New research by Commvault, in collaboration with research firm GigaOm, has found that the UK experiences a higher rate of critical cyber incidents than any other country. A cyber incident can be defined as an event or series of events that negatively affects the security of data systems or digital information within an organization, including a security breach or ransomware attack.
Only 7% of the UK businesses surveyed report never having experienced a business-critical incident, compared to 14% across the rest of the world. This means that 93% of surveyed UK businesses have experienced a business-critical incident, of which 57% occurred in the past 18 months.
As well as experiencing more frequent major incidents than the global average, UK organizations are falling behind when it comes to their readiness to react and recover from cyberattacks. According to the research, they are 21% less likely to have deployed a dedicated recovery environment, and 11% less likely to have tested their recovery plans within the last month compared to the other countries – two aspects of a recovery plan that are widely considered fundamental.
The survey also highlights key findings tied to the minimum viable company (MVC) concept. This concept outlines the core operations necessary to resume business quickly after a cyberattack. In an age where cybercriminals are increasingly sophisticated, infiltrating backups with malware or planting dormant ransomware that activates after restoration, this approach is fundamental to operating in a state of continuous business.
Survey respondents stated that the biggest challenge preventing UK businesses from achieving minimum viability is the complexity of existing systems and applications (52%), followed closely by the struggle to keep recovery plans in line with changing business needs (47%).
Almost a third (30%) cited difficulties separating ‘core’ systems from less business-critical, ‘broader’ operations as another primary barrier to implementing the MVC concept.
However, nearly two-thirds of UK businesses have laid some foundational steps in their efforts to be resilient against attacks, with 65% having an inventory of business-critical systems and dependencies, and 61% creating defined runbooks, roles, and processes for incident responses. This is ahead of the global averages of 50% and 41%, respectively. This suggests that while UK businesses are investing time and resources into incident response preparations, that is not translating into real-world recovery readiness.
Many of these cyber readiness practices are directly relevant to establishing what’s needed to adopt an MVC approach. Yet only 36% of UK organizations strongly believe that they should prioritise the minimum viability approach.






