Skip to main content

Experts challenge myths around reporting cyber attacks to help break cycle of crime

Blog post from the NCSC and ICO aims to dispel common misconceptions that can discourage organisations from reporting a cyber attack.

image credit: istock.com/Golden Sikorka
  • A blog post from NCSC and ICO aims to dispel common misconceptions that can discourage organisations from reporting a cyber attack
  • NCSC and ICO are concerned about incidents going unreported, which denies organisations the opportunity to learn from them and prevent future attacks
  • Advice on best practice offered to help organisations understand their responsibilities and the risk to their data and reputation.

Leading cyber security experts are pressing organisations to be more open about their experience of cyber attacks, to encourage reporting and prevent future incidents.

In a new joint blog post, the National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO) identify six misconceptions that can discourage organisations from reporting attacks, particularly ransomware attacks, and is setting out to dispel them.

The misconceptions include the mistaken belief that reporting cyber attacks to the authorities makes it more likely the incident will become public, and that paying a ransom automatically makes the incident go away.

With cyber attacks continuing to cause significant disruption, the NCSC and ICO are concerned about incidents which go unreported because every 'hushed up' case that isn't shared or fully investigated makes other attacks more likely as no one can learn from them.

But being open with the authorities will give victims access to expert support and advice, and will be taken into account favourably by the ICO when considering their regulatory response.

The six ‘myths’ which the NCSC and the ICO have identified as commonly held by organisations that have fallen victim to cyber incidents are:

  1. If I cover up the attack, everything will be OK
  2. Reporting to the authorities makes it more likely your incident will go public
  3. Paying a ransom makes the incident go away
  4. I’ve got good offline backups, I won’t need to pay a ransom
  5. If there is no evidence of data theft, you don’t need to report to the ICO 
  6. You’ll only get a fine if your data is leaked

Eleanor Fairford, NCSC Deputy Director for Incident Management, said:

“The NCSC supports victims of cyber incidents every day, but we are increasingly concerned about the organisations that decide not to come forward.

“Keeping a cyber attack secret helps nobody except the perpetrators, so we strongly encourage victims to report incidents and seek support to help effectively deal with the fallout.

“By responding openly and sharing information, organisations can help mitigate the risk to their operations and reputation, as well break the cycle of crime to prevent others from falling victim.”

Whilst the NCSC, as the national technical authority on cyber security, and the ICO, as the national data protection regulator, have different functions, both organisations work with victims of cyber incidents every day and have seen a wide range of incident responses.

Mihaela Jembei, ICO’s Director of Regulatory Cyber, said:

“It’s crucial that businesses are aware of their own responsibilities when it comes to cyber security. The fact remains that there is a regulatory requirement to report cyber incidents to the ICO, but transparency is more than simply complying with the law. Cyber crime is a borderless and global threat and it’s through knowledge sharing that we can help organisations help themselves.

“It’s also really important that businesses do not lose sight of their basic cyber hygiene practices in a world where we are always hearing about new and exciting technologies and the risks they may pose.”

Victims that are proactive with reporting can benefit from expert NCSC advice and following this can positively impact the ICO’s response.

The blog post also addresses assumptions about data risk, highlighting that a lack of evidence that data has been stolen does not mean theft did not take place, while paying a ransom to criminals to restore services quickly can increase the likelihood of being retargeted and does not guarantee stolen information will not be leaked later.

The NCSC and ICO recommend that victims are open in the aftermath of an attack, reporting incidents via the government’s cyber reporting service and separately to the ICO to fulfil regulatory responsibilities. They also encourage sharing lessons learned with other organisations to help improve wider awareness and cyber resilience.

More guidance on how to effectively detect, respond to and resolve cyber incidents can be found on the NCSC website, including dedicated advice on handling ransomware attacks.

The NCSC is not a regulator; it provides support to victim organisations in confidence and does not share information about an incident with the ICO without an organisation’s consent. Victim organisations should report breaches to the ICO.

Read the joint blog post between Eleanor Fairford and Mihaela Jembei