A mere 17% of organisations in the UK have a ‘Mature’ level of readiness needed to build cyber resilience against modern cybersecurity risks, according to Cisco‘s first-ever Cybersecurity Readiness Index.
Developed against the backdrop of a post-COVID, hybrid world where users and data must be secured wherever work gets done, the report highlights where businesses are doing well, and where gaps in security will widen if necessary actions are neglected.
Hybrid working presents new and unique cybersecurity challenges for companies. Previous static models have been rapidly replaced by flexibility, while companies increasingly operate from multiple devices in multiple locations, connect to multiple networks, access applications in the cloud and on the go, generating enormous amounts of data across an increasing number of entry points.
The Research
To investigate the readiness level of businesses across the UK, Cisco conducted a double-blind survey of 6,700 private sector cybersecurity leaders across 27 markets to indicate which solutions they had deployed and the stages of development they were in.
The measures were categorised into five core pillars forming a baseline of required defences: identity, devices, network, application workloads, and data.
Companies were then classified into four stages of increasing readiness: beginner, formative, progressive, and mature.
Findings
Alongside the stark finding that only 17% of companies in the UK are at the Mature stage, 44% of companies fall into the Beginner (4%) or Formative (40%) stages.
While this is better than the global average, which sees 15% of companies at the Mature stage, the number is still concerningly low given the risks associated with poor cybersecurity.
Despite the low number, companies seem aware of dangers: 80% of respondents said they expect a cybersecurity incident to disrupt their business in the next 12 to 24 months. The costs of being unprepared can be substantial, as 59% of respondents said they had a cybersecurity incident in the last 12 months and 47% of those affected said it cost them at least £408,160.
“The move to a hybrid world has fundamentally changed the landscape for companies and created even greater cybersecurity complexity. Organizations must stop approaching defense with a mix of point tools and instead, consider integrated platforms to achieve security resilience while reducing complexity,” said Jeetu Patel, executive vice president and general manager of security and collaboration at Cisco. “Only then will businesses be able to close the cybersecurity readiness gap.”
Business leaders need to invest in establishing a baseline of ‘readiness’ across the five security pillars to build secure and resilient organisations, the report stresses.
85% of respondents plan to increase their security budgets by at least 10% in the next 12 months, showing how critical this investment is.
In the UK, 26% of organisations were deemed ‘Mature’ in their protections for identity, with 25% at the Progressive stage, 33% at Formative, and 16% only Beginners.
Device protection faired better in the UK, with 41% of UK companies deemed Mature. Still, 19% were Beginner, with 29% Formative and 11% Progressive.
Network protection had more varied results, with 39% of business falling under Formative in the UK, with 30% Progressive, 22% Mature, and 9% Beginner.
The UK’s readiness to protect application workloads seemed to struggle, with 47% only at the Formative stage, 28% Progressive, 12% Beginner, and only 13% deemed Mature.
36% of UK companies were deemed Progressive in their protections for data, with 26% Formative, 24% Mature, and 14% Beginner.
Recommended
- Credit Suisse Takeover | What You Need to Know
- How Many Tech Leaders Expect Revenue Growth This Year?
- The Cost of Robocall Scams
Recommendations
Cisco recommended five key dimensions to build security resilience.
- Closing gaps in the company’s system to create one, open platform to ensure less entry points and establishing a unified, secured system across devices.
- Seeing more and always be monitoring – instead of waiting for a cyber incident to respond to, consistent monitoring to ensure employees are abiding by best practices to reduce risk.
- Anticipating what is next using actionable intelligence – consistently making cybersecurity part of a company’s advancements and understanding cyber risks that are part of transformative policies.
- Prioritising what matters most – making sure data stays secure as part of a business plan rather than an after thought.
- Automating responses to bounce back fast – using automation at the early stages of a cyber incident can be a game changer in identifying and quickly responding to incidents.





