Cyber security is now firmly cemented as a key issue in the boardroom of FTSE 350 companies, but this isn’t reflected in the training that management receive in dealing with cyber incidents.
In a survey carried out by KPMG as part of the Government’s Cyber Governance Health Check, over half (54 per cent) of businesses place cyber risk as a top group risk when compared with other threats that a company faces – up from the 29 per cent who did so in 2014. Boards are also more likely to debate and agree their tolerance for cyber risk than in previous years. More than half (53 per cent) have this “clearly set and understood”, an improvement on the 33 per cent from 2016.
However, it’s clear that even though cyber as an issue is recognised and understood more than ever by boards, the training in how to deal with the issue is still lagging. Over two-thirds (68 per cent) said they have not received any training to deal with a cyber incident, and only two per cent stated they have received comprehensive training. More worryingly, 10 per cent of businesses revealed that they do not have a plan in place to respond to a cyber incident.
Paul Taylor, UK head of Cyber Security at KPMG, said:
“Cyber attacks continue to pose a growing threat to business. While cyber security has cemented itself onto the board’s agenda, they often lack the training to deal with incidents. This is hugely important as knowing how to deal confidently with an incident in the heat of the moment can save time and money. The aftermath of a cyber-attack, without the appropriate training in managing the issue, can result in reputational damage, litigation and blunt competitive edge.”
With General Data Protection Regulation (GDPR) less than a year away, 46% of boards still do not review and challenge reports on the security of their customer’s data – even though this figure has decreased by 15 percent from last year. Yet, 71 per cent of businesses describe themselves as somewhat prepared to meet the requirements of the GDPR, but only 6 per cent say they are completely prepared.




