Home Technology Business Reporter – Responsible Business
Technology

Business Reporter – Responsible Business

Share


The threat landscape is moving faster than the defensive posture of much of the UK economy, and the gap is widening at the smaller end of the supply chain

 

According to the recent UK government Cyber Security Breaches Survey, just over four in ten businesses (43 per cent) and roughly three in ten charities (28 per cent) suffered a cyber-incident in the past year. The threat landscape is moving faster than the defensive posture of much of the UK economy, and the gap is widening at the smaller end of the supply chain.

 

The resilience gaps in most organisations may not be where most boards think they are. They often sit in the supply chain, in operational technology, in identity and access and in the rehearsal of incident response, rather than in the firewall.

 

High-profile data breaches in recent years have illustrated how a compromise originating with a supplier or a contractor can halt production lines and empty shelves within days. Large firms have invested heavily in their own perimeters, but their assurance over fourth- and fifth-tier suppliers often remains thin. Many smaller firms in those supply chains are running unsupported software, single-factor authentication on admin accounts, and may have no formal incident response plan in place.

 

Manufacturing, logistics and energy firms have spent 20 years connecting industrial control systems to corporate networks for efficiency reasons. That convergence is now the principal route by which a ransomware infection in an office environment shuts down a production facility. Segmentation between information technology and operational technology is still the exception rather than the rule.

 

Phishing remains the most common entry vector, experienced by 38 per cent of businesses and 25 per cent of charities, according to the Cyber Security Breaches Survey. AI-generated phishing has lowered the cost of crafting convincing lures, including voice clones used in business email compromise. Multi-factor authentication is widespread on paper, but phishing-resistant MFA, meaning hardware security keys or platform-bound credentials, is still rare outside the largest firms. Most firms have a written plan, however far fewer have tested it within the last year. The first time a board reads its own playbook should not be in the early hours of the morning during a live incident.

 

What is hindering organisational preparedness?

 

The UK has a well-documented cyber skills gap of tens of thousands of practitioners. Smaller firms cannot compete on salary with banks, big tech or central government, so they go without, or they pay for a managed service that may itself be under-resourced.

 

Passing Cyber Essentials, or ticking the boxes for a sector standard, is treated by some firms as the end of the journey, when it should be the entry point. Compliance certifies a baseline. It does not certify resilience. Policies are tightening their requirements, but a residual belief persists that an insurance payout will cover the loss. It will not cover the brand damage, the customer attrition, the regulatory inquiry, or the cost of reputational rebuild.

 

When a year passes without a major breach in a particular sector, investment slows and attention drifts elsewhere. The attackers do not take that year off. Responsibility is often split between IT, risk, operations and legal, with no single accountable owner. In a crisis, this slows decision-making at exactly the moment when speed matters most. Ultimately, cost and skills explain part of it, however the deeper reason is that cyber security is still treated as an IT department line item rather than a strategic business risk owned at board level.

 

Top tips for boosting resilience

 

There is no silver bullet, but a small set of controls, taken together, will eliminate the majority of preventable incidents. None of them requires a six-figure budget.

 

The starting point is Cyber Essentials Plus. It is not glamorous, but it forces patching discipline, multi-factor authentication, access control and boundary firewalling, and it is already a precondition for many public sector contracts, so the cost is recoverable. From there, the single highest-value technical investment is phishing-resistant MFA on every privileged account. Hardware security keys or platform passkeys remove the most common attack vector at a stroke, and they cost less per user per year than a decent lunch.

 

Beyond identity, firms should segment their networks, particularly between IT and operational technology environments. A compromised office laptop should never be able to reach a production line controller, and yet in many manufacturing firms it still can. Alongside segmentation sits the discipline of tested backups: the 3-2-1 rule, with at least one copy offline or immutable, and a restore rehearsed at least quarterly. Backups that have never been restored are not backups, they are hopes.

 

On the governance side, every board should conduct a tabletop exercise at least once a year. The chief executive should know what they will say to the press, the regulator and the staff before the incident, not after. Supply chain assurance follows the same logic: contractual cyber-minimums should be imposed on suppliers and then verified, with evidence of certification preferred over self-attestation. Finally, firms need proportionate logging, monitoring and detection. A small business does not need a 24-hour security operations centre, but it does need someone, internal or contracted, who actually looks at the alerts.

 

Underpinning all of this is a shift in mindset. Resilience is not the absence of attacks. It is the ability to detect, contain, recover and learn from them within hours rather than weeks. Firms that internalise this stop asking whether they will be attacked and start preparing for when.

 

The minister is right that more needs to be done, but the responsibility does not sit with government alone. Every board in the country should be asking three questions of its leadership team this week: when did we last test our incident response; do we know who our most critical suppliers are; and would we know within an hour if we had been breached? If the answer to any of those is no, the work starts there.


 



Source link

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Technology

Three UK airports hit by criminal hackers as ‘cyber security incident’ declared

Three major UK airports have been hit by a "cyber security incident"...

Technology

UK power generator forced to shut down for four days after cyber attack by Iranian hackers

The incident is thought to have happened at around the same time...

Technology

Green Party seeks critical infrastructure de-listing of data centres

The Green Party has urged ministers to end the automatic designation of...