
Paulo Rodriguez at Vanta examines the reasons for security compliance failures in the UK and describes the impacts of AI on trust management
UK businesses are navigating an unprecedented security landscape. So much so that in January, the UK government called for cyber-security issues to become a key focus for businesses in 2024, launching a new code of practice for cyber-governance to ensure businesses and organisations have the tools and support to protect themselves against cyber-threats.
The urgency of this matter is clear. Vanta’s State of Trust Report, revealed that two-thirds of UK business leaders believe that they need to improve their organisation’s security levels. In addition, the UK’s official Cyber Security Breaches Survey uncovered that 39 percent of UK businesses had faced a cyber-attack last year, demonstrating that the risks of poor security are not overhyped.
However, there’s a real disconnect between the widely understood risks, best practices and technical solutions, and the actions that businesses are compelled to take in light of the economic situation.
Vanta’s State of Trust Report found that 62 percent of business leaders have already reduced their IT budgets or are planning to, while 21 percent have reduced their IT staffing levels. Nearly half (45%) of UK leaders have deprioritized compliance due to the time it takes, and 40 percent said the same due to the investment it demanded.
Respondents also shared that they allocated nine percent of their overall IT budget towards security and compliance activity while 33 percent reported that these security budgets were shrinking due to an adverse economy.
But given the levels of cyber-security risk reported in the government’s data, this may not prove to be worth the savings. Those official UK figures show that the average cost of a cyber-attack for a medium to large business is almost £20,000, with regulatory penalties such as GDPR into the millions.
If the cost of failing to comply with security regulation was not enough to jolt UK businesses into action around compliance, data now highlights the influence of compliance status on customers’ purchasing decisions.
A majority (67%) of UK leaders stated that customers and other stakeholders are increasingly demanding proof of security and compliance. Of the businesses surveyed, 68 percent said having this proof strengthens customer trust and thus improves the position of the business.
Alongside budget cuts and compliance time drains, a third (33%) of UK businesses say they are failing to prove and demonstrate their security externally due to a lack of staffing, while 30% cite a lack of automation to replace manual, time consuming processes.
It’s harder to be forward-thinking without a good handle on compliance and risk levels. Less than half (42%) believe their risk visibility is strong and one in four UK leaders say their security and compliance strategy is reactive. In their current position, many UK companies are waiting for security and compliance issues to land on their plate - rather be ready and prepared.
‘Fail to prepare or prepare to fail’ could not be more apt than for businesses’ security posture - yet so many businesses continued to find themselves in this situation last year.
AI and other automation solutions are clearly seen as the solution to breaking down these barriers to stronger security and compliance. An overwhelming majority, 83 percent of UK leaders, have or will increase their use of AI and automation to reduce manual work.
Becoming compliant and then maintaining and proving it has traditionally been a piecemeal, painstaking set of manual processes. But new uses of AI are changing this from a required ‘grudge’ activity to an enabler of trusted supplier status and new sales.
Trust management is the solution category offering a holistic approach to defining, managing, maturing, and proving security and compliance to customers and other parties. A trust management platform provides a single source of truth for centralising and accelerating these efforts.
Powered by AI, trust management platforms enable unified security programme management, automated compliance, and streamlined security reviews. This removes hours of weekly burden from staff - 7.5 hours on security compliance each week in the UK alone, totalling over working nine weeks per year. This time is spent managing programmes, hunting for data, taking screenshots, filling in questionnaires, navigating between security tools, and navigating detail-oriented compliance workflows.
UK businesses feel the biggest potential for AI-powered trust management lies in improving the accuracy of security questionnaire responses, eliminating manual work, streamlining vendor risk reviews and onboarding, and reducing the need for large teams.
Even better, getting trust management right allows businesses of all sizes to move from point-in-time assessments of their risks to real-time visibility of security posture, increasing efficiency, reducing risk, and continuously demonstrating trust to stakeholders.
The combination of rising economic friction and shrinking resources will continue to necessitate a balancing act in 2024.
Automation, driven by AI, reduces the manual work of security and compliance tasks and saves businesses time and money. It also enables organisations to build greater trust by proactively demonstrating a strong security posture.
That’s when security and compliance, traditionally the last obstacle to hurdle in the sales process, become a marketable advantage by unlocking customer deals and growth.
Paulo Rodriguez is Head of International at Vanta
Main image courtesy of iStpckPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543