Disruptive cyber attacks – reducing their impact, reducing the risk
How to recover your organisation, be better prepared for future incidents and make them less likely.
Pages
Page 13 of 16
2. Reducing exposure to attack
A cyber attack can start from many different entry points. Reducing your attack surface makes it harder for attackers to gain an initial foothold. This section outlines measures to achieve this.
2.1 Establish baseline cyber security practices
A strong foundation starts with applying baseline cyber security practices. Frameworks such as Cyber Essentials or the Cyber Assessment Framework (CAF) provide a structured way of reducing common risks of attack, such as:
- securing configurations
- managing access
- keeping systems up to date
2.2 Reducing common entry points
Cyber security teams should ensure that common attack routes are being addressed. Table 1 shows some of the common techniques attackers use to gain entry to a network, and the relevant NCSC guidance to help prevent or mitigate them.
| Common ways an attacker can gain access to your network | Relevant NCSC guidance |
|---|---|
2.2.1 Using stolen credentials Attackers often use compromised usernames and passwords to gain access to systems. |
|
2.2.2 Finding an exploitable vulnerability Attackers gain unauthorised access by exploiting vulnerabilities or insecurely configured services that are exposed to the internet. |
|
2.2.3 Targeting forgotten or unknown systems Attackers can gain entry via systems you aren’t monitoring or even aware of. |
|
2.3 Encourage reporting and early detection
Early reporting increases your chances of identifying and stopping attacks before they escalate. People across the organisation are likely to be the first to notice signs of an attack, so you should ensure they can report issues easily. To support this, you should:
- provide clear and simple reporting mechanisms
- promote a culture where reporting of suspicious activity and mistakes is both expected and supported