The significant cybersecurity pressures on UK businesses

New research by Keeper Security has revealed that 92% of UK businesses have experienced a cyberattack in the last 12 months, with over two-thirds (72%) successfully breached at least once.

UK businesses are struggling to deal with multiple urgent cybersecurity challenges, new research by Keeper Security has revealed. The 2021 Cybersecurity Census Report shows cyberattacks are becoming more vicious, frequent and sophisticated, while UK businesses are underprepared and too slow to counter these attacks. As a result, senior leaders within UK organisations are preoccupied with playing a cyberattack blame game instead of investing in boosting their defences.

The report has found that more than nine in ten (92%) UK businesses suffered a cyberattack in the last 12 months and three quarters (78%) feel unprepared to deal with this threat. Nearly a third (31%) believe CTOs should take the blame in the case of a successful cyberattack. Such a weight of responsibility means cybersecurity standards are dropping: 36% of senior IT leaders confess to having kept a cyberattack to themselves, while 32% admit to using weak credentials such as ‘password’ or ‘admin’ to protect their data.

“UK businesses are clearly worried about their cybersecurity and, as our report has found, the challenges are manifold, affecting everything from budgets to productivity,” said Darren Guccione, CEO & co-founder, Keeper Security. “While there is a desire to boost security efforts, companies are facing many competing challenges right now and, understandably, might not always make cybersecurity investments a priority. Our report is an urgent reminder for organisations to proactively address their cybersecurity challenges as a priority since deferring them will make the consequences far more severe.”

Key findings include:

  • Almost all (92%) UK organisations are aware of gaps or weak links in their cybersecurity defences are, but less than half (40%) are actively addressing all of them
  • Two-thirds (66%) of UK organisations have relaxed their cybersecurity policies over the past 12 months so staff can work remotely or in order not to stifle productivity
  • 58% of IT professionals feel employees at their organisations do not understand the full consequences of poor cyber-hygiene
  • 61% of UK companies have a skills shortage in cybersecurity
  • The financial fallout of cyberattacks has been damaging, too, costing nearly one in ten (8%) UK businesses over £1 million
  • An overwhelming 87% of IT leaders support the creation of a nationwide governing body to hold businesses to account when it comes to best online security practices
  • And almost all (91%) are in agreement that UK businesses should be legally required to have basic cybersecurity protections in place to be allowed to operate

“Companies are struggling to put the right solutions in place to cope with cyberattacks and the consequences are both damaging and costly,” said Craig Lurey, CTO and co-founder, Keeper Security. “The conditions caused by Covid-19 have led to an increased amount of hybrid working, making effective cybersecurity defences even harder to achieve. But if businesses want to bounce back fully after the pandemic, they must get their security hygiene in order without delay.”

Despite the rise in cyberattacks and increasing pressures felt by security teams, more than a quarter of UK companies (28%) do not consider IT to be even in their top three priorities as they plan for the next 12 months. This is particularly worrying, given almost all (92%) UK organisations know where the gaps or weak links in their cybersecurity defences are but well under half (40%) are actively addressing them.

READ MORE:

Guccione concludes: “While this situation can’t be rectified overnight, there are straightforward steps UK businesses can take to boost their cyber defences. First, organisations should do a comprehensive cybersecurity audit, looking at where the gaps lie and how they can be addressed. Next, they need to put in place a clear plan of action for how to address these challenges. Running cybersecurity training sessions to educate employees and introducing a password management platform to keep credentials safe and secure are two simple, yet highly effective actions businesses can take today, to be better prepared against cyberattacks tomorrow.”

For more news from Top Business Tech, don’t forget to subscribe to our daily bulletin!

Follow us on LinkedIn and Twitter

Amber Donovan-Stevens

Amber is a Content Editor at Top Business Tech

Is It Time for a VMware Alternative?

Wind River • 22nd May 2025

Companies have options when it comes to replacing VMware as their cloud platform, to address rising costs, support concerns, and a shrinking partner ecosystem. If you are ready to contemplate a different vendor, here are five reasons why Wind River Cloud Platform should be on your short list of VMware alternatives.

AI Leads as VivaTech Unveils Top 100 Startups

Viva Technology • 14th May 2025

Viva Technology has unveiled the first edition of its “Top 100 Rising European Startups for 2025,” spotlighting the most promising young companies shaping Europe’s tech future. Germany, France, and the UK lead the ranking, which highlights high-growth startups across 13 countries. Artificial intelligence dominates the list, with 15 companies spanning AI agents, models, and infrastructure....

Birmingham Unveils the UK’s Best Emerging HealthTech Advances

Kosta Mavroulakis • 03rd April 2025

The National HealthTech Series hosted its latest event in Birmingham this month, showcasing innovative startups driving advanced health technology, including AI-assisted diagnostics, wearable devices and revolutionary educational tools for healthcare professionals. Health stakeholders drawn from the NHS, universities, industry and front-line patient care met with new and emerging businesses to define the future trajectory of...

Why DEIB is Imperative to Tech’s Future

Hadas Almog from AppsFlyer • 17th March 2025

We’ve been seeing Diversity, Equity, Inclusion, and Belonging (DEIB) initiatives being cut time and time again throughout the tech industry. DEIB dedicated roles have been eliminated, employee resource groups have lost funding, and initiatives once considered crucial have been deprioritised in favour of “more immediate business needs.” The justification for these cuts is often the...

The need to eradicate platform dependence

Sue Azari • 10th March 2025

The advertising industry is undergoing a seismic shift. Connected TV (CTV), Retail Media Networks (RMNs), and omnichannel strategies are rapidly redefining how brands engage with consumers. As digital privacy regulations evolve and platform dynamics shift, advertisers must recognise a fundamental truth. You cannot build a sustainable business on borrowed ground. The recent uncertainty surrounding TikTok...