European Cyber Security Month: What happens after the click?
European Cyber Security Month - What happens after the click? @channel Hope ECSM has started well for you all! This week’s awareness topic is Phishing 🎣, and we usually focus on one moment: the click. Don’t click it, report it! That advice is right, but someone, somewhere in every organisation, will eventually click. We have to prepare because what decides the impact is what happens next, and how quickly. Case one: undetected for twenty months, fined almost £1 million 💰 In September 2020, an employee at South Staffordshire Water opened a phishing email attachment ✉️. It installed malicious software that sat quietly inside the network for 20 months. Nobody noticed. By 2022 the attacker had moved through the network, gained top-level administrator access and took the personal data of 633,887 customers and employees, including bank details and National Insurance numbers. It was all published on the dark web. In May 2026 the Information Commissioner’s Office (ICO) fined the company £963,900. Crucially, the ICO did not fine them for being phished. It fined them for missing the basic controls that should have caught what happened next 🤦. Only 5% of the IT environment was being monitored, and some systems ran software that had been out of support for years. Case two: stopped in two hours, still 1.3 million records lost 😔 On Thursday 24 September 2026, at around 11:30am, an employee of the Arizona Supreme Court received an email and clicked a malicious link. The court’s IT team spotted the intrusion and shut it down in under two hours. By then, the attackers had already copied a backup server. It held the names and Social Security numbers of around 1.3 million people, drawn from 30 years of court debt records. More than 150,000 confidential foster care reports were taken too. The FBI is now investigating. Fast containment limited the damage, but it did not prevent it. Two hours was still too long! 🕑 Things to consider This week we are educating staff on the importance of detecting and reporting malicious phishing attempts, but when the inevitable happens, we need to be ready 🏃. So ask yourself:
- 1.
Are your staff certain that they will not be in trouble if they report their mistake?
- 2.
Awareness is not the only control, so consider how strong the other controls are. The regulator considered the controls behind the people: monitoring, patching, access rights, least privilege etc.
- 3.
What incident response processes are in place after that click happens, and how fast do they work?
- 4.
Where is your data stored? Arizona’s exposure was so large because 30 years of data sat on a single backup server. Protecting and minimising data access limits the blast radius of a click.
I’ll be back next week to discuss Voice Scams! kjzz.org/text/politics/2026-09-29/arizona-supreme-court-data-breach-exposed-reports-on-children-in-foster-care fox10phoenix.com/news/arizona-court-system-targeted-cyberattack-compromising-personal-records ico.org.uk/about-the-ico/…/fine-of-nearly-1m-issued-against-south-staffordshire-plc-and-south-staffordshire-water-plc watermagazine.co.uk/…/ico-issues-fine-of-nearly-1m-against-south-staffordshire-plc-and-south-staffordshire-water-plc-following-major-cyber-attack-and-data-breach
