Government warns of cyber knowledge shortage at board level in the UK

Cyber Governance Health Check highlights the lack of understanding around cyber threats

Board members round a table

Board level executives at some of the UK's biggest companies still don't fully understand the potential impact of a cyber attack, according to a government report.

The Cyber Governance Health Check looks at the approach the UK's FTSE 350 companies take towards cyber security and the 2018 report published on Tuesday, showed that less than 16% of boards had a comprehensive understanding of the impact of a cyber attack.

This is despite 96% having a cyber security strategy in place and even more worryingly, only around half of those test their plans on a regular basis.

"The UK is home to world-leading businesses but the threat of cyber attacks is never far away," said Digital Minister Margot James. "We know that companies are well aware of the risks, but more needs to be done by boards to make sure that they don't fall victim to a cyber attack."

There are some positives with awareness of cyber attacks increasing year-on-year; almost three-quarters of respondents, 72%, acknowledge the risk of cyber threats is high, up from 54% in 2017.

The report said this is largely down to the introduction of the General Data Protection Regulations (GDPR), which has had a positive effect in increasing the attention that boards are giving cyber threats. In 2018, 77% of those responding to last years health check said that board discussion and management of cyber security had increased since GDPR came into force in May 2018.

"Boards need to recognise that they have a responsibility to drive changes to business and IT operating models to enable their organisations to be securable," Richard Horne, cyber security partner at PwC.

"Managing cyber risk is about far more than just building security controls, and requires board-driven business change. At PwC, we work with a variety of organisations and there's always a noticeable difference in those who have a strong understanding of cyber risk at board level."

Featured Resources

How to be an MSP: Seven steps to success

Building your business from the ground up

Download now

The smart buyer’s guide to flash

Find out whether flash storage is right for your business

Download now

How MSPs build outperforming sales teams

The definitive guide to sales

Download now

The business guide to ransomware

Everything you need to know to keep your company afloat

Download now

Recommended

Cisco to acquire threat intelligence provider Kenna Security
Acquisition

Cisco to acquire threat intelligence provider Kenna Security

14 May 2021
What is the Computer Misuse Act?
Policy & legislation

What is the Computer Misuse Act?

14 May 2021
Hackers use open source Microsoft dev platform to deliver trojans
Security

Hackers use open source Microsoft dev platform to deliver trojans

14 May 2021
What’s next for the education sector?
Whitepaper

What’s next for the education sector?

14 May 2021

Most Popular

KPMG offers staff 'four-day fortnight' in hybrid work plans
flexible working

KPMG offers staff 'four-day fortnight' in hybrid work plans

6 May 2021
Dell XPS 17 (2021) review: A big laptop for big jobs
Laptops

Dell XPS 17 (2021) review: A big laptop for big jobs

10 May 2021
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

29 Apr 2021