根据政府最新的技能调查,超过一半的英国企业对自己执行至少一项基本网络安全任务的能力缺乏信心。
More than half of UK businesses lack confidence in their ability to perform at least one basic cybersecurity task, according to the government's latest skills survey.
年度研究发现,57%的企业报告存在基本技术技能缺口,高于去年的49%,尽管国家标准更加严格,政府也多次就网络韧性发出警告。
The annual research found 57 percent of businesses reported a basic technical skills gap, up from 49 percent last year despite tighter national standards and repeated government warnings about cyber resilience.
这相当于约80.8万家企业,其网络安全负责人对执行九项任务中的至少一项不够自信,这些任务包括安全存储数据、配置防火墙、检测和清除恶意软件。去年的同类估算为69.9万家企业。
That equates to approximately 808,000 businesses whose cybersecurity leads were not confident in carrying out at least one of nine tasks, including storing data securely, configuring firewalls, and detecting and removing malware. The equivalent estimate last year was 699,000 businesses.
研究人员警告说,这一增长可能反映了组织对自身安全状况的认知提高,而非其实际能力的下降。
The researchers cautioned that the increase might reflect greater awareness of organizations' security posture rather than an actual deterioration in their capabilities.
访谈表明,近期发生的高调数据泄露事件促使高管和董事会更仔细地审视网络安全。
Interviews suggested that recent high-profile breaches had prompted executives and boards to scrutinize cybersecurity more closely.
检测和清除恶意软件呈现出最大的技能缺口:38%的企业、47%的慈善机构和23%的公共部门组织对执行该任务缺乏信心。
Detecting and removing malware produced the largest reported skills gap: 38 percent of businesses, 47 percent of charities, and 23 percent of public sector organizations lacked confidence in performing the task.
在所有九项被测量的基本技能中,公共部门报告的问题比企业和慈善机构都少。
The public sector reported fewer problems than businesses and charities across all nine basic skills measured.
网络安全咨询公司Bridewell的首席运营官Sam Thornton表示,这些数据反映了中小企业和慈善机构的现状,在这些组织中,网络安全往往"只是某人更广泛职责的一部分,而非专职工作。""恶意软件演变迅速,AI正日益帮助攻击者生产更难被发现的变种,"他告诉The。"跟上步伐需要持续关注,而当安全负责人同时还要处理其他多个角色时,这可能更难做到。"
Sam Thornton, COO at cybersecurity consultancy Bridewell, said the figures reflected the position of smaller businesses and charities, where cybersecurity is often "just one part of someone's wider role rather than a dedicated job." "Malware is evolving quickly, and AI is increasingly helping attackers produce faster variants which are harder to spot," he told The. "Keeping pace requires constant attention, which may be harder when the person responsible for security is also handling several other roles.
这可能意味着人员更多地依赖 AI 工具来支持网络防御,而这反过来又可能使组织面临更大的风险,因为需要足够的技能水平来理解和解读此类 AI 模型的输出。NCC Group 网络情报与响应副总裁 Matt Hull 表示,有限的资源因日益复杂的 IT 环境而雪上加霜。
"This could mean that personnel lean on greater use of AI tooling to support cyber defences, which in turn could induce further exposure to the organization where sufficient skill levels are needed to understand and interpret the output of such AI models." Matt Hull, veep of cyber intelligence and response at NCC Group, said limited resources were compounded by increasingly complex IT environments.
他说:“企业越来越依赖云基础设施、SaaS 平台、API、第三方以及不断增长的人类和机器身份。这些环境变化迅速,导致在整个组织中一致地应用安全基础变得更加困难。”
"Businesses increasingly rely on cloud infrastructure, SaaS platforms, APIs, third parties and growing numbers of human and machine identities," he said. "These environments can change rapidly, making it much harder to apply security fundamentals consistently across the organization."
Hull 表示,该行业还“习惯于追逐最新的炫酷更新”,而现实中大多数问题源于组织忽视了基础。“这有点像保养汽车。你可以在最新的安全功能和出色的音响系统上花大钱,但如果轮胎光秃秃的,或者挡风玻璃看不清,这些都没多大用处。”
Hull said the industry also has "a habit of chasing the latest shiny update," when in reality most problems arise when organizations overlook the fundamentals. "It's a bit like looking after your car. You can spend a fortune on the latest safety features and a brilliant sound system, but none of that helps much if your tyres are bald or you can't see through the windscreen."
其他报告的差距还包括:安全地存储和传输个人数据、限制可运行的软件、配置防火墙、选择安全的设备设置、启用自动更新以及安全地创建用户账户。
Other reported gaps included storing and transferring personal data securely, restricting which software could run, configuring firewalls, selecting secure device settings, enabling automatic updates, and creating user accounts securely.
在大多数衡量指标上,慈善机构报告的技能差距最宽,尽管企业在安全存储和传输个人数据方面的信心较低。尽管公共部门在本次调查中的得分优于企业和慈善机构,但其整体基础技能差距较去年的 14% 近乎翻倍,达到 27%。这尽管已有关于政府系统弱点的反复警告。2025 年,国家审计署发现,在其审查的大多数关键系统中存在“重大”差距和不成熟的控制措施。影响法律援助署、外交部、大英图书馆以及 NHS 供应商 Synnovis 的事件,充分展示了潜在后果。
Charities reported the widest skills gap on most measures, although businesses were less confident about storing and transferring personal data securely. Although the public sector scored better than businesses and charities in this survey, its overall basic skills gap nearly doubled from 14 percent last year to 27 percent. That comes despite repeated warnings about weaknesses in government systems. In 2025, the National Audit Office found "significant" gaps and immature controls across most critical systems it examined. Incidents affecting the Legal Aid Agency, Foreign Office, British Library, and NHS supplier Synnovis have provided ample demonstrations of the potential consequences.
政府的应对措施包括一项耗资2.1亿英镑的“网络行动计划”(Cyber Action Plan),该计划于年初宣布,旨在加强中央政府的系统安全,并推行强制性的安全要求。提供关键服务的机构可以使用英国国家网络安全中心(NCSC)制定的“网络评估框架”(Cyber Assessment Framework)来评估自身的安全韧性;而规模较小的组织则可以选择获得“网络安全基本要求认证”(Cyber Essentials Certification)作为安全保障的最低标准。
Among the government's responses is the £210 million Cyber Action Plan, announced at the start of the year to strengthen central government systems and introduce mandatory security requirements. Operators of critical services can use the NCSC's Cyber Assessment Framework to assess their resilience, while smaller organizations can seek Cyber Essentials certification as a baseline. The Cyber Security and Resilience Bill, now making its way through the Lords, would impose additional requirements on operators of essential services and their suppliers.
目前,这项名为《网络安全与韧性法案》(Cyber Security and Resilience Bill)正在上议院审议中,该法案将对提供关键服务的机构及其供应商提出更严格的安全要求。该法案旨在取代现有的《NIS条例》(NIS Regulations 2018),但并不适用于中央政府和地方政府。英国政府认为,“网络行动计划”实际上已经将公共部门的安全标准提升到了与新法案相同的高度,不过这种提升并不附带任何法律约束力。
The bill is intended to replace the NIS Regulations 2018 but excludes central and local government. The UK government believes the Cyber Action Plan essentially holds the public sector to the same standard as those in scope of the new bill, but does so without any legal obligations. Thornton argued that tighter regulation was unlikely to close the skills gaps among small businesses and charities without practical support tailored to their limited resources.
桑顿(Thornton)指出,如果没有针对小型企业和慈善机构的具体支持措施(尤其是考虑到它们资源有限的情况),更严格的监管措施很难缩小这些机构在网络安全方面的能力差距。他说:“当超过一半的英国企业对自身的网络安全基础缺乏信心,且近一半负责安全工作的相关人员觉得自己无法有效应对网络攻击时,整个经济体系就更容易受到攻击,同时也更难以快速恢复。供应链底层日益严重的技能缺口会削弱英国整体的安全韧性。虽然更严格的监管有助于保护关键基础设施,但它们不太可能改善小型企业和慈善机构的安全能力。要缩小这一差距,就需要为这些组织提供经济实惠且实用的支持措施——无论是通过托管服务、更简单的安全工具,还是保险公司的激励措施——从而使基本的安全标准成为所有企业的‘默认选择’,而不仅仅是大型企业才能负担得起的选项。”
"When more than half of UK businesses lack confidence in the basics, and nearly half of those responsible for security don't feel equipped to handle an attack, we have an economy that is both easier to breach and slower to recover," he said. "A growing skills gap at the bottom of the supply chain weakens the UK's resilience as a whole. Tighter regulation will help protect critical infrastructure, but it's unlikely to improve the skills in smaller businesses and charities. "Closing the gap will need affordable, practical support for smaller organisations, whether through managed services, simpler tools or incentives from insurers, so that good baseline security becomes the default rather than something only larger firms can afford." ®