One in five UK firms hide cyberattacks

A significant proportion of UK businesses, approximately one in five, have failed to disclose serious cyber incidents, potentially violating data protection laws, a Databarracks survey reveals.
Legal deadlines and hidden incidents
Under the UK GDPR and the Data Protection Act 2018, companies have 72 hours to notify regulators after becoming aware of a personal data breach. Databarracks surveyed 500 IT decision-makers and found that about 20% of UK firms would rather avoid the fallout of reporting an incident.
Charlie Maclean-Bristol, deputy resilience director at Databarracks, remarked: “It’s concerning to see how many cyber incidents are kept behind closed doors.” The study also notes that this secrecy hides the true extent of disruption caused by cyber attacks.
“Besides any legal implications, by not informing the police, NCSC or other relevant authorities, you may also be obscuring a wider attack on a sector or region,” he said. “Authorities cannot identify the pattern if incidents are not reported to them,” adding that concealing attacks can also damage trust.
Read Also: First Africans Gain Certified International Trade Credential
Rising ransomware and supplier risks
The survey tracks an increase in the number of firms suffering a ransomware attack in the past 12 months, rising from 22% to 25%. It also finds that 18% of UK firms surveyed do not have cyber insurance.
Even with the growing danger, 59 % of entities that faced ransomware in the previous 12 months were able to restore systems using backups and avoided paying the ransom, while 18 % complied with the demand. More than half, 57 %, report having a formal minimum viable company plan, and 56 % have exercised a ‘scorched-earth’ drill to prove they can function after a total IT collapse.
The data shows supplier resilience is becoming a bigger worry, with one out of four respondents saying a cyber event originated from a supplier or third-party. Yet nearly half, 48 %, of the firms continue to work with the same suppliers.
While 76% of firms say they are more resilient than they were 12 months ago, 65% admit a serious cyberattack could threaten their survival. Databarracks says confidence levels “likely exceed capability in many cases” as it reveals that 43% of organisations that are very confident in their response to a ransomware attack have tested their recovery in the past year.