Site navigation

Which Sectors Are Investing the Least in Cybersecurity Training?

Thom Carter

,

Which Sectors Are Investing the Least in Cybersecurity Training
According to recent findings from Indusface, an app security company, the sectors of accommodation and food, education, and transport are the three industries investing the least in cybersecurity training.

Amid the UK Government’s estimation that there have been 2.39 million instances of cyber-crime across all UK businesses from April 2022 to April 2023, Indusface surveyed over 2,200 respondents across 16 different industries to gauge each sector’s commitment to cybersecurity training.

Specifically, the survey uncovered that accommodation and food is the sector investing in cybersecurity training the least, with 75% of respondents saying their company doesn’t actively invest in cybersecurity training. Notably, 67% of respondents within this sector highlighted that their business has experienced a cyber-attack.

Ranking in second place is the education sector, with 69% of respondents working in this area saying that cybersecurity training isn’t being actively invested in. Regarding the question of “Has your business ever experienced a cyber-attack?,” 78% of respondents whose work is based in education said yes, the highest response from all the sectors surveyed.

Jointly ranking in second place alongside the education sector is transport, with 69% saying their company doesn’t actively invest in cybersecurity training.

Following the transport and education sectors is retail and wholesale at 53%, arts and entertainment at 31%, admin and support at 26%, professional and technical services at 26%, IT and communications at 25%, public sector and defence at 20%, and financial services at 16%.

On the flip side — when it comes to the sectors most investing in cybersecurity training — the utilities industry leads with 96% of respondents in this sector saying their company does actively invest in cybersecurity training, then construction at 94%, manufacturing at 92%, real estate at 91%, and health and social care at 90%.

The survey also highlighted, perhaps unsurprisingly, that email hacking is the most prevalent form of attack. However, “the way it is carried out is very versatile,” noted Indusface founder Venky Sundar, citing phishing, bot attacks such as credential stuffing, and the exploitation of SQL injection vulnerabilities.


Recommended reading


The aforementioned estimation of 2.39 million instances of cyber-crime among UK businesses between April 2022 and 2023 comes from the UK Government’s Cyber security breaches survey 2023 report, published in April of this year.

The report outlined that 32% of UK businesses and 24% of charities recall cyber breaches or attacks between those twelve months. Somewhat positively, this is a decrease from 39% of businesses and 30% of charities who recalled an attack in the year previous.

Further, the report’s authors estimated the average (mean) annual cost of cyber-crime for businesses to be approximately £15,300 per victim.

Thom Carter

Staff Writer, DIGIT

Latest News

Cybersecurity

Manchester Airport Group Suffers Data Breach of Customer Info

AI Cybersecurity Editor's Picks Security

Google, Microsoft and OpenAI Call For Cyber Defence Push

Featured Finance

Final Extension Announced for Scottish Fintech Awards

Business

Business Confidence in Scotland Rises as Trading Outlook Climbs