Existing cybersecurity literature lacks a source of empirical, representative data as to the true nature of cyberattacks on Critical National Infrastructure. We have obtained UK-wide data on incidents reported under the Network and Information Systems (NIS) Regulations in 2024 causing "a significant impact on the continuity" of essential services and comparator data from intelligence agencies. We find that 29% of NIS reports already concern cybersecurity incidents. As the UK Government seeks to extend cybersecurity reporting, we find the NIS Regulations are limited in their effectiveness; whilst our requests revealed 30 cybersecurity incidents reported under the NIS regulations, there were 89 incidents classified as "highly significant and significant" captured by the National Cyber Security Centre in the 2024 reporting year. Whereas 36% of Cybersecurity and Infrastructure Security Agency reported attacks concerned espionage, from NIS data we find 100% NIS-reportable cyberattacks concerning healthcare systems in England in 2024 were ransomware.
翻译:现有网络安全文献缺乏关于关键国家基础设施网络攻击真实性质的实证性、代表性数据来源。我们获取了2024年根据《网络与信息系统(NIS)法规》报告的、对基本服务连续性造成重大影响的全英国事件数据,以及来自情报机构的对比数据。研究发现,29%的NIS报告已涉及网络安全事件。在英国政府寻求扩展网络安全报告范围之际,我们注意到NIS法规的有效性存在局限性:尽管我们的请求显示有30起根据NIS法规报告的网络安全事件,但国家网络安全中心在2024报告年度捕获了89起被归类为"高度重大和重大"的事件。相比之下,网络安全与基础设施安全局报告的36%攻击涉及间谍活动,而根据NIS数据,我们发现2024年涉及英格兰医疗系统的、符合NIS报告要求的网络攻击中,100%为勒索软件攻击。