Site navigation

Boards at UK’s Biggest Companies “Must do More” to be Cyber Aware

Ross Kelly

,

UK Companies Cyber Aware

While cyber awareness can be improved at a boardroom level, the implementation of GDPR in May last year has led to a greater focus on cyber resilience.

Boards at some of Britain’s largest companies still do not fully understand the damage that cyber attacks can cause, according to a new government report.

The UK Government’s Cyber Governance Health Check assesses the cybersecurity practices of some of the UK’s top firms, and found that less than one-fifth (16%) of boards have a “comprehensive understanding” of the impact that cyber attacks could have on their business.

Boards do not completely understand the threat landscape despite the fact that almost all (96%) of the companies surveyed say they have a cybersecurity strategy in place.

The report also founded that, although 95% of businesses have a cybersecurity incident response plan, only 57% test them on a regular basis.

Recommended: Openreach Unveils £485,000 Investment in Livingston Training Facility

Commenting on the report publication, Digital Minister Margot James said: “The UK is home to world-leading businesses but the threat of cyber attacks is never far away. We know that companies are well aware of the risks, but more needs to be done by boards to make sure that they don’t fall victim to a cyber attack.

“This report shows that we still have a long way to go but I am also encouraged to see that some improvements are being made.”

Cyber awareness has increased among the UK’s businesses, the report found. Nearly three-quarters of respondents said they acknowledge growing cyber threats – marking an improvement from 54% in the Government’s 2017 report.

The implementation of GDPR has, the report acknowledges, positively impacted businesses. An increasing awareness over the handling/use of consumer data and growing cybersecurity threats has led to a greater understanding among management figures.

More than three-quarters (77%) of respondents said that board discussion and management of cybersecurity had increased since GDPR. As a result of GDPR implementation, more than half of those businesses said they had put in place “increased security measures”.

A stronger emphasis on cyber resilience has also come about due to the implementation of GDPR, the report found, with more businesses focusing on how to improve their level of resilience.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data