UK: Advice For Your Business Following The Meltdown And Spectre CPU Flaw Revelations

Last Updated: 8 January 2018
Article by William Haig and Beth Price
Taylor Vinters

Cybersecurity has hit the headlines again this week with news of two critical security flaws in the architecture of the central processing units (CPUs) of the world's three largest chip producers, including Intel.

The bugs, known as Meltdown and Spectre, affect nearly every computer and device. They allow access to potentially sensitive data via unencrypted kernel and system memory, previously assumed to be protected at a hardware level.

There is currently no evidence that the flaws have been used by criminals. However, now that their existence has entered the public domain, we are likely to see a surge in malicious activity as hackers scramble to exploit the vulnerabilities before they can be patched.

Growing risks

As software companies rush out security patches and Intel and others are forced to redesign their CPU architecture from the ground up, it is vital that businesses prioritise cybersecurity.

As companies continue to generate and store ever-increasing volumes of personal and commercially sensitive data, the incentives for a cyber-attack are growing. This risk is further exacerbated by the increasing interconnectivity of devices and appliances known as the Internet of Things.

The number of companies affected by cybercrime is also rising. According to PwC's Global State of Information Security Survey 2018, 29% of respondents reported loss or damage of internal records as a result of a security incident. These numbers are likely to dramatically underestimate the true figures, as a further 28% reported that they simply did not know how many cyber-attacks they had had.

Preparing for an attack

Although businesses can't eliminate the risk of a cyberattack, they can dramatically reduce it by following these steps:

The consequences

A data breach can cause significant business disruption and financial costs combined with potential irreparable reputational damage.

Even if a breach stems from the Meltdown and Spectre bug, this will not absolve a company which loses its data or that of its customers. The potential claims and sanctions could cost anywhere from tens of thousands to millions of pounds.

On top of this, a company hit by a data breach will have to manage the storm of negative publicity and invest in trying to regain the trust of their customer base. Every minute staff and management spend trying to close this digital Pandora's box means less time is spent on the day-to-day running of the business incurring further cost and resources.

No matter whether your business is large or small, you are faced with the same risks, so make sure you put measures in place to minimise these and ensure a fast and effective response should your business suffer an attack.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

To print this article, all you need is to be registered on Mondaq.com.

Click to Login as an existing user or Register so you can print this article.

Authors