Cyber budgets actually shrank during the pandemic

Cyber consultants call on businesses to act now, or risk budgets shrinking further in ‘real terms’ during 2022 – leading to increased cyber vulnerability.

  • 2 years ago Posted in

The cyber budgets of UK enterprises actually shrank (-1%) during the pandemic, according to their cyber budget holders. This left cyber spend stagnating at an average of around £18 million ($24.9 million) for the 2021 financial year. This is despite the fact that 79% reported having suffered a major cyber incident. Of this group, the majority (73%) had experienced an incident in the past three years. 

 

Over half (54%) of organisations either ‘hit pause’ or decreased their cyber budgets during the pandemic. Now, IT leaders expect to increase their cyber budget by an average of 7.4% in the next twelve months, taking the average budget to £19.4 million. But taking into account inflation, which is currently 3%, this still may not be enough to make up for lost time during the pandemic. If this trend continues, a cyber spending ‘deficit’ will emerge that makes businesses more vulnerable to cyber incidents, as attacks become more frequent and more sophisticated.  

 

The problem is compounded by a lack of confidence among decision makers in how they spend their cyber budgets: 

40% said their organisation needed a better understanding of how to prioritise areas for cyber investment.  

Half (50%) reported they had a cyber strategy but had not been able to fully implement it – meaning that cyber investments are not realising their full potential.  

 

“Businesses need to act now to lock in their cyber spending for next year,” said Jamie Smith, Head of Cyber Security at S-RM. “The readiness with which we saw businesses pull back their budgets during the pandemic is concerning. Next year’s cyber budgets cannot be futureproofed against all forms of disruption, but there are trends business leaders should watch closely. A major one is the rising cost of cyber insurance - premiums are going up. This is because cyberattacks are becoming more frequent. What’s more, insurers are looking to reduce the risk they take on when they provide cyber policies. As a result, insurers want companies to prove how cyber resilient they are before providing cover.” 

 

“UK cyber budgets shrunk at a time when the cost of cybercrime and frequency of attacks is increasing at an alarming rate. The average immediate damage of a cyber incident is in the region of £1.3 million. But the secondary costs like higher insurance premiums and recovery services can more than double this.”  

 

“Businesses have been failing to keep pace, and if they don’t commit to strategic investment in their cyber security, they risk serious financial and reputational damage.” 

 

The analysis, developed by S-RM, will guide UK organisations who are looking to utilise their cyber spend more effectively. It also found a clear correlation in the data which suggests that cyber confidence comes from the top. Businesses with boards who had a highly proactive approach to cyber security were more likely to say they are investing cyber budget in all the right places (73%) compared to those who do not experience proactive support from the top (44%). 

 


Research shows ‘game needs to be changed,’ with security innovation years behind that of the attackers, the board a decade behind security discussions and regulation needing more industry input.
Node4 has released its Mid-Market IT Priorities Report 2021. The independent report reveals that the UK’s Mid-Market IT Leadership expects to see a shortfall in IT spend in 2022. While 52% of IT decision-makers believe their 2021 budget met the ambitions of their team, there seems to be less certainty and confidence about future finances — 61% think their budget will need to increase in 2022, but only 13% expect it to.
Atos has launched Atos OneCloud Sovereign Shield, a set of solutions, methodologies, and operational cloud services that is unique on the market, enabling clients across the world to meet the challenges of managing their data in the edge to cloud continuum, in line with the highest jurisdictional data governance requirements. Part of the Atos' OneCloud initiative, Atos OneCloud Sovereign Shield is a comprehensive edge to cloud platform ecosystem and highly secure service that improves the level of control clients have over the data they produce and exchange, helping them regain control and effectively deal with legal dependencies.
New distribution agreement set to bolster Westcon-Comstor’s Zero Trust offering in more markets across Europe with further expansion into APAC planned.
Research from Avast has found that employees in almost a third (31%) of Small and Medium Businesses (SMBs) in the UK are connecting to the corporate network using personal devices that do not have any security controls in place, according to IT Decision Makers (ITDMs) within SMBs.
This year, over half of MSPs or their end customers have been attacked by ransomware but only 53% offer backup services.
Trend Micro has published new research revealing that 90% of IT decision makers claim their business would be willing to compromise on cybersecurity in favor of digital transformation, productivity, or other goals. Additionally, 82% have felt pressured to downplay the severity of cyber risks to their board.
State of Industrial Cybersecurity report reveals only 21% of organizations achieved full maturity for ICS/OT cybersecurity and regularly inform the C-suite and board about OT cyber status.