Skip to main content
CybersecurityVulnerability Management

UK Businesses Expose Gaps in Basic Cyber Skills

Employees work at desks with concerned expressions, surrounded by computers and a whiteboard with scribbled notes.

"When more than half of UK businesses lack confidence in the basics, and nearly half of those responsible for security don't feel equipped to handle an attack, we have an economy that is both easier to breach and slower to recover," Sam Thornton, COO at cybersecurity consultancy Bridewell, told The Register.

Survey snapshot: 57 percent of businesses report a basic technical skills gap

The UK government's annual skills survey found 57 percent of businesses reported a basic technical cybersecurity skills gap, up from 49 percent last year. That proportion translates to an estimated 808,000 businesses whose cybersecurity leads said they were not confident in carrying out at least one of nine basic tasks; the equivalent estimate last year was 699,000 businesses. The research teams cautioned the rise may partly reflect greater awareness of organisations' security posture rather than an absolute decline in capability, and interviews suggested recent high‑profile breaches had prompted more scrutiny from executives and boards.

Malware detection and removal is the largest single shortfall

Across the nine tasks measured — which included storing data securely, configuring firewalls and detecting and removing malware — the largest reported gap was in detecting and removing malware. The survey found 38 percent of businesses, 47 percent of charities and 23 percent of public sector organisations lacked confidence in performing that task. Sam Thornton warned that "malware is evolving quickly, and AI is increasingly helping attackers produce faster variants which are harder to spot," a dynamic that he said makes sustained attention to detection tools and expertise essential.

Smaller organisations and charities: security as a secondary role

Charities reported the widest skills gap on most measures in the survey, while businesses were notably less confident than charities and the public sector about storing and transferring personal data securely. Thornton attributed much of the shortfall to the structure of smaller organisations: cybersecurity is often "just one part of someone's wider role rather than a dedicated job." He argued that tighter regulation alone is unlikely to close these gaps: "Tighter regulation will help protect critical infrastructure, but it's unlikely to improve the skills in smaller businesses and charities. Closing the gap will need affordable, practical support for smaller organisations, whether through managed services, simpler tools or incentives from insurers, so that good baseline security becomes the default rather than something only larger firms can afford," he told The Register.

Public sector response: Cyber Action Plan, the bill in the Lords, and recent audits

Although the public sector scored better than businesses and charities on the survey's basic skills measures, its reported basic skills gap nearly doubled from 14 percent last year to 27 percent. The National Audit Office's 2025 review found "significant" gaps and immature controls across most critical systems it examined, and recent incidents affecting the Legal Aid Agency, Foreign Office, British Library and NHS supplier Synnovis have underscored those weaknesses. In response, the government announced a £210 million Cyber Action Plan at the start of the year to strengthen central government systems and introduce mandatory security requirements. Operators of critical services can use the NCSC's Cyber Assessment Framework to assess resilience, while smaller organisations can seek Cyber Essentials certification as a baseline. Separately, the Cyber Security and Resilience Bill — currently making its way through the Lords — would impose additional requirements on operators of essential services and their suppliers and is intended to replace the NIS Regulations 2018; the bill explicitly excludes central and local government. The government says the Cyber Action Plan effectively holds the public sector to the same standard as those in scope of the bill, but without legally binding obligations.

What this means for technologists, policymakers, and charities

  • Technologists and security teams: Expect the greatest pressure on basic defensive tasks such as malware detection and secure configuration as organisations of all sizes struggle to maintain expertise. Matt Hull, veep of cyber intelligence and response at NCC Group, said increasingly complex IT environments — cloud infrastructure, SaaS platforms, APIs, third parties and rising numbers of human and machine identities — make applying fundamentals harder and mean defenders must prioritise consistent basics over chasing "the latest shiny update." He warned that neglecting fundamentals causes most problems.
  • Policymakers and regulators: The government has matched audit findings with a £210 million Cyber Action Plan and new legislative proposals via the Cyber Security and Resilience Bill. The bill would raise obligations for operators of essential services and their suppliers while excluding central and local government; the government positions the Cyber Action Plan as the non‑statutory equivalent for the public sector.
  • Charities and small businesses: Where cybersecurity is part of a broader job remit, organisations are likely to lean on third‑party services and automation. Thornton cautioned that increased use of AI tooling by under‑resourced teams "could induce further exposure to the organisation where sufficient skill levels are needed to understand and interpret the output of such AI models."

The government's survey draws a stark line under the UK's remaining exposure at the basic defensive level: more organisations report uncertainty about core tasks than last year, and the largest gaps sit where rapid change — malware evolution, cloud complexity and tool proliferation — meets thin resourcing. The policy response bundles funding, frameworks and fresh regulation, but the survey and expert commentary point to a persistent implementation challenge: getting affordable, practical support into the hands of smaller organisations so baseline security becomes routine rather than exceptional.

Original story — The Register