Industries with the Most Cyber Attacks in the UK

office_workers_cyber_security

With cyber crime becoming increasingly prevalent, many businesses may fall victim to cyber-attacks, but which sectors have experienced the most cyber-attacks?

Indusface.com was keen to investigate further, surveying 2,200 respondents from 16 different industries to discover which sector has experienced the most cyber- attacks, as well as which type of cyber attacks are the most common among businesses. They sked questions such as whether respondents had experienced a cyber attack, and which form of cyber attack they had experienced

According to the survey findings, the Education sector has experienced the most cyber attacks, with 78%of businesses reporting this. 

Nearly half (49%) of UK businesses have experienced a cyber attack, the study found, indicating the evolving threat of cybercrimes to businesses.

 

Key Study findings:

  • Nearly half (49%) of all UK businesses have experienced a cyber attack.
  • 78% of the Education sector have experienced a cyber attack.
  • Over one in four (26%) UK businesses in the Financial Services sector have experienced a cyber attack
  • Email hacking is the most common form of cyber attack (64% of respondents across all businesses fell victim to it).

“The cyber security of any business, whether an SME or a larger corporation, is vital to its integrity,” said Venky Sundar, Founder and President of Indusface. “With technology and the internet being an integral, useful part of how many businesses operate, it is important that every company understands the risks of it being inadequately protected. If cyber-attacks occur, a business can suffer from lost business data, a degraded reputation, and potentially a large financial cost.”

 

Top 10 sectors experiencing the MOST cyber attacks:

 

hooded-cyber-security-attacker

The survey revealed that 83% of the Education sector don’t actively train their employees in cyber security — the third lowest percentage after Transport (89%) and Accommodation (97%).

A cyber attack can have highly problematic outcomes for businesses within the Education sector specifically, such as hackers gaining access to an administrator or teacher’s sessions, and confidential personal information. 

The Arts, Entertainment and Recreation sector ranks second, with 68% of respondents  having experienced a cyber attack. 32% of businesses in the sector are not actively training employees in cyber security. 

This can result in Arts, Entertainment and Recreation businesses experiencing email hacking attacks across industries (61.54%).

The Accommodation and Food sector ranks in third place, with 67% of survey respondents reporting that they have experienced a cyber attack. 97% of respondents in this sector are not actively providing employee training in cyber security.

Top ten sectors experiencing the most cyber-attacks 

Rank

Sector

Percentage of respondents that have

experienced a cyber attack

1

Education

78%

2

Arts, Entertainment and Recreation

68%

3

Accommodation and Food

67%

4

Real Estate Activities

58%

5

Health and Social Care

52%

6

IT and Communications

51%

7

Retail and Wholesale

50%

8

Construction

49%

9

Other Services

47%

10

Public Sector and Defence

46%

 

Email Hacking is the most common form of cyber attack

 

communication-connection-email-messages

Almost two thirds (64%) of all survey respondents reported that email hacking was the method used in their cyber attack, suggesting more training needs to be done in this particular area to ensure the industry can keep its systems safe. 

“While we found that email hacking is the most prevalent, the way it is carried out is very versatile,” said Venky Sundar, Founder and President of Indusface. “Phishing is a much talked about threat, however, bot attacks such as account-takeover and credential stuffing could also be used to hack emails and get access to email accounts.”

“The other method is when hackers exploit an SQL injection vulnerability on a table and extract all credentials through the vulnerability. In addition to training all employees on how to evade phishing attacks, organizations will also find it worthwhile to run regular security assessments and implement a WAAP solution to filter out malicious attacks right at the perimeter before the attacks hit the application servers.” 

 

Industries with the Least Cyber Attacks

 

Meanwhile, the industries with the least cyber-attacks include Financial Services and Admin and support:

Top five sectors that experience the LEAST cyber attacks:

Rank

Sector

Percentage of respondents that have

experienced a cyber attack

1

Financial Services

26%

2

Admin and Support

31%

3

Professional and Technical

32%

=4

Transport

41%

=4

Manufacturing

41%

Sundar concluded by stressing on the importance of cyber security investment and training among all business sectors:

“Finally, it is important to build defenses in depth. All systems are to be designed while assuming that they don’t get compromised even in case an email is hacked. This problem is especially bad in the SME space as security software needs to be constantly updated and the acute shortage of talent and resources mean that SMEs run outdated security software products.”