British Cyber Security Spending Is Rising

Two thirds of British based organisations will increase their cyber security budgets in 2021, despite the financial problems arising from the Covid-19 pandemic, according to a survey of cyber security decision-makers. 

This is because of the likely increase in cyber attacks in 2021, according to new research from NCC GroupTheir Report reveals that just 7% of respondents from public and private sector organisations anticipate overall budgetary cuts, suggesting a widespread determination to maintain cyber security spending amid an increasingly complex threat landscape.

However, 27% reported cuts to cyber security budgets in 2020, and three in 10 reported delays or cancellations to cyber security projects. The average UK cyber security budget is around $900,000, compared to an average of $1.46 million globally, according to Hiscox. 

The government has been urged to pump more money into cyber defences after new research revealed that more than 1m small businesses would collapse if they were targeted by hackers.A poll of more than 500 business leaders found nearly a quarter of UK SMEs, equivalent to 1.3m companies, were likely to go bust if they were forced to deal with the average cost of a cyber attack. Furthermore, a survey of 290 senior cybersecurity  professionals suggests that many security teams are actually downsizing because of the Coronavirus pandemic, which has simultaneously increased their workload

Only about thirty percent of UK organisations have done a cyber risk assessment in the last 12 months, according to the UK Government's report into cyber security breaches.

  • With Covid-19 being exploited by cyber criminals and forcing hasty migrations to remote working, 40% of organisations have frozen new cyber security  recruitment.
  • While 29% made redundancies, and 20% have furloughed staff.
  • 30% have experienced delays or cancellations to their cyber resilience projects.
  • 27% have reported actual cuts to their cyber security budgets. 

The data also suggests that these measures could have negatively affected cyber security resilience:

  • 70% of organisations that cut budgets, made redundancies or delayed or canceled their cyber projects reported an increase in cyber attacks. 

This operational shift also exposed concerns about the impact of people on cyber resilience:

  • Of the 39% that reported an increase in insider threats, 51% believed that an increase in remote working was the cause. 
  • Over 60% of decision makers claimed that they would increase the total amount spent on cyber security this year, with ‘making security improvements’ the highest priority area for investment.
  • 30% of UK business say they lost clients after a data breach and that nearly 40% of US organisations lost business because of security issues.
  • 66% of those polled said they planned to plug the gap with outsourcing in 2021, 50% of whom cited recruitment and retention as a key motive amid the world’s cyber skills shortages.

The NCC Group survey finds that those organisations that cut budgets or the size of their teams were more likely to suffered cyber attacks in general, while many respondents blamed home working for rises in insider threats and phishing and ransomware attacks. 

The proportion of those polled who considered their employer ‘very resilient’ fell from nearly half to 38% year on year.

  •  90% expressed confidence that they could promptly diagnose and remediate the root cause of a potential data breach and alert authorities within 72 hours, in comliance with  General Data Protection Regulations (GDPR) 
  • 49% of organisations scanned their network perimeter frequently.
  • 50% say that it is taking a week or more to patch vulnerabilities, while only 21% said all network-connected devices were regularly patched.
  • Understanding the threat landscape (70%) and securing funding (68%) were seen as the two biggest challenges currently facing organisations.

Decision-makers were far from bullish about surmounting these hurdles: 

  •  71% admitted to being ‘not confident’ about improving their organisation’s cybersecurity preparedness. 
  •  90% admitted to struggling to evaluate the costs and benefits of cyber security measures.
  •  31% agreed that benchmarking security activities was an effective solution.
  • 18% of UK organisations say that they don’t know how many cyber attacks they suffered in 2020.

Security incidents are costing organisations more than ever and 79% of UK companies have suffered down-time because of them. 

Growth within the cyber security sector has been driven considerably within the last two years by the introduction of the GDPR and enhanced business understanding of the risks and potential consequences of failing to store data securely.  New initiatives such as the NCSC sponsored Cyber Essentials programme have increased demand for cyber security advisory support across the UK economy.

These measures can only lead to better ways of maintaining effective cyber security and a more widespead recognition of its central place in doing business securely. 
 

NCC Group:      GovUK:       PWC:        CSO:     City AM:     Portswigger:      Image: Unsplash

You Might Also Read: 

Cyber Security: Take  Action:

If you would like more advice and recommendations about how you can improve your business cyber security, please contact Cyber Security Intelligence.

 

 

« European Banking Authority Attacked
Ethical Hackers Are Getting Rich »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

E-Tech

E-Tech

E-Tech has been providing system support and information technology consulting services including Internet and Network Security assessments.

StickyMinds

StickyMinds

StickyMinds is the web's first interactive testing community exclusively engaged in improving software quality throughout the software development lifecycle.

Napatech

Napatech

Napatech develops and manufactures high speed network accelerators specifically designed for real-time network monitoring and analysis applications.

ISGroup (Information Security Group)

ISGroup (Information Security Group)

ISGroup services include network penetration testing, Web application penetration testing, ethical hacking, vulnerability assessments, code review and associated training.

Securitybulls

Securitybulls

Securitybulls is an information security firm offering an encyclopedic penetration testing & IT security assessment service for your organization.

Cyber Forensic & Investigation (CFI)

Cyber Forensic & Investigation (CFI)

Cyber Forensic & Investigation (CFI) is recognized as Thailand’s leader in cyber investigations and digital forensics.

HITRUST Alliance

HITRUST Alliance

HITRUST provides widely-adopted common risk and compliance management frameworks, related assessment and assurance methodologies.

Industrial Defender

Industrial Defender

Committed to ICS Cybersecurity. Industrial Defender provides a fully automated solution to discover, track and report on assets across your ICS footprint.

Cythereal

Cythereal

Cythereal is the leader in predicting and preventing advanced malware attacks. Security Automation for the Overwhelmed Administrator.

Cyber Dacians

Cyber Dacians

Cyber Dacians offers Information and Cyber Security Consulting Services. We help you to test the effectiveness of your security defenses and build a secure infrastructure.

Vantea SMART

Vantea SMART

Vantea SMART have decades of experience in cybersecurity resulting in an approach of proactive prevention - Security by Design and by Default.

Cisco Networking Academy

Cisco Networking Academy

Cisco Networking Academy is the world's largest classroom, bringing technology education, 21st-century skills, and improved jobs prospects since 1997.

N-able

N-able

N-Able deliver simple and sophisticated monitoring, security, and business solutions that empower you to solve your toughest IT challenges.

Beaming

Beaming

Beaming is an established Internet Service Provider for businesses across the UK. We deliver reliable voice, data and managed services, including cybersecurity.

CeTu

CeTu

CeTu - Data Orchestration for the Modern SOC. Strengthen security and optimize costs with the world's first AI-native platform for scaling and future-proofing your data stack.

SureStack

SureStack

SureStack is an AI-native cybersecurity platform that provides organizations with continuous validation, optimization, and real-time security of their cybersecurity stacks.