Site navigation

Report: 93% of UK Firms Hit by ‘Business-Critical’ Cyber Incidents

Tom Quinn

,

Uk business cyber-attack
“If complexity is killing efforts to prepare for recovery, executive leaders need to assume control and set business-level priorities, so they can keep the organisation running after an attack,” said Howard Holton, GigaOm.

UK businesses face the highest global risk of major cyber-attacks, yet most are lagging dangerously behind in recovery readiness, new data from Commvault has revealed.

After polling 1,000 senior decision-makers at enterprise firms around the world in collaboration with research firm GigaOm, the cybersecurity provider found that UK companies are the most exposed, as almost all (93%) have experienced a business-critical cyber incident, with 57% occurring in just the past 18 months. 

Only 7% of the UK companies said they had never experienced a crippling cyber incident, half the global average (14%), meaning that British businesses are among the most targeted and at-risk anywhere in the world.

Despite experiencing more frequent devastating incidents than the global average, Commvault found that UK organisations are falling behind when it comes to readiness and recovery from cyber-attacks. 

According to the research, they are 21% less likely to have deployed a dedicated recovery environment and 11% less likely to have tested their plans within the last month, widely considered to be fundamental aspects of a successful recovery.

The survey tied its key findings to the concept of Minimum Viability Company (MVC), which outlines the core operations necessary to resume business quickly after a cyber incident. 

As cyber-criminals become increasingly sophisticated, infiltrating backups with malware or planting dormant ransomware, Commvault said that an MVC approach is fundamental to operating a robust and continuous business.

For UK firms, the biggest challenge to achieving this minimum viability is the complexity of existing systems and applications (52%), followed closely by the struggle to keep recovery plans in line with changing business needs (47%).

Added to that, almost a third (30%) cited difficulties separating core systems from less business-critical, broader operations, leading only 36% strongly believe that they should prioritise a minimum viability approach.


Recommended reading


However, regardless of that view, nearly two-thirds of UK companies have laid some foundational steps in their efforts to build resiliency against attacks. For example, 65% have built an inventory of business-critical systems and dependencies, while 61% have created defined runbooks, roles, and processes for incident response.

This is ahead of the global averages of 50% and 41%, with Commvault suggesting that while UK businesses are investing time and resources into their incident response preparations, it is not translating into real-world recovery readiness.

“Business-scale cyberattacks are now the norm, not the exception,” said Howard Holton, chief operating officer at GigaOm.  

“If complexity is killing efforts to prepare for recovery, executive leaders need to assume control and set business-level priorities, so they can keep the organisation running after an attack.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data