Home Technology More than one in eight UK organisations have no mandatory cyber security training at all, VinciWorks poll finds
Technology

More than one in eight UK organisations have no mandatory cyber security training at all, VinciWorks poll finds

Share


As the UK’s Cyber Security and Resilience Bill enters its committee stage in the House of Lords this month, a new poll suggests many organisations’ cyber security training is not keeping pace with either the risk or what the incoming law will expect them to prove. VinciWorks surveyed 156 IT, compliance and security professionals in September 2026 and found that more than one in eight (12%) said their organisation has no mandatory cyber security training at all.

 

 A little over half of respondents (51%) said staff complete mandatory cyber security training only once a year, and just one in five (20%) train quarterly or more often. A further six per cent said training happens but is not tracked consistently. Combined with those who have no training at all, that means almost one in five organisations (18%) cannot reliably show that training took place at all, whether because it was not tracked or did not happen.

 

Nick Henderson-Mayo, head of compliance at VinciWorks, said, “Training that is not tracked is training that did not happen. If a regulator asks an organisation to show that staff understood their responsibilities before an incident, a memory of a session from last spring is not evidence. HR and L&D teams are usually the ones holding the actual completion records, and under this Bill, those records are critical for compliance.”

 

The Cyber Security and Resilience (Network and Information Systems) Bill brings a much wider range of organisations into scope, including managed service providers, data centres and a new category of “critical suppliers”, and gives regulators stronger powers to demand evidence and carry out audits. The expanded rules are expected to be phased in through 2027 and 2028. 

Getting this wrong carries a real financial cost. Under the Bill, regulators will be able to impose fines of up to £10m or 2% of an organisation’s worldwide turnover for less serious breaches, rising to £17m or 4% of worldwide turnover, whichever is higher, for more serious failures, with daily fines of up to £100,000 for continuing non-compliance. 

The same poll found people, not just systems, remain the biggest source of risk. Asked how concerned they were that a cyber attack could severely disrupt their organisation’s operations, over a third (34%) said they were very concerned and a further 34% said they were fairly concerned. Not a single respondent said they were not concerned at all, yet that concern has not yet translated into consistently tracked training.

Nick Henderson-Mayo added, “Mapping your suppliers, testing your escalation plan and properly tracking training aren’t the most glamorous of tasks, but they are exactly what regulators, and increasingly customers, will expect to see evidence of once this Bill is in force. Training is usually the first thing HR and L&D teams are asked to evidence after an incident, so it is worth getting right before one happens, not after.” 

VinciWorks recommends five steps HR and L&D teams can take this week to start preparing for the Bill:

  • Audit your current training records to confirm you can show, not just assume, which staff have actually completed mandatory cyber security training.
  • Move away from annual, one-off sessions towards ongoing, tracked training that reflects how attackers increasingly target people rather than just systems.
  • Agree clear ownership of training completion evidence between HR, L&D and IT, so no one function assumes another is tracking it.
  • Build cyber security awareness into onboarding and regular refreshers, rather than treating it as a single annual event.
  • Prepare a plan for communicating with staff during a live incident, since regulators and customers will expect to see this was thought through in advance, not improvised.



Source link

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Technology

JCA Engineering revenue boosted by data centre demand

JCA Engineering has reported a 44 per cent jump in turnover, as...

Technology

More Than One-Third of Industrial Organizations See Cybersecurity Risk as a Top Obstacle to Growth, New Global Study Finds

Industrial companies are increasing cybersecurity investment as connected operations, AI adoption and...

Technology

Xpansiv and Verdane Announce Strategic Partnership and Capital Raise to Advance Global Acquisitions and Product Expansion

Xpansiv, the leading infrastructure provider for the global energy transition markets, and...

Technology

In the race to roll out 6G, the UK and Europe are caught between technology’s superpowers

Even as the rollout of the 5G network continues around the world,...