New research by audit, tax and consulting firm RSM has revealed the extent to which middle-market businesses are exposed to cyber attacks in the UK, with 56% of businesses operating without any form of cyber-security insurance. This is despite one in five companies reporting an attack in the past 12 months and the likelihood of a continued surge in cyber attacks in the coming months, and beyond.
Of the companies reporting a cyber attack, over half said security breaches were up in 2020 compared to the previous year. Some 73% of those surveyed also said their business was at risk of unauthorised users deliberately and illegally attempting to access their data or systems over the next 12 months.
RSM’s The Real Economy survey questioned over 400 middle-market business leaders to uncover the cyber-security challenges they have faced during the coronavirus pandemic.
80% of those who had experienced a breach said the attack was an indirect result of the pandemic. The sudden shift in remote working practices from March 2020 and the need to adapt in such a short space of time appears to have created a weakened cyber infrastructure that criminals have capitalised on.
With security breaches a certainty for many businesses and yet well over half of companies still having no cyber-security insurance policy in place, it is perhaps surprising that 92% of those surveyed were confident in their existing measures to safeguard sensitive data.
Sheila Pancholi, technology risk assurance and cyber security partner at RSM, said: ‘We know many businesses are facing significant challenges around managing the impact the pandemic has had. With employees working remotely and not being fully safeguarded by corporate infrastructures, recognising and mitigating against cyber threats is more important than ever.
“The challenge with cyber insurance sits in the fact that businesses still don’t know what they need their insurance to provide cover over. Conversely, the complexities and intangible nature of what’s required for that business make it difficult for insurance companies to provide coverage that has an adequate reach and is sufficiently tailored.
“The burden of the time and cost of recovering from an attack is where a cyber insurance policy could prove invaluable. There is still a lot to be done to define what cyber insurance looks like for businesses, as a policy that would have provided effective cover one month ago might not cover the new threat variation.”
She added: “Additionally, questions remain on whether the UK workforce is adequately skilled with technically-trained cyber-security professionals, and the hand-in-hand role security measures will have for businesses when looking at their wider cyber footprint.”
RSM’s cyber security survey was the second in The Real Economy series of topical quarterly surveys focusing on the middle market as a powerhouse of the UK economy. It is also the first authoritative source of economic data for this crucial area of the UK market, sharing insight and perspective for the wider economy.