High profile cyber incidents of 2024: The fallout and lessons learnt. 

High profile Cyber incidents of 2024

Data breaches, cyber incidents and cybersecurity attacks remain a common threat for UK businesses in 2024. According to a survey carried out by the National Cyber Strategy at the end of 2023, 50% of business and around a third of charities report having experienced form of cybersecurity breach in the last 12 months. That equates to around 8,000 attacks per year. 

Based on Mimecast’s State of Email Security Report for 2023, the threat of cyber incidents is now one of the most important global risks to businesses, not only affecting organisations financially but impacting customer trust and brand reputation.  

We explore some of the high-profile cyber incidents in the UK from 2024 so far and how the companies affected handled the fallout and what lessons can be learned for future cybersecurity failings.    

 

CrowdStrikeglobal IT meltdown 

Although CrowdStrike is an American cybersecurity firm, it became an internationally recognised brand for all the wrong reasons last month, after a faulty software update led to potentially one the of largest global IT outages in history.  

UK businesses were impacted for several days including flights being grounded, payment systems compromised at supermarkets and IT disruption across GPs and pharmacies postponing appointments.  

 

How did CrowdStrike respond? 

As soon as the news of the outage broke, CrowdStrike’s CEO George Kurtz appeared on morning TV to explain the current situation and answer questions from the media.  

Throughout the crisis, CrowdStrike tried to regain customer trust by issuing statements and detailed explanations of the causes and measures taken to prevent future outages. Only this week they released the reasons behind the global IT breakdown 

One response that didn’t go to plan was the offer of $10 Uber Eats gift cards to contractors that helped to manage the crisis. News spread across social media that the gift card offer was for anyone that was affected by the outage, not just the contractors. CrowdStrike had to quickly respond to clarify who the gift cards were for, causing them another communications headache for them to react to.    

 

Lessons learnt 

  • Transparency and timely responses are vital during a crisis. Keeping stakeholders, clients, partners and investors up to date with accurate information in real-time is crucial for businesses to plan their responses accordingly and maintains trust in the CrowdStrike brand.  
  • Appropriate responses are required. The offer of the Uber Eats voucher faced heavy criticism leading to only more reputation management for CrowdStrike. Instead, it may have been a better option for CrowdStrike to stay fully focused on keeping stakeholders updated on the situation and apologising for the disruption caused. 
  • Planing. The CrowdStrike meltdown reminds us of the importance of having a crisis comms plan in place and making sure it is communicated to all employees and partners at all levels to ensure everyone understands their roles when things go wrong.  

 

 

Synnovis cyber attack 

At the start of June, NHS England had to react quickly when Synnovis, a pathology laboratory, which processes blood tests on behalf of NHS organisations was the victim of a cyber-attack. The attack forced around 1,100 operations to be postponed and impacted levels of blood supply, with NHS England London putting out an emergency call for O positive and negative blood donations.  

 

How did Synnovis and NHS England respond? 

The healthcare body released a statement on its website which outlined the news and answered key questions for patients in the South London area who were worried about their personal data being compromised.  

 

Lessons learnt

  • Preparation. Interestingly after the news of the breach broke, it was claimed that NHS England had flagged to Synnovis for some time that it was worried about an attack happening. So, could this crisis have been avoided? Andrew Whaley, Senior Technical Director of Promon, sees this as the final wake-up call for the healthcare industry: “Being in a situation where patients can’t receive life-saving blood transfusions because the hospital isn’t equipped to defend against cyber-attacks is simply unacceptable; the NHS is in critical condition without the threat of cyber warfare. Never should a healthcare organisation which cares for millions of people find itself struck down and unable to serve its primary function (saving lives) due to an IT issue.”  

 

BBC Pension scheme breach 

The BBC found itself being the lead story back in May, when around 25,000 past and present employees were affected by a data leak of their pension scheme which saw personal details such as names, National Insurance numbers, dates of birth and home addresses exposed.  

 

How did the BBC respond? 

The BBC apologised and wrote to pension scheme members to assure them that there was no evidence that the affected files had been misused and the situation was being closely monitored. The email warned those affected to remain vigilant for unsolicited and unexpected communications that request personal details.  

The BBC also encouraged employees to enable two-factor authentication to protect their accounts and offered 24 months of credit and web monitoring with Experian 

 

Lessons learnt  

  • Education. The BBC took the interesting step to provide advice to its employees on how to secure their data, is this the answer? The public are more aware of cyber-attacks and perhaps education from companies on how to protect their data will retain trust, so when a strike does happen, they know they have taken the precautionary steps needed and so have the company in question.  

 

As with any crisis there will always be criticisms and lessons to be learnt. The ever-evolving cybersecurity landscape is getting more challenging for companies across all sectors to navigate. With future threats coming from AI-powered attacks, it is even more essential for businesses to invest in the necessary security measures and response planning, through regularly updating their crisis communications plan, preparing staff through ‘fire drill’ training and making sure senior management are media trained ready to respond to any fallout from the crisis. If they don’t, they risk reputational damage which can be just as far reaching as the financial losses.