UK National Cyber Security Centre (Part of GCHQ) Issued A Threat Report Regarding Targeted Attacks Against UK Legal Sector

Date Posted:Wed, 11th Sep 2024

UK National Cyber Security Centre (Part of GCHQ) Issued A Threat Report Regarding Targeted Attacks Against UK Legal Sector

This is an excellent report, and contains great advice on how to protect against such attacks. It’s 24 pages long, and quite dry, but here’s our take on it.

 

1) It’s not just the UK legal sector being targeted – this is a global issue affecting other sectors including Accounting, Healthcare, Engineering, Construction, Hospitality, and Education.

2) The advice isn’t anything new or specific to the legal sector.

3) Confidentiality (therefore trust) and money is at stake.

Summarized below is the advice from the report, and how we and our partners can help:

The above looks pretty complicated, but it’s not really that difficult or expensive to implement, and can be done in stages at a pace that works for your business, and doesn’t cause operational issues for the business.

We would consider the above recommendations to be the absolute minimum steps that you should be implementing to help protect your business, but it’s a good starting point. Our policies and procedures will take you beyond the above recommendations.

For all businesses, the first step should always be an assessment, then start working on reducing risk as transparently as possible.

Typically, these will include:

- Implement Mail Aegis.

- Implement MFA across all platforms.

- Implement a Systems Management and XDR platform.

- Implement recommended policies and procedures.

- User Awareness/Training

- Supply Chain mapping & associated security audit/validation.

Our policy is to work with your existing IT team or IT services provider, and where there are gaps, make recommendations on how to fill them.

We don’t provide any public customer references, or publicly share which resellers we work with due to confidentiality and security reasons, however these can be provided on request and agreement of all concerned parties.

If you already work with an IT services supplier, we can work directly with them where they can resell our service, retaining simplicity for your business, both from a billing and support perspective.

Contact us at [email protected] 

Click here to review the UK National Cyber Secuirty Centre (Part of GCHQ) report