04/12/2018 Cyber security – could do better says survey of Channel Islands businesses
Grant Thornton Limited logo - click for high-res version

'Cyber security – could do better' says survey of Channel Islands businesses

2018-11-14

November 14, 2018, Channel Islands. Press Dispensary. Fewer than half of Channel Island organisations are certain they haven’t been hacked in the last year, almost a third have no member of staff nominated to look after information security and nearly one in five have no plans to review their information security. These are some of the headlines revealed in the first cyber security survey of Channel Islands organisations, carried out by the CI independent accounting and consulting practice Grant Thornton Limited.

In an age when even the world’s largest tech companies, who live and die by their technical know-how, have had to admit to global breaches of confidential data, more than 2000 enterprises, offering a good representation of the islands’ business profile, were invited to take part in the survey. The results yielded concern and reassurance in roughly equal measure.

The report’s author and senior consultant in information security, David Cartwright, said: “Some of what we learned was pretty much as expected but there were real surprises. On the one hand, only 49% of respondents were certain they hadn’t been hacked in the previous 12 months, with another 26% saying they ‘don’t believe so’ – this could suggest over-confidence, given the difficulties of detecting many cyber attacks, and certainly implies a need for much more security testing, which really ought to be done at least once a year.

“But in contrast, over two-thirds provide information security training at least once a year to all staff, which is reassuring given the expectation by a similar number that a future breach was likely to be due to user error, with many also fearing problems from malware and dodgy file downloads. Only 13% feared malicious user behaviour.

“However, this leaves a fair number of organisations that really aren’t up to speed. 37% have no certification and don’t work to a security standard. 32% say they work to a standard but I’d suggest quite a few could find themselves short if they were actually to test that. And only 8% hold Cyber Essentials certification, despite it being inexpensive, straightforward … and mandatory for most UK government suppliers, with the States of Jersey to follow suit in 2020. Meanwhile, 31% of all respondents have nobody nominated to look after information security and 28% don’t give regular training.

“This means, overall, that a third – perhaps many more – of Channel Islands organisations are potentially more vulnerable than the rest to cyber attack and, frankly, are doing nothing about it.”

Grant Thornton’s head of marketing, David Spring, added: “When we started the survey this summer we didn’t know how well Channel Islands organisations might be faring. The results have shown the exercise to be extremely worthwhile. There is much to chew over and there are clear improvement recommendations for many businesses. Perhaps seeing these results might itself be a catalyst for many of them.”

The full report, Cyber Security Survey – Results, with detailed results, commentary and recommendations, may be downloaded from Grant Thornton at https://www.grantthorntonci.com/en/News-Centre/cyber-security/cyber-survey/

- ends -

Notes for editors
Grant Thornton Limited is a leading Channel Island practice with offices in Guernsey and Jersey with combined staffing strength of approximately 100 people. The practice is the Channel Island member of Grant Thornton International, one of the world's leading international organisations of independently owned and managed accounting and consulting firms. Grant Thornton International is not a worldwide partnership. Services are delivered independently by the member firms and as a member firm within Grant Thornton International, the practice has access to member and correspondent firms in over 130 countries, offering clients specialist local knowledge supported by international expertise and methodologies.

For further information please contact
David Spring, head of marketing
Grant Thornton Limited
Tel: 01684 592214
Email:
Site: www.grantthorntonci.com

LinkedIn: https://www.linkedin.com/groups/3747258/profile
Twitter: https://twitter.com/GrantThorntonCI
Facebook: https://www.facebook.com/GTCI.Recruitment/

Media contacts

David Spring, head of marketing
Tel: 01684 592214
Email:
Site: www.grantthorntonci.com

LinkedIn: https://www.linkedin.com/groups/3747258/profile
Twitter: https://twitter.com/GrantThorntonCI
Facebook: https://www.facebook.com/GTCI.Recruitment/

Keywords/tags
cyber security information security security training security testing penetration testing Cyber Essentials certification Grant Thornton David Cartwright David Spring

Permalink: http://bit.ly/GTCI-CyberReport

Images for download
Click on any image to view or download in higher resolution.