Strengthen Cyber Resilience for Hybrid Working

Strategies to Strengthen Your Cyber Resilience for Hybrid Working

Key Considerations in a World of Hybrid Work

A recent survey by Forbes found that 63% of respondents worked remotely or in a hybrid model, showcasing that even years after the COVID 19 pandemic, hybrid working remains the norm. The importance of securing employees and the systems they access, whether they are working in the office or remotely, cannot be understated.

In this blog, we discuss distributed nature of hybrid working, the risks and cyber threats that hybrid working organisations are exposed to, alongside some recommendations and best practices that organisations can implement for securing hybrid and remote working environments.


Remote and Hybrid Working in the UK: Before and After the Pandemic

According to a report by the Wales Institute of Social and Economic Research and Data (WISERD) just 4.7% of UK employees worked from home in 2019, prior to the COVID-19 pandemic. However, by April 2020, 46.6% of employees did at least part of their job from home, and in 2022, a quarter of all UK employees worked in hybrid environments and 13% were working fully remotely.

The speed and scale at which the pandemic shifted a significant portion of UK’s workforce to hybrid/remote working, underscores the massive increase in cyber threats and incidents that followed, and the challenges that businesses and organisations would need to address in order to adapt. [source: ONS]


Cyber Threats and Risk Implications for Hybrid Working

Cyber attacks Up 238% Since the Pandemic

According to a study by Alliance Virtual Offices, the frequency of cyber attacks has surged by 238% since the shift to widespread remote working, largely driven by vulnerabilities in home networks and personal devices. Remote work has also increased the cost of data breaches for companies by an average of £104,077 (converted from $USD). Despite this, only 56% of remote employees receive regular cyber security training, increasing the risks for organisations operating in a more digital environment. [source: Yahoo Finance]

BYOD and Home Networks Expand Attack Surface

Research from Lookout found that 32% of remote workers use apps not approved by their company’s IT department, and 90% access corporate networks from multiple locations, including coffee shops and public Wi-Fi, which increases cyber risk. This can also increase exposure to threats like phishing and malware attacks, especially as 46% of employees save work files on personal devices. [source: IT Security Guru]

Common Attack Vectors – An increase in RDP Abuse

In light of so many organisations migrating to remote/hybrid working models, threat actors have turned their sights to exploiting remote/virtual desktop technologies as a means of bypassing external defensive parameters and gaining a foothold on the internal network.

Remote desktop protocol (RDP) is a common method for establishing remote access on Windows systems. According to a recent report by Sophos found that cyber criminals abused remote desktop protocol in 90% of attacks. This was the highest incidence of RDP abuse since Sophos began releasing its Active Adversary reports in 2021, covering data from 2020.

Remote Work Security Gaps

Cyber security experts also warn that hybrid work models expose companies to new risks. Remote workers that use unsecured personal devices and networks are a target for cyber criminals as they increasingly target collaboration apps like Slack and Teams to launch social engineering attacks. With the introduction of faster 5G networks, attacks on mobile devices are also expected to rise, as noted by UpGuard.


Cyber Threats and Risk Implications for Hybrid Working

The evolution of digital security is now at a pivotal point. The old models, based on clear boundaries between “inside” and “outside,” no longer hold. IT and InfoSec teams now have to contend with much greater digital attack surfaces, endpoint and firmware management challenges and company-wide adherence to remote/hybrid working policies.

Forrester study in 2023, found that remote and hybrid working models has magnified IT operational challenges for 75% of participating organisations. Below are some best practices and essentials for secure remote/hybrid working models:

Implement Strong Access Controls

Organisations must ensure that only authorised users can access corporate systems. This includes multi-factor authentication (MFA) and device authentication, which requires pre-registering devices before allowing network access. Zero-trust security models that continuously verify user identities and devices are also highly recommended for hybrid environments (Security Boulevard).

Adopt Zero Trust Architecture

Zero Trust is an architectural approach where inherent trust in the network is removed, the network is assumed hostile, and each request is verified based on an access policy. By implementing a “never trust, always verify” approach to network security, requiring continuous authentication and least-privilege access to ensure that every request—whether from inside or outside the network—is fully verified before access is granted, organisations can significantly reduce lateral movement from possible threat actors and improves security across cloud, on-premises, and hybrid environments. NIST has published further guidance on Zero Trust Architecture here.

Develop and Enforce a BYOD Policy, Using Encryption and Backups

Clear policies for using personal devices for work must be established, covering security measures such as mandatory installation of security software and limiting personal use on company devices, while limiting the amount of access through personal devices. This minimises the risk of unauthorised access and data leakage.

Encrypting all stored data on devices used for remote work adds an extra layer of protection in case of theft or unauthorised access. It’s also essential to back up important data regularly, ensuring it can be restored in the event of a cyber attack or system failure. Additionally, enabling remote wipe capabilities for lost or compromised devices ensures sensitive data can be erased quickly.

Use Secure Networks and Tools

Remote workers should avoid public Wi-Fi where possible due to its high vulnerability. Instead, they should rely on personal hotspots or secure VPNs, which encrypt data and protect it from potential attackers on unsecured networks. Similarly, using secure video conferencing platforms and company-approved email systems helps reduce the risk of unauthorised access to communications.

Regular Penetration Testing and Red Teaming

Penetration testing and Red Team exercises are crucial for identifying vulnerabilities across their external and corporate networks, applications or devices before attackers can exploit them. By conducting Targeted Attack Simulations (TAS) or Red Team exercises that simulate exploiting vulnerabilities or gaps in remote/hybrid working environments companies can evaluate their overall security posture of their remote working infrastructure and focus resources on vulnerable areas to improve their defences against such attack vectors.

Regular Software Updates and Endpoint Protection

Ensuring that all devices, including personal ones used for work (BYOD), have up-to-date antivirus and firewall protection is crucial. 

Regularly updating and patching software, coupled with continuous vulnerability assessments, is vital for maintaining a secure infrastructure. Cyber security as a Service (CSaaS) solutions, such as HackRisk, can help companies manage vulnerabilities effectively without overburdening internal teams.

Phishing and Social Engineering Awareness Training

Employees are often the first line of defence against cyber threats. Regular training sessions on phishing, social engineering, and secure data handling can significantly reduce the risk of human error leading to a security breach

Managed Detection and Response (MDR)

Endpoint detection alone is no longer sufficient given today’s digital threat landscape. Organisations must now employ an “always-on” threat detection and monitoring capability. However, employing and retaining qualified cyber security analysts, engineers can very expensive and hard to come by, let alone the continuously high costs of using XDR and SIEM technologies. Running a 24/7 SOC (Security Operations Centre) in-house with experienced analysts and security experts with state-of-the-art defensive technologies are typically reserved for multi-national conglomerates and banks.

MDR services (Managed Detection and Response) provide continuous monitoring and analysis of an organisation’s entire estate, including endpoints, network traffic and activity logs. By outsourcing to experts, firms can ensure that threats are detected and mitigated in real-time, reducing the risk of a successful attack.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

Your Pen Test Report

Your CREST Accredited Penetration Test Report Explained Clearly

What Does a Good Penetration Test Report Cover?

Penetration Testing or Pen Testing is a crucial tool in your IT security toolbox. It provides a method for gaining assurance that an IT system or infrastructure is secure through the use of simulated tools and attacks that are used in the real world, to attempt to breach or gain access.

Gavin Wood, CEO at CyberLab, uncovers what a Penetration Test report should provide, including…

  • What is Penetration Testing?
  • What is a Penetration Testing Report and What Should it Contain?
  • Prevention v Cure


What is the Purpose of a Penetration Test?

The purpose of a Penetration Test is to discover any risks and allow you or your security team to act on them before anyone else does.

Typically pen tests are used to identify the level of risk from any hardware or software vulnerabilities and or any configuration issues within your environment.

The output of a Pen Test is usually in the form of a report that will grade any issues or vulnerabilities found so that these can be addressed, and any gaps closed.


What is a Penetration Testing Report and What Should it Contain?

A Penetration Test report, details any threats or vulnerabilities found and the recommended remedial actions.

Threats and vulnerabilities will be ranked in order of criticality. The report will also contain an executive summary and attack narrative which will explain the risks in business terms.

A penetration test report should involve the following areas…

  • Risk and Executive Summary
  • Approach, Scope and Caveats
  • Findings Summary and Remedial Advice

Risk Summary

A risk summary details management and high level issues. These issues will be highlighted into 6 categories: Critical, high, medium, low, very low and informative.

Pen Test Report Example

Executive Summary

A executive summary details management and high level issues, breaking down the report details to illustrate the level of risk that is exposed across the systems tested. This will highlight the total number of vulnerabilities identified during the assessment, along with their severity.

Pen Test Report Example 2

Approach, Scope and Caveats

This section introduces the in-depth reporting gathered from the Penetration Testing undertaken. It details the approach taken, the scope of engagement, and any limitations identified, such as, anything not attempted which could have risk of impact to service availability or system performance.

Findings Summary and Remedial Actions

The findings summary is where you can find the technical information regarding the assessment conducted. This section is broken down into: summary, technical details, recommendations and systems affected.

Your Pen Test Report
View Example Pen Test Report

Prevention v Cure

With the risk of being controversial I am going to make an analogy between Pen Testing and vaccination.

We all know how vaccines work; they are a pre-emptive action against an illness to stop you getting the full affects and or be able counter the actual illness should you come in to contact with it.

A Pen Test is a pre-emptive action that allows you to discover and remediate any issues before someone else does.

Having a Pen Test should be part of your prevention strategy for IT security. Simply put you can’t manage what you can’t see, if you don’t know you have vulnerabilities, you cannot close them down. Pen Testing is an ideal way to give you the visibility of these issues and allows you to take remediation action to correct.

Given that cyber incidents are the 3rd biggest business risk for 2021* (that year’s top risk) and the average cost of remediating a ransomware attack now at $1.85 Million** prevention must be better than the cure!

However, Pen Testing is not a magic bullet, and it does have limitations; it’s a point in time test of the infrastructure. If a vulnerability is introduced after the pen test has been conducted it can still impact on your security. So regular testing is essential, especially after deploying new systems and technologies and as a part of your security continual improvement lifecycle.

Penetration Testing

Leave it to our team of expert penetration testers to identify vulnerabilities in your environment.

Our tailored assessments can cover every aspect of network security from general vulnerability identification to fully exploiting vulnerable web applications.

Get a Quote

Top Cyber Threats in Fintech New

The Top Cyber Threats in Fintech and How to Reduce Cyber Risk

Securing the Future of Financial Technology: Navigating Cyber Security Challenges in a Rapidly Evolving Landscape

The finance sector is one of the biggest targets of cyber threat actors with 65% of organisations hit by ransomware in 2024, according to recent research by Sophos. As the financial technology (Fintech) sector continues to revolutionise the way we handle money, the stakes for cyber security have never been higher.

The integration of innovative digital solutions, from AI-driven financial services to blockchain technology, has opened up new opportunities for growth, but it has also expanded the threat landscape.

This blog explores the current cyber security challenges facing the financial technology industry, the impact of these threats, and the best practices that companies can adopt to safeguard their operations and customer trust.


The Rising Threats in Fintech: A Snapshot of Today’s Cyber Security Landscape

The Fintech industry, characterised by its rapid adoption of cutting-edge technologies, is a prime target for cybercriminals. According to recent reports, the financial services sector experiences cyber-attacks 300 times more frequently than other industries, with Fintech companies being particularly vulnerable due to their digital-first nature. The rise of AI and machine learning in Fintech has further complicated the threat landscape, as these technologies can be both a tool for defence and an instrument for sophisticated attacks.

Key Threats Facing Fintech Today

  • Data Breaches: With vast amounts of sensitive financial data at stake, data breaches remain one of the most significant risks for Fintech and financial services firms. Recent breaches, such as the SolarWinds attack, have highlighted the vulnerabilities in supply chains and third-party providers, making it clear that no organisation is immune.
  • AI-Driven Cyber Attacks: The same AI technologies that enable personalised financial services are also being used by cybercriminals to automate attacks, enhance phishing campaigns, and exploit vulnerabilities faster than traditional methods. For instance, AI can create highly convincing deepfake videos and emails, making it easier to deceive even the most vigilant employees.
    One of the most alarming examples occurred in earlier this year, when cybercriminals targeted a Hong Kong-based financial services firm in a first-of-its-kind heist. Using advanced deepfake technology, the attackers impersonated the firm’s Chief Financial Officer (CFO) during a video conference call. They convincingly replicated the CFO’s voice and appearance, deceiving an employee into transferring nearly £20 million to a fraudulent account. [source: Ars Technica]
  • Regulatory Challenges: With evolving regulations such as GDPR and PSD2 in Europe, and new guidelines from the FCA and other financial authorities worldwide, Fintech companies must navigate a complex web of compliance requirements. Failure to comply not only risks legal substantial penalties, but also damages brand reputation.

The Future of Fintech Security

Quantum Computing

The Fintech industry faces a significant challenge with the advent of quantum computing, particularly regarding encryption. As quantum technology advances, traditional cryptographic methods could become obsolete, necessitating a costly overhaul of encryption standards. The transition to quantum-resistant encryption is crucial for maintaining data security but will require significant investment and regulatory adjustments across the global Fintech sector. According to a recent report by Moody’s Ratings “Quantum computing’s threat to asymmetric encryption is currently mitigated by challenges in error correction, scalability, talent shortages and limited computing power…” However, quantum computing could break asymmetric encryption within 5 to 30 years. [source: Fintech Magazine]

The Global Treasurer predicts that quantum computing will revolutionise the Financial Services and Fintech industries, particularly in financial modelling, analysis, payment systems and cyber security. Financial institutions will need to adopt quantum-resistant algorithms, shifting towards more dynamic and adaptive security strategies. This evolution will require collaborative efforts across the global financial sector, including international cooperation, to build resilient global payment systems, enforce standardised regulations, and ensure a secure, efficient future leveraging quantum technology.

Compliance and regulations in quantum computing is not just becoming central to cyber security in Financial Services, but also to ensuring market viability. The Director of Quantum at KPMG, Michael Egan states that “While quantum technologies are rapidly developing, the threat of ‘Harvest now, Decrypt later’ is real and immediate. With increasing legislation, together with long procurement and mitigation cycles, there is a need to act now.” [source: KPMG]


The Role of Compliance and Regulatory Standards in Strengthening Cyber Defences

Compliance with industry standards is not just a legal obligation; it is a critical component of a robust cyber security strategy. Frameworks such as ISO/IEC 27001 and guidelines from regulatory bodies like the FCA in the UK provide a structured approach to managing sensitive data and mitigating risks.

Key Compliance Measures for Fintech

  • Data Protection Compliance: Ensuring adherence to FCA, GDPR and other data privacy and financial authority regulations is essential for protecting customer data, and arguably the integrity of Fintech and Financial Services industries. This includes implementing robust data encryption, conducting regular audits, and maintaining clear data governance policies.
  • PSD2 and Open Banking: With the advent of open banking, Fintech companies must ensure that their APIs are secure, and that customer consent is properly managed. Compliance with PSD2 not only protects consumer data but also enhances trust in digital financial services.
  • Adoption of Cyber Security Frameworks: Leveraging established cyber security frameworks like NIST, ISO/IEC 27001 or the Cyber Essentials scheme in the UK can help Fintech firms standardise their security practices and stay ahead of emerging threats.


Best Practices for Cyber Security in Fintech

To navigate the complex cyber security landscape, Fintech companies must adopt a proactive approach. Here are some best practices that should be integral to any Fintech firm’s cyber security strategy:

  • Regular Penetration Testing and Red Teaming: Penetration testing and red teaming exercises are crucial for identifying vulnerabilities before attackers can exploit them. By simulating real-world attacks, these practices allow Fintech companies to evaluate their security posture and improve their defences.
  • Managed Detection and Response (MDR): MDR services provide continuous monitoring and analysis of an organisation’s security environment. By outsourcing to experts, Fintech firms can ensure that threats are detected and mitigated in real-time, reducing the risk of a successful attack.
  • Incident Response and Recovery: Having a robust incident response plan is essential for mitigating the damage caused by cyber incidents. Fintech companies should invest in both in-house and outsourced incident response teams to ensure a swift and effective reaction to breaches.
  • Employee Training and Awareness: Employees are often the first line of defence against cyber threats. Regular training sessions on phishing, social engineering, and secure data handling can significantly reduce the risk of human error leading to a security breach.
  • Vulnerability Management: Regularly updating and patching software, coupled with continuous vulnerability assessments, is vital for maintaining a secure infrastructure. Cyber security as a Service (CSaaS) solutions, such as HackRisk, can help Fintech companies manage vulnerabilities effectively without overburdening internal teams.


Building a Resilient Cyber Security Strategy in Fintech

As Fintech continues to reshape the financial services landscape, the importance of cyber security cannot be overstated. By understanding the current threats, complying with regulatory standards, and implementing best practices, Fintech companies can build a resilient security posture that not only protects their operations but also fosters trust with their customers.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

CDI MMU

CyberLab Collaborates with CDI & Manchester Metropolitan University

Healthcare Under Siege Event: Cyber Security for Healthcare Professionals

On Thursday, 28 November 2024, CyberLab, in collaboration with the Centre for Digital Innovation and Manchester Metropolitan University, hosted a highly impactful event: Healthcare Under Siege: Cyber Security for Healthcare Professionals.

Held at the GM Digital Security Hub (DiSH) in Manchester, the event attracted healthcare and cyber security professionals eager to address the alarming rise of cyber threats targeting the healthcare sector.


Highlights of the Day

The day centred around a live cyber attack simulation and an in-depth exploration of the vulnerabilities faced by healthcare organisations. Participants gained actionable insights to enhance their security posture.

Live Cyber Attack Simulation

The event featured a riveting session led by Ryan Bradbury, CTO of CyberLab, supported by a team of CREST, CHECK, and Cyber Scheme-approved engineers. The simulation demonstrated how a hacker could breach an organisation’s defences within just five minutes. Attendees were taken step-by-step through the methods malicious actors use to exploit vulnerabilities.

Understanding Healthcare-Specific Risks

Ryan delved into the unique challenges faced by healthcare organisations, highlighting statistics like the 67% of healthcare organisations hit by ransomware in 2024, as reported by Sophos. He addressed the critical need for stronger defences in a sector where data breaches can have life-altering consequences.

Best Practices for Cyber Security in Healthcare

The session concluded with practical recommendations tailored for healthcare professionals. These included strategies for improving password hygiene, implementing multi-factor authentication, regular security training, and ensuring robust data backup protocols.


Key Takeaways

Healthcare is a Prime Target for Cyber Attacks

With sensitive data and critical systems at stake, healthcare organisations must prioritise cyber security.

Understanding Vulnerabilities is Essential

The simulation showcased how easily breaches can occur, underlining the importance of identifying and mitigating weak points.

Proactive Measures Save Lives

Beyond financial loss, breaches in healthcare can directly impact patient care, making proactive security an ethical imperative.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

CyberLab x Lancaster University Event: Human vs AI Intelligence & Cyber Risk

CyberLab x Lancaster University Event: Human vs AI Intelligence & Cyber Risk

Understanding the Interplay Between Human Intelligence & AI

On Tuesday November 19th 2024, CyberLab, in collaboration with Lancaster University, hosted the highly anticipated event Human vs AI Intelligence & Cyber Risk at the GM Digital Security Hub in Manchester.

The event brought together professionals, academics, and thought leaders to explore the evolving challenges posed by artificial intelligence and cyber threats.

Over the course of three insightful workshops, attendees gained a deeper understanding of the interplay between human intelligence and AI in the context of cyber risk.


Highlights of the Day

The event delivered a powerful blend of practical insights and interactive learning through three workshops designed to illuminate the complexities of cyber risk in the age of AI.

Workshop 1: Under Siege

Led by Ryan Bradbury, CTO of CyberLab, this session featured a live cyber attack simulation. Attendees watched as vulnerabilities were exploited in real-time, gaining first-hand insights into how cyber criminals operate. Ryan provided practical advice on fortifying defences to protect against similar scenarios, leaving participants with actionable takeaways.

Workshop 2: Defining & Measuring Cyber Risk

In this session, Anna Dyson from Lancaster University guided participants through the process of defining and assessing cyber risk. Using tools and frameworks, attendees learned to measure potential losses and better understand attack motivations, helping them to evaluate their organisation’s vulnerabilities more effectively.

Workshop 3: Bot or Not?

Researchers from Lancaster University put attendees to the test in distinguishing between human and AI-generated voices. This fascinating exercise highlighted the advancements in forensic linguistics and AI detection, showcasing the difficulty of identifying AI-driven content and the implications for cyber security.


Key Takeaways

Cyber Criminals are Leveraging AI

The rise of AI technologies has introduced new dimensions to cyber attacks, increasing their scale and sophistication.

Risk Measurement is Critical

Effective strategies begin with understanding and quantifying risks to prioritise defences and allocate resources.

Human Expertise Remains Crucial

Despite AI’s capabilities, the role of human intelligence in identifying and mitigating risks is irreplaceable.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

Top 5 Cyber Security Predictions 2025

Top 5 Cyber Security Predictions for 2025 and How to Prepare Now

Preparing for the Unpredictable: Trends Shaping the Future of Cyber Defence

As the digital landscape evolves, so do the threats and opportunities in cyber security. With 2025 on the horizon, organisations face an increasingly complex web of challenges – from AI-powered attacks to the growing influence of regulation. To stay ahead, it’s crucial to understand where the industry is heading over the next 12 months.

In this blog, we outline our top 5 cyber security predictions for 2025, offering insights into emerging trends and practical strategies to bolster your cyber defences. It’s no surprise that advancements in AI are shaping the future of cyber security, driving both innovation and new challenges in the year ahead.


AI: The Double-Edged Sword of Cyber Attacks

Artificial Intelligence continues to revolutionise the way we approach cyber security, but it’s also empowering attackers with unprecedented capabilities. In 2025, we predict a significant rise in AI-driven cyber threats, from hyper-realistic phishing scams to automated vulnerability exploitation at scale. Deepfake technology, for example, is being used in phone scams and social engineering attacks, mimicking voices and appearances with unsettling accuracy to deceive victims. These attacks will be faster, more sophisticated, and harder to detect, leveraging AI’s ability to mimic human behaviour and analyse defences in real-time.

To counteract this, organisations must embrace AI-enhanced security solutions, invest in workforce training, and prioritise threat intelligence sharing. The battle against AI-powered attacks will demand a proactive and adaptive approach.


Ransomware Reloaded: The AI-Powered Threat

Ransomware attacks are expected to surge in 2025, with AI adding a dangerous new dimension. Attackers are increasingly leveraging AI to identify vulnerabilities more efficiently, automate their attacks, and tailor their tactics for maximum impact. Ransomware attacks can be supported through AI, which can adapt in real time, encrypting files faster or evading detection by mimicking legitimate processes.

The National Cyber Security Centre (NCSC), part of GCHQ, has reinforced this warning in a recent report. It concludes that AI is already being used in cyber attacks and will almost certainly increase the scale and severity of ransomware incidents over the next two years. The report urges organisations and individuals to adopt stronger protective measures as AI-driven attacks become more sophisticated and harder to detect.

The stakes are higher than ever, as these sophisticated attacks target not only businesses but also critical infrastructure and individuals. To combat this, organisations must invest in advanced threat detection systems, conduct regular security audits, and ensure robust incident response plans are in place to minimise downtime and financial loss.


Cyber Insurance 2025: Adapting to the AI-Driven Risk Landscape

Our next prediction for the top 5 cyber security threats of 2025 is that cyber insurance is expected to undergo significant shifts as the landscape of digital threats evolves. The market for cyber insurance is projected to grow to $22.5 billion over the course of 2025*, reflecting the increasing complexity and risks businesses face from cyber attacks.

One of the major factors influencing this change is the rapid growth in AI-driven threats. Insurers will be looking for businesses to demonstrate robust cyber resilience, particularly through proactive risk management practices such as implementing advanced cybersecurity measures and understanding the full scope of potential cyber exposures.

Coverage will likely expand beyond just ransom payments, with an increased focus on protecting against broader costs like business interruption, reputational damage, and legal repercussions.

As the sector matures, businesses will need to balance cost-effective measures with comprehensive protection, and insurers may offer discounts for companies that adopt stronger cyber security protocols, such as multi-factor authentication and endpoint detection.

Tales from the CyberLab: Cyber Insurance Explained with Marsh

Cyber risk has evolved into a dynamic threat for organisations that requires proactive management.

Eric Alter, Senior VP Risk & Cyber Engagement Leader from Marsh joins the podcast to explain the complexities of cyber insurance and how it protects your organisation when cyber incidents occur.


Jailbreaking AI: Exploiting Language Models for Sensitive Data

In 2025, we anticipate a rise in the misuse of AI language models like ChatGPT through a technique known as jailbreaking. By exploiting vulnerabilities in the model’s safeguards, attackers can bypass restrictions and manipulate the AI into generating harmful content or aiding in illicit activities.

For instance, these jailbroken models might be used to craft highly convincing phishing emails, simulate conversations to extract sensitive information, or even provide step-by-step guidance for malicious actions. As AI becomes increasingly integrated into businesses and everyday life, it’s vital to establish clear usage policies, monitor for abuse, and stay updated on advances in AI safety to mitigate these risks.


Securing the Backbone: OT and Physical Security Threats to Critical Infrastructure

As we move into 2025, threats to Operational Technology (OT) and physical security are expected to rise significantly, particularly in sectors that rely heavily on critical national infrastructure (CNI). These infrastructures, such as energy grids, water treatment plants, and transportation systems, often use legacy systems that were not designed with modern cyber security in mind.

This makes them vulnerable to both cyber and physical attacks, especially as they become more interconnected with internet-enabled systems. The convergence of IT and OT increases the risk of cyber criminals or state-sponsored actors gaining access to these systems, potentially disrupting operations or even causing physical damage.

The Director of National Intelligence recently released a report where it found that “Iran-affiliated and pro-Russia cyber actors gained access to and in some cases have manipulated critical US industrial control systems (ICS) in the food and agriculture, healthcare, and water and wastewater sectors in late 2023 and 2024”.

In line with evolving threat landscapes, the UK’s National Cyber Security Centre (NCSC) now classifies data centres as part of critical national infrastructure (CNI), recognising their essential role in supporting digital services and national security.

Additionally, the dependence on third-party vendors and suppliers for essential services can introduce further vulnerabilities, creating a lucrative target for attackers. Given these challenges, enhancing the security posture of CNI has become a priority for governments and organisations worldwide, with increased collaboration and regulations to address these threats.


Looking Ahead: Navigating the Future of Cyber Security in 2025

As we look toward 2025, the cyber security landscape is set to become even more dynamic and complex. Emerging threats driven by AI, the convergence of IT and OT systems, and the growing reliance on cloud technologies will continue to challenge organisations across all sectors. Ransomware will evolve, aided by AI, while critical infrastructure faces mounting risks from both cyber and physical attacks.

The increased focus on cyber insurance, evolving regulations, and the growing importance of threat intelligence will shape how businesses approach security. Adapting to these changes requires a proactive mindset, robust security strategies, and a commitment to constant learning and adaptation to stay one step ahead of the ever-evolving cyber threat landscape.

With vigilance and innovation, organisations can better navigate these challenges and secure their futures in 2025 and beyond.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

Cyber Security Essentials for Websites and Applications

Cyber Security Essentials for Websites and Applications: Safeguarding E-Commerce

Safeguarding E-Commerce Success

With e-commerce thriving as a cornerstone of retail, securing websites and applications has never been more critical. Cyber criminals target vulnerabilities in commercial platforms and websites to exploit sensitive customer data and disrupt operations.

This month, we explore the cyber threats and implications facing online retail and e-commerce, as well as delving into some best practices and frameworks like OWASP, and secure development methodologies, to help organisations stay secure online.


Why Application Security Matters for E-Commerce

Threat Landscape

Cyber crime targeting e-commerce platforms remains a top concern, according to the NCSC, 50% of UK businesses experienced a cyber attack in 2023 alone. 18% of breaches that were reported in 2023 to the Information Commissioner’s Office (ICO) were in the retail sector.

Rising Threats

Cyber crime targeting online businesses in the UK is being driven by increasingly sophisticated attacks, with the number of affected businesses only set to increase year on year. Common threats include SQL injection, cross-site scripting (XSS), and API breaches.

Impact

A single breach can result in financial loss, reputational damage, and even regulatory penalties. For example, Magecart’s attacks on British Airways showcased the devastating impact of compromised third-party integrations, resulting in the flag carrier airline having to pay a £20m data protection fine. [source: The Register]

Trust and Loyalty

Ensuring robust security builds customer trust, enhances brand reputation, and protects critical data like payment information and personal details.


The Rise of API Breaches and the Importance of Secure Third-Party Integrations

APIs (Application Programming Interfaces) are the backbone of modern web applications, enabling integration between systems, other applications, and services. According to Business Wire, a survey in 2022 found that 97% of enterprise business leaders agree that successfully executing an API strategy is essential to secure organisations’ future revenue and growth.

However, their rapid adoption has also made them a prime target for attackers. In 2021, Gartner predicted that APIs would become the top attack vector used to target applications.

Fast forward to 2024 and there have already been some notable breaches…

Peloton API Breach (2021)

Hackers exploited a vulnerability in Peloton’s API that enabled users to make an unauthenticated request for account data to the API without the API first verifying if that user has authorisation to access said data.

The API enables the end users’ bikes to capture and upload data back to Peloton’s servers. Sensitive user data for around 3 million individuals was exposed due to insecure API configurations.

This included personal details such as names, emails, and workout statistics. Peloton’s inadequate authentication and authorisation measures highlighted the critical need for robust API security protocols. [source: Threatpost]

Facebook Data Breach (2021)

An API misconfiguration in Facebook’s (Meta’s) contact importer feature was exploited by malicious actors, exposing the personal data of approximately 533 million users from 106 countries.

Personal data such as phone numbers, full names, and locations were leaked, with the issue originally stemming from scraping public profiles before the vulnerability was patched in 2019. [source: Twingate]


Tales from the CyberLab: Cyber Security for Websites & Apps Explained


Best Practices for Web Application Security

Penetration Testing

Penetration testing is a cornerstone of application security, especially for retail and e-commerce businesses handling vast amounts sensitive customer data and requiring 24/7 availability online.

While large enterprises like Amazon may have the capacity to conduct internal pen testing, most organisations in this space face cost and resource constraints that make outsourcing these services more practical and effective. Partnering with external cyber security experts provides access to specialised skills, tools, and up-to-date threat intelligence that many internal teams simply can’t maintain.

Moreover, hiring third-party testers eliminates the bias that might come with in-house testing and ensures that vulnerabilities are approached with a fresh perspective. The cost of penetration testing is often outweighed by the potential financial and reputational damage of a breach, particularly in high-stakes industries like retail.

Independent testing not only provides peace of mind but also aligns with compliance requirements and industry best practices, ensuring businesses are well-protected against the ever-evolving threat landscape.

Code Reviews

Code reviews are an essential part of any secure development process, ensuring that security vulnerabilities are caught early in the development lifecycle. This practice involves systematically examining source code to identify flaws, errors, or opportunities for improvement, with a strong focus on maintaining high security standards.

For retail and e-commerce businesses, where customer trust is paramount, code reviews play a vital role in protecting sensitive user data and ensuring seamless functionality. Conducting thorough code reviews:

  • Identifies Common Vulnerabilities: Helps uncover issues such as injection flaws, insecure data handling, and authentication weaknesses, which align with risks highlighted in the OWASP Top 10.
  • Enhances Collaboration: Encourages teamwork among developers, fostering a culture of accountability and shared responsibility for secure coding practices.
  • Reduces Costs: Fixing security vulnerabilities during development is significantly less expensive than addressing them after deployment or following a breach.

Given the fast pace of the e-commerce sector, it may be tempting to bypass code reviews to save time. However, the long-term risks far outweigh the short-term gains. Engaging third-party experts or employing tools like static application security testing (SAST) solutions can streamline this process, providing an additional layer of confidence before your code goes live.

Ultimately, code reviews are more than just a quality check – they are a proactive defence against cyber threats, reinforcing the integrity of your applications from the very foundation.


Open Web Application Security Project (OWASP)

Top 10 Vulnerabilities

OWASP (Open Web Application Security Project) offers a globally recognised framework for understanding the most common and prevalent risks facing open web and mobile applications.

Here’s a snapshot of the OWASP Top 10 vulnerabilities every e-commerce platform must address:

  1. Broken Access Control: Unrestricted access to sensitive functionalities or files.
  2. Cryptographic Failures: Insufficient cryptographic mechanisms leading to compromise of sensitive data.
  3. Injection: Exploiting input fields to manipulate databases or applications (e.g., SQL Injection).
  4. Insecure Design: A broad category representing different weaknesses, expressed as “missing or ineffective control design”.
  5. Security Misconfiguration: Default settings or unpatched software creating vulnerabilities.
  6. Vulnerable and Outdated Components: Relying on outdated libraries and frameworks, or application technologies with known vulnerabilities.
  7. Identification and Authentication Failures: Weak authentication and authorisation processes enabling unauthorised access.
  8. Software and Data Integrity Failures: Code and infrastructure that does not sufficiently protect against integrity violations
  9. Security Logging and Monitoring Failures: Insufficient logging, detection, monitoring, and active response, enabling unnoticed breaches. The application cannot detect, escalate, or alert for active attacks in real-time or near real-time.
  10. Server-Side Request Forgery (SSRF): SSRF flaws occur whenever a web application is fetching a remote resource without validating the user-supplied URL. It allows an attacker to coerce the application to send a crafted request to an unexpected destination, even when protected by a firewall, VPN, or another type of network access control list (ACL). This is increasingly common in modern web applications.


Secure Development Life Cycle (SDLC)

SDLC emphasises embedding security into every stage of the development process, from ideation to deployment. Key steps include:

  • Planning: Identify security requirements early.
  • Design: Threat modelling to anticipate potential attack vectors.
  • Implementation: Use secure coding practices and tools to detect vulnerabilities in real time.
  • Testing: Conduct automated and manual tests, including code reviews and penetration testing.
  • Deployment: Monitor applications continuously and ensure robust change management.
  • Maintenance: Regularly update, patch, and audit systems post-launch.

More information about SDLC practices can be found here.

Tools and Resources for Strengthening Security

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

CyberLab at the CDI Roadshow

CyberLab at the Centre for Digital Innovation (CDI) Roadshow

Live Hacking at the Cyber Security & Digital Health Innovation Event

On 30th January 2025, CyberLab was proud to participate in the Cyber Security and Digital Health Innovation in Education event, hosted at City Campus Manchester as part of the CDI Roadshow.

The event brought together industry experts, educators, and business leaders to explore the evolving landscape of cyber security, digital health, and education.

Our team delivered an impactful live hack demonstration, providing attendees with a first-hand look at how cyber criminals exploit vulnerabilities in real time.


CyberLab’s Live Hack: “Under Siege – How a Hacker Can Break Into Your Organisation in 5 Minutes”

CyberLab took centre stage during the demo session, delivering a step-by-step live simulation of a cyber attack. The session exposed the rapid and sophisticated methods used by cyber criminals to infiltrate systems. 

With support from CREST, CHECK, and Cyber Scheme-approved engineers, our demonstration showcased: 

• Common vulnerabilities that hackers exploit within minutes. 

• Real-world attack strategies, including phishing, credential theft, and privilege escalation. 

• Best practices for securing systems and mitigating risk. 

Attendees witnessed first-hand the devastating impact of a cyber breach, reinforcing the urgency of proactive cyber defence strategies. 


Looking Ahead: Empowering Organisations with Cyber Resilience

CyberLab remains committed to bridging the gap between industry and education, ensuring that businesses, institutions, and individuals stay ahead of evolving cyber threats.

We extend our thanks to the CDI consortium, GMColleges, and event organisers for bringing together such an inspiring and forward-thinking community. As cyber threats continue to evolve, so must our collective approach to defence.

Cyber Security for Education

Cyber attacks are highly disruptive, impacting your systems and data security while disturbing the educational environment for students, faculty, and staff.

Our range of education security solutions has been crafted to meet the specific security needs of today’s educational institutions, drawing on years of experience working with schools, universities, and other educational organisations.

We’ve put together these recommendations to ensure uninterrupted learning, protect your systems and networks, and safeguard sensitive data.

View Education Hub

Your Security Questions Answered

Your Cyber Security Questions Answered: Questions Every Business & IT Leader Asks

Top Questions Every Business & IT Leader Asks

Security is now a core business risk, not just an IT concern.

Cloud adoption, hybrid work and a fast‑moving threat landscape mean leaders need simple, practical answers to three recurring questions:

  • Has security really changed that much in the past few years?
  • Am I using the best‑in‑class security vendors today?
  • Do I have the right skills and time in‑house to manage these solutions?

CyberLab addresses each question and outlines a pragmatic way forward.


Has Security Really Changed That Much?

Yes. The perimeter has shifted, and so have attacker methods and business expectations.

  • Hybrid work and SaaS sprawl
    People, devices and data now operate beyond the office. Access happens from anywhere, often to third‑party applications. Security must follow identity and data, not only networks.
  • Identity is the new control point
    Strong authentication, conditional access and least privilege are now essential. Compromised credentials remain one of the most common root causes of incidents.
  • Cloud as default
    Security needs to be built for cloud platforms and APIs. Posture management, workload protection and secure configuration now sit alongside traditional controls.
  • Detection, response and resilience
    Prevention is vital, but it is not enough on its own. Organisations need visibility, rapid response and tested recovery. Backups, restore testing and incident playbooks are part of core security.
  • Supply chain and third parties
    Vendors, partners and integrators can introduce risk. Contracts, minimum controls and periodic assurance need to be part of the operating model.

The model to aim for is identity‑first, least privilege, assume breach, with layered controls that prevent, detect, respond and recover.


Are We Using Best‑In‑Class Security Vendors Today?

“Best” depends on outcomes, integration and operational fit, not just features. Many estates grew into a patchwork of point products. Consolidation around fewer, well‑integrated platforms often improves security and reduces effort.

What good looks like in a modern stack

  • Identity and access
    Enterprise identity provider, phishing‑resistant MFA, conditional access, privileged access management, lifecycle governance.
  • Endpoint and server security
    EDR or XDR with behaviour‑based detection, central policy, and response tooling. Coverage for Windows, macOS, Linux and mobile.
  • Email, web and DNS security
    Advanced phishing protection, attachment sandboxing, impersonation and brand spoofing controls, safe link handling and DNS filtering.
  • Cloud and SaaS posture
    Cloud security posture management for IaaS and PaaS, and configuration governance for SaaS. Guardrails and continuous checks.
  • Network security
    Secure web gateway, ZTNA for private apps, and segmentation. Where appropriate, an SSE or SASE approach to apply consistent policy from anywhere.
  • Data protection and backup
    Classification, DLP, encryption and secure, isolated backups with regular restore tests.
  • Vulnerability and patch management
    Accurate asset inventory, regular scanning, prioritised remediation and clear service levels.
  • Logging and monitoring
    Centralised log collection, correlation, detection content mapped to common frameworks, and alert triage.

Selection principles that help

  • Prioritise integration and coverage over feature checklists.
  • Favour open standards and proven interoperability.
  • Demand outcome measures, not only demos.
  • Consider operational cost. The best tool is one the team can run well.

Common anti‑patterns to avoid

  • Buying duplicate tools that overlap.
  • Deploying without hardening defaults.
  • Ignoring decommissioning, leaving legacy exposure.
  • Running security in silos that do not share telemetry or policy.


Do We Have The Right Skills And Time In‑House?

Many incidents are caused by misconfiguration rather than missing tools. Operating security well is a discipline that combines people, process and technology.

Operate to a plan, not heroics

  • Define standards and baselines for identity, endpoint, cloud and data.
  • Use automation for onboarding, patching, certificate and key management.
  • Maintain runbooks and playbooks for detection and response.
  • Track metrics such as mean time to detect and recover, patch compliance and simulation results.

When to consider managed services

  • You need 24×7 detection and response but cannot staff it continuously.
  • You want co‑managed operations, where a partner handles monitoring and escalation while your team owns design decisions.
  • You have gaps in specialist skills such as cloud security engineering, incident response or penetration testing.

Roles and responsibilities that matter

  • Risk owner to align controls with business priorities.
  • Security engineering to design and harden platforms.
  • Operations for monitoring, patching and access governance.
  • Incident response with clear authority to act.


Building an In-House Security Team vs Outsourced Security Support


A Practical 90‑Day Action Plan

  • Baseline your posture
    Inventory identities, devices, critical apps, internet‑facing assets and third parties.
  • Close the high‑impact gaps
    Enforce MFA everywhere feasible. Disable legacy protocols. Review and tighten privileged access.
  • Harden endpoints
    Deploy EDR or XDR to all supported devices. Remove unsupported operating systems where possible.
  • Improve email defences
    Enable advanced phishing controls. Publish and monitor SPF, DKIM and DMARC with alignment.
  • Patch with purpose
    Implement a clear patch cadence and fast‑track critical updates for internet‑facing systems.
  • Secure backups and test restores
    Maintain immutable or isolated copies. Prove you can restore key services within business‑agreed times.
  • Scan for vulnerabilities
    Run internal and external scans. Prioritise based on exploitability and business impact.
  • Strengthen cloud configuration
    Apply baseline policies, guardrails and automated checks in cloud platforms and key SaaS.
  • Train and test people
    Short, regular awareness modules and varied phishing simulations with friendly feedback and easy reporting.
  • Prepare to respond
    Document playbooks, define roles and run a tabletop exercise for a realistic scenario such as business email compromise.


How CyberLab Helps

CyberLab supports organisations with a practical, outcome‑focused approach:

  • Posture assessments and roadmaps aligned to recognised frameworks.
  • Testing and assurance including vulnerability assessments and penetration tests by accredited specialists.
  • Managed detection and response with actionable reporting and co‑managed models.
  • Identity, email and endpoint hardening to raise the baseline quickly.
  • Awareness and simulation programmes that build positive security culture.
  • Certification support for standards such as Cyber Essentials and similar schemes.

If your organisation would like a clear view of current risk and a right‑sized plan to improve, we are available for an initial discussion to align goals, constraints and next steps.

Free Posture Assessment

Understand your security risks and how to fix them.

Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.

Claim your free 30-minute guided posture assessment with a CyberLab expert.

Claim Free Consultation

Manchester Digital Ecommerce Conference 2025

CyberLab Sponsors the Manchester Digital Ecommerce Conference 2025

Championing Innovation in Ecommerce

The future of ecommerce is evolving rapidly, and security is at the forefront of this transformation.

That’s why CyberLab was proud to sponsor the Manchester Digital Ecommerce Conference 2025 – a premier event that brought together key players in ecommerce, digital innovation, and retail technology. The conference served as a dynamic platform for exchanging ideas, showcasing solutions, and driving forward the future of secure online commerce.


Our Commitment to the Ecommerce Sector

The ecommerce landscape is evolving rapidly, with emerging technologies reshaping business operations and consumer interactions.

The Manchester Digital Ecommerce Conference provided a strategic platform to explore critical developments in AI, blockchain, immersive technologies, and data-driven security solutions.


“CyberLab was proud to sponsor and speak at the Manchester Digital Ecommerce Conference 2025.

As online retail continues to thrive, safeguarding digital platforms and customer data from cyber threats has never been more critical. We remain committed to empowering businesses with the tools and expertise they need to innovate securely and confidently.

The event provided a fantastic opportunity to connect with industry leaders, engage with our customers, and help shape the future of secure ecommerce.”

– Gavin Wood, CEO at CyberLab


What Happened at the Conference

Held on 24th April 2025 in Manchester, the Manchester Digital Ecommerce Conference brought together thought leaders from across the industry to explore the evolving intersection of ecommerce and cyber security. The event featured insightful sessions on:

  • AI’s role in enhancing cyber security for ecommerce platforms
  • Blockchain’s impact on security, transparency, and trust in online transactions
  • Emerging threats in the digital commerce landscape and proactive mitigation strategies
  • Data protection and regulatory compliance in a fast-changing environment

CyberLab’s Expert Engagement

As an official sponsor, CyberLab was proud to contribute to the conversation. Our team engaged with attendees to discuss the latest cyber security challenges and shared tailored solutions for the ecommerce sector. Visitors had the opportunity to speak directly with our experts and explore how CyberLab helps protect people, systems, and data in an increasingly complex digital environment.