The research, commissioned by Cowbell, underscores the lack of readiness in UK small and medium-sized enterprises (SMEs) to combat cyber threats effectively.
According to them, only about one in five (19%) of SMEs have a recommended cyber incident response plan in place. Alarmingly, the research finds that 8% of CEOs said they would just engage with the threat actor directly.
Beyond this, the research found that there was a critical absence of in-house security measures, with 77% of SMEs lacking in house security measures, leaving them more vulnerable to various threats.
“Almost every day we see a new major cyber attack hit the headlines – and that’s just the ones big enough to warrant news coverage. Whether we put our heads in the sand or not, attacks are on the up,” said VP and general manager of Cowbell UK, Simon Hughes.
Despite the escalating threat landscape, about one third (32%) of CEOs expressed unwarranted confidence that their business would remain unaffected by a cyber attack. And 10% of business leaders believe there is no necessity to enhance their cyber risk posture at all.
“As developments in AI continue, we will almost certainly see an increase in the volume, complexity and impact of cyber attacks in the coming years. It’s not a case of if, but when. But now is not the time to scaremonger, it’s time for proactive planning,” continued Hughes.
The gravity of these statistics is further underscored by the financial toll cyber incidents impose on UK businesses. According to IBM, data breaches cost an average of £3.2 million last year, with the UK being the sixth most expensive country for data breaches in the world.
Recommended reading
- NCSC Releases New SMB Cybersecurity Guide
- Report: SMBs Facing Growing Cyber-threats in 2023
- Ransomware Still Top Cyber-threat for SMBs
Compounding this is the lack of consensus among C-suite executives regarding appropriate responses to cyber breaches, with only 20% of CHROs, 22% of director roles and 28% of CEOs considering cyber threats to be their biggest risk.
Most notably, the risk of cyber threats fell to second last on CFOs’ radar out of 14 possible threats, with only 8% considering it their biggest threat.
“The message is clear: resolving the confusion around first responses is a matter of urgency. More support and education on cyber risk and Incident Response Planning needs to happen if businesses are to navigate these incidents and recover quickly,” said Catherine Aleppo, a broker specialist at Cowbell UK.





