Site navigation

Google: Legacy Tech and GenAI is Leaving UK Firms Vulnerable

Tom Quinn

,

genAI cybersecurity
A new survey from Google has found UK security teams are under mounting pressure, thanks to outdated systems and unlicensed AI use.

New research from Google suggests that IT and security leaders in the UK are feeling more pressure than their international counterparts, driven largely by the burden of legacy technology and the rapid rise of genAI threats.

The latest Google Workspace survey, Security at a tipping point, found that 75% of UK security leaders believe legacy technology has left them ill-equipped to handle the challenges of modern security threats, compared to 59% globally, creating vulnerabilities that cyber-criminals are more easily able to exploit.

The survey, from 2,000 business and security decision makers, highlights a persistent problem as organisations opt to expand existing tools rather than switching outdated ones for more modern, secure-by-design solutions, with 62% of security leaders admitting to reusing older security tools rather than replacing them. 

Despite 96% of firms expressing high confidence in their ability to manage security, the fact is by relying on legacy systems, organisations are leaving themselves vulnerable, with complex and unwieldy security environments being more difficult to manage effectively. 

Google’s survey also showed that security leaders are increasingly wary of the threat posed by genAI, despite other business areas becoming reliant on AI tools. Over three-quarters (77%) of UK security executives believe that genAI threats have contributed to a rise in security incidents, underscoring the need for proactive measures to address the evolving security landscape.

Worryingly, most UK organisations have also been slow to act on these concerns, as only 27% of UK respondents said that they had introduced genAI-specific security policies, compared to the global average of 41%. 

According to Google, the increase in security concerns related to AI can be attributed to several factors, including the rise of “shadow AI” inside of companies – the use of genAI tools that haven’t been vetted or authorised by IT and security teams.

Almost two-thirds (63%) of decision makers reported that unlicensed genAI tools are being used on a weekly basis, despite less than half (44%) believing them to be safe.

Unsanctioned and ad hoc use of genAI creates a much more challenging environment for security administrators who are forced to protect against threats they can’t see and can’t measure, leading 63% to report that their organisation’s technology landscape is less secure than it was in the past.

Those pressures have taken a toll on IT and security teams, with 43% of security leaders in the UK reporting that their teams are overwhelmed and burned out by security threats, 15% higher than the global average. 

It’s also impacting the bottom line, with the average cost of a data breach in the UK now £3.5 million, 7.6% higher than last year, with businesses reporting spending more cybersecurity insurance (37%), upgrading cyber defences (35%), renewing licences (34%), and finding new security providers (31%).  

Despite snowballing costs, 60% of UK security leaders say they’re open to new approaches that cost more to close the gaps in their defence.

“Decision-makers are telling me they’re worried and kept up at night,” said Rachel Tobac, CEO of SocialProof Security.

“Technical tools aren’t perfect, and they require a lot of human oversight, so decision makers are very stressed out. Teams need to audit their purchased tools to gain an understanding of which capabilities they already have before buying the same protection again and again.”


Recommended reading


To address these challenges, Google has some key recommendations for UK organisations:

Embrace modern, secure by design solutions

By moving away from legacy technology to streamlined solutions it’s easier to address the vectors where most attacks start, like phishing, stolen credentials, and software exploits.

Begin with small steps

Don’t try to modernise an entire software ecosystem at once, but instead used a phased approach to make meaningful security gains, with minimal impact on end users.

Prioritise account security

Strengthen defences by implementing authentication measures like 2FA and phishing resistant Titan Security Keys, that can help protect against compromised user IDs.

Leverage AI (carefully) for added protection

Using AI in certain tools like spam filters can radically reduce instances of phishing or other emerging threats, with Google reporting that thanks to LLMs Gmail now blocks 20% more spam and 120 million phishing attempts a day.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI Startups

UK Gov Launches £100M Competition for AI Startups Boosting Public Services

Robotics

Glasgow Uni Researchers Guide Future of Social Robot Design

Business

Techscaler Selects 10 Scottish Founders for Silicon Valley Programme

Cybersecurity

Manchester Airport Group Suffers Data Breach of Customer Info