More than half of UK businesses are not confident doing at least one cyber security basic
Cyber Security

More than half of UK businesses are not confident doing at least one cyber security basic

The government's annual skills study puts the figure at 57 per cent, about 808,000 businesses, up from 49 per cent. Removing malware tops the list. The report itself suggests some of the rise is businesses looking harder at their own security.

29 September 20265 min read

The Department for Science, Innovation and Technology published Cyber security skills in the UK labour market 2026 on 29 September. The research, carried out by Ipsos and Perspective Economics, is the eighth in an annual series. Its headline for ordinary businesses is that 57 per cent had what it calls a basic technical skills gap, meaning the person responsible for cyber security was not confident carrying out at least one of nine basic tasks. That equates to approximately 808,000 UK businesses, up from 49 per cent, or about 699,000, in last year's study.

The nine tasks

The tasks combine the technical areas covered by the government-backed Cyber Essentials scheme with other basics. The share of businesses not confident in each was: detecting and removing malware, 38 per cent; storing or transferring personal data securely, 31 per cent; restricting the software that runs on their devices, 28 per cent; setting up configured firewalls, 26 per cent; choosing secure settings for devices or software, 15 per cent; setting up automatic updates, 11 per cent; setting up new user accounts and authentication securely, 10 per cent; controlling who has admin rights, 9 per cent; and creating backups, 7 per cent. The malware figure was 23 per cent in last year's study. The report says the gap was especially wide for small businesses and charities.

Worse, or just more aware?

The report is careful here. It says the change may be due to higher awareness of organisations' cyber security posture rather than a decline in what they can do, and that in interviews, cyber leads said recent high-profile breaches at well-known UK companies had put more attention on security in their organisations. The survey fieldwork ran from August to October 2025, so the figures describe last year.

Dealing with an attack

Incident response is measured separately. Almost half of the people responsible for cyber security in UK businesses, 47 per cent, lacked the confidence to deal with a breach or attack and had not outsourced that job. In large businesses the figure was 11 per cent. Overall, 35 per cent of businesses outsource at least one aspect of their cyber security, a figure the report says is consistent with previous years, and medium and large businesses are more likely to.

Commenting to The Register, Sam Thornton, COO at the consultancy Bridewell, said that in smaller businesses and charities security is often "just one part of someone's wider role rather than a dedicated job", and that closing the gap will need affordable, practical support, whether through managed services, simpler tools or incentives from insurers. Matt Hull of NCC Group told The Register that the industry has "a habit of chasing the latest shiny update" when most problems come from overlooking the fundamentals.

What this means for your business

Use the report's own list as a checklist. Sit down with whoever looks after IT, even if that is you, and go through the nine tasks one at a time: could you confidently do this today, and when was it last checked? Anything that gets a hesitant answer is your gap. Most of the list maps onto Cyber Essentials, so certification is a sensible way to work through it with a deadline. Then answer the incident question on paper: if a laptop was infected tomorrow morning, who would you call, and how would you know which accounts to lock? If that has no clear answer, it is worth fixing first. Helping businesses across Exeter and the South West work through exactly this list is part of what we do.

#WEARECOBALT

Ready when you are.

Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.