exploitation and increases the potential impact of attacks which have the potential to cause
physical damage, injury to persons and, in a worst case scenario, death.
The rapid implementation of connectivity in industrial control processes in critical systems,
across a wide range of industries such as energy, mining, agriculture and aviation, has created the
Industrial Internet of Things. This is simultaneously opens up the possibility of devices and
processes, which were never vulnerable to such interference in the past, being hacked and
tampered with, with potentially disastrous consequences.
2.2.2 Poor cyber hygiene and compliance
Awareness of technical vulnerabilities in software and networks, and the need for cyber hygiene,
has undoubtedly been ignored due to lack of awareness and initiatives to promote cyber safety,
Cyber-attacks are not necessarily sophisticated or inevitable and are often the result of exploited
– but easily rectifiable and, often, preventable – vulnerabilities. In most cases, it continues to be
the vulnerability of the victim, rather than the ingenuity of the attacker, that is the deciding factor
in the success of a cyber-attack. Businesses and organizations decide on where and how to invest
in cyber security based on a cost-benefit assessment, but they are ultimately liable for the
security of their data and systems. Only by balancing the risk to their critical systems and
sensitive data from cyber-attacks, with sufficient investment in people, technology and
governance, will businesses reduce their exposure to potential cyber harm.
2.2.3 Insufficient training and skills
The lack of skills and knowledge to meet our cyber security needs across both the public and
private sector is a cause for concern. In businesses, many staff members are not cyber security
aware and do not understand their responsibilities in this regard, partially due to a lack of formal
training. The public is also insufficiently cyber aware.
We also need to develop the specialist skills and capabilities that will allow us to keep pace with
rapidly evolving technology and manage the associated cyber risks. This skills gap represents a
national vulnerability that must be resolved.
2.2.4 Legacy and unpatched systems
Many networks continue to use vulnerable legacy systems until their next IT upgrades. Software
on these systems will often rely on older, unpatched versions. These older versions often suffer