Cyber attacks

Cyber attacks experienced by the council

28 August 2022

Your requests

  1. How many times has your council experienced an attempted cyber-attack over each of the past five years? For this and all relevant questions below, please provide data broken down into calendar year including 2022 to date, or failing that, by relevant 12-month period (e.g. 2020/21, 2021/22 etc.) · 2022 · 2021 · 2020 · 2019 · 2018
  2. Of these attacks, how many resulted in the criminal being able to obtain data or disable systems? · 2022 · 2021 · 2020 · 2019 · 2018
  3. thinking about cyber-attacks where the criminal was able to obtain data or disable systems, how much have these cost your council in each of the past five years? If possible, please include the sum total of monies lost to hackers, legal costs and GDPR fine - · 2022 · 2021 · 2020 · 2019 · 2018
  4. what is the most common type of cyber-attack your council has experienced in 2022 so far? (e.g. phishing, DDoS, ransomware, password attack, malware, insider attacks)
  5. in the last 12 months have you employed an external expert to give you advice on how to mitigate the risk of cyber-attacks? If you have but not in the last 12 months please state when.
  6. does your council currently hold a cyber-insurance policy to protect against the consequences of a cyber-attack?
  7. if so, have you claimed on this policy?
  8. have you increased cyber security in the last year to mitigate the risk of cyberattacks?
  9. when did your council last hold training for employees aimed at reducing the role of human error in cyber-attacks and data breaches, e.g. to prevent phishing?
  10. where on your corporate risk register is cyber risk ranked?
  • we don’t have a risk register
  • it is not on our risk register
  • outside of the top 10
  • three – ten
  • top three

Our response 

  1. 2022 = 1; 2021 =0; 2020 =2; 2019 =3; 2018 =9.
  2. none.
  3. none.
  4. phishing.
  5. October 2020
  6. no.
  7. N/A
  8. yes
  9. 2021/2022
  10. three - ten