In today’s rapidly evolving digital landscape, cybersecurity has become a critical concern for businesses of all sizes. As cyber threats become more sophisticated and pervasive, the role of Human Resources in protecting organisational data and systems is more vital than ever.
The latest UK Government Cyber Security Breaches Survey for 2024 paints a stark picture of the cybersecurity landscape. Last year, UK businesses were targeted by approximately 7.78 million cyber crimes, including 116,000 non-phishing incidents. This staggering number highlights the variety of threats businesses must contend with daily, from phishing and malware to ransomware and insider threats .
To put this into context, there are approximately 5.6 million private sector businesses in the UK. If each cyber incident affected a different business, it would imply that 139% of the UK business population could be impacted, highlighting the extensive potential reach and impact of cyber crimes. This percentage illustrates why robust cybersecurity measures are not just advisable but imperative for businesses of all sizes .
One of the biggest misconceptions is that only large, tech-heavy companies are targeted by cyber attacks. However, the reality is quite different. Over 60% of cyber attacks target small to medium-sized businesses, challenging the notion that smaller enterprises are ‘under the radar’ of cybercriminals. This highlights the universal nature of cyber threats and the need for businesses across all sectors to prioritise cybersecurity .
Major Cyber Threats
Cyber threats come in various forms, each with unique characteristics and potential to disrupt business operations:
- Phishing: Fraudulent communications that appear to come from reputable sources, aiming to steal sensitive data or install malware.
- Malware: Malicious software, including viruses, worms, and trojans, designed to harm or exploit any programmable device or network.
- Ransomware: A form of malware that encrypts the victim’s files, making them inaccessible until a ransom is paid. In the past year, 73% of UK organisations reported facing a ransomware attack, marking a 15% increase from the previous year. The consequences of ransomware include operational disruption, financial loss, and reputational damage .
- DDoS Attacks: Distributed Denial of Service attacks flood a system’s bandwidth, making services unavailable to users.
HR’s Role in Cybersecurity
HR’s responsibility extends beyond traditional personnel management to include safeguarding the organisation against cyber threats. Here are some critical points of risk in HR processes:
- Recruitment and Onboarding: Handling personal data and system access.
- Data Management: Protecting employee details and sensitive information.
- Payroll and Benefits: Securing financial and personal data.
- Technology and System Access: Ensuring the security of HR management software.
Recent Example Highlighting HR Involvement in Cybersecurity
UK Electoral Commission Breach (2023): In August 2023, the UK Electoral Commission reported a significant data breach where hostile actors accessed the electoral registers containing personal information of about 40 million people. This incident highlighted vulnerabilities in their systems and underscored the need for robust cybersecurity measures in handling sensitive data. The breach was attributed to running unpatched software and failing a Cyber Essentials audit, which could have prevented such attacks if addressed timely (Cognisys).
Proactive Measures HR Can Take
Conducting Regular Risk Assessments:
- Identification: Identify all assets within the HR department that could be affected by a cyber attack.
- Analysis: Analyse potential threats to these assets.
- Evaluation: Evaluate the impact and likelihood of these threats.
- Mitigation: Develop strategies to mitigate these risks.
- Monitoring: Continuously monitor the effectiveness of these strategies.
Developing an Incident Response Plan:
- Preparation: Prepare for potential incidents.
- Detection: Detect incidents promptly.
- Containment: Contain the impact of incidents.
- Eradication: Eradicate the threat.
- Recovery: Recover from the incident.
- Lessons Learned: Learn from incidents to improve future responses.
Importance of Employee Education. Ongoing education is one of the most effective defenses against cyber threats. Regular training helps employees stay ahead of potential security challenges, turning them from potential risks into proactive protectors of data. Effective cybersecurity training should include engaging content, regular updates, real-world scenarios, and metrics to measure success .
The role of HR in maintaining robust cybersecurity is critical. By understanding the threats, conducting regular risk assessments, developing incident response plans, and continually educating employees, HR professionals can significantly strengthen their organisation’s cybersecurity posture. As cyber threats continue to evolve, staying informed and proactive is essential to protecting our most valuable assets: our people and their data.
Free Resources:
This blogpost was written by Nina Szewczak one of our CIPD tutors here at Oxford College of Management. If you’re interested in taking your HR or People Management career to the next level, take a look at our wide range of CIPD qualifications and Human Resources courses.