulations for all staff to help instil the importance of keeping cybersecurity front-of-mind.

Another important element of cybersecurity best practice is maintaining good cyber hygiene. This should comprise elements like strong encryption, privilege access management and multi-factor authentication (MFA) to deepen defences and help prevent a hacker from accessing sensitive information if they gain access to a council’s environment.

Conducting frequent vulnerability scans and penetration testing also helps to go beyond the legal ITHC requirement and provide more holistic protection. These identify any security weaknesses and potentially exploitable vulnerabilities across systems and networks, giving organisations the chance to remediate gaps in their security posture. Because an ITHC only provides a snapshot of a council’s cybersecurity posture at the time it takes place, it’s important to be conducting cyber risk assessments year-round to uncover any other security deficiencies.

Looking ahead

Unfortunately, the threat landscape continues to expand. Hackers are growing in sophistication and all industries are at risk. For local councils who provide essential services 24/7/365, it’s critical to avoid treating cybersecurity as a tick-box exercise, and follow the example set by Wiltshire Council of going beyond the basics and engaging with it as a core element of day-to-day business. While this may initially appear complex and costly, investing in going beyond the bare minimum will prove hugely valuable long-term.

Rick Jones is CEO and co-founder of DigitalXRAID

Selling the family silver image

Selling the family silver

Ryan Swift, research fellow at IPPR North, urges the next Government to stop the mass sell off of council assets.
SIGN UP
For your free daily news bulletin
Highways jobs

Senior Social Worker

Wakefield Council
£40,221.00 - £43,421.00, Grade 10, 37 hours, Permanent
Community Mental Health Senior Social worker (level two) post at Baghill House Pontefract. Baghill House, Health & Wellbeing Centre, Walkergate, Pontefract, WF9 1QW
Recuriter: Wakefield Council

Senior Social Worker

Wakefield Council
£40,221.00 - £43,421.00, Grade 10, 37 hours, Permanent
An exciting opportunity has arisen for a full time (37 hour) senior social work position within Connecting Care East. Castleford Civic Centre, Ferrybridge Road, Castleford, WF10 4JH
Recuriter: Wakefield Council

Senior Care Assistant (Days)

Wakefield Council
£21,422.43 - £23,731.62, Grade 6, 30 hours, Permanent
Dovecote lodge is a short term placement unit which support the hospital with admissions, predominantly from the emergency department. Dovecote Lodge Dovecote Lane Horbury Wakefield West Yorkshire WF4 6DJ
Recuriter: Wakefield Council

Complex Needs Support Worker

Wakefield Council
£19,697.84 - £21,064.05, Grade 5, 30 hours, Temporary
Dovecote Lodge currently has a vacancy for a 30 hour complex support worker, the rota includes days, afternoons and nights over a 10 week period. Dovecote Lodge Dovecote Lane Horbury Wakefield West Yorkshire WF4 6DJ
Recuriter: Wakefield Council

Multi Skilled Operatrive x4

Wakefield Council
£22,737.00 - £29,269.00, Career grade 3-6, 37 hours, Permanent
We are seeking enthusiastic and capable colleagues to join our Highway Operations team that forms part of the Highway Network Management. Wakefield, West Yorkshire
Recuriter: Wakefield Council
Linkedin Banner

Partner Content

Circular highways is a necessity not an aspiration – and it’s within our grasp

Shell is helping power the journey towards a circular paving industry with Shell Bitumen LT R, a new product for roads that uses plastics destined for landfill as part of the additives to make the bitumen.

Support from Effective Energy Group for Local Authorities to Deliver £430m Sustainable Warmth Funded Energy Efficiency Projects

Effective Energy Group is now offering its support to the 40 Local Authorities who have received a share of the £430m to deliver their projects on the ground by surveying properties and installing measures.

Pay.UK – the next step in Bacs’ evolution

Dougie Belmore explains how one of the main interfaces between you and Bacs is about to change.