Call us today

Cybersecurity failings are rife amongst UK SMEs

Get in touch today - call Kent on 01634 570 390 or Surrey on 01737 370 493

Book a FREE consultation

If you would like to get some impartial advice, simply book a free consultation and we'll get in touch with you as soon as we can.

Cybersecurity failings are rife amongst UK SMEs

UK-based SMEs are not doing enough to ensure the data they hold is secure, it has been reported.

Findings from a newly-published report show that more than two out of three SMEs considered that there was room for improvement in protecting their business data, while four out of 10 questioned said they did not have a cybersecurity policy in place.

The figures were published with just six months remaining until the General Data Protection Regulation (GDPR) comes into force in May 2018.

GDPR sets tough new standards for organisations’ data protection procedures, with steep penalties for those found to be non-compliant or guilty of a breach.

A key requirement of GDPR is that businesses which hold sensitive data on a large scale will need to appoint a data protection officer. At the moment, just 84 per cent of businesses questioned said they had a dedicated employee responsible for IT and cybersecurity.

Individuals will receive a number of new rights under the GDPR – which will also strengthen some of the existing rights offered under the Data Protection Act.

According to the Information Commissioner’s Office (ICO), once the new legislation takes effect, individuals will have the following rights:

  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • Rights in relation to automated decision making and profiling

Whilst many of the principles from the DPA will remain, the GDPR will bring with it several new concepts and approaches, which have been described as a “game changer for everyone”.

Businesses in particular will be adversely affected – as many will need to implement organisation-wide changes to ensure that any personal data is processed in compliance with the GDPR’s requirements.

One notable change is that companies that currently rely on ‘consent’ as a legal basis for processing personal data will need to assess the consents that they currently hold and the mechanisms through which such consents are provided in future. This is because ‘implied consent’ will no longer be deemed valid under the GDPR.

It is crucially important that businesses ensure they are fully compliant with the new regime, as enforcement powers will also increase under the GDPR – meaning that non-compliance may result in harsher ICO investigations than was previously the case.

The ICO has published full guidance to the GDPR on its website here.

Link: Overview of the GDPR

Link: UK SMEs are negligent – and complacent – when it comes to cybersecurity


Urgent COVID-19 Notice
Working From Home

Our first priority is the health and well-being of our team and our community. Therefore, with a heavy heart we have made the decision to temporarily work from home with immediate effect.

We are listening to the government’s daily updates, taking each day as it comes, and will reopen our offices as soon as it is safe to do so.

If you have any questions or need to discuss any issues at all please do email or call us on our usual number 01634 570 390.

The general email is

We hope everyone is keeping well and staying safe.

This website uses cookies to enhance your browsing experience... moregot it