Jersey Financial Services Commission warns of potential cyber attack

Posted: 30/10/2013

The Jersey Financial Services Commission (JFSC) has issued a warning that financial services firms on the island are to be targeted by cyber attacks.

In an email that was sent out to a number of CEOs, compliance officers and relevant individuals at a number of organisations, the JFSC said that it had 'received credible information that Jersey based financial institutions are to be the target of cyber-attacks in the near future. We are advised that the expected attacks will be across multiple threat vectors including Distributed Denial of Service (DDoS) attacks as well as potential email attacks of virus injections.'

It went on to say: 'It is alleged that a splinter group of the 'Anonymous' network (#opbanksters) has “scraped” a significant list of email addresses from local websites and it is anticipated that these addresses will be included in an attack. Other information thought to be in their possession are detailed lists of host-names and IP addresses for use in attacks.'

Commenting on the JFSC email, Matt Palmer, Chairman of the Channel Islands Information Security Forum (CIISF) said: “Local finance companies need to take this warning seriously. We know that hacker groups are targeting the finance sector and we know there is interest in jurisdictions such as Jersey. Whilst it is good to have the warning, we are exposed to this threat every day and it is important that companies take precautions to protect their people and their systems.

"If you have not tested your network and systems to ensure they are resilient against a denial of service attack, now is the time to do so. Few businesses can afford costly interruptions. Putting in place sensible technical controls to detect malware and prevent staff from running unauthorised applications will also help, however it is essential that businesses ensure their staff understand the risks and how to identify a malicious email.”

This is a sentiment echoed by Paul Dutot of Jersey-based security company Cyberkryption on the Digital Quadrant website – who also warns Jersey-based businesses that their websites are a weak link in their security. “One of the first forms of attack is a phishing attack. For this to happen you need valid email addresses," he told DQ. "Attackers will profile a site and the more information they have, the more likely they are to succeed. Also, many websites are not maintained properly or security tested, this weakens the security posture of the site.”

The JFSC recommended that its email be passed on to 'appropriate specialists' in the recipient's company and that appropriate preventative measures be taken, including:
• Ensuring that all antivirus software is up-to-date
• Ensuring that all firewalls and edge security devices are patched up-to-date
• Notifying data network service providers that you anticipate DDoS incidents as they may be able to deploy upstream technologies to mitigate any impact on your services.
• Reviewing cyber security guidelines issued by CESG



Add a Comment

  • *
  • *
  • *
  • *
  • Submit
Kroll

It's easy to stay current with blglobal.co.uk.

Just sign up for our email updates!

Yes please! No thanks!