Site navigation

One in Ten UK Firms “Wouldn’t Survive” a Cyber-Attack

Tom Quinn

,

UK cyber-attack
Poor cyber hygiene, limited training, and a widespread susceptibility to phishing are leaving British businesses dangerously exposed.

One in ten UK firms could be wiped out by a cyber‑attack similar to those that paralysed major retailers and car manufacturers last year, according to new research from Vodafone Business.

Polling 1,000 senior leaders across businesses of all sizes, the study paints a troubling picture of inadequate crisis preparedness, poor password practices, and staff vulnerability to phishing scams, leaving businesses exposed to rampant cyber-crime.

Over 10% of businesses admitted they would be unlikely to survive a cyber-attack like those that crippled systems at Marks and Spencers, Co-op, and Jaguar Land Rover, although almost all (89%) said these high‑visibility breaches against household brands have made them far more alert to cyber threats.

Despite those claims, fewer than half (45%) of firms have ensured all employees have basic cyber awareness training, and nearly three-quarters of business leaders (71%) believe that at least one member of their staff would fall for a convincing phishing email.

Bosses said that their workers lacked the awareness and training to spot phishing lures, or were “too busy” to report them, highlighting a dearth of strict protocols for verifying and flagging suspicious messages.

Human error is still a major risk factor, according to Vodafone, with employers estimating that, on average, their staff use their work password for up to 11 other personal accounts, including social media and dating sites.

Meanwhile, the emergence of AI and deepfake scams is causing concern, with seven in ten business leaders admitting that criminals’ use of sophisticated deepfakes has made them more wary of video calls from senior colleagues or executives.

Those anxieties appear particularly justified following news that a Swiss entrepreneur was recently duped out of “several million Swiss francs” after crooks used voice deepfakes to pose as a trusted business partner over the course of two weeks.


Recommended reading


Vodafone said that the UK Government’s announcement of a second Telecommunications Fraud Charter, set to launch later this year, marks a vital step in strengthening businesses’ defence against these increasingly sophisticated cyber-enabled crimes. 

By enhancing collaboration and setting clearer standards for prevention, detection and response, Vodafone claimed that the new charter provides a stronger, more coordinated framework that brings industry and government together to close vulnerabilities, disrupt criminal activity, and protect businesses from financial or operational harm.

“The revelation that one in ten business leaders believe their company would not survive a cyber-attack highlights the scale of vulnerability facing UK firms today,” said Nick Gliddon, business director for VodafoneThree.

“In this context, the Government’s announcement of its second Telecommunications Fraud Charter, coupled with a new fraud strategy to be launched next year, marks a significant and timely development.

“This renewed focus from policymakers underscores the seriousness of the threat and the necessity of a united approach between industry and government to effectively tackle online fraud and cybercrime.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data