-
-
FOI request (FOIR-431163803)
Council cyber-attacks
Requested Tue 21 June 2022
Responded Tue 28 June 2022For all relevant questions below, please provide data broken down into calendar year (2018, 2019, 2020, 2021, and 2022 to date), or failing that, by relevant 12-month period (2018/19, 2019/20, 2020/21, 2021/22, 2022/23).
1. How many times has your council experienced an attempted cyber-attack over each of the past five years?
2. Of these attacks, how many resulted in the criminal being able to obtain data or disable systems?
3. Thinking about cyber-attacks where the criminal was able to obtain data or disable systems, how much have these cost your council in each of the past five years? If possible, please include the sum total of monies lost to hackers, legal costs and GDPR fines.
4. What is the most common type of cyber-attack your council has experienced in 2022 so far (for example phishing, DDoS, ransomware, password attack, malware, insider attacks)?
5. In the last 12 months have you employed an external expert to give you advice on how to mitigate the risk of cyber-attacks? If you have but not in the last 12 months please state when.
6. Does your council currently hold a cyber-insurance policy to protect against the consequences of a cyber-attack?
7. If so, have you claimed on this policy?
-
8. Have you increased cyber security in the last year to mitigate the risk of cyber-attacks?
9. When did your council last hold training for employees aimed at reducing the role of human error in cyber-attacks and data breaches (for example, to prevent phishing)?
10. Where on your corporate risk register is cyber risk ranked?
Response
Notice of Refusal
Disclosure of information relating to ICT infrastructure and security constitutes a security risk as it would leave the Council's computer assets more vulnerable to a malicious hacking attack. This means that disclosure would:
• Make the Council more vulnerable to crime (Section 31)
• Risk harming the systems on which the day-to-day business of the Council relies (Section 43)
Section 31 (Law Enforcement)
Section 31(1)(a) states that information is exempt if its disclosure is likely to prejudice the prevention or detection of crime. ICO guidance states that this can be used to protect information on a public authority's systems which would make it more vulnerable to crime. This exemption can be used by a public authority that has no law enforcement function:
• To protect the work of one that does
• To withhold information that would make anyone, including the public authority itself, more vulnerable to crime
The crime in question would be a malicious attack on the Council's computer systems. Since the disclosure of the withheld information would make the Council's systems more vulnerable to such crime, the exemption is engaged.
The exemption is subject to the public interest test. There is an overwhelming public interest in keeping the Council's computer systems secure which would be served by non-disclosure. This outweighs the public interest in accountability and transparency that would be served by disclosure.
Section 43 (Commercial Interests)
Section 43(2) states that information is exempt if its disclosure would, or would be likely to, prejudice the commercial interests of any person (including the public authority holding it).
Disclosure of information relating to ICT infrastructure and security puts the council at risk of a malicious hacking attack.
This would compromise the Council's ability to provide its services and carry out 'business-as-usual' should our systems be compromised. Were our systems to be compromise, the cost of a system recovery would be detrimental to the Council's commercial interests.
The exemption is subject to the public interest test. There is an overwhelming public interest in keeping the Council's computer systems secure which would be served by non-disclosure. This outweighs the public interest in accountability and transparency that would be served by disclosure.
Freedom of Information
Contact
Contact us if you have a question about democratic services.
Comments
The content on this page is the responsibility of our Democratic Services team.