The survey, which measures confidence across nine fundamental cybersecurity activities, revealed that detecting and removing malware produced the largest reported skills gap: 38 percent of businesses, 47 percent of charities, and 23 percent of public sector organizations lacked confidence in performing the task. Other gaps included storing and transferring personal data securely, restricting software execution, configuring firewalls, selecting secure device settings, enabling automatic updates, and creating user accounts securely.
Researchers cautioned that the increase may reflect greater awareness of organisational security posture rather than an actual deterioration in capabilities, noting that recent high-profile breaches have prompted closer scrutiny by executives and boards.
Sam Thornton, COO at cybersecurity consultancy Bridewell, said the figures reflected the position of smaller businesses and charities, where cybersecurity is often "just one part of someone's wider role rather than a dedicated job." He warned that malware is evolving quickly and AI is helping attackers produce faster variants that are harder to spot, making it harder for staff juggling multiple roles to keep pace.
Matt Hull, vice president of cyber intelligence and response at NCC Group, said limited resources were compounded by increasingly complex IT environments. "Businesses increasingly rely on cloud infrastructure, SaaS platforms, APIs, third parties and growing numbers of human and machine identities," he said. "These environments can change rapidly, making it much harder to apply security fundamentals consistently across the organization."
Charities reported the widest skills gap on most measures, while the public sector—though scoring better overall—saw its basic skills gap nearly double from 14 percent last year to 27 percent, despite repeated warnings about weaknesses in government systems highlighted by incidents affecting the Legal Aid Agency, Foreign Office, British Library, and NHS supplier Synnovis.
The government has responded with the £210 million Cyber Action Plan, announced at the start of the year, aimed at bolstering national cyber resilience.