2). The findings highlight that a lack of commercial rationale is a significant barrier for
organisations, and was identified to be an even more severe barrier for micro and small
organisations.
Respondents highlighted that a lack of commercial rationale was particularly due to
organisations being unable to justify the cost of investment in cyber risk mitigations
without clear articulation and proof of the benefits. The evidence confirms that cyber
security investment decisions are not currently underpinned by clear, easily accessible or
assured information. For example, the Call for Evidence findings indicate that
organisations are attempting to use information on impact to inform cyber security
investment decisions. However, 86% of respondents stated that an inability to fully
understand and anticipate the direct and indirect impact of cyber attacks is a moderate or
severe barrier to effective risk management. These types of information failure are
currently preventing many organisations from being able to accurately make an
assessment of their cyber risk. Accordingly, in the short to medium term, it is likely that
organisations will continue to face barriers in developing a strong commercial rationale
for investment in their cyber security risk mitigation activities.
The Call for Evidence also sought input on where Government should focus the
development of a new programme of activity. The majority of respondents (75%) agreed
that additional Government solutions are required for assuring and standardising
information used in cyber risk management, whether this is information on the cyber
threat, impact of a cyber breach, or mitigation activity. A large number of respondents
provided suggestions for this information being provided through the introduction of
new, or improvement of existing, frameworks and standards. The Call for Evidence
responses also highlighted key issues around SMEs, who are less likely to have specialised
cyber security teams. They often therefore lack technical expertise and cyber security is
likely an additional responsibility of staff focused on other areas.
The onset of Covid-19 has increased the overall risk surface through a rapid increase in
the use of and reliance on digital technologies - from individuals, to small businesses, to
the FTSE 100. This rapid adoption has only exacerbated the real need for easily
understood and standardised ways of communicating what minimum expectations and
best practice in managing digital risks. This is a necessity if we are to embed cyber
security as part and parcel of every business’ business continuity and risk management.
Additional suggestions were provided for embedding this information in existing
corporate governance and business assurance mechanisms, including supplier
management, or by Government using additional regulation, incentives, and advice and
guidance. In the context where businesses are becoming ‘digital’ overnight or are seeking
to provide new online services or business models, procurement and management of
digital suppliers becomes a critical part of business continuity. However, we know the
great majority of organisations struggle with managing supplier risks, with the Cyber
Security Breaches Survey 2020 showing just 15% of businesses currently review their
supplier risks.
4/27