Header image

Lack of Responsibility and 24/7 Staffing Concern UK Cyber Professionals

Only a third have what they feel is sufficient staffing for full time coverage.


According to research from Trend Micro, UK organisations lack sufficient resources and leadership buy-in to measure and mitigate risk across their digital attack surface.

The survey of 100 UK cybersecurity leaders found the top three gaps in cyber-resilience revealed by respondents were:

  • Sufficient staffing for 24x7x365 cybersecurity coverage – which 31% have

  • Attack surface management techniques to measure the risk of the attack surface (used by 32%)

  • Using proven regulatory and other frameworks like the NIST Cybersecurity Framework (34%)

Also, 48% of global respondents claimed that their leadership doesn’t consider cybersecurity to be their responsibility and when asked who does or should hold responsibility for mitigating business risk, respondents returned a variety of answers, indicating a lack of clarity on reporting lines. A quarter (25%) of UK respondents said the buck stops with organisational IT teams.

Bharat Mistry, technical director at Trend Micro said: “A lack of clear leadership on cybersecurity can have a paralyzing effect on an organisation - leading to reactive, piecemeal and erratic decision making.

“Companies need CISOs to clearly communicate in terms of business risk to engage their boards. Ideally, they should have a single source of truth across the attack surface from which to share updates with the board, continually monitor risk, and automatically remediate issues for enhanced cyber-resilience.”


Dan Raywood
Dan Raywood Senior Editor SC Media UK

Dan Raywood is a B2B journalist with more than 20 years of experience, including covering cybersecurity for the past 16 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Conference, BSides Scotland, Steelcon and ESET Security Days.

Outside work, Dan enjoys supporting Tottenham Hotspur, managing mischievous cats, and sampling craft beers.

Dan Raywood
Dan Raywood Senior Editor SC Media UK

Dan Raywood is a B2B journalist with more than 20 years of experience, including covering cybersecurity for the past 16 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Conference, BSides Scotland, Steelcon and ESET Security Days.

Outside work, Dan enjoys supporting Tottenham Hotspur, managing mischievous cats, and sampling craft beers.

Upcoming Events

No events found.