Back to blog

How to tailor your cyber security to your sector or industry

Cyber security best practice applies to every business and every sector. However, industries have their own vulnerabilities, and your cyber security strategy cannot be one-size-fits-all. Some sectors are softer targets, some are more lucrative, and some have specific weaknesses that attract or invite cyber threats.

The article below covers the sectors Arc works with most closely, explaining why each is targeted, what the specific risks look like, and what a tailored cyber security strategy should include. Whether you are in manufacturing, financial services, healthcare, legal, or the charity sector, the threats facing your organisation are distinct enough to warrant a response built specifically around your environment.

Here are the world’s cyber attacks by sector share, and some sector-specific principles for building a cyber security strategy, using as examples the three most attacked sectors.

Statistic: Distribution of cyber attacks across worldwide industries in 2022 | Statista
Find more statistics at Statista

Source: Statista

 Cyber Security for Manufacturing

Share of cyber attacks: 24.8%

Why is manufacturing targeted with cyber attacks? 

The more that manufacturing processes become a blend of software and hardware, and systems integrate more technology like the Internet of Things (IoT), the more ‘surface area’ there is for attack, and the more disruption an attack can cause.

If an attacker can make a manufacturing process grind to a halt, it’s obvious how costly that is — last year the sector lost £1.3tn to unplanned downtime. If the attacker were, for instance, to hold the systems for ransom, they could be confident that the victim would pay the demanded sum. The chance that a paying ransomware victim (from whatever sector) is then attacked again is 80%.

Strategy and cyber security services for manufacturing

The first step is to take stock of your systems and your vulnerabilities — software, access points, hardware, and networks. Then you can test them, and one powerful approach to that is penetration testing.

Penetration testing uses the same techniques and methods that a cyber attacker would likely use on your systems. By attempting to breach your own system (or having a cyber security consultant do it) you reveal where and what the points of weakness are.

After that, you can reinforce the priority areas.

Cyber security for healthcare

Healthcare organisations hold some of the most sensitive personal data of any sector. Patient records, clinical data, and payment information combine to make healthcare providers high-value targets for ransomware, data theft, and extortion. Attacks on healthcare organisations also carry a unique dimension of risk: disruption to clinical systems can directly threaten patient safety, making the pressure to restore operations as quickly as possible extremely high.

In the UK, NHS-linked organisations and private healthcare providers are subject to the Data Security and Protection Toolkit (DSPT), which sets out mandatory requirements for information governance and cyber security across organisations handling NHS patient data. The DSPT requires annual submission and assessment, and failure to meet its standards can result in loss of NHS contract eligibility.

Why healthcare is targeted

Healthcare organisations are targeted for several overlapping reasons. Patient data is highly valuable on criminal markets and can be used for identity fraud, insurance fraud, and targeted extortion. Clinical systems are often built on legacy infrastructure that is difficult to patch and update without disrupting operations, creating persistent vulnerabilities. And the urgency of patient care means healthcare organisations are more likely than most to pay ransoms to restore access to critical systems quickly.

Cyber security strategy for healthcare

A healthcare cyber security strategy needs to address both the technical environment and the operational constraints of a clinical setting. Key priorities include endpoint protection across all devices including medical equipment with network connectivity, strict access controls ensuring clinical staff can only access the data they need, encrypted data storage and transmission for all patient records, regular data backups that can restore systems quickly without paying a ransom, DSPT compliance as a baseline, and staff awareness training that reflects the specific social engineering tactics used against healthcare workers.

Arc supports NHS-aligned and private healthcare organisations with managed IT support and cyber security services. Get in touch to find out more.

Cyber security for law firms and solicitors

Law firms handle some of the most confidential data in any profession. Client files, financial transactions, litigation strategies, and commercially sensitive agreements are all prime targets for cybercriminals. The legal sector is also subject to specific regulatory obligations under the Solicitors Regulation Authority, which places clear requirements on firms to protect client data and maintain appropriate cyber security controls.

Cyber attacks on UK law firms increased by 77% between 2023 and 2024 according to the Law Society Gazette. The most financially damaging attacks on law firms tend to exploit the high-value financial transactions that solicitors routinely facilitate, particularly in conveyancing.

Why law firms are targeted

Law firms are targeted for the value of the data they hold, the financial transactions they facilitate, and the reputational and regulatory consequences of a breach. Three attack types are particularly prevalent in the legal sector. Ransomware attacks encrypt client files and demand payment for their release, knowing that the disruption to active matters creates immediate commercial pressure. Friday afternoon fraud, also known as business email compromise, involves criminals intercepting or spoofing communications around property transactions to redirect client funds to fraudulent accounts. Phishing campaigns target fee earners and support staff to gain initial access to email systems, from which attackers can monitor communications and identify high-value transaction opportunities.

Cyber security strategy for law firms

A legal sector cyber security strategy must address both the firm’s technical environment and its regulatory obligations. Key priorities include multi-factor authentication on all systems and email accounts, email security including DMARC to prevent spoofing and impersonation, endpoint protection across all devices used to access client files, staff awareness training with specific focus on Friday afternoon fraud and phishing, SRA-aligned access controls and incident response procedures, and encrypted storage and transit for all client documentation.

Arc provides specialist IT support and cyber security services for law firms across the UK. Get in touch to find out more.

Cybersecurity for Finance and Insurance

Share of cyber attacks: 18.9%

Why are Finance and Insurance targeted with cyber attacks? 

A cyber breach could give attackers access to money, payment details, and personal data. Criminals know the reputational damage and regulatory punishment that financial or insurance businesses could face, and that the victim will want to end the attack as soon as possible to minimise damage and disruption. If ransomware is part of the attack strategy, here’s another example of an industry that may be willing to pay.

Strategy and cyber security services for finance and insurance

As with other sectors, a cyber security review will expose any vulnerabilities. That being said, human behaviour will always present a risk – no matter how technically advanced your security may be. In fact, across all sectors, human error is in some way responsible for 88% of data breaches.

Whether you’re a competing challenger bank or a heritage financial institution, it’s very easy for attackers to use social engineering to trick someone into compromising security. That someone could be of any level, from an ambitious new employee in their first job, to a founder or C-level executive looking to grow their business’s revenue or reputation. For example, one Australian hedge fund was brought down permanently by a cyber attack, after one of the founders clicked a link to a fake Zoom meeting invitation.

You can prevent some high-risk behaviour with awareness training. Take phishing for example — 90% of ransomware attacks start with a phishing email. Would your team know one when they saw it? Some businesses send dummy phishing emails to their teams to a) find out if they would click anything and b) illustrate very clearly how easy these scams can be to fall for.

Cybersecurity for professional services

Share of cyber attacks: 14.6%

Why are professional services targeted with cyber attacks? 

Professional services, typically have valuable client data, often from businesses with high turnovers, or even high net worth individuals. Firms also trade on reputation, with referrals and new business depending on the trust they have built. Finally, most professional service firms and practitioners within them will be chartered professionals, members of governing bodies, or both, and face sanctions if they are found to be non-compliant with cyber security rules.

Strategy and cyber security services for professional services

One of the most pressing issues to navigate is the question of remote work. Though hybrid working has undeniably settled as the reality for a lot of firms, many still haven’t adapted their security measures or processes accordingly. For example, in many cases there’s nothing to stop a remote worker from logging on to the Wi-Fi on a train, a café, or a co-working space. Those networks are not secure — 43% of people have had their security compromised through public Wi-Fi, and that should be an unacceptable level of risk for your firm.

A Virtual Private Network (VPN) is always a good idea to protect remote and hybrid workers, and for added safety, you should have endpoint protection in case a VPN fails (or someone forgets to log in to it).

Summary: cyber security for all sectors

Whatever the sector, any business needs to start with the basic building blocks of cyber security. Once you are sure you have those in place, then you can start building a cyber security strategy that’s tailored to your sector and bespoke to your business.

For example, Arc’s managed cyber security services give you ongoing protection, not only by designing protection to fit your business, but also by giving you an ongoing assessment of the threat landscape and your readiness to face evolving threats.

If you would like a free cyber security review, you can book yours here. Or, if you have specific questions that you’d like expert answers to, get in touch on 01268 288 100 or info@arcsystems.co.uk.