CyberLab Deliver an Attack Simulation In Front Of Cyber Crime Police
The CyberLab Team Delivered an Attack Simulation in Front of Over 30 Eastern Region Special Operations Unit (ERSOU) Officers
CyberLab’s penetration testing team of CREST, CHECK, and Cyber Scheme accredited engineers and Wayne Price, Commercial Director, delivered a live hack demonstration in front of ERSOU officers.
Over 30 attendees, a mix of Cyber Protect officers providing signposting and advice to individuals and organisations within the region and Cyber Pursue officers investigating cyber crime, joined the event to see how malicious agents can break into an organisation’s network in less than 5 minutes.
The CyberLab Penetration Testing Engineer, Alexandru Blanaru, showcased how an attacker can exploit multiple attack vectors to penetrate a network, escalate access, and breach valuable data. Together Wayne Price and Alex Blanaru covered the best cyber security practices organisations can adopt to protect their data.
“It is always great to collaborate with industry to ensure that, through shared learning, we remain at the forefront of protecting the region from cyber threats.
“The input from CyberLab helped our officers and investigators develop their skills around the complexities of different attack methodologies, and how they could be used by criminals.
“This, in turn, allowed further discussion about preventative measures, both technical and behavioural, to better inform our advice to the public.”
– John Greenwood, Cyber Protect Co-ordinator at ERSOU
Created in 2010, ERSOU operates across the seven police forces that make up the Eastern Region – Bedfordshire, Cambridgeshire, Essex, Hertfordshire, Kent, Norfolk and Suffolk.
It is made up of a Regional Organised Crime Unit (ROCU) and a Counter Terrorism Policing unit, which respectively manage the threat of serious and organised crime and terrorism across the region.
Working closely with local forces, external stakeholders and partners such as the NCA, the ROCU tackles and disrupts organised criminality such as drugs and firearms importation, cyber attacks, large-scale fraud, and much more.
“It was an honour to be invited to present in front of the Eastern Region Special Operations Unit, deliver the attack simulation and discuss the latest trends our team of engineers discover during their work in the field.
The cyber team at ERSOU are doing an amazing job operating in an incredibly complex and ever-evolving field and Dark Web”
– Wayne Price, Commercial Director at CyberLab
What is Penetration Testing?
Penetration Testing is a way to identify vulnerabilities before attackers do, evaluate how effectively companies can respond to security threats, assess compliance with security policies, and improve the level of security awareness among staff.
Using industry-standard methodologies, 15 of the UK’s top Penetration Test experts, our team of CREST, CHECK, and Cyber Scheme approved engineers undertake ethical attack simulations to uncover areas of concern in infrastructure, policies, and procedures.
The CyberLab team delivers attack simulations and educational sessions as part of customer and public engagements, as well as at events and industry conferences.
About CyberLab
CyberLab is a specialist cyber security company that provides a wide range of security solutions and services.
Your one-stop cyber security advisor, the CyberLab team is equipped with the right technology, knowledge, and expertise to help businesses of all sizes, including large public sector organisations.
By leveraging world-class technology, decades of experience, and their extensive vendor partnerships, CyberLab have helped to secure thousands of organisations across the UK.
Our unique Detect, Protect, Support approach makes us the perfect partner to review and reinforce your cyber security defences.
To contact the CyberLab Team, email [email protected].
About Eastern Region Special Operations Unit (ERSOU)
ERSOU’s ROCU leads the response to organised crime across the region.
Working closely with local forces, external stakeholders and partners such as the NCA, the ROCU tackles and disrupts organised criminality such as drugs and firearms importation, cyber attacks, large-scale fraud, and much more.
The team’s work has also been showcased several times on Channel 4’s 24 Hours in Police Custody.
To contact the ERSOU press office, email ERSOU Corporate Communications:Â [email protected].
Free Posture Assessment
Understand your security risks and how to fix them.
Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.
Claim your free 30-minute guided posture assessment with a CyberLab expert.
Strategies to Strengthen Your Cyber Resilience for Hybrid Working
Key Considerations in a World of Hybrid Work
A recent survey by Forbes found that 63% of respondents worked remotely or in a hybrid model, showcasing that even years after the COVID 19 pandemic, hybrid working remains the norm. The importance of securing employees and the systems they access, whether they are working in the office or remotely, cannot be understated.
In this blog, we discuss distributed nature of hybrid working, the risks and cyber threats that hybrid working organisations are exposed to, alongside some recommendations and best practices that organisations can implement for securing hybrid and remote working environments.
Remote and Hybrid Working in the UK: Before and After the Pandemic
According to a report by the Wales Institute of Social and Economic Research and Data (WISERD) just 4.7% of UK employees worked from home in 2019, prior to the COVID-19 pandemic. However, by April 2020, 46.6% of employees did at least part of their job from home, and in 2022, a quarter of all UK employees worked in hybrid environments and 13% were working fully remotely.
The speed and scale at which the pandemic shifted a significant portion of UK’s workforce to hybrid/remote working, underscores the massive increase in cyber threats and incidents that followed, and the challenges that businesses and organisations would need to address in order to adapt. [source: ONS]
Cyber Threats and Risk Implications for Hybrid Working
Cyber attacks Up 238% Since the Pandemic
According to a study by Alliance Virtual Offices, the frequency of cyber attacks has surged by 238% since the shift to widespread remote working, largely driven by vulnerabilities in home networks and personal devices. Remote work has also increased the cost of data breaches for companies by an average of ÂŁ104,077 (converted from $USD). Despite this, only 56% of remote employees receive regular cyber security training, increasing the risks for organisations operating in a more digital environment. [source:Â Yahoo Finance]
BYOD and Home Networks Expand Attack Surface
Research from Lookout found that 32% of remote workers use apps not approved by their company’s IT department, and 90% access corporate networks from multiple locations, including coffee shops and public Wi-Fi, which increases cyber risk. This can also increase exposure to threats like phishing and malware attacks, especially as 46% of employees save work files on personal devices. [source: IT Security Guru]
Common Attack Vectors – An increase in RDP Abuse
In light of so many organisations migrating to remote/hybrid working models, threat actors have turned their sights to exploiting remote/virtual desktop technologies as a means of bypassing external defensive parameters and gaining a foothold on the internal network.
Remote desktop protocol (RDP) is a common method for establishing remote access on Windows systems. According to a recent report by Sophos found that cyber criminals abused remote desktop protocol in 90% of attacks. This was the highest incidence of RDP abuse since Sophos began releasing its Active Adversary reports in 2021, covering data from 2020.
Remote Work Security Gaps
Cyber security experts also warn that hybrid work models expose companies to new risks. Remote workers that use unsecured personal devices and networks are a target for cyber criminals as they increasingly target collaboration apps like Slack and Teams to launch social engineering attacks. With the introduction of faster 5G networks, attacks on mobile devices are also expected to rise, as noted by UpGuard.
Cyber Threats and Risk Implications for Hybrid Working
The evolution of digital security is now at a pivotal point. The old models, based on clear boundaries between “inside” and “outside,” no longer hold. IT and InfoSec teams now have to contend with much greater digital attack surfaces, endpoint and firmware management challenges and company-wide adherence to remote/hybrid working policies.
A Forrester study in 2023, found that remote and hybrid working models has magnified IT operational challenges for 75% of participating organisations. Below are some best practices and essentials for secure remote/hybrid working models:
Implement Strong Access Controls
Organisations must ensure that only authorised users can access corporate systems. This includes multi-factor authentication (MFA) and device authentication, which requires pre-registering devices before allowing network access. Zero-trust security models that continuously verify user identities and devices are also highly recommended for hybrid environments (Security Boulevard).
Adopt Zero Trust Architecture
Zero Trust is an architectural approach where inherent trust in the network is removed, the network is assumed hostile, and each request is verified based on an access policy. By implementing a “never trust, always verify” approach to network security, requiring continuous authentication and least-privilege access to ensure that every request—whether from inside or outside the network—is fully verified before access is granted, organisations can significantly reduce lateral movement from possible threat actors and improves security across cloud, on-premises, and hybrid environments. NIST has published further guidance on Zero Trust Architecture here.
Develop and Enforce a BYOD Policy, Using Encryption and Backups
Clear policies for using personal devices for work must be established, covering security measures such as mandatory installation of security software and limiting personal use on company devices, while limiting the amount of access through personal devices. This minimises the risk of unauthorised access and data leakage.
Encrypting all stored data on devices used for remote work adds an extra layer of protection in case of theft or unauthorised access. It’s also essential to back up important data regularly, ensuring it can be restored in the event of a cyber attack or system failure. Additionally, enabling remote wipe capabilities for lost or compromised devices ensures sensitive data can be erased quickly.
Use Secure Networks and Tools
Remote workers should avoid public Wi-Fi where possible due to its high vulnerability. Instead, they should rely on personal hotspots or secure VPNs, which encrypt data and protect it from potential attackers on unsecured networks. Similarly, using secure video conferencing platforms and company-approved email systems helps reduce the risk of unauthorised access to communications.
Regular Penetration Testing and Red Teaming
Penetration testing and Red Team exercises are crucial for identifying vulnerabilities across their external and corporate networks, applications or devices before attackers can exploit them. By conducting Targeted Attack Simulations (TAS) or Red Team exercises that simulate exploiting vulnerabilities or gaps in remote/hybrid working environments companies can evaluate their overall security posture of their remote working infrastructure and focus resources on vulnerable areas to improve their defences against such attack vectors.
Regular Software Updates and Endpoint Protection
Ensuring that all devices, including personal ones used for work (BYOD), have up-to-date antivirus and firewall protection is crucial.
Regularly updating and patching software, coupled with continuous vulnerability assessments, is vital for maintaining a secure infrastructure. Cyber security as a Service (CSaaS) solutions, such as HackRisk, can help companies manage vulnerabilities effectively without overburdening internal teams.
Phishing and Social Engineering Awareness Training
Employees are often the first line of defence against cyber threats. Regular training sessions on phishing, social engineering, and secure data handling can significantly reduce the risk of human error leading to a security breach
Managed Detection and Response (MDR)
Endpoint detection alone is no longer sufficient given today’s digital threat landscape. Organisations must now employ an “always-on” threat detection and monitoring capability. However, employing and retaining qualified cyber security analysts, engineers can very expensive and hard to come by, let alone the continuously high costs of using XDR and SIEM technologies. Running a 24/7 SOC (Security Operations Centre) in-house with experienced analysts and security experts with state-of-the-art defensive technologies are typically reserved for multi-national conglomerates and banks.
MDR services (Managed Detection and Response) provide continuous monitoring and analysis of an organisation’s entire estate, including endpoints, network traffic and activity logs. By outsourcing to experts, firms can ensure that threats are detected and mitigated in real-time, reducing the risk of a successful attack.
Free Posture Assessment
Understand your security risks and how to fix them.
Take the first step to improving your cyber security posture, looking at ten key areas you and your organisation should focus on, backed by NCSC guidance.
Claim your free 30-minute guided posture assessment with a CyberLab expert.

