Latest News

  • Home /
  • Latest News

Mitigo: Cybersecurity in a year of crisis

25 November 2020
A must read for all IFAs, their leaders and everyone responsible for security and business resilience

When this year has seen a global pandemic, urgent concerns about climate change, and the uncertainty of Brexit consume much of our lives, TV and the press, some business leaders may have taken their eye off the growing threat posed to businesses in general – and financial services firms in particular – by the proliferation and increasing sophistication of cybercrime.

The emergence of new and disturbingly effective methods of cyberattack during the last 12 months only serve to demonstrate the ingenuity of the criminal gangs responsible, and why your cyber risk controls may well no longer be secure. As methods of attack continue to evolve – and they most certainly will - so must our defences and controls.

A doubling of opportunities for ransomware

One of the most frightening forms of attack, ransomware can leave firms operationally crippled, waste senior management time, and seriously damage or even destroy client relationships. It has been estimated that the average downtime (i.e. material business disruption) following an attack is now 19 days.

Previously the malware usually got into your system when someone clicked on a link, letting in the ransomware that automatically found data and files to encrypt. Now, criminals can automatically scan firewalls, looking for ports and vulnerabilities to gain access. And with so many people currently working remotely on poorly configured connections and devices, they are hitting the jackpot.

Worse still, the way the attack progresses has also changed. Once you’ve been breached, the bad guys no longer just go straight to the encryption stage. They often take their time examining confidential client and proprietary data.

Then they steal the material they think will cause you maximum pain if it’s made public. Which gives them two ransom opportunities. First, they demand payment for the decryption key. Next, they threaten to release publicly, piece by piece, the confidential data they’ve stolen about you and your clients. Unless, of course, you pay up.

The critical thing to understand here, is that even if you have perfectly configured backups (which we rarely see), they will still not be enough to protect you and your clients. No surprise, then, that amounts demanded as ransom, and the amounts actually being paid out, have shot up. You need seriously to consider additional protection.

Multi factor faking

Another thing that’s evolved is how very easily people can sign into and misuse your email account.

A while ago, crooks would usually get hold of your email address and password via phishing attacks or by buying your credentials on the dark web. Then they could login, send and receive emails as if they were you, spy on your mail, steal information, divert payments and so on.

Office 365 Multi factor authentication (MFA) was designed to put a stop to this, preventing anyone else from logging into your account unless they had second factor authentication, usually a code sent by text to your mobile phone. But not any more.

2020 has seen new ways of getting around MFA.  Notably, fraudsters can now accurately mimic the 365 login page. So you think you’re typing into Office 365, but in fact, it’s a fake cover page. Which automatically inputs your credentials into the real Office 365 page, except on the fraudster’s computer.

When the text with the code comes through to your mobile, you do the same - why wouldn’t you? And the criminals have successfully logged in as you. Free to do what they want. And when they’ve enabled the optional 60 day validity period, they’ve given themselves 60 days’ access.

The growth of the criminal ecosystem

Of all the many routes there are to cyber attack businesses, the exponential growth of ransomware is arguably the most telling. So let’s pick up the story again and take a look at where it’s heading. This is a high stakes game, and given the kind of data held, financial services firms are at existential risk.

So why the rapid growth? Well, it’s becoming more easily achievable. It can be hugely profitable. And the chances of criminals being brought to book are almost non-existent.

Attack tools are now freely available, as are low cost Ransomware as a service (Raas) kits. So aspiring cyber crooks no longer need high levels of technical knowledge to get involved. Affiliate ransomware platforms offering Raas provide easy market entry, and especially with more remote working, ample opportunity for good returns.

At the same time, there has been an increase in so called ‘big game hunting’ – the process we mentioned earlier - where more thoughtful and focussed attacking gangs more closely examine the opportunities that successful breaches provide for financial gain, whether by theft of money or by high value ransom.

Lower ranking criminals add to the risk, using the Raas model to function as ‘lead generators’, earning a cut or commission by passing on the opportunity to the big boys, who will be better able to fully exploit the financial blackmail potential of the breach.

The cost of ignoring the problem

Ransom inflation, as we indicated, is compounding the problem. Research suggests that by Autumn 2020, the average ransom being paid was $233,000 (approximately £177,000), rising sharply for larger organisations.

This is no surprise: the crippling business disruption, combined with the exfiltration of high value data (the ‘steal then encrypt’ model), results in criminals having much greater negotiating power over their victims. So that firms feel under greater pressure to give way to ransom demands to prevent their own and their clients’ confidential data from public release, even when system recovery from backups is possible.

From the attacker’s business perspective, the ransomware to payment ‘conversion rate’ has gone up very substantially, including for the smaller Raas players who are also now seeking higher ransom returns.

A market that’s here to stay

Given the amounts of money involved, the sophistication of organised cybercrime gangs shouldn’t come as a shock. This is a thriving market. And like any successful business, these operations now have their own PR machines, with websites and press releases announcing breaches, naming names, and the theft of data – threatening to make it public, if ransoms aren’t paid.

This market, again, like any other, has its own dynamics. And analysis shows that the ‘market share’ of different ransomware players and affiliate programmes has changed throughout the year. Big players like Sodinokibi (aka REvil), Maze and Phobos saw their share of total attacks go down due to the incursion of smaller players and the emergence of new entrants to the market.

This speaks to two somewhat disturbing issues. One that this is an established market that is not going to go away. And two, that the proliferation we spoke of is accelerating.

The critical concerns of the FCA

The rise in the volume and sophistication of cyber attacks in the sector and the accompanying threat to business operations are of increasing concern to the FCA.

A relatively large proportion of all incidents reported to the FCA now relate to cyber attacks, with disruption from cybersecurity incidents one of the biggest challenges to operational resilience.

Effective cybersecurity is not just a technology issue. Rather, the biggest vulnerability lies in the day-to-day practices of people. So effective configuration of technology must be accompanied by proper training and effective policies and controls.

Firms should also question their reliance on third party IT providers to provide security. And a big concern is that many firms are still not taking the right steps to test or audit their policies, processes and systems, which should be reviewed regularly, by someone independent.

All regulated firms are expected to have appropriate cyber risk management in place and a “security culture” from the Board down. Firms should bear in mind that, even in the absence of cybersecurity being specifically allocated in an SM’s statement of responsibilities, ultimately, responsibility will fall on the firm’s CEO/ Partners, on the basis of their overriding responsibility to run the business in accordance with proper governance and risk management principles.

Successful cyber attacks are now happening with increasing frequency against firms of all sizes. Leaders have a responsibility to satisfy themselves that the right measures are in place and regularly reviewed to protect the firm, their partners and clients. They should not be relying on generalist IT support. Savvy leaders already know this.

Paradigm has partnered with Mitigo to offer technical and cyber security services to our members. 

Take a look at Mitigo’s full service offer at https://www.consultparadigm.co.uk/strategic-partners/mitigo 

For more information contact Mitigo on 0161 8833 626 or email [email protected] 

 

 

2 December 2025

Intelliflo- The new outsourcing: why advice firms are increasingly turning to technology


10 November 2025

Retirement Planning: Blending certainty with opportunity


5 November 2025

Blending Drawdown and Annuities: A Modern Approach to Retirement Planning


30 October 2025

Trick or treat? Dispelling the myths about AI in advice


24 September 2025

Simplify retirement advice with one solution


23 September 2025

What do F1 teams and advice firms have in common?


20 August 2025

Delivering peace of mind in an age of uncertainty


18 August 2025

The Prudential Guaranteed Income Plan


21 July 2025

intelliflo's 2025 advice efficiency survey


14 July 2025

The Prudential Guaranteed Income Plan


3 July 2025

Where does PruFund invest across the Globe?


23 June 2025

Pudential - New interactive PruFund client videos are live!


19 June 2025

intelliflo innovate 2025: welcome to tomorrow


19 May 2025

Four essential insights from intelliflo’s 2025 eAdviser index


7 May 2025

Prudential - Where PruFund invests in the UK


10 April 2025

Intelliflo - Bridging the gender advice gap


12 March 2025

intelliflo’s 2025 Advice Map of the UK


5 March 2025

Defaqto - BREAKING: New exclusive Member offers for Defaqto Engage


4 March 2025

Prudential - The growing appeal of insurance bonds, tax efficient strategies and the fast approaching TYE


3 March 2025

Paradigm Powerhouse: Celebrating Our Team's APCC Success!


17 February 2025

The future of advice tech: Five key trends for 2025


27 January 2025

What does 2025 hold for AI in financial advice?


13 January 2025

Happy New Tax Year End


30 December 2024

An evolving industrial landscape: post-election insights from the US


30 December 2024

The outlook for 2025


10 December 2024

Beyond the Budget – Unpacking IHT changes for your clients


4 December 2024

Triple Point Venture VCT - Early bird discount extended


3 December 2024

A Postcard from Boston: Onshoring, AI and the regulation of water


3 December 2024

The second Nucleus UK Retirement Confidence Index


25 November 2024

Investing alongside science to deliver a sustainable world


11 November 2024

Triple Point - What Budget changes to Business Relief mean for clients


4 November 2024

Edwards Lifesciences: shaping the future of cardiac care


28 October 2024

Gene therapy is set to change the face of medicine


22 October 2024

What China’s economic stimulus measures could mean for investors


16 October 2024

Triple Point - Venture VCT announces 2p tax-free dividend


7 October 2024

Triple Point - VCTs: a powerful way to help clients pay less income tax


2 October 2024

The next smart move for your clients


26 September 2024

Puma VCT 13 launches new £50m fundraise


24 September 2024

3 steps advisers can take to close the gender pension gap


19 September 2024

Puma Investments- Launches Puma AIM VCT


18 September 2024

M&G Wealth - Six ways to keep clients invested for long-term success


10 September 2024

M&G Wealth - Dash to cash: why it pays to think longer-term with your client’s money


6 September 2024

Join the Defaqto Future of Advice conference


2 September 2024

Triple Point - Understanding Venture Capital Trusts (VCTs)


28 August 2024

M&G Wealth - Keeping it smooth since 2004


19 August 2024

Prudential - Cost reductions and changes to our Strategic Asset Allocation


15 August 2024

Liontrust - Building a sustainable future with social housing


15 August 2024

Puma Investments - Join our CPD webinar: Closing the gaps: IHT and Estate planning featuring Tony Wickenden


7 August 2024

Liontrust - Plugging into the energy transition


6 August 2024

Defaqto - The Future of Advice - The Defaqto Adviser Conference


26 July 2024

Hello Kitty: A big cat in the investment universe?


24 July 2024

Liontrust – A postcard from Japan: enabling the sustainable transition


18 July 2024

Liontrust - Does a brighter future for housebuilding lie ahead?


16 July 2024

Triple Point – Holistic Estate Planning Strategy for Clients


8 July 2024

Triple Point – Join our CPD webinar: helping investors plan for big life events


1 July 2024

Intergenerational wealth planning for difficult times


24 June 2024

Liontrust Sustainable Investment: Annual Review 2023


19 June 2024

Investing in the energy transition


18 June 2024

Triple Point is partnering with ESG Accord to host a webinar: "A Practical Guide to SDR and Investment Labels for Advisers."


17 June 2024

Latest PruFund monthly investment updates


13 June 2024

Defaqto MPS Comparator: the UK's only accurate MPS performance tool


12 June 2024

Hear about Triple Point Venture VCT - 18th June 2024


6 June 2024

The Nucleus Retirement Confidence Index


24 May 2024

Join us for our Breakfast Briefing with Foresight! June 4th at 9:30am


17 May 2024

Looking forward with optimism


8 May 2024

The retirement income advice red paper


8 May 2024

Liontrust Views: Why smaller can be beautiful for US equities


7 May 2024

CPD Horizon Series: Tax planning for life’s key events


18 April 2024

Liontrust: Opportunities from secular growth trends


15 April 2024

Defaqto Roadshow - The challenges and opportunities of pursuing Income


11 April 2024

Liontrust: US small caps are overlooked and undervalued


4 April 2024

Q1 2024 Rebalance – we think the backdrop is good for stocks


21 March 2024

25 years of ISAs: a quarter of a century of tax-efficient savings and investing


4 March 2024

Stepping out of cash needn’t be daunting


26 February 2024

Managing lifetime wealth – trends in the UK retirement advice industry


23 February 2024

Empowering advice for women in finance


14 February 2024

Tech Matters is here!


5 February 2024

Defaqto upcoming event – Engage webinar 22nd February


1 February 2024

The gender divide in retirement confidence


30 January 2024

SDGs in focus: climate and nature


26 January 2024

Tax year end prep. We’re here to help.