Site navigation

75% of UK Businesses Had a Cyber Incident Last Year

Michael Edgar

,

Charity cybersecurity
Less than one quarter of UK businesses and charities were unscathed by a cybersecurity incident last year. 

New figures from the UK government have revealed that a staggering 75% of businesses and 79% of charities encountered a cybersecurity incident in 2023. This is according to the Cyber Security Longitudinal Survey (CSLS), which has been monitoring the cybersecurity landscape of approximately 1000 UK businesses and charities since 2021. 

Despite ongoing efforts to bolster cybersecurity measures, the survey indicated limited improvements in organisations’ cybersecurity posture between 2022 and 2023. 

Approaches to Cybersecurity

The survey covered different approaches to cybersecurity between businesses and charities. Charities were found to adopt a less formal approach compared to businesses, with a higher likelihood to allow staff to access systems using personal devices. Businesses were also more likely to mandate the use of VPNs for remote access. 

Only about a third of both businesses and charities adhere to at least one of the three major cybersecurity certifications, aimed at enhancing baseline security measures within organisations: Cyber Essentials Standard, Cyber Essentials Plus, and ISO 27001. 

Looking at incident response readiness, the majority of businesses and charities reported having written procedures in place, although a significant number of them had not tested the procedures within the past year. 

Email Threats & Cybersecurity Governance

Email threats emerged as the most common type of incident across surveyed organisations, consistent with trends from previous years. However, 2023 witnessed an increase in attempted hacks targeting websites, social media platforms and user accounts.

The report reinforced the importance of boardroom involvement in cybersecurity governance, since a significant portion of organisations had board members overseeing cybersecurity, discussions at the board level remained relatively low.

In response to these challenges, the UK government recently published a new Code of Practice on cybersecurity governance, aiming to elevate cybersecurity as a strategic priority for directors and senior business leaders.


Recommended reading


Outlook

As cyber threats continue to evolve and escalate, the imperative for robust cybersecurity practices becomes ever more critical for businesses and charities alike.

The UK government’s efforts to elevate cybersecurity governance and promote boardroom engagement signify a step towards building a more resilient cybersecurity ecosystem, but concerted action from organisations across sectors will be essential in effectively mitigating cyber risks in a digital world.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data