Three-quarters of UK and 79% of charities have experienced at least one cybersecurity incident in the last 12 months.

According to research from the British government, only some limited improvements were made to the cybersecurity of organizations between 2022 and 2023. The Cyber Security Longitudinal Survey (CSLS) has been examining around 1000 businesses and charities in the UK since 2021. The latest findings relate to cybersecurity in these organizations in 2023.
The data showed that charities took a less formal approach to cybersecurity than businesses. For example, they were much more likely to allow access to their systems via a personal device.
See also: Regulatory measures boost the cybersecurity industry
On the other hand, businesses are more likely to require staff to use VPNs for remote accessthan charities.
Around a third of businesses (38%) and charities (36%) comply with at least one of the three key cybersecurity certifications: Cyber Essentials Standard, Cyber Essentials Plus and ISO 27001. The majority had five technical audits required to achieve Cyber Essentials accreditation .
When it comes to responding to cybersecurity incidents, the majority of businesses and charities follow a specific process. Around half (46%) of businesses and a third (34%) of charities have tested cybersecurity incident response policies in the last 12 months.
It is also worth noting that only a small percentage uses artificial intelligence or machine learning to improve their cyber resilience.
Furthermore, the research showed that large enterprises implemented more cybersecurity measures compared to small and medium-sized organizations.
See also: How to prioritize cybersecurity spending?

Encouraging evidence
The report highlighted some encouraging evidence regarding the involvement of organizations' board members in cybersecurity posture.
About half of businesses and charities have a board member dedicated to overseeing cybersecurity strategies.
Board-level cybersecurity training is available to 50% of businesses and 35% of charities. However, the proportion of organisations reporting regular discussions about cybersecurity at board level remains quite low.
What are the proposed solutions for upgrading cybersecurity?
One important solution is to educate staff on cybersecurity issues. Employees need to be aware of the risks and tactics used by attackers so they can identify and avoid threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: How do international conflicts affect cybersecurity?
Additionally, the use of advanced technologies, such as intrusion detection systems and the implementation of anti -malware, can help protect networks and systems from attacks.
Implementing cybersecurity policies is also critical for businesses. There should be clear rules for accessing data and applications, using personal devices , and sending sensitive information.
Finally, continuous monitoring and evaluation of systems is essential to address new threats and adapt to changing conditions.
Source: www.infosecurity-magazine.com
