Search this site
2025 results found with an empty search
- Cyber Security Remains A Significant Concern For Family Firms
A new report reveals over a fifth (21%) of SME owners are concerned by overseas cyber threats in the midst of heightened cyber security threats from Russian hackers. The annual 2022 business challenges report carried out by card payments specialist takepayments Limited , surveyed SME business owners and decision-makers across the UK to discover the current small business landscape for the year ahead. Over the past two years, the ICO reports that there has been a steady and significant increase in cyber-attacks towards UK businesses. This is reflected in takepayments report as more than a quarter (27%) of small business owners now state cyber security as the biggest threat to their business in 2022, a staggering 247% increase from 2021 (8%). As the UK imposes more sanctions on Russia, the threat of an over seas cyber attack could continue to increase and businesses within the engineering and manufacturing sector (32%) are the most concerned about the prospect of an over seas cyber attack, followed by the law and security sector (31%). Takepayments have partnered with cyber security expert James Bore, Director of Bores Security Group to provide their top tips in staying safe online. 1. Backup. Back up everything in at least some form separately from your business’s devices, and test the backups. Nowadays, if you’re using good cloud storage services, they can provide a high level of availability, screening for any known malware, and online storage that business owners can access from anywhere they need for a low cost rather than having to invest in expensive backup hardware. Given the cost of good cloud storage these days, business owners can either identify the most important things to backup or in most cases just ensure absolutely everything data-related is replicated online. 2. Be Aware Of Malware. Malware is any malicious software. There are various different kinds, including viruses, and just like human viruses, no protection will be perfect. Protecting your business from malware is about hygiene – business owners should make sure that their antivirus or antimalware software is installed and turned on (there are good, free options as well as commercial ones, but do your research), make sure staff are not downloading and installing anything dodgy, do regular patching or turn on automatic updates, set up firewalls on machines, and try to avoid using USB sticks or memory cards – with cloud storage these should be largely unnecessary anyway. 3. Hygiene Extends To Phones And Tablets As Well. Turning on password protection, using some of the tools business owners are most likely already paying for to make sure devices that go missing can be found, or wiped, keeping everything up to date, and if they use public wifi assume everything they’re doing is visible to someone so don’t do anything sensitive. 4. Passwords. A lot of password device is old fashioned. If business owners have the option, secure passphrases (a collection of random words strung together or written in a sentence) are much more secure and easier to remember than a scrabble of letters and symbols. Business owners should also, for anything sensitive, use 2FA (two-factor authentication) – Google and Microsoft provide their own free Authenticator apps, and another good one is Authy – with an app installed on their phone or tablet. 5. Don’t Get Hooked. The vast majority of attacks happen because of malicious emails, commonly known as phishing emails. There are lots of lists of tips about how to avoid them, many of which are highly technical, but as a very basic piece of advice I usually say that if any message (email or voice) is asking a business owner to do anything out of the ordinary, or causing any sort of emotional response (excitement, fear, etc) then take a few seconds to verify it. To do this do not use any of the contact details provided in the e-mail, instead use a phone number they know to be right, a live chat page on a website, or any other method they know to be safe to confirm that the e-mail is genuine. Sandra Rowley at takepayments limited said: “Cyber security should ultimately be taken as seriously to a business owner as taking out business and liability insurance. More than one in five small business owners created a website for their business during the pandemic according to our recent report, and cyber security should come as a top priority for any business looking to move online. Unfortunately, as further sanctions are implemented towards Russia, the threat of cyber security attack’s could increase so now is more important than ever for businesses to implement as many cyber security measures as they can to ensure their business is protected as much as possible.”
- Small Businesses Urged To Improve Cyber Security
In light of the recent cyber attacks on M&S and Co-op, businesses are being urged to improve their digital security or run the risk of cyber-attacks. That’s the warning from tech expert Juliet Moran from TelephoneSystems.Cloud who claims the UK’s small businesses are ill equipped to deal with data breaches and hacking. It comes after the news that M&S says its online services will continue to be disrupted until July, with the company expecting a fall in profits of £300m. According to figures from The Cyber Security Breaches Survey, half of businesses (50%) experienced some form of cyber security breach or attack in the last 12 months. For medium businesses the number was 70% and for large businesses 74%. She believes with increased knowledge and by making some adjustments, small businesses could increase their cyber security considerably. Backing up systems, running updates, replacing outdated software and using password manager will all add up to instant improvements when it comes to protecting business data. Juliet Moran from TelephoneSystems.Cloud said: “Digital security is a necessity for small businesses with cyber threats evolving rapidly. There are some simple steps businesses can take straight away." "Using a password manager, for example, improves security by generating and storing complex passwords and reducing the risk of breaches from weak or reused passwords." “Implementing two-step verification adds an extra layer of security, making it much harder for attackers to gain access even if passwords are protected." “Taking proactive measures means small businesses can protect themselves and their assets and leave themselves less at risk from future digital security issues.” Here is TelephoneSystems.Cloud ’s advice for improving digital security: Back Up Data Backing up your data means if you lose access to the original, you can restore it via the backup. You can back up using cloud storage or removable media including an external hard drive, USB. Strong Passwords Do not use the same password across multiple accounts - this is a really easy way for cyber criminals to access various email accounts, bank details, in fact anything that is password protected. Always use a strong and separate password. Password Manager A password manager stores all your passwords, so you don’t have to remember them. This means you can have unique passwords for every account, significantly reducing the risk of cyber-attack. Most browsers will save passwords for you - this is safe to do on your own device. Never do it on a shared device or one others have access to. Software Updates If a laptop, desktop or any device is asking you to update software, make it a priority. They’re the best way of ensuring you have protection against the latest types of cyber-attack. Updates will include protection from viruses and other kinds of malware. 2-Step Verification On important accounts, turn on 2-step verification. When you set it up, you may be sent a pin or code to verify it’s you accessing your phone or email. Sometimes it may be your fingerprint or a face scan. Think Before You Click If a link or email looks suspicious, don’t click on it or open it. Inspect links and make sure they're from trusted senders. Make sure you educate your team on cyber security and encourage them to become vigilant. VPNs There are security risks associated with using public and personal WiFi networks so make sure you and your team are clear on which ones are safe to use. Consider VPNs (Virtual Private Networks) for remote working or when working on unknown or untrusted networks and ensure 2FA is enabled on your router.
- Stolen Credentials Tops Causes Of Cyber Breaches In 2023
Stolen credentials through phishing attacks were the most common cause of cyber breaches among UK businesses last year, a new study has revealed. Cybersecurity firm IDEE commissioned an independent survey of more than 500 IT and cybersecurity professionals within UK businesses. It found that 61%) of businesses experienced a cyber breach in 2023, with 25% suffering three or more. When asked to name the cause or causes of their most recent breach, 35% said it was the result of stolen credentials (passwords, tokens, etc.) through phishing attacks, making it the most common reason. The next most frequently selected factor with 29% was ‘a vulnerability that was not patched by their cyber security solution.’ The data also raises questions about the efficacy of password-based Multi-Factor Authentication (MFA) solutions, with 23% indicating that their MFA solution was bypassed or compromised in their latest breach. The same number (23%) suffered a breach due to a backdoor attack (malware that sidesteps authentication procedures to gain access). Al Lakhani, CEO of IDEE, said: “The data perfectly encapsulates the fundamental flaw behind so many MFA solutions: they are password reliant." “The cyber industry’s ‘best’ solutions in recent years have tried to bolster security with additional authentication factors like OTPs, push notifications, or QR codes, but these methods remain tethered to centrally stored passwords and are therefore susceptible to phishing attacks. Consequently, businesses continue to suffer breaches and account takeovers because they focus on detection rather than actually preventing the breach in the first place." “Businesses’ dependence on password-reliant MFA is a case of herd mentality. It’s time to stop following others and embrace solutions rooted in transitive trust and robust identity proofing. Hopefully this research acts as a wake-up call for cyber teams across the country.”
- Consumers Lack Trust In Firms After A Data Breach
Two-thirds of consumers do not trust a company after a data breach. A cybersecurity expert explains the significance of cyberattacks and ways to minimize reputational damage. Cybersecurity breaches are a significant threat to a company's financial health and its reputation. While the immediate consequences of cybercrime often involve data loss, corrupted information, and compromised accounts, the long-term implications can be far more devastating. Reputation management should be a priority for business executives. Cybersecurity plays a crucial role in this effort because security incidents can significantly ruin an organization's reputation. Research by ISACA indicates that 78% of respondents view the impact on an organization's reputation as the top concern regarding cyberattacks. "High-profile cyberattacks attract media attention, especially when they involve well-known organizations or affect a large number of customers," says Andrius Buinovskis, head of product at NordLayer , a network security company. "The negative publicity can further diminish public trust, leading to a tarnished brand image and potential loss of market share. Then you lose the foundation of your business relationships, and it's an uphill battle to rebuild consumers’ trust in you." Statistics On Consumer Trust After A Cyberattack A survey found that 75% of consumers expressed their readiness to sever ties with a brand in the aftermath of any cybersecurity issue. Moreover, 66% of US consumers stated they would not trust a company that experiences a data breach with their data. A cyberattack will also affect stakeholder trust. When the financial services company Capital One disclosed a data breach, its share price dropped nearly 6% in after-hours trading. Over the next two weeks, the share price fell by almost 14% as investors struggled to repair the damage to the company's reputation. Businesses can assess the financial impact of a data breach, but the toll on a company's reputation is often more challenging to measure. However, industry experts found a 60% failure rate among small and medium-sized businesses (SMBs) within 6-12 months of disclosing a breach. Recovering From Reputational Damage In Cybersecurity Recovering from the reputational damage caused by a cybersecurity incident is a significant challenge that requires a strategic and long-term approach. Effective communication is crucial in managing this type of crisis because timely and accurate information can help control the breach's impact and rebuild stakeholder trust. Buinovskis explains that when a cybersecurity incident occurs, companies must communicate with all relevant stakeholders, including customers, employees, investors, and regulators. Businesses should be transparent, acknowledge any vulnerabilities that may have contributed to the breach, and demonstrate a sincere commitment to improving their security practices. "Rebuilding trust after a cybersecurity incident requires you to demonstrate to your stakeholders that you've learned from your mistakes and are taking steps to prevent future incidents." "Regular communication and a long-term plan to enhance your cybersecurity posture is essential for any organisation seeking to regain the confidence of its customers and partners."
- Five Ways To Prevent Cloud Security Mistakes
After it was revealed almost nine in ten cyber-attacks are caused by human error, experts have named five ways organisations can guard themselves against staff mistakes. IT experts from HostingSystems.co.uk have issued a warning to UK businesses after it was revealed 88% of cyber breaches were caused by preventable employee mistakes. Now they have named the five most common, and easily preventable, mistakes made by businesses which could leave them exposed to criminals. The majority of businesses encounter a security breach due to unsecure systems which have often been left running outdated software. But with the cost of cybercrime to the UK economy estimated to be around £27 billion, organisations should ensure teams are trained to update systems and keep cybersecurity front of mind. Since the pandemic, Cloud services and applications have aided the transition to remote working and drastically improved how businesses operate. However, organisations who have made the transition without proper cybersecurity management in place could be leaving the backdoor open for criminals to exploit. Weak passwords are one example of poor security which can leave corporate cloud services defenceless against automated software used by hackers to test weak passwords against accounts. The storage and sharing of data must follow GDPR legislation which means data owners must undertake risk assessments and vetting to ensure that the location in which their data is stored will be secure and that there is no chance of a breach. Unless there is clear evidence of negligence from the cloud service provider, investigators usually find data owners to be at fault because of internal misconfigurations. Juliet Moran, founder of HostingSystems.co.uk says that although cloud providers manage business-sensitive data in their system with complete security measures, business leaders are ultimately the owners of the data and must take care of some measures to protect it from external threats. She said: “Cyber attacks are costing firms billions every year so many business leaders may be shocked to learn the majority can be blamed on preventable human error." “Businesses are responsible for their infrastructure, so the data owner is almost always liable for security breaches unless there is evidence the cloud service is responsible." “A breach can result in the compromising of data from within the organisation, so businesses utilising cloud services must ensure that internal processes, policies and processes are watertight." “It is also important that decision-makers within a company vet cloud services and explore their options before choosing to store data with them, to ensure they are secure and have suitable privacy measures." “With the incorrect security measures in place, such as insufficient credential management and poor network security, businesses are putting themselves at risk." “The cloud is now a fundamental part of modern businesses because of how it has helped to transform processes, cut costs, streamline data and create easily accessible work environments." “Data stored in the cloud is encrypted and most providers have built-in threat detection software, so as long as companies introduce proper security measures, solutions and procedures to ensure risks are minimised, there is no reason to still be relying on physical data and servers.” Here are HostingSystems.co.uk tips to avoid making common cloud security mistakes: 1 - Make Sure Passwords Are Secure IT departments with poor password security are putting the business at risk of cyber security attacks. Weak passwords that have under 14 characters, with no capitalization or special characters become vulnerable to cyber attackers who can use automated software to test weak passwords. For this reason, it is important to stay clear of basic and common passwords, as well as avoid password reuse across multiple accounts. This will prevent hackers from being able to use the same password to get into other corporate cloud services or programs. 2 - Make Sure To Monitor Networks Employees dealing with the cloud should have an understanding of the system and how to detect if there is suspicious activity. It may sound simple, but systems that are not managed properly have weak spots that will be more vulnerable to attackers trying to access the system. Business leaders should share best practices so that people can spot an adversary and report it before damage is done. It is also important to be able to check that the network security is strong enough to be resilient against attacks, regularly review and update access controls and amend security settings because it is easy for users to misconfigure assets leaving vulnerable spots. 3 - Don’t Rely Solely On The Cloud Providers After making sure that a provider is reliable, businesses must work on creating a system to ensure that they keep their cloud system secure. Businesses have a responsibility to take the necessary precautions and steps to address any infrastructure issues to protect the security of the cloud. Although the misconception around data responsibility is somewhat understandable, business leaders should be doing their research into GPDR legislation before making the switch. 4 - Add An Extra Layer Of Security Organisations should implement strategies to protect themselves. Whether that be a data-recovery strategy that enables them to manage storage and requirements simply and easily, by re-evaluating how many employees have access to the cloud, or by adding multi-factor authentication. Methods should be used around the wider organisation that are going to stop vulnerabilities. It is also essential to educate employees as to why these measures are so important and how to use them effectively. 5 - Keep Systems Up To Date It is important to always keep cloud software up to date because outdated software is much more vulnerable to attacks and malware infections. Cybercriminals can scan for outdated software and gain unauthorized access to launch attacks and steal or compromise sensitive data. "It is vital to maintain and patch systems, and organisations should make sure they are always on top of updates that are important to their security."
- Ransomware Surge In 2024 Demands Coordinated Global Response
Amid intensifying geopolitical tensions, ransomware attacks in 2024 are set to reach record levels, escalating the risks faced by companies worldwide. There is a shift toward more sophisticated extortion tactics, emphasizing the urgent need for coordinated global action and robust incident response strategies as organizations confront increasingly aggressive and persistent cyber threats, says GlobalData , a leading data and analytics company. GlobalData’s latest Thematic Intelligence report, “Deep Dive into Ransomware,” reveals that 2023 was the third worst year on record for ransom attacks and the worst for payments, which reached over $1 billion, citing Chainalysis. David Bicknell, Principal Analyst of Thematic Intelligence at GlobalData, comments: “Companies are under constant threat from ransomware attacks and, once breached, must decide whether to pay the ransom to recover their operations and data. The surge in attacks reflects a shift toward a more aggressive ransomware landscape. What began as phishing-led incursions requiring decryption keys has evolved into sophisticated extortion, where attackers post victims’ data on the dark web, leading to further attacks by other groups.” Companies that have suffered ransomware attacks include Boeing, Caesars Entertainment, MGM Resorts, Change Healthcare, Royal Mail, Johnson Controls, the UK’s National Health Service (NHS), Sony, Capita, and Dish Network. Jordan Strzelecki, Associate Analyst of Thematic Intelligence at GlobalData, adds: “High-profile law enforcement takedowns are increasingly disrupting ransomware gangs." Successful action against Hive, LockBit, and AlphV temporarily stemmed the tide of attacks and sent a warning to cybercriminals that their days could be numbered. “However, the ransomware industry is never static, and new gangs continually emerge to replace those that have been taken down or have become less effective. Gang affiliates are taking a larger slice of ransom payments and are making repeat attacks. Ransomware gangs are now actively competing to attract talent.” Bicknell continues: “Government and cyber authority action on ransomware and ransom payments must be coordinated and international. Countries will fail to combat bad actors if they spend their time trumpeting their own cybersecurity credentials and competing with other nations. The battle against ransomware can only be won if countries, cyber authorities, law enforcement, and companies work together.” “Every business must develop and test an incident response plan, see the bigger picture around paying ransoms, and stay informed about ransomware developments to protect their organizations in the event of a successful attack."
- The Global Face Of Fraud & How To Mitigate The Risks
Global expansion is the way forward for businesses looking to upscale in 2023 and beyond. The past few years have laid the foundation for international expansion, and now more and more merchants are embracing the opportunities. But as they’re venturing into new markets, certain challenges appear along the way. One of them is cross-border payment. While businesses might be familiar with the fraud situation in their home market, new territories present new fraud obstacles. Here, Signifyd Director , Amal Ahmed, explains some of the fraud risks associated with expanding internationally and how to alleviate them. Mitigating Fraud Challenges With Fraud Familiarisation Card-not-present fraud (CNP) is one of the biggest cross-border fraud challenges. In 2020, global CNP fraud cost merchants £27,171 billion ($32.39 billion), and this number is expected to increase to £34,076 ($40.62) billion by 2027. Cross-border ecommerce is an appealing target for fraud rings, as there are a high number of payment paths created by overseas suppliers, contractors, or international subsidiaries that can be attacked. These payment paths may become hard to manage, thus becoming a weak spot for fraudsters. To mitigate the international expansion fraud risks, merchants need to familiarise themselves with the fraud challenges of the market they’re expanding into. The best way to do so is by utilising existing data to build fraud profiles and match that with a robust fraud solution. North America: Tackling Synthetic Identities In a post-pandemic world, North America has experienced a significant increase in fraud. In 2021, fraud attacks increased by 140% in the U.S. compared to 2020, and by 52% in Canada. This is the largest year-on-year increase the region has seen, and it’s in part due to the sudden boom in online transactions. Some of the biggest fraud challenges for merchants in the region include synthetic identities and other account-related fraud. The reason for that is the struggle to find the balance between fraud detection and an outstanding customer experience. Merchants expanding in the region need to focus on verifying digital identities and evaluating transaction risk. A fraud solution that leverages machine-learning, cybersecurity, and the deliverance of a seamless digital experience is the key to tackling synthetic identity fraud. The Golden Era Of Fraud In Europe During the COVID-19 pandemic, Europe experienced its golden era of fraud. The advancement of fraud tactics matched with the new Strong Customer Authentication (SCA) regulation presented merchants with severe fraud concerns. Fraud innovation was under way and more vulnerable links, such as account creation, account login, and payment forms, were largely at risk. Fraud challenges such as return fraud, fraudulent fulfilment disputes, and synthetic identities flourished. The key to overcoming these challenges is adopting innovative fraud solutions that utilise data about historical and real-time transactions to capture red flags and approve genuine orders through automation. Account Takeover Dominates China Currently, China is experiencing a monument market growth with online sales reaching just over the £1.67 trillion ($2 trillion) mark in 2021. But there is one weak link that is giving way to fraudsters – the lack of fraud tools. Ecommerce is moving with such a rapid pace that merchants have no time to step back and secure their online shops. To keep up with the rapid growth and the implementation of new technology across social media and ecommerce platforms, account takeover took precedence as the main fraud challenge. Merchants need to build a data pool of transactions to help them use advanced digital tools, such as automation and machine-learning, thus securing their transactions. Tapping Into The Buyer’s Profile In Latin America Latin America has experienced the most rapid ecommerce growth given its previous stagnation. In 2021, the region reached £71 billion ($85 billion) in ecommerce sales, which is a 25% increase from £57 billion ($68 billion) in 2020. Nevertheless, the region has also been faced with heavy financial instability. Amid the two, fraud attacks emerged. According to Cybersource and MRC’s 2021 Global Fraud Report, 3.5% of ecommerce transactions in Latin America during 2021 were fraud attempts, higher than the global average of 2.6%. To protect your business from fraud attacks in the region, it’s important to develop an understanding of buyers’ shopping behaviour. Each sector has a different type of a persona, and that informs the types of fraud risks and fraud protection you’re going to use. Gather consumer behaviour data about the region you’re expanding into and match that with a robust fraud solution tool to detect fraudulent transactions and approve genuine ones. With the right use of fraud solutions and the implementation of data, you will be able to guard your business against any type of fraud attacks in the new markets you’re expanding into. As a result, you will optimise your revenue and thrive as a business.
- Deloitte Release Fourth Future Of Cyber Survey Results
Deloitte Global has released the fourth edition of the Global Future of Cyber survey, which found that cybersecurity is increasingly becoming a cornerstone of many organisations’ growth strategies and business plans amidst today’s advanced and complex threat landscape. The findings from Deloitte Global’s largest cyber-related survey to date show how decision-makers are shifting their responses to cyber threats. Among other strategies, businesses are increasing the responsibility and strategic influence assigned to chief information security officers (CISOs), promoting further involvement from the board on cybersecurity-related matters, and turning to measures like artificial intelligence (AI). In recent years, the ever-evolving tech environment has led Deloitte to identify organizations based on their level of cyber-maturity in the survey findings. Key indicators of a high-performing, cyber-mature organization include increased efforts of cyber planning, implementation of key cybersecurity activities, cyber engagement at the board level, and deployment of AI within their cyber programs. This year’s survey reinforces the urgency of securing cyber systems, as 25% of respondents from cyber-mature businesses reported 11 or more cybersecurity incidents in the past year, a 7% increase of incidents since the 2023 survey. Stemming from the climbing number of cyberattacks, the report underlines the growing responsibilities CISOs are having as important allies to their CEOs and boards, particularly as their influence expands across an increasingly tech-savvy C-suite. One aspect in making the role exceedingly important has been the growing wave of AI-generated threats, which can target enterprises to exploit vulnerabilities by impersonating trusted sources. While the CISO’s expertise gains value, organizations are turning simultaneously to AI-enabled tools to strengthen cybersecurity and combat risks. Each of this suggests an increasingly integrated cyber function across business and technology: Around one-third of respondents report a significant increase in CISO involvement during strategic conversations about tech-related capabilities in the past year. Over the last decade CISOs have traditionally reported to the chief information officer (CIO), however they are increasingly gaining the ear and trust of CEOs, as 20% of decision-makers revealed their CISOs now report directly to their CEO. Cyber is playing a large role in securing an organization's investment in tech capabilities, particularly when it comes to priority areas such as cloud (48%), Generative AI (41%), and data analytics (41%). On average 39% of respondents are using AI capabilities in their cybersecurity programs to a large extent. "The rise of AI and other evolving technologies has significantly transformed the threat landscape. As threats become more sophisticated and impactful to core business, CISOs are increasingly required to adopt a more strategic role driving cross business risk prioritization and mitigation,” says Emily Mossburg, Deloitte Global Cyber Leader. “The close relationship between CISOs and CEOs is a testament to the role security plays in a business’s long-term success. Today, CISOs are not only protectors against outside threats, but key players helping their organization find success by integrating cyber considerations in the strategic decision-making process.” Organizations continue to embrace cyber as an essential component of their enterprise tech stack, budgeting strategies, and future business plans. They also increasingly rely on technology-driven programs to fuel growth and innovation. As business leaders realize the potential of cyber, the report finds: The top three expected outcomes from cybersecurity initiatives are protecting intellectual property (46%), improving threat detection and response (44%), and increasing efficiency and agility (44%). Overall, 83% of respondents agree or completely agree that measures like qualitative risk assessments and benchmarking are an integral part of their overall cybersecurity strategy. 58% of respondents also expect to begin integrating cybersecurity spending with budgets for other programs, such as digital transformation initiatives, IT programs, and cloud investments. “This year’s report highlights how the connection between cybersecurity and business outcomes continues to grow stronger, enabling cyber to have greater impacts in achieving organizational objectives” adds Mossburg. ”The increased reliance organizations have on their technology-driven programs is evolving the CISO roles and their cyber initiatives into essential components in driving business growth in a tech-powered future.” The Future of Cyber findings exhibit how cybersecurity is integral to building trust in a tech-powered future and point to why organizations should continually invest in areas throughout their business to increase cyber efficiency and overall growth. Specifically, organizations should focus on hiring and developing cyber talent, executing thorough digital planning, and collaborating with extended ecosystems, all while incorporating cyber into strategic business initiatives. For more information, please visit Global Future of Cyber Survey , 4th Edition.
- Data Reveals CEOs Neglecting Cybersecurity Amid Rising Threats
As Cybersecurity Awareness Month draws attention to the growing importance of digital security, new research reveals that cybersecurity is being neglected by UK CEOs, posing significant risks to businesses. A survey conducted by compliance training provider Skillcast found that only 6% of CEOs list cybersecurity as a top priority, ranking it ninth out of twelve major regulatory concerns. Despite the increasing frequency of cyberattacks and data breaches, many CEOs continue to focus on areas such as customer satisfaction and revenue growth, leaving critical vulnerabilities unaddressed. Another report commissioned by Skillcast also shows that senior-level employees are three times less likely to report compromised passwords or suspicious IP addresses compared to entry-level staff, exacerbating cybersecurity risks within organisations. Reporting from senior management level is crucial to mitigate risks as it not only allows organisation’s to make swift decision-making but embeds a culture of proactive security. Additionally, nearly half of UK workers (48%) would not immediately report a phishing email, with 41% delaying the reporting of compromised work passwords. Younger CEOs (18-24 years) prioritise anti-bribery regulations, with 43% listing it among their top three concerns, while older CEOs (55-64 years) show more focus on cybersecurity and tax compliance. While customer satisfaction (21.4%) and revenue growth (18.4%) top the list of business priorities, compliance and risk management, including cybersecurity, are deprioritised, with only 4% of CEOs ranking it as their top concern. Despite rising cyber threats, senior employees, who often have access to sensitive data, are significantly less likely to report cyber incidents such as phishing emails or suspicious IP addresses. This reluctance to report security threats—particularly among higher-ranking staff—leaves businesses exposed to preventable breaches, further compounding the risks posed by the lack of focus on cybersecurity among leadership. Vivek Dodd, CEO of Skillcast, comments on the findings: “The data reveals a dangerous gap between the perception of cybersecurity risks and the actions being taken to mitigate them." "Senior employees, not reporting cybersecurity threats, can leave companies particularly vulnerable to serious breaches. With cyberattacks becoming more sophisticated and regulatory scrutiny tightening, businesses cannot afford to ignore this area.” “Cybersecurity needs to be embedded into every level of an organisation’s culture, from entry-level employees to senior leadership. During Cybersecurity Awareness Month, it’s critical to recognise that training and reporting mechanisms must be in place to ensure potential threats are identified and mitigated quickly. Every employee must be empowered to act as the first line of defence.” In light of these findings, experts are urging businesses to prioritise cybersecurity training and reporting processes, particularly for senior staff who hold access to sensitive systems and data. As regulatory oversight intensifies, companies that fail to adequately address cybersecurity may face legal, financial, and reputational repercussions. Ensuring comprehensive cybersecurity awareness and preparedness across all levels of an organisation is crucial to protecting against evolving threats.
- Cybersecurity Skills Shortage Drives IT Hiring Surge Across UK
New research from international recruitment firm, Robert Half, has revealed that nearly half (45%) of UK employers are planning to increase permanent headcount in their IT & Technology functions before the end of 2025. A further 36% are investing in contract professionals to maintain agility and address critical skills shortages in the function, with cybersecurity driving much of the demand. The findings, part of Robert Half’s latest Hiring Intentions data, show that while AI continues to reshape the tech landscape, employers are prioritising security and infrastructure as key areas for investment. Cybersecurity topped the list of in-demand skills, with 48% of respondents identifying it as a priority for recruitment. A further 42% of businesses indicated that they are actively planning to hire IT security experts in the coming months. However, the data also highlights growing concerns around talent availability. Nearly half (44%) of employers believe that cybersecurity professionals will require premium salaries to attract candidates, underscoring the pressure on this talent pipeline. Machine Learning and Infrastructure Also In Focus Beyond security, businesses are also ramping up recruitment for machine learning (ML) skills, with 42% planning to recruit for this specialism. Given the relative infancy of ML in many organisations, it’s no surprise that 37% of respondents expect candidates with experience in this area to command higher remuneration packages. Other areas of planned headcount growth include IT Infrastructure (38%) and IT Service/Support (36%), reflecting a broader push to strengthen operational resilience and digital capabilities. Craig Freedberg, Regional Director at Robert Half commented: “It is clear that UK businesses are taking a proactive approach to building out their IT and technology teams. However, the challenge lies in sourcing the right talent in what remains a very competitive market." "Cybersecurity is no longer just a technical concern, it is a business-critical priority and organisations are willing to pay a premium to secure the expertise they need as threats continue to grow. With widespread reports of brands facing significant repercussions from cyber attacks, demand will remain strong even as businesses face pressure on resources." “At the same time, the rapid rise of machine learning and AI is driving new demand for specialist skills that are still in short supply. For many employers, this creates a dual challenge: competing for scarce expertise while also needing to plan for the longer-term evolution of these technologies." "Adding to this complexity, businesses are navigating challenging macroeconomic conditions and rising employment costs in the UK which can make investment decisions even more difficult." "To stay ahead, employers will need to look beyond traditional hiring strategies and consider upskilling, reskilling and tapping into new talent pools." “As we move into the final quarter of the year, businesses should use this period not only to reassess their tech capabilities and strengthen hiring strategies, but also to prepare for navigating an increasingly complex and challenging digital landscape.”
- Cybersecurity: Going Back To Basics Is Key To Success
HLB has released its fifth annual Cybersecurity Report, providing crucial insights from over 600 senior IT professionals. This year's theme, "Cybersecurity Fundamentals," explores the pressing need for organisations to focus on essential security practices amidst a landscape of increasing vulnerabilities and evolving technological challenges. HLB undertook this research to empower organisations with the knowledge and strategies necessary to safeguard their digital assets. This annual report aims to provide valuable guidance and build a proactive approach to cybersecurity. By understanding the key challenges and trends identified in the report, HLB helps businesses enhance their resilience against cyber threats, ultimately contributing to a more secure and stable digital environment globally. Report Highlights Include: Resilience & basic practices: A staggering 92% of participants noted ongoing cyberattacks, indicating the need for robust resilience strategies and fundamental cybersecurity measures like misconfiguration management and cyber hygiene practices. Third-party risk & regulatory compliance: With over a third of organisations experiencing vendor-related breaches, the report emphasises the importance of managing third-party risks and adhering to regulations such as NIS2 and DORA. AI & data protection: While AI offers revolutionary capabilities, it also poses significant security challenges. Only 30% of respondents have implemented additional security controls for AI, highlighting a critical gap in AI governance and data protection strategies. Amy Spillard, Head of Technology Partnerships said: "Cybersecurity is more than just an IT issue; it's a business imperative. This report illustrates the urgent need for organisations to adopt proactive security measures and ensure all employees are well-trained." "Despite heightened concerns, the report shows promising trends, with over 90% of businesses considering cybersecurity a strategic priority and more than 80% having comprehensive incident response plans in place.” Gareth Rees, The Missing Link added, "While 45% of organisations now have dedicated teams focusing on cyber compliance, the findings of HLB's report demonstrate the true measure of success lies not just in resources but in the effectiveness and real-world application of security protocols." "Effective security awareness training, regular security reviews and improved third-party vendor security measures, offers a high return on investment in mitigating these risks." Download and read the full report here:
- Significant Global Cybersecurity Challenges
A new World Economic Forum report provides a snapshot of the multifaceted challenges facing the global cybersecurity landscape. While increased geopolitical tensions and economic instability continue to concern industry experts, the report spotlights widening cyber inequity and emerging technologies, such as artificial intelligence, as key rising risks for the year ahead in the fast-growing cybersecurity sector. Key Findings: With ‘cyber insecurity’ still featuring prominently among the top ten risks in the Global Risks Report, a new report explores the key trends shaping the global cybersecurity landscape. There has been a sharp increase in cyber inequity globally, with 90% of executives warning that urgent action is needed to address it. 81% of those surveyed feel more or as exposed to cybercrime than they did last year. The Global Cybersecurity Outlook 2024 report, developed in collaboration with Accenture, distils insights of industry experts and global executives about key cyber trends that leaders will need to navigate in 2024, based on a series of surveys carried out between June and November 2023. Given the increasingly complex cyber threat landscape, the report also calls for concerted collaboration, across borders and industries, to counter these interrelated threats and build a more resilient environment. “As the cyber realm evolves in response to emerging technologies and shifting geopolitical and economic trends, so do the challenges that threaten our digital world,” said Jeremy Jurgens, Managing Director, World Economic Forum, Switzerland. “We urgently need coordinated action by key public-private stakeholders if we are to collectively address these complex, ever-evolving threats and build a secure digital future for all.” The increasingly stark divide between cyber-resilient organizations and those that are struggling has emerged as a key risk for 2024. The number of organizations that maintain minimum viable cyber resilience is down 30% compared to last year. While large organizations have demonstrated notable gains in cyber resilience, small and medium-sized companies showed significant decline. This growing inequity is being fuelled by macroeconomic trends, industry regulation and, crucially, early adoption of paradigm-shifting technology by some organizations. In addition, the cyber skills and talent shortage continues to widen at an alarming rate. Only 15% of all organizations are optimistic about cyber skills and education significantly improving in the next two years. In an interconnected world this growing rift means no organisations are completely safe. According to the report, external partners are both the greatest asset and the biggest hindrance to the cybersecurity of any organisation. In fact, 41% of the organizations surveyed that suffered a material incident in the past 12 months say it was caused by a third party. “No country or organization is spared from cybercrime, yet many are direly underequipped to effectively face the threats, and we cannot have effective global response mechanisms without closing the capacity gap,” said Jürgen Stock, Secretary-General of INTERPOL. “It is crucial that key stakeholders work collaboratively towards immediate, strategic actions that can help ensure a more secure and resilient global cyberspace." Emerging technologies, such as artificial intelligence (AI), are another key trend to watch in this year’s outlook. Fewer than one in 10 respondents believe that in the next two years generative AI will give the advantage to defenders over attackers, and approximately half of experts surveyed agree that generative AI will have the most significant impact on cybersecurity in the next two years. Its rise is stoking fears among experts about the exacerbation of long-standing challenges, with around half of executives saying that AI-driven advances in adversarial capabilities of cyber criminals (phishing, malware, deepfakes) present the most concerning impact of generative AI on cybersecurity. Despite these concerns, experts also highlighted an encouraging increase in focus on the importance of cybersecurity globally, particularly at the executive and CEO levels. The incorporation of cyber resilience into organizational risk management is also becoming more common, as per the report. “Cyber resilience is increasingly dependent on a C-suite team that closely collaborates and communicates security priorities across the business and the industry,” Paolo Dal Cin, Global Lead, Accenture Security. “This approach provides a clear view of cyber risks and allows security to be embedded from the start in all strategic business priorities as well as across third parties, vendors and suppliers.” You can read the full report here:











