Existing cybersecurity literature lacks a source of empirical, representative data as to the true nature of cyberattacks on Critical National Infrastructure. We have obtained UK-wide data on incidents reported under the Network and Information Systems (NIS) Regulations in 2024 causing "a significant impact on the continuity" of essential services and comparator data from intelligence agencies. We find that 29% of NIS reports already concern cybersecurity incidents. As the UK Government seeks to extend cybersecurity reporting, we find the NIS Regulations are limited in their effectiveness; whilst our requests revealed 30 cybersecurity incidents reported under the NIS regulations, there were 89 incidents classified as "highly significant and significant" captured by the National Cyber Security Centre in the 2024 reporting year. Whereas 36% of Cybersecurity and Infrastructure Security Agency reported attacks concerned espionage, from NIS data we find 100% NIS-reportable cyberattacks concerning healthcare systems in England in 2024 were ransomware.
翻译:现有网络安全文献缺乏关于关键国家基础设施网络攻击真实情况的实证性、代表性数据来源。我们获取了2024年依据《网络与信息系统条例》报告的、对关键服务连续性造成"重大影响"的英国范围内事件数据,以及情报机构提供的对比数据。研究发现,29%的《网络与信息系统条例》报告已涉及网络安全事件。在英国政府拟扩大网络安全报告范围的背景下,我们发现该条例的有效性存在局限:尽管我们的申请获取了30起依据该条例报告的网络安全事件,但国家网络安全中心在2024年报告年度捕获了89起被归类为"具有高度显著性和显著性"的事件。相较于网络安全与基础设施安全局报告的36%攻击涉及间谍活动,我们从该条例数据中发现,2024年英格兰地区依据该条例可报告的医疗系统网络攻击中100%为勒索软件攻击。