A new report from the Department for Culture, Media and Sport (DCMS) has found that businesses neglect cybersecurity procedures until after they’ve suffered an attack.
There was a consensus across all four organisations that cyber-crime is a significant and growing business risk, with cyber-attacks increasing in both volume and technical sophistication.
Knowledge of this fast changing ‘threat landscape’ did, however, vary significantly between study participants. In response to these increasing levels of risk, nearly all participants acknowledged the need for ever greater levels of vigilance and investment in cyber-security, as the controls that were appropriate a few years ago are now seen as less effective.
While interviewees from medium and large organisations said they tended to have formal plans in place and budget allocated for further cybersecurity investment, those from smaller organisations were more likely to assert they did not, largely citing resource constraints.
Their response to the perceived growing cybersecurity risk could therefore be deemed as being largely piecemeal and reactive.
The majority of participants felt their organisations put more of an emphasis on technology than employees to stay secure. For some, technology was a tool to ‘help people do the right thing’, reflecting the widespread notion that people and culture are more of a cybersecurity ‘weak spot’ than the technology deployed at their organisation.
Participants also reported varying levels of support and interest in cybersecurity from their leadership teams within their respective organisations. Most said that their leadership had grasped the importance of cybersecurity and was increasingly supportive of investing in it, with some already treating it as a ‘board level business problem’.
At the same time, not all were sure that their leadership teams fully understood the ‘scale of the threat’, or the ‘cultural transition’ required to meet the growing cyber-security challenge.
Recommended
- Albert King reflects on his time as chief data officer
- Apple security vulnerabilities: Is your device at risk?
- Full-fibre network extension boosting connectivity for rural Scots
One positive outcome of the breaches was that it was a tangible means to demonstrate that ‘these cyber threats are real’ to leadership, underscoring the importance of cybersecurity.
Consequently, for many organisations in the study, leadership became more engaged in the cybersecurity challenge post-breach and has since demonstrated more serious intent to help the organisation improve.
As for the breaches themselves, in most instances organisations in the study were able to determine the cause and fix the ‘weakness’, often drawing on the support of external vendors.
For some participants, the breach was a cause of considerable personal stress and upheaval – some of which has proved long lasting – while others were more sanguine, characterising the episode as an inconvenience rather than a calamity.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





