UK Firms Struggle with Proposed 24-Hour Cyber Incident Reporting Deadline
Cisco's Relentless Defence Report has found that many UK organisations are not prepared to meet the proposed 24-hour cyber incident reporting deadline. The report, which surveyed 8,000 security professionals across 30 markets, shows that 64% of respondents could not update security controls within 24 hours of a new threat being identified.
Under the proposed legislation, organisations would have to notify regulators and the National Cyber Security Centre within 24 hours of a significant cyber incident, followed by a fuller report within 72 hours. The study suggests that AI is adding to the pressure on security teams while creating new concerns about governance and oversight.
The UK's top-performing group, dubbed Relentless Defenders, represents 12% of organisations in the country. These organisations were more likely to combine broad protection, faster response times, and closer coordination across teams. They also had stronger use of AI in operations, with a quarter reporting that AI had improved threat-detection speed by more than 100%.
Cisco's Chief Technology Officer, EMEA, Chintan Patel said 'Boards have stopped asking whether AI will deliver. They are asking whether their organisation is secure enough to use it.'