Scottish businesses are less likely than their UK counterparts to put in place critical data security policies and procedures, according to Shred-it’s eighth annual State of the Industry Report.
The annual study highlights the current information and data security risks that threaten enterprise and small businesses in the UK. According to the survey, Scottish businesses consistently lacked behind their UK counterparts in a number of areas, including general information and security policy, employee information security policies and data security protocols.
Lagging Behind?
Ipsos conducted a quantitative online survey of three specific sample groups in UK industry; with 1,000 small business owners, over 100 C-Suite Executives of large organisations and in excess of 1,100 consumers/employees.
Fieldwork for the report was conducted between April 9th and April 23rd 2018, and grouped respondents’ industry sectors into specific categories, including:
- Retail: Wholesale & Retail and New Car Sales
- Business Services: Professional/Scientific/Technical Services & IT Communications
- Finance/Legal/Insurance
- Public Services: Health & Social Care, Education, Public Sector and Justice
- Real Estate: Real Estate Agents & Brokers, Facilities Management and Hospitality
The report findings highlight a concerning lack of security awareness among Scottish businesses and suggests that businesses are consistently failing to implement rugged security procedures.
Scottish firms were less likely than those in other regions to have a general information security policy. Most concerning is the revelation that over one-third (36%) had no information security policy in place at all. This represents a massive disparity policy implementation compared to London (17%), Wales (19%) and the North (29%).
By quite a staggering margin, Scottish businesses are the least likely to have any policies requires employees to report an information security issue, which is now an integral aspect of GDPR compliance. 60% of Scottish businesses admitted they had no policy in place at all, compared to 44% in Wales, 55% in the Midlands and 42% in London.
Staff working off-site for Scottish businesses also have very little data security protocols, with 46% of firms reporting they have no policy for this at all. Businesses in Wales (42%), the North (34%) and London (24%) all fared far better than their Scottish counterparts.
Scottish businesses also ranked poorly in terms of data security practices in the following areas:
- Having a known and understood policy on storing and disposing of confidential information – nearly half (45%) have none at all
- Training staff on information security procedures – 36% never train their staff in this critical area
Protecting Consumers and Employees
Neil Percy, Shred-it’s VP of Market Development and Integration EMEA, believes that some businesses may be complacent in regards to information and data security, believing it to be common sense. To counter this, training and education on these issues is essential.
He said: “It might feel like rough justice for employees to be held to account when training is not comprehensive, but it reflects how difficult this process is, even for businesses with extensive resources.
“There may also be an assumption that some elements are common sense, but that potentially belies how easy it is to be duped by skilled phishers and hackers, or even to lose confidential info during the course of a busy day. Mindfulness is key and training helps.”
With GDPR raising the stakes for businesses and organisations across Europe, the need to ensure that employees are adequately trained has never been greater. The report, Percy says, suggests employees aren’t receiving nearly enough information or education on the subject.
“The lack of ubiquitous training on GDPR, for example, suggests that a large proportion of the British workforce is not appropriately trained for the kinds of safeguards necessary under GDPR.”
Eamonn Keane, the Head of Cyber Security and Innovation at the Scottish Business Resilience Centre, told DIGIT:
“Scotland’s cyber industry continues to witness a growing vibrancy and agility where global enterprises seek Scotland as a base for international operations. Reflecting this growth the Scottish Business Resilience Centre enthusiastically supports Scotland’s SME market with its unique challenges, growing economy and rurality. We continue to support and promote the recently published Scottish Government Public, Private and Third Sector Cyber Security Action Plans to raise standards across all sectors in protecting businesses and crucially promoting resilience with growth.
“These are exciting and opportune times in digital and cyber. Scotland’s innovation, agility and academic conveyor belt of excellent talent, place us in a favourable position to support and grow our SME’s as the backbone of Scottish industry.”





