CCI staff share recent surveys, reports and analysis on risk, compliance, governance, infosec and leadership issues. Share details of your survey with us: editor@corporatecomplianceinsights.com.
Just 1 in 10 UK organizations could meet proposed breach reporting standards
Only 10% of UK enterprises are confident they could meet cyber breach reporting deadlines proposed in a bill working its way through Parliament, according to a survey by VinciWorks.
The survey of 156 IT, compliance and security professionals found just one in 10 organizations were confident they could meet the Cyber Security and Resilience Bill’s 24-hour and 72-hour breach reporting deadlines, a duty that would fall on managed service providers and data centers.
The bill is in a House of Lords committee, and if it becomes law, in-scope organizations would be required to send an initial notification to their regulator within 24 hours of becoming aware of a reportable cyber incident followed by a full report in 72 hours.
Most organizations surveyed believe they could meet the deadlines, but that confidence hasn’t been tested yet. Almost two-fifths (38%) of compliance and security professionals said they would meet the 24-hour and 72-hour deadlines in theory, but had never actually tested the process. Just over a quarter (26%) said they weren’t sure if they could meet those reporting requirements, while 17% said they were working toward it. About 9% admitted they could not currently meet the deadlines.
“Cyber incidents rarely happen in office hours, on a good day, with everyone available,” Nick Henderson-Mayo, head of compliance at VinciWorks, said in a statement. “An escalation process that has never been tested under real pressure is only a guess about what will happen when an incident actually strikes.”
The survey also found that 68% of organizations said they were fairly to very concerned about cyber attacks disrupting business, and 51% reported staff must complete cybersecurity training once a year.
Vast majority of companies don’t assess all third parties
Nearly nine in 10 companies don’t look into every third party they work with in a time when not doing such examinations is the most perilous, according to a survey by security software provider Drata.
In a survey of 309 IT and security leaders and practitioners in the US, UK and Canada, 87% reported that they don’t assess all third parties, and staffing and tools play a big role.
More than three-quarters (78%) reported they have limited capacity to complete thorough assessments on all third parties. About half (49%) rated their ability to cover all third parties as less than good. That limited capacity comes as 85% reported that their companies experienced at least one third-party incident in the past 12 months, and 75% said their concern about third-party risks has increased over the past two years.
A large proportion of the third-party assessment issues for companies is a lack of people, with 59% citing insufficient staff as the greatest obstacle to effective third-party risk management (TPRM). The survey also revealed a contradiction. More than two-thirds (69%) expanded their third-party risk management teams but are still having trouble keeping up, while only 11% said they plan to add to their headcount in the next year, despite insufficient staffing ranking as the most significant barrier to examining risk with third parties.
Evidence highlights that more people and assessments help companies manage third-party risks. Of the companies that experienced six or more third-party incidents, 90% agreed that people or tool limits are constraining their assessments, compared to 60% that had no third-party incidents.











