ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Cyber-hygiene and culture: declining from a low base

Steven Furnell at the University of Nottingham explains how organisations can facilitate a security-first mindset and encourage a cultural shift among staff

 

The establishment of cyber-hygiene and cyber-security culture should ideally be fundamental issues for modern organisations. However, the reality is that they appear to be increasingly aspirational targets.  

 

The latest UK Cyber Security Breaches Survey paints a worrying picture about some aspects of cyber-security and our direction of travel. The survey presents findings from businesses, charities, and educational institutions.  This article will draw specifically from the results relating to businesses, but further details on the other groups can be found by consulting the full survey. 

 

The first indicator of concern is the extent to which cyber-security was reported as a high priority for directors and other senior managers. This has generally increased over the years, from 69 percent 2016 to 82 percent by 2022.

 

However, in 2023 the proportion has dropped back to 71 percent, effectively wiping out the prior gains. A deeper inspection reveals that the drop is primarily driven by a decline among micro businesses, which account for just over 60 percent of the sample base. Here, the level of prioritisation has fallen from 80 percent to 68 percent in the space of a year, with reasons being linked to economic concerns in the current climate.

 

The effect of the drop is evident from wider results, and one of the significant points headlined in the 2023 report is the progressive decline in basic cyber-hygiene measures over the last three waves of the survey. The proportion of businesses reporting the use of password policies, network firewalls, restriction of admin rights, and the timely application of software security updates have all dropped by around 10 percent this time around. 

 

This change again proves to be more prominent in smaller organisations, with micro businesses the most affected and large businesses basically unchanged.

 

Although they are not massive drops, and most organisations are still taking most of the actions, declining cyber-hygiene nonetheless suggests that security is seen as something that can be sacrificed in tough times. This in turn potentially says something about the culture and mindset of the organisations, who are seemingly questioning whether they can afford security, when the real question ought to be whether they can afford not to.  

 

This link to mindset can be considered more widely.  Indeed, if we really want an indication of the extent to which businesses understand security, then it is relevant to examine how much they help their staff to do so.

 

However, the situation becomes even less positive when examining the proportion of businesses that report having had training or awareness-raising sessions on cyber-security in the past 12 months, with the overall total standing at a mere 18 percent. It’s notably better when only looking at large organisations, where 77 percent report doing so, but this still leaves a quarter of large businesses suggesting that they don’t.

 

Of course, they may do something less than annually, but this seems an unlikely basis for building a security culture amongst the staff.  

 

We may wonder whether businesses are light on training and awareness because they don’t need it and haven’t faced related incidents. While this is possible, it is rather unlikely, especially in view of the volume of incidents in which staff awareness and behaviour could be a factor in facilitating a breach. 

 

For example, by far the most prominent category of incidents continues to be phishing, reported by 79 percent of businesses. So, staff awareness will undoubtedly be relevant in whether these attempts succeed or not.  

 

Another notable indicator is what businesses find themselves doing when something goes wrong.  The survey suggests that the most prominent action in the wake of the most disruptive breaches is additional staff training or communications, reported by 19 percent of businesses that experienced an incident. This puts it in clear first place in the list of responses, and at least twice as prominent as technical responses such as software updates and configuration changes.

 

Given the relative lack of regular awareness and training, one cannot help wondering whether proactive efforts would have helped to prevent the disruptive breaches from occurring. 

 

We need to move the dial somehow, because this entire situation is essentially unchanged throughout the lifetime of these surveys, dating back to 2016. It’s also worth noting that even then, the results only signify that businesses have done something – it does not necessarily mean that this was good or effective. 

 

It is no secret that people-focused attacks and breaches occur. Our users can be both the target and the cause of incidents, and it very often has little to do with any negative intent on their side. Supporting them to play their part effectively ought to be a standard part of our efforts toward cyber-hygiene.

 

However, this doesn’t simply mean handing them a policy or dealing them some anodyne annual box-ticking to pass as training. We need to communicate with them in terms that they understand, and recognise that culture-building is not simply a top-down process of instruction.  At the same time, this requires a step change when regular training and awareness of any form is lacking in most of our businesses.

 

We have a long way to go, but awareness of our need to change is a useful first step.

 


 

Steven Furnell is a IEEE senior member and professor of cyber-security at the University of Nottingham 

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543