UK firms have ‘alarming gaps’ in cybersecurity readiness

7 May 2025, 09:24

A woman's hand pressing keys on a laptop
Cyber security. Picture: PA

A new report warns the vast majority of UK organisations are not adequately prepared to deal with modern cyber attacks.

The vast majority of UK firms are not at the required level of readiness to be able to withstand modern cyber attacks, a new report has warned.

Software giant Cisco’s annual Cybersecurity Readiness Index found that only 4% of UK organisations achieved its “mature” level of readiness – although this was a slight increase from the just 2% that achieved the status last year.

Cisco said the study, which included a survey of 8,000 private sector security and business leaders from 30 countries, showed there were “alarming gaps” in cybersecurity preparedness, and also warned of a “lack of urgency” in addressing the issue.

This year's report continues to reveal alarming gaps in security readiness and a lack of urgency to address them. UK organisations must rethink their strategies now or risk becoming irrelevant in the AI era

Jeetu Patel, Cisco

The findings come as major retailers continue to battle with the fallout from substantial cyber attacks.

On Tuesday, Co-op was unable to take card payments in some stores and shoppers have faced empty shelves because of an ongoing cyber attack for which the firm has apologised after it confirmed hackers had extracted members’ personal data such as names and contact details.

Meanwhile, Marks & Spencer (M&S) is continuing to deal with disruption caused by its own recent cyber incident, after first witnessing issues two weeks ago.

The retailer has reportedly been unable to offer some meal deals in some of its stores after product availability was hit.

In its report, Cisco said artificial intelligence (AI) is becoming an increasingly important tool, not just to help with cyber defences, but also in upskilling low-level hackers to enable them to carry out more sophisticated attacks.

According to its study, 78% of UK organisations said they had faced an AI-related security incident in the last year, but only 52% of those surveyed said they are confident their staff fully understand AI-related threats or grasp how the technology can be used to carry out attacks.

As AI transforms the enterprise, we are dealing with an entirely new class of risks at unprecedented scale - putting even more pressure on our infrastructure and those who defend it

Jeetu Patel, Cisco

Cisco chief product officer Jeetu Patel said: “As AI transforms the enterprise, we are dealing with an entirely new class of risks at unprecedented scale – putting even more pressure on our infrastructure and those who defend it.

“This year’s report continues to reveal alarming gaps in security readiness and a lack of urgency to address them. UK organisations must rethink their strategies now or risk becoming irrelevant in the AI era.”

Other cybersecurity experts, and the UK’s National Cyber Security Centre (NCSC), have also raised concerns about the rise of “ransomware as a service”, where less-skilled hackers turn to pre-made tools to launch attacks on organisations more easily.

The NCSC said there has been a “clear shift” towards this approach, which is seen as a way of reducing the difficulty for criminals to carry out cyber attacks and extort ransom payments from firms.

By Press Association

More Technology News

See more More Technology News

People ride an upward escalator next to the Dior store at the Icon Siam shopping mall on June 12, 2024 in Bangkok, Thailand.

Luxury fashion giant Dior latest high-profile retailer to be hit by cyber attack as customer data accessed

A plane spotter with binoculars from behind watching a British Airways plane landing

‘Flying taxis’ could appear in UK skies as early as 2028, minister says

Apple App Store

Take on Apple and Google to boost UK economy, think tank says

A survey of more than 1,000 employers found that around one in eight thought AI would give them a competitive edge and would lead to fewer staff.

One in three employers believe AI will boost productivity, research finds

Hands on a laptop showing an AI search

One in three employers believe AI will boost productivity, research finds

Music creators and politicians take part in a protest calling on the Government to ditch plans to allow AI tech firms to steal their work without payment or permission opposite the Houses of Parliament in London.

Creatives face a 'kind-of apocalyptic moment’ over AI concerns, minister says

Ngamba Island Chimpanzee Sanctuary on Lake Victoria, Uganda

Chimps use medicinal plants to treat each other's wounds and practice 'self-care' as scientists hail fascinating discovery

Close up of a person's hands on the laptop keyboard

Ofcom investigating pornography site over alleged Online Safety Act breaches

The Monzo app on a smartphone

Monzo customers can cancel bank transfers if they quickly spot an error

Co-op sign

Co-op to re-stock empty shelves as it recovers from major hack

The study said that it was often too easy for adult strangers to pick out girls online and send them unsolicited messages.

Social media platforms are failing to protect women and girls from harm, new research reveals

Peter Kyle leaves 10 Downing Street, London

Government-built AI tool used to cut admin work for human staff

In its last reported annual headcount in June 2024, Microsoft employed 228,000 full-time workers

Microsoft axes 6,000 jobs despite strong profits in recent quarters

Airbnb logo

Airbnb unveils revamp as it expands ‘beyond stays’ to challenge hotel sector

A car key on top of a Certificate of Motor Insurance and Policy Schedule

Drivers losing thousands to ghost broker scams – the red flags to watch out for

Marks and Spencer cyber attack

M&S customers urged to ‘stay vigilant’ for fraud after data breach confirmed