20 Section 3 STRATEGIC CONTEXT The overall cyber risk to an organisation from insider threats is not just about unauthorised access to information systems and their content. The physical security controls protecting those systems from inappropriate access, or removal of sensitive data or proprietary information on different forms of media, are equally important. Similarly, a robust personnel security culture that is alive to the threat posed by disaffected employees, fraud in the workforce and industrial and other forms of espionage is an important element in a comprehensive approach to security. ‘Script Kiddies’ 3.14. So-called ‘script kiddies’ – generally less skilled individuals who use scripts or programmes developed by others to conduct cyber attacks – are not assessed as posing a substantive threat to the wider economy or society. But they do have access to hacking guides, resources and tools on the Internet. Due to the vulnerabilities found in internet-facing systems used by many organisations, the actions of ‘script kiddies’ can, in some cases, have a disproportionately damaging impact on an affected organisation. National Cyber Security Strategy 2016 CASE STUDY 1: TALKTALK COMPROMISE On 21 October 2015, UK telecommunications provider TalkTalk reported a successful cyber attack and a possible breach of customer data. Subsequent investigation determined that a database containing customer details had been accessed via publicfacing internet servers, with the records of approximately 157,000 customers at risk, including names, addresses and bank account details. On the same day, several TalkTalk employees received an email with a ransom demand for payment in Bitcoins. The attackers detailed the structure of the database as apparent proof that it had been accessed. TalkTalk’s report of the breach helped the police, supported by specialists at the National Crime Agency, to arrest the main suspects, all based in the UK, in October and November 2015. The attack demonstrates that, even within large cyber-aware organisations, vulnerabilities can persist. Their exploitation can have a disproportionate effect in terms of reputational damage and operational disruption, and this incident generated substantial media attention. TalkTalk’s rapid reporting of the breach enabled law enforcement to respond in a timely manner, and both the public and government to mitigate the potential loss of sensitive data. The incident cost TalkTalk an estimated £60m and the loss of 95,000 customers, as well as a sharp drop in their share price.

Select target paragraph3