Government warns of cyber knowledge shortage at board level in the UK

Cyber Governance Health Check highlights the lack of understanding around cyber threats

Board members round a table

Board level executives at some of the UK's biggest companies still don't fully understand the potential impact of a cyber attack, according to a government report.

The Cyber Governance Health Check looks at the approach the UK's FTSE 350 companies take towards cyber security and the 2018 report published on Tuesday, showed that less than 16% of boards had a comprehensive understanding of the impact of a cyber attack.

This is despite 96% having a cyber security strategy in place and even more worryingly, only around half of those test their plans on a regular basis.

"The UK is home to world-leading businesses but the threat of cyber attacks is never far away," said Digital Minister Margot James. "We know that companies are well aware of the risks, but more needs to be done by boards to make sure that they don't fall victim to a cyber attack."

There are some positives with awareness of cyber attacks increasing year-on-year; almost three-quarters of respondents, 72%, acknowledge the risk of cyber threats is high, up from 54% in 2017.

The report said this is largely down to the introduction of the General Data Protection Regulations (GDPR), which has had a positive effect in increasing the attention that boards are giving cyber threats. In 2018, 77% of those responding to last years health check said that board discussion and management of cyber security had increased since GDPR came into force in May 2018.

"Boards need to recognise that they have a responsibility to drive changes to business and IT operating models to enable their organisations to be securable," Richard Horne, cyber security partner at PwC.

"Managing cyber risk is about far more than just building security controls, and requires board-driven business change. At PwC, we work with a variety of organisations and there's always a noticeable difference in those who have a strong understanding of cyber risk at board level."

Featured Resources

Security analytics for your multi-cloud deployments

IBM Security QRadar SIEM solution brief

Download now

Five reasons to move to the cloud

Join the enterprises moving their workloads to the cloud

Download now

Architecting hybrid IT and edge for digital advantage

Why business leaders should consider a hybrid IT strategy

Download now

Six reasons to accelerate remote asset monitoring with AI

How to optimise resources, increase productivity, and grow profit margins with AI

Download now

Recommended

Lazarus APT hacking group is targeting the defense industry
Security

Lazarus APT hacking group is targeting the defense industry

26 Feb 2021
Microsoft open sources CodeQL queries used in Solorigate inquiry
Security

Microsoft open sources CodeQL queries used in Solorigate inquiry

26 Feb 2021
CISA warns of ongoing Accellion File Transfer Appliance attacks
hacking

CISA warns of ongoing Accellion File Transfer Appliance attacks

25 Feb 2021
What is a Trojan?
Security

What is a Trojan?

25 Feb 2021

Most Popular

How to build a CMS with React and Google Sheets
content management system (CMS)

How to build a CMS with React and Google Sheets

24 Feb 2021
Oxford University COVID lab falls victim to hackers
hacking

Oxford University COVID lab falls victim to hackers

26 Feb 2021
Npower shuts down app after hackers steal user data
hacking

Npower shuts down app after hackers steal user data

25 Feb 2021