Их Британийн бизнесүүдийн кибер аюулгүй байдлын ур чадвар хангалтгүй байна

Published:

Энэхүү мэдээ, нийтлэлийг хиймэл оюун боловсруулав.

Засгийн газрын тайлангаар тус улсын компаниудын 57 хувь нь кибер аюулгүй байдлын үндсэн даалгавруудыг гүйцэтгэхэд бэрхшээлтэй тулгарч байгааг тогтоожээ

Их Британийн Засгийн газраас явуулсан жил тутмын судалгаагаар тус улсын бизнесүүдийн 57 хувь нь кибер аюулгүй байдлын наад захын ур чадварын дутагдалтай байгааг илрүүлэв. Энэ нь өмнөх жилийн 49 хувьтай харьцуулахад өссөн үзүүлэлт бөгөөд ойролцоогоор 808 мянган бизнес өгөгдөл хадгалах, галт хана (firewall) тохируулах, хортой программ илрүүлэх зэрэг үндсэн есөн үүрэг даалгаврыг гүйцэтгэхэд итгэлгүй байгаагаа илэрхийлжээ. Судлаачид энэхүү өсөлтийг байгууллагуудын аюулгүй байдлын талаарх мэдлэг дээшилсэнтэй холбоотой байж болзошгүй гэж үзэж байна.

Хортой программ хангамжийг илрүүлэх, устгах ажиллагаа нь хамгийн том ур чадварын дутагдалтай салбар болон гарч ирсэн бөгөөд судалгаанд оролцсон бизнесүүдийн 38 хувь, буяны байгууллагуудын 47 хувь нь уг ажлыг гүйцэтгэх чадваргүй гэж хариулжээ. Bridewell компанийн гүйцэтгэх захирал Сэм Торнтоны тайлбарласнаар, жижиг байгууллагуудад кибер аюулгүй байдлын үүрэг нь үндсэн ажлын зөвхөн нэг хэсэг болдог тул хиймэл оюун ухаанаар дэмжүүлсэн халдлагад өртөх эрсдэл өндөр байна.

NCC Group-ийн мэргэжилтэн Мэтт Халл үүлэн тооцоолол болон SaaS платформуудын хэрэглээ нэмэгдэж, мэдээллийн технологийн орчин улам бүр төвөгтэй болж байгааг онцлов. Тэрээр байгууллагууд шинэ технологийн шинэчлэлд анхаарахаас илүүтэйгээр кибер аюулгүй байдлын суурь зарчмуудыг мөрдөх нь чухал гэдгийг санууллаа.

Засгийн газраас 210 сая фунт стерлингийн өртөг бүхий Кибер үйл ажиллагааны төлөвлөгөөг баталж, төрийн байгууллагуудын аюулгүй байдлыг чангатгах арга хэмжээ авч байна. Хэдийгээр Кибер аюулгүй байдал ба тэсвэрлэх чадварын тухай хуулийн төсөл хэлэлцэгдэж байгаа ч мэргэжилтнүүд зөвхөн дүрэм журам чангатгах нь жижиг бизнесүүдэд практик дэмжлэггүйгээр үр дүн авчрахгүй гэж үзэж байна.

Дэлгэрэнгүйг эх сурвалжаас харах

↓Эх сурвалжийг нээх ↓

More than half of UK businesses lack confidence in their ability to perform at least one basic cybersecurity task, according to the government’s latest skills survey. The annual research found 57 percent of businesses reported a basic technical skills gap, up from 49 percent last year despite tighter national standards and repeated government warnings about cyber resilience. That equates to approximately 808,000 businesses whose cybersecurity leads were not confident in carrying out at least one of nine tasks, including storing data securely, configuring firewalls, and detecting and removing malware. The equivalent estimate last year was 699,000 businesses. The researchers cautioned that the increase might reflect greater awareness of organizations’ security posture rather than an actual deterioration in their capabilities. Interviews suggested that recent high-profile breaches had prompted executives and boards to scrutinize cybersecurity more closely. Detecting and removing malware produced the largest reported skills gap: 38 percent of businesses, 47 percent of charities, and 23 percent of public sector organizations lacked confidence in performing the task. The public sector reported fewer problems than businesses and charities across all nine basic skills measured. Sam Thornton, COO at cybersecurity consultancy Bridewell, said the figures reflected the position of smaller businesses and charities, where cybersecurity is often “just one part of someone’s wider role rather than a dedicated job.” “Malware is evolving quickly, and AI is increasingly helping attackers produce faster variants which are harder to spot,” he told The Register. “Keeping pace requires constant attention, which may be harder when the person responsible for security is also handling several other roles. “This could mean that personnel lean on greater use of AI tooling to support cyber defences, which in turn could induce further exposure to the organization where sufficient skill levels are needed to understand and interpret the output of such AI models.” Matt Hull, veep of cyber intelligence and response at NCC Group, said limited resources were compounded by increasingly complex IT environments. “Businesses increasingly rely on cloud infrastructure, SaaS platforms, APIs, third parties and growing numbers of human and machine identities,” he said. “These environments can change rapidly, making it much harder to apply security fundamentals consistently across the organization.” Hull said the industry also has “a habit of chasing the latest shiny update,” when in reality most problems arise when organizations overlook the fundamentals. “It’s a bit like looking after your car. You can spend a fortune on the latest safety features and a brilliant sound system, but none of that helps much if your tyres are bald or you can’t see through the windscreen.” Other reported gaps included storing and transferring personal data securely, restricting which software could run, configuring firewalls, selecting secure device settings, enabling automatic updates, and creating user accounts securely. Charities reported the widest skills gap on most measures, although businesses were less confident about storing and transferring personal data securely. Although the public sector scored better than businesses and charities in this survey, its overall basic skills gap nearly doubled from 14 percent last year to 27 percent. That comes despite repeated warnings about weaknesses in government systems. In 2025, the National Audit Office found “significant” gaps and immature controls across most critical systems it examined. Incidents affecting the Legal Aid Agency, Foreign Office, British Library, and NHS supplier Synnovis have provided ample demonstrations of the potential consequences. Among the government’s responses is the £210 million Cyber Action Plan, announced at the start of the year to strengthen central government systems and introduce mandatory security requirements. Operators of critical services can use the NCSC’s Cyber Assessment Framework to assess their resilience, while smaller organizations can seek Cyber Essentials certification as a baseline. The Cyber Security and Resilience Bill, now making its way through the Lords, would impose additional requirements on operators of essential services and their suppliers. The bill is intended to replace the NIS Regulations 2018 but excludes central and local government. The UK government believes the Cyber Action Plan essentially holds the public sector to the same standard as those in scope of the new bill, but does so without any legal obligations. Thornton argued that tighter regulation was unlikely to close the skills gaps among small businesses and charities without practical support tailored to their limited resources. “When more than half of UK businesses lack confidence in the basics, and nearly half of those responsible for security don’t feel equipped to handle an attack, we have an economy that is both easier to breach and slower to recover,” he said. “A growing skills gap at the bottom of the supply chain weakens the UK’s resilience as a whole. Tighter regulation will help protect critical infrastructure, but it’s unlikely to improve the skills in smaller businesses and charities. “Closing the gap will need affordable, practical support for smaller organisations, whether through managed services, simpler tools or incentives from insurers, so that good baseline security becomes the default rather than something only larger firms can afford.” ®

Та юу гэж бодож байна?

Сэтгэгдлээ оруулна уу!
Please enter your name here

MFC.mn сайтад сэтгэгдэл оруулахад анхаарах зүйлс

Холбоотой

spot_img

Шинэ

spot_img