Verder naar navigatie Doorgaan naar hoofdinhoud Ga naar de voettekst

News reaction: UK businesses struggle with basic cyber security skills

30 september 2026

A new UK Government report has revealed a rise in businesses reporting basic cyber security skills gaps, increasing from 49% last year to 57% in 2026.

 

Matt Hull, VP of Cyber Intelligence and Response at NCC Group, commented: 

 

“The increase in UK businesses reporting basic cyber security failures is concerning because these aren’t particularly jazzy corners of cyber security. We’re talking about secure configuration, protecting data, managing identities, patching systems and detecting malware. We often call these the ‘basics’, but basic shouldn't be confused with easy.

“One reason these figures are getting worse is that the environments organisations need to secure have become much more complex. Businesses increasingly rely on cloud infrastructure, SaaS platforms, APIs, third parties and growing numbers of human and machine identities. These environments can change rapidly, making it much harder to apply security fundamentals consistently across the organisation.

“There’s also a skills and capacity issue. Knowing what good looks like is one thing; having enough people with the right skills, time and resources to make it happen across a complex organisation is another challenge altogether.

“As we see in incident response work and public reporting, most successful attacks still don’t require an extraordinary new tactic or technique. They often start with an everyday opportunity: an exposed internet-facing system, stolen credentials, weak identity controls, configuration drift or a temporary exception that quietly becomes permanent.

“The cyber security industry also has a habit of chasing the latest shiny update at the expense of the fundamentals. Whether it's nation-state threats, zero-days, AI or the sheer volume of new vulnerabilities, organisations need to understand these threats, plan for them and be ready to respond.

“But the problem comes when the shiny thing comes at the expense of the fundamentals. These aren’t competing priorities. Organisations need to tackle emerging threats while still getting the basics right: knowing what they have, keeping it securely configured, managing identities, patching where possible, protecting data and practising for when things inevitably go wrong.

“It’s a bit like looking after your car. You can spend a fortune on the latest safety features and a brilliant sound system, but none of that helps much if your tyres are bald or you can’t see through the windscreen.

“AI is a good example as it can help attackers find weaknesses faster, try more approaches and target more organisations at scale. That makes getting the fundamentals right more important, not less.

“For UK cyber resilience, that’s where I think the focus needs to be. Organisations have limited control over an attacker’s motivation or capability, but considerably more influence over the opportunities available to them. That means sustained investment in asset management, identity, secure configuration, vulnerability management and resilience, rather than continually shifting attention and budgets to the latest threat or shiny new object.

“Ultimately, the fundamentals of cyber security may not be very sexy, but quite frankly, attackers don’t care whether a weakness is interesting or exciting. They only care that it works and gets them in.”

 

Matt Hull biography 

Matt Hull is Vice President of Cyber Intelligence and Response at NCC Group, leading the global Cyber Response and Intelligence (CRI) capability.  

A former Detective Constable specialising in cybercrime, Matt brings deep operational experience across investigation, response, and intelligence-led operations. He leads multidisciplinary teams supporting organisations through complex incidents, advanced threat activity, and the development of mature detection and response capabilities.

Matt is recognised across the industry for his authenticity and clear communication, speaking at major conferences and featuring in media including BBC News, the Financial Times and Channel 4’s Hunted. He also serves as Chair of the Threat Intelligence Focus Group and sits on the CREST International Council.