Skip to main content
  • Home
  • About us
    • Board of Commissioners
    • Directors
    • Contact us
    • Data protection
    • Making a complaint
    • Our teams
      • Enforcement
      • Policy and Risk
      • Registry
      • Supervision
      • Intelligence
    • Strategic Roadmap
  • Careers
  • Industry
    • Codes of Practice
      • Alternative Investment Funds Code of Practice
      • Certified Funds Code of Practice
        • Certified Funds Code of Practice Schedule 1
        • Certified Funds Code of Practice Schedule 2
        • Certified Funds Code of Practice Schedule 3
        • Certified Funds Code of Practice Schedule 4
        • Certified Funds Code of Practice Schedule 5
      • Fund Services Business Code of Practice
      • General Insurance Mediation Business Code of Practice
      • Insurance Business Code of Practice
      • Investment Business Code of Practice
      • Money Service Business Code of Practice
      • Trust Company Business Code of Practice
    • Consultations
      • Fee consultation No 3 2024 - Feedback Paper
      • 2024 consultations
      • 2023 consultations
      • 2022 consultations
      • 2021 consultations
      • 2020 consultations
      • 2019 consultations
      • 2018 consultations
      • 2017 consultations
      • 2016 consultations
    • Examinations
    • Fees
    • Financial crime
    • Innovation Hub
      • About
      • Help
      • Collaboration
      • Regtech
      • Fintech
      • Suptech
      • Virtual Asset Service Providers
      • Local partnerships and associations
      • Innovation reports
    • Forms
    • Guidance and policy
    • International-co-operation
      • International assessments
      • Memoranda of Understanding
      • Sanctions
    • Legislation
    • Regulated entities
    • Risk
      • National Risk Assessments
    • Sectors
      • Auditors
      • Banking
      • Funds
        • Fund statistics FAQs
      • General Insurance Mediation Business
      • Insurance
      • Investment Business
      • Financial Crime - Schedule 2 Business
      • Trust Company Business
      • Non- profit organisations
        • Non-profit organisations legislation
        • NPO risk assessment
        • Non-profit-organisations-risk-assessment
      • Financial Institutions
      • Money Service Business
    • Schedule 2 Business FAQs
    • Sustainable finance
  • News and events
    • Events and webinars
    • Industry updates
    • News
    • Public statements and warnings
    • RSS feeds
    • Subscribe
  • Protecting the public
    • Fraud prevention
    • Investment mis-selling
    • World Investor Week
    • Retail business accepting large sums of cash
  • Publications
    • Annual reports
    • Business plans
    • Presentations
    • Service reports
    • Engagement reports
  • Registry
    • Annual confirmation
    • Beneficial ownership information
    • Register or make a change
    • Registry fees
    • Registry forms
    • Registry legislation
    • Registry notices
      • Public notices
    • 2025 Registry fees
    • 2024 Registry fees
  • Whistleblowing
  • Login
Jersey Financial Services Commission Jersey Financial Services Commission
  • About us
  • Industry
  • Registry
  • Protecting the public
  • News and events
  • Login

Popular searches

  • Industry Survey
  • Annual confirmation statement
  • Business Plan
  • Compliance monitoring
  • Guidance notes
  • myProfile
  • myRegistry
  • Outsourcing
  • Sanctions
  • Sound business policy
  • Consumer credit

You are here

  • Home
  • News and events
  • Invasion of Ukraine – Raised Cyber Threat
News 03 March 2022

Invasion of Ukraine – Raised Cyber Threat

A statement from Jersey's Cyber Emergency Response Team (CERT)

Jersey’s Cyber Emergency Response Team has been closely monitoring recent developments in Ukraine including a series of cyber attacks in January and February 2022. These attacks have included both distributed denial of service attacks (DDoS) and malware designed to render information systems inoperable. Several of these attacks have been attributed by UK and US authorities to Russia’s Main Intelligence Directorate (GRU).

Whilst there is no evidence of a specific threat to Jersey organisations, there has been an historical pattern of cyber-attacks on Ukraine with international consequences and local organisations are asked to prepare for an increase in malicious cyber activity. Similar warnings have been issued by other national cyber authorities including NCSC (UK) and CISA (USA).

Such attacks are likely to be followed by an increase in criminal or hacktivist (cyber activist) led cyber- attacks. We are currently tracking follow-on cyber activity targeted primarily at government bodies, financial services, critical infrastructure and their direct supply chains.

The situation is increasingly unpredictable and this raised threat level is likely to persist.

Jersey based organisations operating in the financial services, government and public services, professional services and critical infrastructure sectors are therefore strongly encouraged to take the following immediate steps to minimise the risk of a successful cyber attack. The below advice is also appropriate for organisations outside these sectors as cyber attacks can be indiscriminate.

Awareness and Alerting

  1. Register for NCSC’s Early Warning Service. We have confirmed that NCSC will make this service available to all Jersey based organisations. This provides alerts when intelligence suggests your network or systems may be compromised.
  2. Register for NCSC’s Cyber Information Sharing Portal (CiSP) – Channel Islands Node to receive and share intelligence on potential or actual attacks. CERT.JE will sponsor applications for CiSP from Jersey based organisations following a request to hello@cert.je.
  3. Register for updates from CERT.JE via our newsletter or social media (twitter and LinkedIn) so we can inform you quickly if the situation develops.
  4. Inform CERT.JE of any unusual cyber activity via CiSP (Channel Islands Node) or alternatively via email to incidentreports@cert.je.

Operation of Critical Cyber Security Controls

  1. Ensure that good cyber hygiene practices are followed consistently and internal controls are assessed against a recognised framework such as CyberEssentials Plus, NIST CSF, NCSC’s Common Assurance Framework or ISO 27001.
  2. Follow guidance from NCSC on actions to take when the threat level is heightened.
  3. Ensure patching is up to date on all systems including device firmware, with a particular focus on core IT infrastructure and externally facing systems.
  4. Ensure externally facing services such as websites are protected from Distributed Denial of Service (DDoS) attacks, for example by implementing cloud-based DDoS protection services.
  5. Implement multi-factor authentication (MFA) for all accounts and operate additional controls to secure highly privileged accounts.
  6. Ensure employees are aware of good cyber hygiene practices, including use of multifactor authentication for personal accounts.

Incident Readiness & Response Planning

  1. Ensure cyber incident response plans are reviewed and tested on a regular basis.
  2. Ensure back up data is effectively segregated and undertake test restores on a regular basis.

Further advice and assistance is available from local cyber security providers and from CERT.JE.

Other news and events

  • Events and webinars
  • Industry updates
  • News
  • Public statements
  • Public statements archive
  • Restricted persons
  • Subscribe

Recent updates

Industry update 08 January 2026

Submit your 2026 annual confirmation

Industry update 08 January 2026

Basel III prudential roadmap update: feedback and next steps

Industry update 07 January 2026

Update: AML/CFT/CPF Handbook

All news

Next events and webinars

Drop-in session one - consultation on Article 36 guideline updates

12 January 2026

Drop-in session: follow-on consultation on complex structures

20 January 2026
All events and webinars
  • Accessibility
  • Contact us
  • Directors
  • Privacy policy
  • Subscribe
  • Whistleblowing
  • Facebook
  • LinkedIn
Back to top
© 2026 Jersey Financial Services Commission

This website uses cookies to analyse our traffic. To find out more read our cookie policy.