Boards at some of Britain’s largest companies still do not fully understand the damage that cyber attacks can cause, according to a new government report.
The UK Government’s Cyber Governance Health Check assesses the cybersecurity practices of some of the UK’s top firms, and found that less than one-fifth (16%) of boards have a “comprehensive understanding” of the impact that cyber attacks could have on their business.
Boards do not completely understand the threat landscape despite the fact that almost all (96%) of the companies surveyed say they have a cybersecurity strategy in place.
The report also founded that, although 95% of businesses have a cybersecurity incident response plan, only 57% test them on a regular basis.
Recommended: Openreach Unveils £485,000 Investment in Livingston Training Facility
Commenting on the report publication, Digital Minister Margot James said: “The UK is home to world-leading businesses but the threat of cyber attacks is never far away. We know that companies are well aware of the risks, but more needs to be done by boards to make sure that they don’t fall victim to a cyber attack.
“This report shows that we still have a long way to go but I am also encouraged to see that some improvements are being made.”
Cyber awareness has increased among the UK’s businesses, the report found. Nearly three-quarters of respondents said they acknowledge growing cyber threats – marking an improvement from 54% in the Government’s 2017 report.
The implementation of GDPR has, the report acknowledges, positively impacted businesses. An increasing awareness over the handling/use of consumer data and growing cybersecurity threats has led to a greater understanding among management figures.
More than three-quarters (77%) of respondents said that board discussion and management of cybersecurity had increased since GDPR. As a result of GDPR implementation, more than half of those businesses said they had put in place “increased security measures”.
A stronger emphasis on cyber resilience has also come about due to the implementation of GDPR, the report found, with more businesses focusing on how to improve their level of resilience.






