24.01.2023
Blog
Cyber Security

Protecting critical infrastructure against cybercrime

Over the past twelve months, operators and suppliers of critical infrastructure have been targeted by cybercriminals at an above-average rate. One KRITIS sector in particular is ill-equipped to deal with these attacks. Our subsidiary, Radar Cyber Security, has summarised which sector this is and how those affected can protect themselves.

Heike Abels
Referentin für Unternehmenskommunikation

Current geopolitical tensions and conflicts have given rise to political and economic difficulties worldwide. Another threat that must not be underestimated is that of targeted cyber-attacks by states that perceive their own interests – or those of countries with which they are allied – to be at risk.

The KRITIS sectors most frequently affected in Germany are the energy and water sectors, telecommunications and the financial sector. In around half of the attacks on critical infrastructure, economic cycles, human lives and, ultimately, the functioning of our society in Europe were put at risk (according to Bitkom, Economic Security Study 2022). One thing seems certain: the number of such incidents will not decrease.

Financial sector particularly at risk

The financial sector is regarded as one of the most vulnerable sectors of critical infrastructure – despite stringent legal regulations. When it comes to information security, financial service providers exhibit above-average levels of shortcomings in the area of technical information security compared to other critical infrastructure sectors. This is described by the BSI in its 2021 Report on the State of IT Security in Germany. The reasons for this lie in the sector’s advanced level of digitalisation. Distributed denial-of-service (DDoS) attacks are particularly common; in the worst-case scenario, these are accompanied by ransomware attacks. Six-figure ransom demands are by no means uncommon.

Managed Security Service or an in-house security operations centre?

Digitalisation and safeguarding business continuity have become top priorities in the financial sector. Cyber security has now become a decisive factor at board level for the further development of financial services.

Managed security service providers can make a significant contribution to business continuity in the financial sector. In financial firms where it is not (yet) possible to set up an in-house security operations centre, a Cyber Defence Centre (CDC) – also known as a Security Operations Centre (SOC) – can, for example, be commissioned.

According to a recent Lünendonk study on cyber security in the financial sector, 24 per cent of clients in the German financial sector are already relying on these security services. The IT monitoring solutions and a Risk & Security Cockpit are set up and deployed directly on-site at the client’s premises. Customer data never leaves the client’s corporate environment at any point during the provision of the service. Currently, around 14 per cent of organisations in the financial sector already operate their own Cyber Defence Centre (Lünendonk study). The trend towards companies in this sector establishing their own security control centres is expected to double over the next five years.

The flood of cyber attacks on critical infrastructure, particularly in the financial sector, is set to intensify further in the future. Consequently, those organisations that invest comprehensively in the early detection of cyber threats will be best protected against far-reaching consequences such as financial losses and reputational damage.

Source: Radar Cyber Security

Heike Abels
Referentin für Unternehmenskommunikation

Heike Abels arbeitet bei Materna als Referentin für Unternehmenskommunikation. Sie betreut redaktionell verschiedene Formate für die externe Kommunikation. Thematischer Schwerpunkt ist der Bereich Cross Market Services. Dazu zählen Enterprise Service Management, Customer Service und Cyber Security.