20
Section 3
STRATEGIC CONTEXT
The overall cyber risk to an organisation
from insider threats is not just about
unauthorised access to information
systems and their content. The physical
security controls protecting those
systems from inappropriate access, or
removal of sensitive data or proprietary
information on different forms of media,
are equally important. Similarly, a robust
personnel security culture that is alive
to the threat posed by disaffected
employees, fraud in the workforce
and industrial and other forms of
espionage is an important element in a
comprehensive approach to security.
‘Script Kiddies’
3.14. So-called ‘script kiddies’ – generally
less skilled individuals who use scripts
or programmes developed by others to
conduct cyber attacks – are not assessed
as posing a substantive threat to the
wider economy or society. But they do
have access to hacking guides, resources
and tools on the Internet. Due to the
vulnerabilities found in internet-facing
systems used by many organisations, the
actions of ‘script kiddies’ can, in some
cases, have a disproportionately damaging
impact on an affected organisation.
National Cyber Security Strategy 2016
CASE STUDY 1: TALKTALK
COMPROMISE
On 21 October 2015, UK
telecommunications provider TalkTalk
reported a successful cyber attack and
a possible breach of customer data.
Subsequent investigation determined
that a database containing customer
details had been accessed via publicfacing internet servers, with the records
of approximately 157,000 customers at
risk, including names, addresses and
bank account details.
On the same day, several TalkTalk
employees received an email with a
ransom demand for payment in Bitcoins.
The attackers detailed the structure of
the database as apparent proof that it
had been accessed.
TalkTalk’s report of the breach helped
the police, supported by specialists at
the National Crime Agency, to arrest the
main suspects, all based in the UK, in
October and November 2015.
The attack demonstrates that, even
within large cyber-aware organisations,
vulnerabilities can persist. Their
exploitation can have a disproportionate
effect in terms of reputational damage
and operational disruption, and this
incident generated substantial media
attention. TalkTalk’s rapid reporting of
the breach enabled law enforcement
to respond in a timely manner, and
both the public and government to
mitigate the potential loss of sensitive
data. The incident cost TalkTalk an
estimated £60m and the loss of 95,000
customers, as well as a sharp drop in
their share price.