Site navigation

UK Boards Failing to Address Cybersecurity Risks

Dominique Adams

,

check point

In the face of rapidly increasing cyber threats, many UK companies are failing to take the dangers seriously, with 63% revealing they had no board member overseeing their cyber security strategy. 

Cybersecurity breaches have cost UK mid-market businesses roughly £30 billion over the past 12 months, a survey has found.

Conducted by assurance, tax and advisory firm, Grant Thornton, the survey revealed that 53% of UK mid-market businesses – which have a turnover between £15 million and £1 billion – have suffered financial losses of between 3% and 10% of their revenue due to a cybersecurity breach.

Those with the most severe cases reported losses as high as 25%. Despite potentially high losses, nearly two-thirds (63%) of surveyed companies had no board member tasked with the responsibility of handling cybersecurity. That same number also said they did not carry out a formal review of their cybersecurity framework or assess their security risk.

In addition to not taking a proactive approach to cybersecurity, the interviewees also revealed they had not adequately made their staff aware of potential cybersecurity risks – just over one-third (36%) said they had provided cybersecurity training for their employees over the past year.

Recommended:

Boards play a crucial role in implementing organisational cybersecurity plans and in encouraging good cyber hygiene within the workplace, according to James Arthur, partner and head of cyber consulting at Grant Thornton. Best practice and promoting cybersecurity awareness is also the board’s responsibility to champion, he said.

“Putting cybercrime onto the board’s agenda is one of the most effective ways to minimise the chances of a successful attack and reduce the financial impact if a breach occurs,” he added. “With that in mind, it is worrying that almost two-thirds of the businesses we interviewed do not have a board member responsible for cybersecurity.

“Often, companies make themselves vulnerable to attack simply by failing to get the basics right. Training to raise employee awareness can have a hugely positive impact on cybersecurity.

“People are often unaware of the important role they play in helping a business to stay protected, so companies of all sizes need to ensure they have regular and ongoing cybersecurity training in place.”

The report also revealed many firms had a somewhat misplaced confidence, with 70% saying they felt confident that their organisation could respond consistently at any time to a cyber-attack; however, 59% did not have a cyber incident response plan in place. Those with a strong response plan in place were less likely to take a large financial hit than those without, according to the survey.

“Cybercrime represents a serious threat to every UK business and, as our research shows, just one successful attack can amount to a huge revenue loss,” said Arthur, noting that mid-market companies were particularly vulnerable because they have a level of resources that make them an attractive target but are less likely to implement best-in-class cybersecurity compared with larger companies.

“Businesses need to understand where their weak points are in order to counter the threat effectively,” he said. “Yet our research shows that perceived and actual vulnerability often don’t match up, with many businesses feeling confident in their cyber management capacity but having no meaningful response plans in place. A pre-prepared, effective response plan allows a business to do the right thing as fast as possible, in a situation where every minute counts.”

To recover quickly from a cyber attack, many companies indicated that they relied on regular data backups to be able to recover quickly from an attack. Unimpressed with this approach, Arthur commented: “With modern ransomware specifically designed to spend up to six months infecting entire networks, including data backups, this cannot be relied upon as a core component of a response plan.”

The report recommended six key areas businesses should focus on to be better prepared for an attack:

  • Establishing a cyber incident response plan;
  • Regularly rehearsing the response plan using a range of different scenarios;
  • Monitoring and managing the risk posed from their supply chain;
  • Ensuring they understand the terms of their insurance and what is covered;
  • Understanding what ‘normal’ looks like for their business, in terms of application usage, so they can identify any unfamiliar patterns;
  • Investing in regular training and raising their people’s awareness of cybersecurity.

Grant Thornton’s survey findings were drawn from interviews with more than 500 UK mid-market businesses.

Dominique Profile Picture

Dominique Adams

Marketing Content Manager, Trickle

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data