UK cyber-security preparedness lags behind awareness
.jpg)
Awareness of cyber-security threats and the need to address it is unprecedentedly strong among global organisations. However, the awareness has not translated into preparedness, said NTT’s global survey. The disparity is stark in European companies, particularly those in the UK, said the report.
More than 90 percent respondents in the UK believe that strong cyber-security is more important than growing revenue and profit (78 percent) to their business over the next 12 months, said the survey.
"Far too few companies – only 58 percent – have a formal security policy. That’s up just one percent from last year," said the report. Of those, only 48 percent said that their employees were fully aware of the policy, putting the total number of companies with fully-understood policies at just 28 percent.
There is still a shocking failure of security policy being understood – or even known about – in the wider workforce, said Maxine Holt, enterprise technology research director at UK-based cyber-security company Ovum.
"At an IT event recently, I witnessed 60 percent of laptops left unlocked whilst unattended – this was in an environment where those individuals worked for rival companies. On a train last month I saw someone had left their locked laptop on a seat – with their user ID and password on a post-it note stuck to the laptop," she recalled.
Budgetary concerns and lack of qualified staff complicates the situation. More than 40 percent of organisations lack the necessary skills and resources to cope with the number of cyber-security threats, found the survey. The figure was 46 percent for the UK, while only 38 percent of Swiss and French companies reported a lack of qualified staff.
"Large organisations with deep pockets frequently attract skilled security people, leaving smaller enterprises to struggle with security challenges with little in-house expertise. There are pockets of initiatives taking place around the country (and indeed the globe) to build security expertise, but this is in no way sufficient to deal with today’s workforce shortages," said Ovum’s Holt.
Exacerbating the situation is the lack of coordination in cyber-security efforts, with only 72 percent of the respondents acknowledging it as a boardroom issue. "Nearly half of all respondents (45 percent) say that cyber-security is the IT department’s problem. This rises to 57 percent for C-level respondents, which demonstrates an alarming hands-off attitude to cyber-risk in the organisations concerned," said the report.
The chinks in the cyber-defence armour are increasing, so is the willingness to surrender to ransom demands. The organisations that would consider paying a ransom in 2019 remained unchanged at 33 percent, while a higher number (36 percent) conceded that they would rather pay a ransom than get a fine for non-compliance.
"Cyber-criminals have developed a more diverse and stealthy network of ransomware operations by devising intelligent ways of using the leak data for commercial and national security implications," said Azeem Aleem, VP at NTT Security. "Cyber-criminals are not bound by any rules; their attacks are shielded and hidden across the organisational network."
The monetary value of the attacks prove the gravity of the situation. According to the respondents, it will cost more than 12 percent of the organisation’s revenue to recover from a breach, up from 10.3 percent in 2018 and 9.9 percent in 2017. Respondents estimated recovery time of 66 days on average, up nine days from 57 days last year.
There is still a lack of confidence in law enforcement agencies’ capabilities to tackle these advanced attacks, Aleem observed. "Incidents have shown in the past that the moment organisations approach law enforcement agencies, cyber-criminals leak their data online, therefore undermining confidence in the security of the company."
"Security is not a do-once project. It is a culture, an approach, an ethos in an organisation. UK companies should pay more than lip-service to security, despite the challenges they should focus on developing the ability to prevent, detect, and respond to cyber-attacks, devote time and resources to building expertise in-house," said Holt.
source scmagazineuk

Latest Jobs
-
- Infrastructure (Network / Security) Engineer | West London commutable | Permanent
- London
- Apply today
-
Infrastructure (Network / Security) Engineer | West London commutable | Permanent This is an in house opportunity. Looking for someone that has on prem / data center experience MUST be a currently hands on config, Install, upgrade, troubleshooting experience Routing, Switching, Network Security (firewall, IDS etc), Microsoft Active Directory / 365. VMWare Scripting / automation experience wanted. Python, Powershell etc Must be commutable to West London twice a week. Visa sponsorship not available. Apply today for more information Book a call via this link https://calendly.com/d/crqf-t28-7tb
-
- Identity & Access Management Architect
- Edinburgh
- Upto £95000 plus bonus and benefits
-
Location: Edinburgh | Hybrid Working | Permanent Are you an experienced Identity & Access Management professional with a passion for designing and implementing cutting-edge security solutions? We are looking for a Lead Architect, where you’ll play a key role in helping clients enhance their IAM capabilities, protect critical data, and navigate complex security challenges. About the Role As a Lead Architect, you will be responsible for shaping and delivering IAM strategies, designing robust security solutions, and driving long-term digital transformation. You’ll leverage your expertise to provide strategic guidance on areas such as: Identity Governance & Administration (IGA) Privileged Access Management (PAM) Access Management (AM) Entitlement Management Directories & Authentication Solutions You will have the opportunity to work with innovative technologies and frameworks, ensuring that businesses can securely manage access to critical assets while enabling growth. What You’ll Be Doing Providing subject matter expertise in IAM and leading transformation projects for clients Developing IAM roadmaps, operating models, and governance frameworks Driving innovation by integrating IAM capabilities into wider digital transformation strategies Building and maintaining strong relationships with clients and stakeholders Designing and implementing scalable IAM solutions to meet business needs What We’re Looking For Proven experience in IAM strategy, solution architecture, or assurance Strong leadership skills with experience guiding technical teams Ability to work in a client-facing role, delivering clear communication and insights A technology-focused, innovative mindset with strong business acumen Willingness to work from our Edinburgh office 2-3 days per week
-
- Security Architect - Cloud - Consultancy London
- London
- N/A
-
Security Architect with a focus into Cloud (AWS, Azure or Google Cloud Platform) needed. You must have client facing consultancy experience. This mean you must have experience working with clients helping them to meet their security design needs. That could include working with existing internal teams to understand, review and mitigate / uplift existing Cloud Security designs, or perhaps helping clients set out / understand their current needs and deliver their cloud security strategy. (Or anything in between) Technical knowledge is of course essential but working with clients to understand and solve their Cloud Security design challenges is vital. You must obviously have a current history working as a cloud security architect. You will need to be commutable to London. Whilst a hybrid role the expectation is 3 days a week in the office / meeting clients. International relocation or Visa sponsorship isn’t available for this role. Apply on this page and arrange a call here https://calendly.com/d/crpz-m7j-wyx