70% of UK bosses have no training to deal with cyber attacks
Britain's business leaders are woefully underprepared for breaches, report shows


Almost 70% of Britain's top business leaders have received no training in how to respond to a cyber attack, a new government report has revealed.
The figures come from the Cyber Governance Health Check, an annual report carried out by the Department for Digital, Culture, Media and Sport (DCMS) to assess the level of cyber security within FTSE 350 companies.
The results showed that out of Britain's top 350 businesses, 10% operate with no cyber incident response plan whatsoever, while two-thirds of boards are not kept updated with cyber security risk information. This is despite more than half of those surveyed identifying cyber security as a top business risk.
"We have world leading businesses and a thriving charity sector but recent cyber attacks have shown the devastating effects of not getting our approach to cyber security right," said minister for digital Matt Hancock.
"These new reports show we have a long way to go until all our organisations are adopting best practice and I urge all senior executives to work with the National Cyber Security Centre and take up the Government's advice and training."
Board-level awareness of the importance of cybersecurity has risen by almost 10% compared to last year's report, but experts have warned that without the confidence to get hands-on in the aftermath of a breach, board members may be putting their businesses at risk.
"While cyber security has cemented itself onto the board's agenda, they often lack the training to deal with incidents. This is hugely important as knowing how to deal confidently with an incident in the heat of the moment can save time and money," said KPMG's UK head of cyber security, Paul Taylor. "The aftermath of a cyber-attack, without the appropriate training in managing the issue, can result in reputational damage, litigation and blunt competitive edge."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Adam Shepherd has been a technology journalist since 2015, covering everything from cloud storage and security, to smartphones and servers. Over the course of his career, he’s seen the spread of 5G, the growing ubiquity of wireless devices, and the start of the connected revolution. He’s also been to more trade shows and technology conferences than he cares to count.
Adam is an avid follower of the latest hardware innovations, and he is never happier than when tinkering with complex network configurations, or exploring a new Linux distro. He was also previously a co-host on the ITPro Podcast, where he was often found ranting about his love of strange gadgets, his disdain for Windows Mobile, and everything in between.
You can find Adam tweeting about enterprise technology (or more often bad jokes) @AdamShepherUK.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
Homeland Security warns businesses of Oracle and SAP ERP vulnerabilities
News Oracle and SAP urge customers to apply patches to secure systems against hackers
By Keumars Afifi-Sabet Published
-
Most CEOs steal IP from previous employers
News Emotionally-driven decisions put companies at risk, finds security report
By Keumars Afifi-Sabet Published
-
Three foolproof ways CEOs and CISOs can work together more effectively
In-depth How involved is your Chief Information Security Officer (CISO) in business decisions?
By Caroline Preece Published
-
CEO's pay should be linked to security performance, says government committee
News New report recommends that CEOs be held directly accountable for data breaches
By Adam Shepherd Published
-
Breach of the data protection peace
In-depth With the ICO rarely fining for breaches of the Data Protection Act, are businesses breaking rules as they can get away with it or is the ICO bringing about some other type of corporate telling off?
By Adrian Bridgwater Published
-
HBGary CEO steps down after Anonymous breach
News HBGary's CEO resigns after Anonymous leaks emails stolen from the security firm.
By Tom Brewster Published