
Cybercrime is a business risk, not just an IT issue, Shannon Chamber event hears
Helen Downes, CEO, Shannon Chamber (centre) pictured at the Cyber Security event in Shannon College of Hotel Management with (from left); Garda Carmel O’Malley, Shannon Garda Station; Det. Sergeant Colin Bane and Det. Sergeant Mary McCabe, An Garda Síochána’s Cyber Crime Unit; David Cadenhead, Atlantic Aviation Group; Javier Olarreta, JLR; Adrian Sylver, Shannon College of Hotel Management; and Garda Thomas Downey, Shannon Garda Station. Photograph by Eamon Ward
Businesses must treat cybercrime as an organisation-wide risk and ensure they are prepared to respond before an attack occurs, attendees at a Shannon Chamber cybersecurity event were told.
The event, organised by Shannon Chamber in conjunction with An Garda Síochána’s Cyber Crime Unit and hosted by Shannon College of Hotel Management, brought together expertise from An Garda Síochána, Atlantic Aviation Group and JLR to examine the evolving cyber threat facing businesses and the practical measures organisations can take to protect themselves.
Speakers highlighted the increasing sophistication and range of cyber threats, including ransomware, business email compromise and invoice redirection, phishing, supply-chain attacks, and the growing use of deepfakes and voice-changing technology in social engineering.
A key message from the event was that no organisation should assume it is immune from an attack. Cyber criminals use automated tools to scan for vulnerabilities, meaning attacks can be opportunistic rather than directed at a particular company.
Atlantic Aviation Group’s interim chief information officer, David Cadenhead, demonstrated the potentially devastating impact of such an incident when he outlined how the company dealt with a ransomware attack last year.
He explained how senior leadership was immediately mobilised, external legal and forensic expertise was brought in, customers and regulators were informed, and manual processes were introduced while the company’s infrastructure was rebuilt from a clean base.
Javier Olarreta, cybersecurity chapter lead and senior security architect with Jaguar Land Rover, shared insights from the company’s experience of cybercrime and organised vehicle theft, including the measures it has taken in conjunction with law enforcement agencies to counter increasingly sophisticated criminal activity.
He also outlined the far-reaching consequences cyber incidents can have for manufacturing and supply chains, reinforcing the need for businesses to examine third-party access and the security resilience of suppliers throughout their supply chains.
Both speakers stressed that preparation can make a critical difference to how effectively a company responds and recovers. They advised businesses to implement multi-factor authentication and strong access controls; regularly test their backups through full restoration exercises; maintain secure backups separated from their main systems; train staff to recognise phishing and other threats; and understand where their data is held and who can access it.
Companies were also encouraged to have a clear incident response plan identifying who takes responsibility and who must be contacted in the event of an attack, and to test that plan rather than allowing cybersecurity policies to exist solely on paper.
The importance of supply-chain security was also addressed. With businesses increasingly interconnected through banking, IT, finance, HR, ordering and other third-party systems, an organisation’s exposure can extend well beyond its own network.
Commenting on the value of hosting an event of this nature for members, Shannon Chamber CEO Helen Downes said: “The cases presented on the day demonstrated that a cyber-attack is not simply an IT problem; it is a business continuity crisis requiring a coordinated response from across an organisation.
“The message to businesses was clear: while it may not be possible to eliminate the risk of cybercrime, preparation, testing, strong security controls, and collaboration can significantly improve an organisation’s ability to withstand an attack and recover from it.
“This event has prompted us to set up a ‘Business Watch/Cyber Awareness’ Forum to enable businesses to share experiences and lessons learnt. This sharing of experiences, via our Lean, Sustainability, HR and CEO Forums, has proved extremely beneficial for our members and we feel that a forum focused on cyber awareness will deliver additional benefits,” Ms Downes added.
Key practical actions highlighted at the event included:
- Introduce and enforce multi-factor authentication and strong password and access policies.
- Test backups by carrying out full restoration exercises, not simply checking that files have been backed up.
- Keep secure, immutable backups separated from primary systems.
- Train employees regularly on phishing, social engineering and emerging cyber threats.
- Have a simple, clearly understood incident response plan setting out responsibilities and first points of contact.
- Conduct tabletop exercises so management and employees know what to do when an incident occurs.
- Identify the suppliers and systems essential to maintaining minimum business operations.
- Verify payment or account-detail changes through established, independent communication channels.
- Review third-party access and security throughout the supply chain.
