The survey was done with 400 IT professionals between January and April 2023 across middle and senior management, to C-suite in UK-based organisations with over 500 employees.
It found that the majority (96%) of respondents believed they had 35,000 or less devices on their network, when in reality, more than half (53%) have over 35,000, 35% of which having over 100,000. In contrast, 2.5% said they have between 35,501 and 100,000, and 1.5% said they had over 100,000.
Additionally, a significant portion of organisations in the UK update their inventory of connected assets infrequently. Only 9.9% of respondents said they updated their inventory on a daily basis, while 2.8% admitted they never updated their inventory.
These revelations come on the backdrop of heightened regulatory environments, staffing and recruitment difficulties, and expanded attack surfaces. This, paired with the lack of visibility into network-assets has led to an increase in security breaches.
According to the UK government, over one in three (32%) businesses recall a cyber breach or attack in the past 12 months. A number which jumps to 69% when looking at just large businesses. In the survey, half of the respondents said they had experienced a cyber attack in the last five years.
Recommended
- Rural Scotland Beset by the Slowest Broadband Speeds in the UK
- Cyber Attack Targets UK HR Provider — BBC, Boots, British Airways Impacted
- UK at Risk of Losing Position as Tech Leader, Warns techUK
Curtis Simpson, CISO at Armis, commented on the findings, saying: “Technology environments continue to become more complex through evolving multi-year transformations. Simultaneously, vulnerabilities are disclosed at an unparalleled rate and attackers are evolving their capabilities at scale. In these circumstances, security programs cannot run on intuition.
“Businesses require continuous visibility and intelligence to understand the technical assets powering the business and how the corresponding attack surface can or is being exploited with the potential for material impact.”
In response, the advice given to companies based on guidance from the National Cyber Security Centre are:
- Verifying the access control through reviewing passwords and third party access, and implementing MFA.
- Reviewing system patching and high severity alerts.
- Creating a comprehensive incident response plan.





