Image Generated by AI

Forty-two per cent of UK CISOs still have no cyber resilience strategy as Cyber Security and Resilience Bill clears second reading

Forty-two per cent of UK chief information security officers say they have not yet implemented a cyber resilience strategy, even as the UK Government’s Cyber Security and Resilience (Network and Information Systems) Bill moves through committee stage in Parliament, according to new research from Absolute Security published on 21 May.

Facebook
LinkedIn
X

Subscribe to our Daily Newsletter

Why? Free to subscribe, no paywall, daily business news digest.

Forty-two per cent of UK chief information security officers say they have not yet implemented a cyber resilience strategy, even as the UK Government’s Cyber Security and Resilience (Network and Information Systems) Bill moves through committee stage in Parliament, according to new research from Absolute Security published on 21 May.

The study, based on a survey of 250 UK-based CISOs and billed by Absolute as the industry’s first dedicated look at the state of cyber resilience in UK enterprises, also finds that 41% of organisations have not yet prioritised resilience above traditional prevention, detection and response. The contrast between those two figures and the regulatory direction of travel is the headline finding the vendor is pushing — and it lands as the Bill, which had its second reading on 6 January 2026 and is now in committee, prepares to extend NIS regulatory scope across more digital and managed service providers.

What the Bill changes for Scottish CISOs

The Cyber Security and Resilience Bill was introduced to Parliament on 12 November 2025 following the policy statement DSIT published in April 2025. It updates the existing Network and Information Systems regime and, on current drafting, brings managed service providers and additional data infrastructure into scope. It also gives the Secretary of State new powers to direct regulators and regulated entities where national security requires it.

For Scottish operators of essential services — energy, water, healthcare, transport, and the digital service providers that underpin them — the practical effect is the same uplift in expectations on incident reporting, recovery planning and supply chain assurance that will apply UK-wide. The Bill does not contain a Scotland-specific carve-out, so Scottish CISOs running critical national infrastructure or large managed services will face the same baseline.

That makes Absolute’s 42% figure worth attention. If accurate at the population level — and it is a vendor-commissioned survey of 250 respondents, which is a caveat to hold throughout — it means roughly four in every ten boards facing the new regulatory bar do not yet have the resilience plan the Bill is intended to require.

Cost, downtime and the NCSC threat picture

Absolute reports that UK organisations are losing approximately $2.5 million per cyber incident on average, with most experiencing around five days of downtime, and 21% reporting operational disruption lasting up to two weeks. The vendor’s wider point — that resilience is now a board-level continuity issue rather than a technical IT concern — is reinforced by its finding that 63% of CISOs say their remit has expanded beyond security and risk to include leading their organisation’s recovery from incidents and software failures.

The Absolute release frames this against the National Cyber Security Centre’s threat data. Andy Ward, SVP International at Absolute Security, said in the release that “the NCSC highlighted that the UK are experiencing four ‘nationally significant’ cyberattacks per week” — a paraphrase of the NCSC’s Annual Review 2025 figure of 204 nationally significant incidents handled in 2024–25, more than double the 89 recorded the previous year. The “four per week” framing is Ward’s; NCSC’s published phrasing is the 204 / 89 comparison.

Ward described cyber resilience as “the ability to ensure defences are operating effectively and to quickly restore business operations following disruptive cyber incidents and software failures,” adding that “a high percentage have not yet taken steps to prioritise resilience at the same level as traditional prevention, detection and response.”

He concluded that with the rise of new frontier AI models, including Anthropic’s recently previewed Mythos system, cyberattacks should be treated as “a matter of when, not if,” and that “security teams require a far more resilient, proactive strategy where prevention alone is not enough.”

The Mythos line — and why it matters for Scottish security teams

The reference to Anthropic’s Mythos is the part of the Absolute release that has drawn external attention. Mythos is a frontier model Anthropic previewed in April 2026, and the World Economic Forum has separately argued that it marks an inflection point in how AI capabilities intersect with offensive cyber operations — accelerating vulnerability discovery and exploitation in ways that compress defender response cycles.

Absolute’s framing — that “most networks and endpoints are more vulnerable than previously imagined” in the face of capabilities like Mythos — is a sales argument for resilience-led platforms over prevention-only stacks. The underlying point, that AI-augmented attack tooling raises the floor on what counts as adequate defence, is the one most likely to land with Scottish CISOs working in critical national infrastructure adjacencies such as offshore energy, hydrogen, subsea cabling, and life sciences data estates.

What to take from this and what to discount

Three things are worth flagging for Silicon Scotland readers using the research in board papers or procurement discussions.

First, the survey is vendor-commissioned. Absolute sells the Cyber Resilience Platform; the research is positioned to support the case that prevention-centric strategies are no longer sufficient. The 250-CISO sample size is reasonable for a UK CISO survey but not large enough to support sub-sector or regional breakdowns, and Absolute has not published the underlying methodology in the press release.

Second, the Absolute release contains an internal inconsistency: it describes 42% of respondents as “1 in 4” in one passage and as “4 in 10” in others. The figure is 42% — closer to four in ten — and that is the number boards should use.

Third, the Bill is not yet law. It cleared its second reading on 6 January 2026 and remains in committee, with Royal Assent and the staged commencement of new duties still ahead. Scottish CISOs planning resilience investment have a runway, but the direction of travel is fixed.

The combination of the Bill’s progress, the NCSC’s threat figures and the emergence of frontier AI capabilities like Mythos points in one direction. For Scottish technology leaders, the gap between the resilience posture Absolute has measured and the bar the new regulatory regime is moving towards is now the relevant planning horizon — not whether to invest, but how fast.

Facebook
LinkedIn
X

Related Stories from Silicon Scotland

Other Stories from Silicon Scotland