Home » Lessons to be learned from TfL cyber security hack

News

Lessons to be learned from TfL cyber security hack

News recently that two hackers received prison sentences amounting to more than ten years for hacking Transport for London (TfL) systems in 2024 will come as little consolation to those affected. The risks faced by the UK’s critical infrastructure are varied and many in number.

The fact that two young and highly skilled hackers were able to cause a reported £29m hit to one of the country’s largest transport organisations over the course of less than a week should act as a salutary lesson for any organisation: no-one is safe.

On the one hand, industry onlookers should be reassured by the speed and relative efficiency in which this case was handled. On the other, it proves that no organisation is immune to threat, and that we are facing risks from a wide variety of sources: individual; foreign agent; and organised crime.

So what can companies do to protect against this type of incident in the future?

Threats can come from any angle

While financial motives haven’t be ruled out of the TfL hack, they equally haven’t been proven. Acting as part of a cybercrime network, these individuals demonstrated their capabilities, while causing disruption and accessing sensitive information.

Equally though, it’s not beyond the realms of possibility that similar hacks could be utilised to try and extort money from an organisation; or indeed be used by a hostile foreign power to exact fear, disruption and economic pain at the heart of the UK’s capital.

Size doesn’t matter

No organisation should assume it is too large, too small or too well resourced to be targeted. If an organisation the size of TfL can be subject to such an attack, even with the resources available to them, then any organisation is at risk.

There is a case to be made that TfL’s size and prominence was a factor in the attack, and created added vulnerabilities, but that isn’t to say that businesses and organisations who fly below the radar are any safer from the threat.

There are basic steps that any organisation can take to ensure resilience in such a scenario; a hygiene factor for any business in today’s threat landscape.

Get the basics right

Ultimately, the hack demonstrated that human error is still a massive factor in the cyber security landscape. Rather than some sophisticated software vulnerability, the hackers convinced a helpdesk worker to reset a known user’s login details, and expanded their access from that point.

In order to ensure the most basic levels of cyber-resilience, technology and human instinct need to work in lockstep, and cyber security needs to be considered as a day-to-day challenge.

Summary

The TfL hack serves to underline the vulnerabilities faced by organisations. This case will have highlighted the potential issues to many, but the question remains: how many lessons have been learnt through the experience?

In the UK there are still too many organisations who treat cyber security threats as something that will ‘happen to someone else’. A high-profile case, along with the media coverage of it, should be used to help educate and better understand the issue.

Xypher Limited
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.