Report warns of the CNI security impacts of economic hardship including insider threats, social engineering attacks, and reduced cyber budgets. Credit: whiteMocca / Shutterstock The cost-of-living crisis could trigger a rise in cyberattacks and security risks impacting UK critical national infrastructure (CNI). That’s according to new research by UK cybersecurity services firm Bridewell, which surveyed 500 UK cybersecurity decision makers in the transport and aviation, utilities, finance, government, and communications sectors. The Cyber Security in Critical National Infrastructure Organisations: 2023 report found that over a third (34%) of organisations across UK CNI anticipate a rise in cybercrime as a direct result of the current economic crisis.The findings come as the ongoing Russia-Ukraine war squeezes oil and gas flows to the UK, causing a spike in prices for fuel and food.Economic downturn may increase insider threats, social engineering attacksThe rising cost of living is putting employees and organisations under increased financial strain. As focus turns to financial stability, security issues could be sliding down the priority list, creating opportunities for insider threats to go unnoticed, the report read.The rising cost of living could lead to an increase in insider threats and employee crime, as workers increasingly steal from their employers to make ends meet, the report said. Over a fifth (21%) of CNI decision makers surveyed now rank employee sabotage among the biggest risks to their organisation’s IT environment. Meanwhile, organised criminal groups could be primed to exploit people’s vulnerabilities by reaching out to individual employees within an organisation, offering them a lucrative payoff in return for access to sensitive data or protected systems. A third (33%) of respondents expect the prevalence of phishing and social engineering attacks to grow because of economic downturns, suggesting that threat actors could prey on employees’ financial fears to gain illicit access to CNI data and systems.Reduced cybersecurity budgets add to CNI security risksAside from evolving security threats, the economic pressures facing CNI are causing some UK organisations to re-evaluate their cyber spend. Almost two-thirds (65%) of respondents across UK CNI have seen some reduction or a significant reduction in their organisation’s cybersecurity budget this year, in sharp contrast to 2022, when cybersecurity budgets rose across all sectors, the report stated. The communications sector has been impacted the least by cybersecurity budget cuts, with almost half (48%) seeing no change in cybersecurity budgets. However, the transport and aviation and utilities sectors (including energy, oil, and gas) have experienced the greatest fall in cyber budgets, with 73% and 69% of respective respondents seeing some reduction or a significant reduction, the research found.CNI must strengthen cyber defences from the inside outAmid increased security risks and decreasing security budgets, IT, and security leaders in the CNI sector must invest in strengthening their cyber defences from the inside out, said Anthony Young, Co-CEO at Bridewell. This should encompass the robust monitoring and testing of systems and access controls, investment in data loss prevention, and the continuous education and training of employees to raise awareness of cyber security best practices.”Last September, the UK’s National Cyber Security Centre (NCSC) released a new version of the Cyber Assessment Framework (CAF) to support CNI organisations that are subject to the Network and Information Systems (NIS) regulations and organisations managing cyber-related risks to public safety. The release came in the wake of research which revealed that the UK CNI sector is struggling to address software supply chain risks and cyber skills shortages. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe