Refine By
Clear all filter
About 91280 results for "*"
CHECKLISTS
ARCHIVED: This Checklist has been archived and is not maintained. Cybersecurity is the infrastructure of technologies, processes and practices used to protect networks, data and technology from unauthorised access. Cybersecurity measures adopted by organisations need to guard against breaches motivated by malicious intent (whether that is financial crime, cyber terrorism, industrial espionage, hacktivism or state-sponsored attacks), or through unfortunate incidents. The ability of malicious third parties to successfully penetrate and damage an organisation is growing. This means that the security of a financial services firm’s network and the safety of its data is increasingly important, and cyber security is the focus of a number of regulatory and industry initiatives. Key dates and publications—2026 Date Description 15 May 2026 BoE, the FCA and HM Treasury (HMT) issued The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience. Key dates and publications—2025 Date Description 3 December 2025 As part of its Fundamental Elements Series, the G7 Cyber Expert Group released G7 fundamental elements
NEWS
TMT analysis: In this libel judgment, the High Court determined the meaning of three articles which linked cyber-attacks on the defendant’s blogs and social media to the company for which the claimant acts as CEO. The court held that the articles carried the meaning that the claimant was a hacker and had undertaken the cyber-attacks referred to. It further held that the articles were defamatory of the claimant.
NEWS
Commercial analysis: German fuel distributor, Mabanaft, and its related company, Oiltanking Deutschland, recently suffered a substantial cyber-attack causing significant disruption to their business operations. In response, they declared force majeure on a number of their contracts. Philip Tansley, Partner, and John Shirley-Rakhra, associate, both at Shoosmiths, analyse the effectiveness of force majeure clauses in the event of a cyber-attack.
NEWS
Law360, London: Brokers in the UK see cyber-insurance as the product with the greatest potential for growth as large numbers of smaller businesses do not have cover against online threats, polling by a data and analytics company shows.
CHECKLISTS
This Checklist is designed to help you determine whether you have the systems in place to prevent and deal with cybercrime. It is intended for compliance professionals in general commercial organisations and is not intended to cover sector-specific requirements applying to the telecommunications, financial services or other essential services sectors. This Checklist should be read in conjunction with subtopics: Cybersecurity and Information security (or for law firms, Information security—law firms). Cybercrime prevention Recommended document or action ☐ Ensure your board/senior management is actively involved in your cybersecurity and cybercrime prevention programme.See Practice Note: Cybercrime prevention. ☐ Consider the extent to which your organisation is at risk from cybercrime.See Precedent: Cybercrime risk assessment. ☐ Consider what IT and information systems you have and whether the operating systems, software, etc is up-to-date.See Precedent: Cybersecurity IT log. ☐ Conduct an audit of your information and cybersecurity arrangements
PRECEDENTS
Quarter 1—Confidential information The tips and reminders for this quarter relate to confidential information. You can find more specific information in the following places: • [insert, eg Clear desk and clear screen policy] • [insert, eg Remote working and removable media policy] • [insert, eg Cybercrime prevention strategy and incident management plan] • [insert, eg Confidentiality and disclosure policy] • [insert, eg Information management and security policy] • [insert, eg Internet, email and communications policy] • [insert, eg Bring your own device (BYOD) policy] • [insert, eg Generative AI policy] Month 1—Think ‘secure’ You work on important and sensitive matters. It’s our duty to make sure those matters stay secure and confidential. Always remember to lock your computer or other device when you’re not using them. This will help to keep these devices secure and those important matters confidential. See our [insert, eg Clear desk and clear screen policy] for more information. Don’t leave sensitive customer or business information lying around on your desk—file it in a locked drawer or shred it. Keeping matters confidential is much easier in a protected workspace like our offices. If you are working from home, you need to be aware
PRACTICE NOTES
Though taking preventative steps obviously makes good sense (see Practice Note: Cybercrime prevention), it is not possible to totally eradicate the risk of cybercrime or cyber attack. An effective mechanism to deal with cybercrime and cybersecurity threats will not only include solid defences, but will also include a plan or strategy to deal with the effects of an attack in the event that it happens. This Practice Note sets out some practical guidance on putting together the incident management element of your Cybercrime prevention strategy and incident management plan. It includes breach notification requirements under the General Data Protection Regulation (UK GDPR), Assimilated Regulation (EU) 2016/679, which apply where the cybercrime incident involves a personal data breach. This Practice Note is intended for compliance professionals in general commercial organisations. It is not intended to cover sector-specific requirements. Cybercrime incident involving a personal data breach Many, but not all, cybercrime incidents will involve a personal data breach. You must notify the Information Commissioner’s Office (ICO) of a personal data breach without undue delay and, where feasible, not later
PRACTICE NOTES
Cybercrime is a crime that has some kind of computer or cyber aspect to it and it takes shape in a variety of different forms. The government’s National Cyber Security Strategy categorises cybercrime into two interrelated categories of crime—cyber-dependent crime and cyber-enabled crime as follows: • cyber-dependent crimes are crimes that can be committed only through the use of information and communications technology (ICT) devices. In these cases, ICT devices act as both the tool for committing the crime and the target of the crime. Examples of such activity includes: ◦ hacking to steal ◦ developing and using malware for financial gain. Common types of malware utilised by cyber criminals include viruses, worms, trojans, spyware and ransomware ◦ damaging, distorting or destroying data and/or network or activity by means of eg denial of service (DOS) or distributed denial of service (DDOS) attacks ◦ phishing • cyber-enabled crime are traditional crimes, such as fraud and data theft, which can be increased in scale or reach by the use of computers, computer networks or
PRACTICE NOTES
Cybercrime is a fast-moving, ever-evolving unpredictable risk to all commercial organisations which must be managed properly. This Practice Note pulls together examples of good practice in terms of generally reducing the risk of cybercrime and cybersecurity breaches. It is aimed at compliance professionals, not cybercrime experts. It does not cover specialist sectors like telecommunications. Responsibility Cyber risk, like any other risk to your business, needs to be managed properly and considered a high priority risk for the internal compliance or legal team. It is a business risk that must be managed within an overall information risk-management and crime prevention framework, and should not be left just to the IT department. A senior person should take overall responsibility for conducting a risk assessment and, from there, developing and implementing your policies and procedures. They should be trained and have adequate resources to ensure those policies and procedures are properly maintained. All staff should be made aware of who this person is. Risk assessment Your starting point should be a risk assessment. A high-quality risk assessment involves
PRECEDENTS
1 Introduction 1.1 This strategy and plan builds on and supplements our other data management and security policies and procedures, namely our: 1.1.1 [ [[Data protection policy;]] 1.1.2 [[Data breach plan;]] 1.1.3 [[Information management and security policy;]] 1.1.4 [[Bring your own device policy;]] 1.1.5 [[Password policy;]] 1.1.6 [[Information and communications technology (ICT) plan;]] 1.1.7 [[Internet, email and communications policy;]] 1.1.8 [Social media policy;] 1.1.9 [[Remote working and removable media policy;]] 1.1.10 [[Business continuity plan (BCP);]] 1.1.11 [Generative AI policy.]] 2 Purpose and scope 2.1 The purpose of this document is to establish systems and controls to protect the organisation from cybercriminals and associated cybersecurity risks, as well as set out an action plan should the organisation fall victim to cybercrime. 2.2 This plan is relevant to all staff[ in every office]. 3 Responsibility 3.1 [Insert name] is responsible for this strategy and plan. 3.2 They are responsible for: 3.2.1 conducting and maintaining cybercrime/cybersecurity risk assessments; 3.2.2 monitoring compliance with this strategy and related policies and procedures; 3.2.3 invoking the relevant incident management plan, as appropriate and in conjunction with the business continuity team. 4 What is cybercrime? Cybercrime is simply a crime that has some kind of computer or cyber aspect to it. It takes shape in a variety of different forms, eg hacking, phishing, malware, viruses
PRECEDENTS
1 Introduction 1.1 We have performed an organisation-wide assessment of the risk of our systems and/or services falling victim to cybercrime. 1.2 The review included consideration of: 1.2.1 our critical IT assets; 1.2.2 the most likely targets; 1.2.3 potential types of attack; and 1.2.4 our defences. 2 Critical IT/data assets 2.1 We have considered our critical IT and data assets. These include: 2.1.1 client data; 2.1.2 [personnel data;] 2.1.3 [website;] 2.1.4 [IT server;] 2.1.5 [e-mail server;] 2.1.6 [transactional data;] 2.1.7 [sensitive information about our business.] 3 Likely targets 3.1 We know that our organisation is particularly attractive to cybercriminals because of the confidential information we hold—about our clients, third parties, [transactions,] staff and the business itself. 3.2 We also know that some cybercrime is committed simply to disrupt genuine commercial operations. 3.3 It follows that the potential targets of cybercriminals are those routes into that confidential information, including weak spots such as: 3.3.1 smart/mobile devices—these devices are highly vulnerable to attack, lack notification methods when vulnerabilities are discovered, and do not always have user-friendly methods to patch new vulnerabilities; 3.3.2 social networks—attacks by cybercriminals are becoming more targeted, and social networks are a useful source of data for crafting these types of attacks. Highly targeted attacks like these are more likely to compromise our network; 3.3.3 out of date hardware/software—letting any hardware or software
PRACTICE NOTES
Cyber risk, like any other risk to your business, needs to be managed properly and considered a high priority risk for the internal compliance or legal team. It is a business risk that must be managed within an overall information and risk management and crime prevention framework, and should not be left just to the IT department. This Practice Note outlines: • the issues surrounding cybercrime (ie why it needs to be on your radar) • the threats posed to commercial organisations by cybercrime, and • key vulnerabilities This Practice Note reflects information security and breach notification requirements in the General Data Protection Regulation (UK GDPR), Assimilated Regulation (EU) 2016/679 but is not intended to cover specialist sector-specific requirements in the: • Network and Information Systems Regulations 2018 (NIS Regulations), SI 2018/506 • Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR 2003), SI 2003/2426 (as amended), and • Financial Services and Markets Act 2000 (FSMA 2000) and the Financial Conduct Authority (FCA) Handbook What is cybercrime? Cybercrime is simply a crime that