New research has found that cybersecurity is being neglected by UK CEOs, posing significant risks to businesses.
In a survey of 1,000 senior executives, conducted by compliance training provider Skillcast, only 6% of CEOs listed cybersecurity as a priority, ranking it ninth out of twelve major regulatory concerns.
Despite the increasing frequency of cyber-attacks and data breaches, many CEOs admitted focusing on other areas, leaving critical vulnerabilities unaddressed.
While customer satisfaction (21%) and revenue growth (18%) top the list of business priorities, compliance and risk management, including cybersecurity, are deprioritised, with only 4% of CEOs ranking it as their top concern.
Younger CEOs (18-24 years) were more likely to prioritise anti-bribery regulations, with 43% listing it among their top three concerns, older CEOs (55-64 years) show more focus on cybersecurity and tax compliance.
Skillcast’s report also shows that senior-level employees, who often have access to the most sensitive data, are significantly less likely to report cyber incidents such as phishing emails or suspicious IP addresses.
In fact, senior level execs are three times less likely to report compromised passwords or suspicious IP addresses compared to entry-level staff, and nearly half (48%) admitted they wouldn’t immediately report a phishing email, and 41% would delay reporting compromised work passwords.
“The data reveals a dangerous gap between the perception of cybersecurity risks and the actions being taken to mitigate them. With cyberattacks becoming more sophisticated and regulatory scrutiny tightening, businesses cannot afford to ignore this area,” said Vivek Dodd, CEO of Skillcast.
“Cybersecurity needs to be embedded into every level of an organisation’s culture, from entry-level employees to senior leadership. Every employee must be empowered to act as the first line of defence.”
Recommended reading
- Ransomware Groups are Adjusting Their Strategies
- NCSC Guide: How To Bridge Cyber With The Boardroom
- NCSC Warns Ransomware Threat to Rise with AI
Research from earlier this year indicated that as well as underestimating the importance of cybersecurity, business leaders are gravely unprepared for dealing with cyber-attacks when they do happen, with 8% of CEOs saying they would engage with threat actors directly in the case of a cyber-attack.
The problem has not gone unnoticed, however. Yesterday, the UK’s National Cyber Security Centre issued guidance to help cybersecurity leaders communicate cyber-risks more effectively with Boards, stressing the importance of messaging, relationship building and de-siloing cybersecurity.





