Over half of UK businesses lack confidence in basic cybersecurity skills, survey finds

Government research shows skills gap widening despite tighter standards and repeated warnings

By LineZotpaper
Published
Read Time2 min
More than half of UK businesses lack confidence in performing at least one basic cybersecurity task, according to the government's latest skills survey. The annual research, published on Tuesday, found that 57 percent of businesses reported a basic technical skills gap, up from 49 percent last year, equating to approximately 808,000 businesses whose cybersecurity leads were not confident in carrying out tasks such as storing data securely, configuring firewalls, and detecting malware.

The survey, which measures confidence across nine fundamental cybersecurity activities, revealed that detecting and removing malware produced the largest reported skills gap: 38 percent of businesses, 47 percent of charities, and 23 percent of public sector organizations lacked confidence in performing the task. Other gaps included storing and transferring personal data securely, restricting software execution, configuring firewalls, selecting secure device settings, enabling automatic updates, and creating user accounts securely.

Researchers cautioned that the increase may reflect greater awareness of organisational security posture rather than an actual deterioration in capabilities, noting that recent high-profile breaches have prompted closer scrutiny by executives and boards.

Sam Thornton, COO at cybersecurity consultancy Bridewell, said the figures reflected the position of smaller businesses and charities, where cybersecurity is often "just one part of someone's wider role rather than a dedicated job." He warned that malware is evolving quickly and AI is helping attackers produce faster variants that are harder to spot, making it harder for staff juggling multiple roles to keep pace.

Matt Hull, vice president of cyber intelligence and response at NCC Group, said limited resources were compounded by increasingly complex IT environments. "Businesses increasingly rely on cloud infrastructure, SaaS platforms, APIs, third parties and growing numbers of human and machine identities," he said. "These environments can change rapidly, making it much harder to apply security fundamentals consistently across the organization."

Charities reported the widest skills gap on most measures, while the public sector—though scoring better overall—saw its basic skills gap nearly double from 14 percent last year to 27 percent, despite repeated warnings about weaknesses in government systems highlighted by incidents affecting the Legal Aid Agency, Foreign Office, British Library, and NHS supplier Synnovis.

The government has responded with the £210 million Cyber Action Plan, announced at the start of the year, aimed at bolstering national cyber resilience.

§

Analysis

Why This Matters

  • The widening skills gap leaves hundreds of thousands of UK businesses vulnerable to cyber attacks, at a time when ransomware and data breaches are becoming more frequent and costly.
  • Small businesses and charities—already resource-strapped—are disproportionately affected, increasing the risk of disruption to essential services and supply chains.
  • The findings pressure the government to demonstrate that its £210 million Cyber Action Plan translates into measurable improvements in workforce capability.

Background

The UK government's annual cyber skills survey tracks confidence in nine fundamental security tasks. Last year's figure was 49 percent; this year's rise to 57 percent comes despite tighter national standards and repeated official warnings about cyber resilience. The government has acknowledged system weaknesses: in 2025, the National Audit Office found significant gaps across most critical government systems. High-profile breaches at the British Library, NHS supplier Synnovis, and other public bodies have underscored the consequences of poor cyber hygiene.

Key Perspectives

UK businesses: Many lack dedicated cybersecurity staff, with the task falling to employees handling multiple roles. Limited resources and rapidly changing IT environments make it difficult to maintain fundamentals. Charities: They report the widest skills gaps across most measures, likely due to tight budgets and competing priorities. Public sector: While performing better overall, the public sector saw its skills gap nearly double, despite being a frequent target and recipient of repeated government warnings. Industry experts: Sam Thornton of Bridewell highlights the challenge of keeping up with AI-enhanced malware; Matt Hull of NCC Group warns against chasing "shiny" new tools at the expense of basics.

What to Watch

  • Whether the £210 million Cyber Action Plan leads to measurable narrowing of the skills gap in next year's survey.
  • Uptake of government cyber skills schemes and training programs among small businesses and charities.
  • Any increase in cyber incidents involving AI-generated malware that exploits the identified skills gaps.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.