Streamline your cloud experience and maximise your cloud investment with Microsoft Azure-aligned public cloud services.
Host all of your workloads in the most appropriate location while experiencing the simplicity of one cloud from Six Degrees.
Enhance your cyber security and safeguard your organisation with our cyber security strategy and advisory, consultancy, and managed services.
Connect your business through a comprehensive connectivity portfolio delivered via our owned and operated core Next Generation Network (NGN).
Secure your productivity on any device, anywhere, any time.
Streamline your hosting with comprehensive colocation services delivered from three UK data centres.
Gain clarity and control of your 5G estate, ensuring ongoing cost efficiencies are managed on your behalf through our managed service.
Gain confidence in your cloud direction and achieve accelerated time to value through our assured and optimised cloud services.
Master today’s complex threat landscape and protect your business with our intelligence-led security services.
Videos and webinars are a great way to digest the latest technology insights.
Our eBooks and whitepapers provide in-depth insights from our experts.
Our thought leaders publish regular blogs on up-to-the-minute topics.
Learn all about the latest news from Six Degrees as we continue to evolve.
We host regular in-person and virtual events for our clients.
Discover how Six Degrees has driven success for others.
Learn how we enable our clients to achieve more; providing superior secure solutions, powered by our passionate people.
We are proud to partner with many of the world’s leading vendors, enabling you to leverage our continual investment in difference-making technology.
Learn how CNS at Six Degrees delivers intelligence-led security services that protect organisations in today’s hostile landscape.
We are committed to operating in an environmentally and socially conscious way. Learn more about our commitments as a business.
We are proud of our secure cloud credentials. Learn why we’re one of the most highly accredited providers in the UK.
We are a friendly and passionate bunch here. Whether you want to work with us or for us, we think you’ll enjoy the Six Degrees experience.
Home » Blogs » What to Do When the Worst Happens: Addressing and Recovering from a Cyber-Attack
It’s no longer just death and taxes that are inevitable – all businesses need to come to terms with the reality that they will be targets for cyber-attacks. And once you’ve accepted that your business will be the target of a cyber-attack not once but continually, it’s safe to assume that eventually one will be successful. What then?
IBM’s Cost of a data breach 2022 report stated that the global average cost of a data breach was $4.35 million. This figure alone should make any business pause for thought – especially if their approach to date has been to bury their head in the sand.
In our most recent Cyber University seminar we explored what to do when the worst happens and an organisation is impacted by a successful cyber-attack. This blog summarises six key take homes from the day.
A fallacy used to pervade that if businesses could fly under the radar they could stay out of cybercriminals’ crosshairs. This could lead to a degree of complacency when it came to implementing appropriate cyber security arrangements.
Any complacency this fallacy feeds is dangerous. Anonymity is not an effective deterrent against a potential attacker – in fact, as we explored in a recent blog, cybercriminals are increasingly setting their sights on smaller businesses precisely because they believe their cyber security postures are less robust than those of larger enterprises.
If you invest sufficiently in your security incident response readiness, you will give your business the best possible chance of reacting effectively to a cyber-attack. During the seminar our Principle GRC Consultant Mark Arcatinis explained the importance of adopting a three phased approach:
Our Head of Cyber Security Assurance Michele Peroli ran the delegates through some real-life examples of how preparedness makes a huge impact on our Cyber Incident Response Team’s ability to deliver effective support to businesses when they are hit by a cyber-attack.
Effective cyber security preparedness is all about prioritising efforts towards where cybercriminals may seek to attack you. Like all organisations, you will be targeted through phishing emails and ransomware attacks. But other methods may well be unique to the industries you operate in.
The MITRE ATT&CK® framework is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. By using the framework, you can triangulate which hacker groups are targeting your industry and the attacks they are using – give you useful intelligence around areas of your cyber security posture you should prioritise.
When your business is hit with a cyber-attack and you need to respond, time is of the essence. Get bogged down in too much bureaucracy, and you risk allowing the attack to spread and worsen when a more streamlined approach would have minimised the damage caused.
During the seminar our Cyber Security Assurance Technical Director Andy Swift explained how creating a small, efficient working group and empowering it to make rapid decisions as an incident evolves is an important aspect of an effective incident response. Nominated senior decision makers should be part of this group – minutes lost escalating decisions can be critical.
Every crisis is unique. The response to every crisis will turn on the facts – how many customers are impacted, what the wider implications are, what you know, what you don’t know, and even what you don’t know you don’t know. This can make it blurry. But the general rules of responding to a crisis are the same. And actually, when you take a step back, they are mostly common sense.
Hannah Sobolewski, Account Director at Touchdown PR, explained to delegates how crisis communications can be separated into three stages:
In the final session of the seminar, our Chief Product and Technology Officer Phil Wood shared first-hand experience of responding to a cyber-attack. One of his insights was around the psychological effects a cyber-attack can have on employees – especially those involved directly in IT and cyber security.
Cyber incidents can elicit a great deal of guilt and anxiety in employees who feel that they are somehow to blame for letting the incident happen. Engage them early on, with the support of your HR department, to reassure them that the business is not trying to apportion blame; their jobs are not at risk; and that the focus is purely on control and recovery.
This is incredibly important messaging to share with them that will not only improve their mental wellbeing but also make them more impactful allies in the business’ journey to recovery.
The cyber security landscape is constantly evolving, with new risks emerging all the time. By accepting that cyber incidents will happen and investing time to prepare ourselves for when they do, we will reduce the cyber security risks we face both as individuals and together as organisations.
Cyber University is an ongoing series of seminars. Register your interest in joining the Cyber University for free here.
Spend five minutes in the cyber security world,…
Last week Six Degrees held its first ever…
Phishing and Ransomware Survival Guide 2023 In the…
More information on our Privacy and Cookies Policy can be found here: https://www.6dg.co.uk/privacy-cookies/. You can update how we contact you in the future by visiting our Communications Preference Centre here: https://www.6dg.co.uk/preference-centre/.