Abstract
With Covid-19 creating an unexpected worldwide situation that has brought about changes to the way that people have had to go about their everyday lives, organizations have also had to change their business practices to comply with social distancing guidance, meaning the adoption of remote work solutions where possible. There has also been an observed increase in Cyber attacks, that risk taking advantage of these sudden changes. This paper analyzes the effect of Covid-19 on remote working practices and the Cybersecurity threat landscape. The research has shown an indication that Cybercriminals and Advanced Persistent Threat actors have adapted common attacks such as phishing and teleconferencing vulnerabilities, to take advantage of the confusion and fear surrounding Covid-19. There is a suggestion that the larger or more technically focused organizations within the UK were best prepared and least affected by the move to remote work yet also had a general lack of policies and plans in the event of pandemics and natural disasters that might affect security operations. Based on these observations, it is recommended that organizations collaborate more and aim to explore the possibility of creating regional cyber first responder groups to help organizations in future situations like Covid-19. It can also be recommended that organizations introduce more tailored cyber security awareness training based around threats of remote working. Also to introduce pandemic related policies and plans into business continuity strategies, as standard. This should also contain plans covering who is responsible for what action or roles in an emergency and what to do if security teams are reduced in size.
Keywords
- Cyber-attacks
- Advanced persistent threat
- Covid-19
- Pandemic
- Cyber first responders
- Security operations
This is a preview of subscription content, access via your institution.
Buying options
Tax calculation will be finalised at checkout
Purchases are for personal use only
Learn about institutional subscriptionsReferences
PWC (2020) Managing the impact of Covid-19 on cyber security. https://www.pwccn.com/en/issues/cybersecurity-and-data-privacy/covid-19-impact-mar2020.pdf. Accessed 10 June 2020
Barracuda Networks (2020) Surge in security concerns due to remote working. https://blog.barracuda.com/2020/05/06/surge-in-security-concerns-due-to-remote-working-during-covid-19-crisis/. Accessed 14 June 2020
Crowdstrike (2020) Survey results: securing remote workforces during COVID19. https://www.crowdstrike.com/blog/global-survey-the-cybersecurity-reality-of-the-covid-19-remote-workforce/. Accessed 19 June 2020
Controlrisks (2020) COVID-19 and remote working. https://www.controlrisks.com/our-thinking/insights/covid-19-and-remote-working. Accessed 23 June 2020
Novetta (2020) COVID-19’s impact on cybersecurity incident response. https://www.novetta.com/2020/05/cyber-covid/. Accessed 24 June 2020
Europol (2020) Catching the virus cybercrime, disinformation and the COVID-19 pandemic. https://www.europol.europa.eu/publications-documents/catching-virus-cybercrime-disinformation-and-covid-19-pandemic. Accessed 16 June 2020
Interpol (2020) COVID-19 cyberthreats. https://www.interpol.int/en/Crimes/Cybercrime/COVID-19-cyberthreats. Accessed 19 June 2020
KPMG (2020) The rise of ransomware during COVID-19. https://home.kpmg/xx/en/home/insights/2020/05/rise-of-ransomware-during-covid-19.html. Accessed 18 June 2020
ESET (2020) ESET issues Q2 2020 Threat Report - cybercriminals cash in on users adjusting to a covidian world. Retrieved from https://www.eset.com/uk/about/newsroom/press-releases/eset-issues-q2-2020-threat-report-cybercriminals-cash-in-on-users-adjusting-to-a-covidianworld-1/
Portswigger (2020) DDoS surge driven by attacks on education, government, and coronavirus information sites. https://portswigger.net/daily-swig/ddos-surge-driven-by-attacks-on-education-government-and-coronavirus-information-sites. Accessed 17 June 2020
Kaspersky (2020) DDoS during the COVID-19 pandemic: attacks on educational and municipal websites tripled in Q1 2020. Retrieved from https://usa.kaspersky.com/about/press-releases/2020_ddos-during-the-covid-19-pandemic-attacks-on-educational-and-municipal-websites
KnowBe4 (2020) Q1 2020 coronavirus-related phishing email attacks are up 600%. https://blog.knowbe4.com/q1-2020-coronavirus-related-phishing-email-attacks-are-up-600. Accessed 20 June 2020
KnowBe4 (2020) The dilemma: should you phish test during the COVID-19 pandemic? https://blog.knowbe4.com/the-dilemma-should-you-phish-test-during-the-covid-19-pandemic. Accessed 21 June 2020
NASA (2020) NASA CIO agencywide memo: alert: cyber threats significantly increasing during coronavirus pandemic. http://spaceref.com/news/viewsr.html?pid=53512. Accessed 21 June 2020
TEISS (2020) Cyber criminals using Gov.uk and HMRC logos in new phishing campaign. Retrieved from https://www.teiss.co.uk/gov-uk-hmrc-phishing-scam/
Steed D (2020) Inicio. http://www.realinstitutoelcano.org/wps/portal/rielcano_en/contenido?WCM_GLOBAL_CONTEXT=/elcano/elcano_in/zonas_in/cybersecurity/ari94-2020-steed-covid-19-reaffirming-cyber-as-21st-century-geopolitical-battleground. Accessed 24 June 2020
EEAS (2020) INTERNAL coronavirus 3rd information environment assessment. https://www.documentcloud.org/documents/6877118-INTERNAL-Coronavirus-3rd-Information-Environment.html. Accessed 20 June 2020
NCSC (2020) Advisory: APT29 targets COVID-19 vaccine development. https://www.ncsc.gov.uk/files/Advisory-APT29-targets-COVID-19-vaccine-development-V1-1.pdf. Accessed 22 June 2020
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2021 The Author(s), under exclusive license to Springer Nature Switzerland AG
About this chapter
Cite this chapter
Lloyd, E., Ibbotson, G., Pournouri, S. (2021). An Investigation into the Impact Covid-19 Has Had on the Cyber Threat Landscape and Remote Working for UK Organizations. In: Jahankhani, H., Kendzierskyj, S., Akhgar, B. (eds) Information Security Technologies for Controlling Pandemics. Advanced Sciences and Technologies for Security Applications. Springer, Cham. https://doi.org/10.1007/978-3-030-72120-6_6
Download citation
DOI: https://doi.org/10.1007/978-3-030-72120-6_6
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-030-72119-0
Online ISBN: 978-3-030-72120-6
eBook Packages: Computer ScienceComputer Science (R0)