Met should thoroughly investigate cyber security practices, say experts

27 August 2023, 12:24

The New Scotland Yard sign
Racist WhatsApp messages charges. Picture: PA

Scotland Yard said it was made aware of ‘unauthorised access to the IT system of one of its suppliers’.

Metropolitan Police chiefs should carry out a thorough investigation of the force’s cyber security practices following an IT breach, industry experts have said.

Scotland Yard said on Saturday that it had been made aware of “unauthorised access to the IT system of one of its suppliers”.

The company in question had access to names, ranks, photos, vetting levels and pay numbers for officers and staff.

The force is now working with the company to understand if there has been any security breach relating to its data, and was unable to confirm how many personnel might be affected.

Cyber security experts said the possible data breach is “extremely worrying” but unsurprising as cyber attackers frequently target third-party companies.

Jake Moore, global cyber security adviser for software firm ESET, told the PA news agency: “This is another extremely worrying episode of what we seem to be seeing quite a lot of this year.

“It’s just worrying to think these police forces are coming under attack in what I would suggest are relatively simple ways.”

Mr Moore said the current suspected breach appears to have been “a targeted attack to test the security within the supply chain” where criminals were “looking for the weakest link”.

He added: “The Met Police are extremely good at keeping their own data secure, but they do use third parties.

“As they have to use these parties, if they aren’t up to date with their own security then that becomes a weakness that could be targeted.”

Mr Moore suggested that current cyber security systems used by police forces, coupled with a lack of resources, may have led to flaws opening up.

He said: “It’s not impossible to stop this. It’s to do with understanding where all your data is.

“When you amalgamate systems, particularly when police forces join together, they tend not to understand completely where all their data is or who has access to it, and that can cause problems down the line.

“They need to do a complete analysis on who has access, why they have access to their data, and to reduce all of those weak points as best they can.

“It will take time – not necessarily too much money – but it will take resources and people power to mitigate this in the future, and hopefully something like this will shake the boots of all the chiefs around the country to wake up and act faster.”

Kevin Curran, professor of cyber security at Ulster University, agreed that the breach is likely to be down to “a third-party supplier issue”.

He said: “I’m not surprised really – data breaches are such a common occurrence and police are no exception.

“They have the same resources as a lot of other companies, where any data systems which have external access to the internet are a risk.”

Mr Curran said questions need to be asked about why third parties have access to such information, and if the Met has the right data classification methods in place.

He added: “It boils down to resources. Every organisation has to allocate a percentage of their IT budget to cyber security.

“It’s a publicly-funded organisation so there’s only a finite amount of resources you have, but we do have best practices and guidelines in the industry on how to protect the systems, so maybe it comes down to someone conducting an external audit in the aftermath to see whether or not they are following these practices.”

By Press Association

More Technology News

See more More Technology News

Peter Kyle answers a question while appearing on the BBC's Sunday with Laura Kuenssberg show

Tech giants must obey UK’s online safety laws, says minister

Peter Kyle

UK must not let AI ‘wash over our economy’, says Science Secretary

Online safety laws must constantly adapt along with tech, says minister

Online safety laws must constantly adapt along with tech, says minister following criticism from Molly Russell's father

Peter Kyle speaks to the press outside Broadcasting House in London

UK will not pit AI safety against investment in bid for growth, says minister

Molly Russell who took her own life in November 2017 after she had been viewing material on social media

UK going ‘backwards’ on online safety, Molly Russell’s father tells Starmer

Ellen Roome with her son Jools Sweeney

Bereaved mother: Social media firms ‘awful’ in search for answers on son’s death

A remote-controlled sex toy

Remote-controlled sex toys ‘vulnerable to attack by malicious third parties’

LG AeroCatTower (Martyn Landi/PA)

The weird and wonderful gadgets of CES 2025

Sinclair C5 enthusiasts enjoy the gathering at Alexandra Palace in London

Sinclair C5 fans gather to celebrate ‘iconic’ vehicle’s 40th anniversary

A still from Kemp's AI generated video

Spandau Ballet’s Gary Kemp releases AI generated music video for new single

DragonFire laser weapon system

Britain must learn from Ukraine and use AI for warfare, MPs say

The Pinwheel Watch, a smartwatch designed for children, unveiled at the CES technology show in Las Vegas.

CES 2025: Pinwheel launches child-friendly smartwatch with built in AI chatbot

The firm said the morning data jumps had emerged as part of its broadband network analysis (PA)

Millions head online at 6am, 7am and 8am as alarms go off, data shows

A mobile phone screen

Meta ends fact-checking on Facebook and Instagram in favour of community notes

Mark Zuckerberg

Meta criticised over ‘chilling’ content moderation changes

Apps displayed on smartphone

Swinney voices concern at Meta changes and will ‘keep considering’ use of X