Department for Digital, Culture, Media and Sport
Businesses and charities urged to take action to prevent cyber attacks
Percentage of businesses experiencing cyber breaches or attacks has dropped.
- Percentage of businesses experiencing cyber breaches or attacks drops from 43% to 32%.
- New laws to strengthen data protection have had a positive impact on cyber security.
- Businesses and charities urged to train more people to help manage cyber risks.
New statistics from the Department for Digital, Culture, Media and Sport (DCMS) have shown a reduction in the percentage of businesses suffering a cyber breach or attack in the last year.
The 2019 Cyber Security Breaches Survey shows that 32% of businesses identified a cyber security attack in the last 12 months – down from 43% the previous year.
The reduction is partly due to the introduction of tough new data laws under the Data Protection Act and the General Data Protection Regulations (GDPR). 30% of businesses and 36% of charities have made changes to their cyber security policies and processes as a result of GDPR coming into force in May 2018.
However, of those businesses that did suffer attacks, the typical median number of breaches has risen from 4 in 2018 to 6 in 2019. Therefore, businesses and charities suffering cyber attacks and breaches appear to be experiencing more attacks than in previous years.
Where a breach has resulted in a loss of data or assets, the average cost of a cyber attack on a business has gone up by more than £1,000 since 2018 to £4,180. Business leaders are now being urged to do more to protect themselves against cybercrime.
The most common breaches or attacks were phishing emails, followed by instances of others impersonating their organisation online, viruses or other malware including ransomware.
Digital Minister Margot James yesterday said:
Following the introduction of new data protection laws in the UK it’s encouraging to see that business and charity leaders are taking cyber security more seriously than ever before. However, with less than three in ten of those companies having trained staff to deal with cyber threats, there’s still a long way to go to make sure that organisations are better protected.
We know that tackling cyber threats is not always at the top of business and charities list of things to do, but with the rising costs of attacks, it’s not something organisations can choose to ignore any longer.
Through the CyberFirst programme, the Government is working with industry and education to improve cyber security and get more young people interested in taking up a career in cyber. The Cyber Discovery initiative has already encouraged 46,000 14 to 18 year olds to get on a path towards the cyber security profession, over 1,800 students have attended free CyberFirst courses and nearly 12,000 girls have taken part in the CyberFirst Girls competition. The Government’s initial Cyber Skills Strategy, published in December, will be followed by a full strategy later this year.
Business and charity leaders are being encouraged to download the free small business guide and free small charity guide to help make sure that they don’t fall victim to cyber attacks. This is available through the National Cyber Security Centre (NCSC).
Clare Gardiner, Director of Engagement at the NCSC, yesterday said:
We are committed to making the UK the safest place to live and do business online, and welcome the significant reduction in the number of businesses experiencing cyber breaches.
However, the cyber security landscape remains complex and continues to evolve, and organisations need to continue to be vigilant.
The NCSC has a range of products and services to assist businesses, charities and other organisations to protect themselves from cyber attacks, and to deal with attacks when they occur. These include the Board Toolkit providing advice to Board level leaders, and guides aimed at small businesses and small charities.
The threat of cyber attacks remains very real and widespread in the UK. The figures published yesterday also show that 48% of businesses and 39% of charities who were breached or attacked, identified at least one breach or attack every month.
Cyber security is becoming more of a priority issue, especially for charities. Those charities who treated cyber security as a high priority has gone up to 75% in 2019, compared with just 53% the year before, and is now at the same level as businesses.
Small businesses and charities are being urged to take up tailored advice from the National Cyber Security Centre. All businesses should consider adopting the Ten Steps to Cyber Security, which provides a comprehensive approach to managing cyber risks. Implementation of the 10 Steps will help organisations reduce the likelihood and cost of a cyber attack or cyber related data breach.
Organisations can also raise their basic defences by enrolling on the Cyber Essentials initiative and following the regularly updated technical guidance on Cyber Security Information Sharing Partnership available on the NCSC website.
Notes to editors:
The annual Cyber Security Breaches survey is part of the Government’s National Cyber Security Strategy, which is investing £1.9 billion over five years to make the UK the safest place to live and work online.
The full report is published online: https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2019
The survey builds on the ongoing programme of Government action on cyber security, which has recently included the publication of the NCSC “Board Toolkit”, the publication of the Cyber Health Check for FTSE350 companies, a series of Ministerial roundtables with leading UK companies, and the Cyber Aware campaign for small businesses and the public.
Businesses and charities can protect themselves online using the practical guidance offered by the National Cyber Security Centre, such as the Cyber Security Guide for Small Businesses and the Cyber Security Guide for Small Charities.
The Cyber Security Breaches Survey 2019 was carried out for DCMS by Ipsos MORI, in partnership with the Institute for Criminal Justice Studies at the University of Portsmouth.
The survey methodology consists of a random probability telephone survey of 1,566 UK businesses (excluding agriculture, forestry and fishing businesses) and 514 UK registered charities undertaken from 10 October 2018 to 20 December 2018. The data have been weighted to be statistically representative of these two populations. In addition, a total of 52 in-depth interviews with survey participants, were undertaken during January and February 2019, to gain further qualitative insights.
The Cyber Security Breaches Survey is an Official Statistic and has been produced to the standards set out in the Code of Practice for Statistics.
Latest News from
Department for Digital, Culture, Media and Sport
£95 million to revive historic high streets16/09/2019 12:12:00
Culture Secretary Nicky Morgan recently (14 September 2019) announced the locations that will benefit from a £95 million heritage boost for high streets in 69 towns across the country.
Hundreds of students to take youth work qualifications after new government investment12/09/2019 15:43:00
Hundreds of students will be able to pursue careers as youth workers through a new £500,000 bursary fund, Minister for Civil Society Baroness Barran announced today.
Proposed reforms to permitted development rights to support the deployment of 5G and extend mobile coverage29/08/2019 12:12:00
This consultation seeks views on the principle of amending permitted development rights to support deployment of 5G and extend mobile coverage.
£30m to spark rollout of next generation 5G in rural areas and help countryside capitalise on tech revolution28/08/2019 10:10:10
New competition launched to test groundbreaking 5G applications in rural areas, alongside proposed planning reforms to improve and extend mobile coverage
Our tech sector has already attracted more foreign investment this year than it did for the whole of 2018: article by Nicky Morgan22/08/2019 09:25:00
Writing in The Telegraph, the Digital Secretary celebrates the record-breaking levels of investment into the UK's tech sector (21 August 2019).
Arts Minister stops export of Pre-Raphaelite work16/08/2019 15:10:00
£9.5 million work by founder of Pre-Raphaelite Brotherhood John Everett Millais is now at risk of permanently leaving the UK
£250,000 boost for broadband in conference centres16/08/2019 11:10:00
Tourism Minister Rebecca Pow launches competition to boost broadband facilities in conference centres across the UK
New boost to increase diversity in nation’s cyber security industry14/08/2019 15:05:00
Delivery lead appointed to set up the new UK Cyber Security Council and latest round of Cyber Skills Immediate Impact Fund launched