UK Firms Unprepared for 24-Hour Cyber Incident Reporting Deadline
Cisco has released research that suggests UK organisations are not prepared to meet the proposed 24-hour cyber incident reporting deadline. The Cyber Security and Resilience Bill is moving through Parliament, which would require organisations to notify regulators and the National Cyber Security Centre within 24 hours of a significant cyber incident.
The study found that 64% of respondents could not update security controls within 24 hours of a new threat being identified. In the UK, 91% of organisations suffered a material business-disrupting cyber incident in the past 12 months, and more than one in three involved an AI-enhanced attack.
AI is adding to the pressure on security teams while creating new concerns about governance and oversight. Nearly nine in ten UK organisations cited at least one significant AI-related security concern, with systems being compromised or manipulated by attackers as a leading concern.