Commentary: ASOS ‘hack’ highlights growing cyber threat to major businesses
After ASOS customers received a notification claiming the retailer had been hit by a cyber attack, Dr Daniel Gardham, Lecturer at the Surrey Centre for Cyber Security, explains why large retailers are attractive targets for cyber criminals, why attacks can be so disruptive and what businesses and customers can do to protect themselves.
“Large businesses are attractive targets for cyber attacks because they concentrate huge amounts of valuable data and are often highly dependent on their digital systems. So, an attack can give hackers access to vast amounts of customer information, payment systems or internal data, while also creating significant impact on operations. This creates leverage as the bigger the company, the greater the consequence and, they're hoping, the bigger the financial reward.
“Recent attacks on major retailers and other large organisations have demonstrated the ‘modus operandi’ – cyberattacks are not just about stealing data but threatening significant disruption. The UK government's most recent figures show that 43 per cent of businesses reported experiencing a cyber breach or attack in the past year, rising to 69 per cent among large businesses.
“I expect this to continue, and potentially even become more prolific, because the underlying incentives for attackers haven't gone away. These attacks are also becoming harder to prevent due to the complexity of modern supply chains – a large organisation may have as many as thousands of suppliers or technology providers, meaning attackers can target a weaker third party as a route into a much larger organisation.
“Businesses need to treat cybersecurity as a critical operational issue rather than simply an IT problem. Standard security practice is the first line of defence: that means strong authentication, rapid patching, network segmentation, monitoring, tested backups and, importantly, rehearsing what happens when systems do go down. Customers can also play their part to help prevent an attack on a company from turning into an attack on an individual; this means using unique passwords and multi-factor authentication, being particularly cautious about messages following a major breach, and monitoring accounts for suspicious activity.”
Media Contacts
External Communications and PR team
Phone: +44 (0)1483 684380 / 688914 / 684378
Email: mediarelations@surrey.ac.uk
Out of hours: +44 (0)7773 479911