Cisco: Overconfidence in cyber security capabilities putting UK firms at risk
Many companies are overconfident about their cyber resilience and security capabilities, according to Cisco
Only 2% of organizations in the UK are properly resilient against today’s cyber security risks, according to new research from Cisco, worse even than the global figure of 3%.
Nearly three-quarters of UK organizations fall into the Beginner or Formative stages of cyber security readiness, analysis from the tech giant found, with just one-in-fifty achieving the required Mature level.
96% of companies said they expect to increase cyber security budgets in the next 12 months, seven-in-ten said a security incident is likely to disrupt their business in the next 12 to 24 months.
Meanwhile, 54% of respondents said they had experienced a cyber security incident in the last 12 months, with just over half of those affected saying it cost them at least $300,000.
But with 78% of companies saying they feel moderately to very confident in their ability to defend against a cyber attack with their current infrastructure, Cisco suggested that companies may be overconfident and failing to assess the true scale of the challenges they face.
"We cannot underestimate the threat posed by our own overconfidence," said Jeetu Patel, executive vice president and general manager of security and collaboration at Cisco.
"Today's organizations need to prioritize investments in integrated platforms and lean into AI in order to operate at machine scale and finally tip the scales in the favor of defenders."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The traditional approach of adopting multiple cyber security point solutions hasn't been particularly effective, the report found, with three-quarters of respondents admitting that it slowed down their team’s ability to detect, respond, and recover from incidents.
And this is a particular concern, Cisco said, with 69% of organizations revealing they have deployed ten or more point solutions in their security stacks, while 29% said they have 30 or more.
Meanwhile, eight-in-ten companies said their employees access company platforms from unmanaged devices, and 40% of those spend one-fifth of their time logged onto company networks from unmanaged devices.
Another quarter reported that their employees hop between at least six networks over a week.
And progress is being further held up by critical talent shortages, with 85% of companies highlighting it as an issue - indeed, four in ten said they had more than ten roles related to cybersecurity unfilled in their organization at the time of the survey.
The good news is that nearly half of organizations are planning to significantly upgrade their IT infrastructure in the next 12 to 24 months - well up from the 31% who planned to do so last year.
Most prominently, seven in ten plan to upgrade existing solutions, six on ten to deploy new solutions and 55% and invest in AI-driven technologies. Almost all expect to increase their cyber security budget in the next 12 months, with 82% saying their budgets will increase by 10% or more.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
The modern workplace: Standardizing collaboration for the enterprise IT leaderHow Barco ClickShare Hub is redefining the meeting room
-
Interim CISA chief uploaded sensitive documents to a public version of ChatGPTNews The incident at CISA raises yet more concerns about the rise of ‘shadow AI’ and data protection risks
-
AI is “forcing a fundamental shift” in data privacy and governanceNews Organizations are working to define and establish the governance structures they need to manage AI responsibly at scale – and budgets are going up
-
Cisco says Chinese hackers are exploiting an unpatched AsyncOS zero-day flaw – here's what we know so farNews The zero-day vulnerability affects Cisco's Secure Email Gateway and Secure Email and Web Manager appliances – here's what we know so far.
-
Researchers claim Salt Typhoon masterminds learned their trade at Cisco Network AcademyNews The Salt Typhoon hacker group has targeted telecoms operators and US National Guard networks in recent years
-
Cisco ASA customers urged to take immediate action as NCSC, CISA issue critical vulnerability warningsNews Cisco customers are urged to upgrade and secure systems immediately
-
Cisco eyes network security gains for agentic AINews New network security updates aim to secure AI agents across enterprises
-
Cisco patches critical flaw affecting Identity Services EngineThe networking giant has urged enterprises to update immediately
-
96% of businesses have low cyber-readiness, claims CiscoThe 2025 Cisco Cybersecurity Readiness Index shows a concerning number of businesses globally are unprepared for rising AI-related threats.
-
Cisco takes aim at AI security at RSAC with ServiceNow partnershipNews The companies claim Cisco AI Defense and ServiceNow SecOps will help address new challenges raised by AI
