March in Review: Three Problems, One Root Cause
Three stories dominated cybersecurity in March. The DSIT breach survey, the ongoing talent shortage, and another wave of framework-compliant organisations posting avoidable incidents. They look unrelated. They are the same story.
1. The breach numbers keep repeating
The UK government's Cyber Security Breaches Survey again put the figure at roughly half of all businesses. The headline has not moved meaningfully in three years. That is not a technology problem. The tooling market has never been better resourced. It is an architecture problem.
2. The talent gap is a capability gap
Open roles are a symptom. The deeper issue is that the skills most organisations are hiring for, SOC analysts and control implementers, are not the skills that would have stopped the incidents. The shortage sits at the intersection of commercial judgement, regulatory fluency, and technical depth. That profile is scarce because most career paths don't produce it.
3. Frameworks without operating models
ISO 27001, SOC 2, Cyber Essentials Plus are all excellent. None of them stop a breach on their own. Organisations that treat certification as the finish line consistently get hit. Organisations that treat it as the baseline and build live operating rhythm around it consistently don't.
The root cause
Security, compliance, and talent are run as three separate budgets, reporting to three different executives, measured on three different outcomes. Until they are treated as one commercial capability, with one owner, one scorecard, and one board narrative, the cycle repeats.
The organisations breaking the pattern are the ones that stopped asking "are we compliant?" and started asking "are we defensible?" The second question is harder. It is also the one that moves the breach number.
Where does this sit on your own risk register?
A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.
Start the Conversation →