The Business Magazine - B2B Business News - Site Logo
The Business Magazine - B2B Business News - Site Logo
The Business Magazine May 2024
Read now
PICK YOUR EDITION

UK Boards of biggest firms must do more to be cyber aware says report

11 June 2019
Share
gchq_poppy_air_9233_large
gchq_poppy_air_9233_large

Boards at some of the UK’s biggest companies still don’t fully understand the potential impact of a cyber attack according to a new report.

The Government’s Cyber Governance Health Check looks at the approach the UK’s FTSE 350 companies take for cyber security. The 2018 report shows that less than a fifth of boards have a comprehensive understanding of the impact of loss or disruption associated with cyber threats. That’s despite almost all having a cyber security strategy in place.

Additionally, although the majority of businesses do have a cyber security incident response plan, only around half actually test them on a regular basis.

Digital Minister Margot James said: "The UK is home to world leading businesses but the threat of cyber attacks is never far away. We know that companies are well aware of the risks, but more needs to be done by boards to make sure that they don’t fall victim to a cyber attack.

"This report shows that we still have a long way to go but I am also encouraged to see that some improvements are being made. Cyber security should never be an add-on for businesses and I would urge all executives to work with the National Cyber Security Centre and take up the government’s advice and training that’s available."

Awareness of the threat of cyber attacks has increased. Almost three quarter of respondents acknowledge the risk of cyber threats is high, which is a big improvement of only just over half in 2017.

The implementation of the General Data Protection Regulations (GDPR) in 2018 has had a positive effect in increasing the attention that boards are giving cyber threats. Over three quarters of those responding to last years health check said that board discussion and management of cybersecurity had increased since GDPR. As a result over half of those businesses had also put in place increased security measures.

Ciaran Martin, CEO of the NCSC, said: "Every company must fully grasp their own cyber risk – which is why we have developed the NCSC’s Board Toolkit to help them. This survey highlights some urgent issues companies will be able to address by putting our Toolkit’s advice into practice.

"Cyber security is a mainstream business risk, and board members need to understand it in the same way they understand financial or health and safety risks."

Meanwhile, more work is being done to improve the cyber resilience of business, and a new project has been announced that will help companies understand their level of resilience. The cyber resilience metrics will be based on a set of risk-based principles to allow firms to measure and benchmark the extent to which they are managing their cyber risk profile effectively.

Once developed these indicators will provide board members with information to understand where further action and investment is needed.

Government is recommending the Boards continue to make improvements to their cyber security. This includes using the guidance published by the National Cyber Security Centre (NCSC) to improve the management of risks.

Companies should also ensure that cyber risks are taken into account in their business strategy and appoint a Chief Information Security Officer (CISO) or other appropriately placed staff members who can clearly communicate information about cyber risks to the board.


Nicky Godding is editor of The Business Magazine. Before her journalism career, she worked mainly in public relations moving into writing when she was invited to launch Retail Watch, a publication covering retail and real estate across Europe.

After some years of constant travelling, she tucked away her passport and concentrated on business writing, co-founding a successful regional business magazine. She has interviewed some of the UK’s most successful entrepreneurs who have built multi-million-pound businesses and reported on many science and technology firsts.

She reports on the region’s thriving business economy from start-ups, family businesses and multi-million-pound corporations, to the professionals that support their growth and the institutions that educate the next generation of business leaders.

Related articles

Latest Deal Ticket

view more
Business consultants Magnetic (London)
have been acquired by
Management consultants Newton Europe (Oxford)
May 2024
UNDISCLOSED
Who's behind the deal?

Upcoming events

view more
06
Jun

South Coast Property Awards 2024

Hilton Southampton
Utilita Bowl
More info
12
Jun

Leadership Roundtable: Developing strategies for financial returns over the next decade

Herrington Carmichael, Farnborough Aerospace Centre, GU14 6XR

More info
09
Jul

Leadership Roundtable: Opportunities and challenges in the Care Sector

Herrington Carmichael
Farnborough Aerospace Centre, GU14 6XR
More info
18
Jul

Thames Valley Tech & Innovation Awards 2024

Reading FC Conference & Events
Select Car Leasing Stadium, Reading
More info
23
Jul

Leadership Roundtable: Search Fund Exits & Acquisitions

Shawbrook Bank
9 Appold Street, London EC2A 2AP
More info
26
Sep

Thames Valley Property Awards 2024

Ascot Pavilion
Ascot Racecourse
More info
03
Oct

South Coast Tech & Innovation Awards 2024

Hilton Southampton
Utilita Bowl
More info
07
Nov

Thames Valley Deals Awards 2024

Reading FC Conference & Events
Select Car Leasing Stadium, Reading
More info
21
Nov

Hampshire Business Awards 2024

Farnborough International
Exhibition & Conference Centre
More info

Related articles

Group Companies

Dorset BIZ NewsHampshire BIZ News