2). The findings highlight that a lack of commercial rationale is a significant barrier for organisations, and was identified to be an even more severe barrier for micro and small organisations. Respondents highlighted that a lack of commercial rationale was particularly due to organisations being unable to justify the cost of investment in cyber risk mitigations without clear articulation and proof of the benefits. The evidence confirms that cyber security investment decisions are not currently underpinned by clear, easily accessible or assured information. For example, the Call for Evidence findings indicate that organisations are attempting to use information on impact to inform cyber security investment decisions. However, 86% of respondents stated that an inability to fully understand and anticipate the direct and indirect impact of cyber attacks is a moderate or severe barrier to effective risk management. These types of information failure are currently preventing many organisations from being able to accurately make an assessment of their cyber risk. Accordingly, in the short to medium term, it is likely that organisations will continue to face barriers in developing a strong commercial rationale for investment in their cyber security risk mitigation activities. The Call for Evidence also sought input on where Government should focus the development of a new programme of activity. The majority of respondents (75%) agreed that additional Government solutions are required for assuring and standardising information used in cyber risk management, whether this is information on the cyber threat, impact of a cyber breach, or mitigation activity. A large number of respondents provided suggestions for this information being provided through the introduction of new, or improvement of existing, frameworks and standards. The Call for Evidence responses also highlighted key issues around SMEs, who are less likely to have specialised cyber security teams. They often therefore lack technical expertise and cyber security is likely an additional responsibility of staff focused on other areas. The onset of Covid-19 has increased the overall risk surface through a rapid increase in the use of and reliance on digital technologies - from individuals, to small businesses, to the FTSE 100. This rapid adoption has only exacerbated the real need for easily understood and standardised ways of communicating what minimum expectations and best practice in managing digital risks. This is a necessity if we are to embed cyber security as part and parcel of every business’ business continuity and risk management. Additional suggestions were provided for embedding this information in existing corporate governance and business assurance mechanisms, including supplier management, or by Government using additional regulation, incentives, and advice and guidance. In the context where businesses are becoming ‘digital’ overnight or are seeking to provide new online services or business models, procurement and management of digital suppliers becomes a critical part of business continuity. However, we know the great majority of organisations struggle with managing supplier risks, with the Cyber Security Breaches Survey 2020 showing just 15% of businesses currently review their supplier risks. 4/27

Select target paragraph3