Six in ten (61%) IT leaders think the attack surface is “impossible to control”, with 90% saying the severity and risk of cyber-attacks have increased in the last year.
This is according to a new report from Appsbroker CTS titled Tipping the cyber scales: How defenders can get back in the game, which delved into the top threats 150 UK IT leaders are most concerned about in the evolving cyber landscape.
Malware, ransomware, and phishing attack topped the list, particularly the threat that these attacks could prevent their company’s operations.
IT leaders were also concerned about a lack of visibility about unidentified security risks, which could come from any angle, internal or external.
Next, leaders were concerned about identities being stolen by threat actors to access private data and systems.
Internal issues were also a concern – misconfigurations that could leave systems vulnerable to attacks, as well as needing to patch and rewrite applications leaving them more open to attack, rounded out the top five list of concerns.
Looking to the future, around eight in ten (79%) of IT leaders surveyed think emerging technologies – particularly genAI – will be game changers when it comes to cybersecurity, potentially leaving them unprepared.
For public sector IT leaders, this concern rises to 94%.
IT leaders also appear at a loss for what to do about emerging cyber threats. While investment has increased according to 97% of leaders, over half (55%) say they feel less secure now compared to last year.
Recommended reading
Leaders seem to be defeated, with over half (57%) feeling cyber-criminals will continue ‘winning’ despite investment, reiterating the 61% said that the attack surface is uncontrollable.
Another barrier for IT leaders is a lack of understanding for governance, processes and controls to safeguard their data.
Due to this, 67% IT leaders say their security is inconsistently applied as their teams are unable to apply governance policies and controls effectively over their environment.
Further, nearly three quarters (71%) say that a lack of access and control over data is leaving them vulnerable to security risks.





