Is Your Organisation Taking Information Security Seriously?

Date Posted: Friday, 7th August 2026

Ask most leadership teams whether information security matters and the answer will be yes. The more useful question is what happens next.

The UK Government's Cyber Security Breaches Survey 2025/2026 found that 72% of businesses considered cyber security a high priority for senior management. Yet only 31% had a board member with explicit responsibility for it. Just 30% had carried out a cyber security risk assessment in the previous 12 months, and only 25% had a formal incident response plan.

That gap matters. There is a real difference between believing information security is important and building an organisation that is genuinely prepared to manage the risk.

What does taking information security seriously actually mean?

An organisation takes information security seriously when cyber risk is treated as a business risk rather than an IT responsibility.

That does not mean eliminating every possible vulnerability. No organisation can remove cyber risk entirely, and trying to would quickly become impractical. As security professionals often point out, security ultimately has to serve the business. Leadership needs to decide what level of risk it is willing to accept, provided that decision is informed rather than accidental.

The National Cyber Security Centre (NCSC) takes a similar governance-led approach. Its Cyber Governance Code of Practice is built around five areas: risk management, strategy, people, incident planning and recovery, and assurance and oversight. Crucially, the guidance is aimed at boards and directors, not just security teams.

In practice, an organisation taking security seriously should be able to demonstrate:

  • clear accountability for cyber risk at senior level
  • an understanding of its most important systems, data and services
  • regular assessment of cyber threats and vulnerabilities
  • security investment linked to genuine business risks
  • appropriate technical controls and monitoring
  • trained employees rather than policies nobody follows
  • tested incident response and recovery plans
  • oversight of suppliers and third parties
  • enough security capability to operate all of the above effectively

The key word is demonstrate. A policy document or a security product is evidence that something has been purchased or written. It is not evidence that the organisation would respond effectively under pressure.

1. Someone senior actually owns the risk

One of the clearest indicators is accountability.

Who can ultimately make decisions about cyber security risk? Who can accept that risk, authorise investment, or challenge the organisation when known vulnerabilities remain unresolved? If the answer is simply "IT", responsibility probably isn't clear enough.

The Government's latest survey found that only 31% of UK businesses had a board member responsible for cyber security, a figure that rises considerably with business size, from 29% of micro businesses to 68% of large ones.

Board ownership doesn't mean directors need to become security engineers. It means they need enough understanding to challenge assumptions, evaluate risk and make informed decisions. The NCSC describes cyber risk as a principal business risk and says boards have a critical responsibility for governing it effectively.

2. Cyber risk is understood in business terms

A serious information security conversation shouldn't begin with the number of attacks blocked last month. It should start with the things the organisation cannot afford to lose, which might include:

  • customer or employee information
  • payment systems
  • intellectual property
  • manufacturing capability
  • operational platforms
  • customer-facing digital services
  • commercially sensitive information
  • access to critical suppliers
  • the ability to continue trading

Grant Thornton made a useful distinction in its original discussion of this issue: organisations cannot keep pace with every possible threat, so they need to identify what represents the greatest danger to the business and prioritise protection accordingly. That remains the better way to think about information security.

A cyber risk register listing dozens of technical vulnerabilities is useful to specialists. A board needs to understand what those vulnerabilities could actually mean for revenue, operations, customers, regulatory obligations and reputation.

3. Risk assessments happen before something goes wrong

There is a difference between fixing vulnerabilities and managing risk. A mature organisation understands its exposure before an incident forces the issue.

Yet only 30% of UK businesses reported conducting a cyber security risk assessment during the previous year, and penetration testing was even less common, at 13%. The appropriate level of testing naturally varies by organisation; a small professional-services firm doesn't need the same security programme as a multinational bank. What matters is whether the level of scrutiny matches the risk.

A serious organisation should know:

  • which systems and services are critical
  • where sensitive information sits
  • who has privileged access
  • which vulnerabilities represent material risk
  • which controls are in place
  • which weaknesses have deliberately been accepted, by whom, and when that decision will be reviewed

Security stops being serious the moment unresolved risks quietly disappear into a backlog.

4. Security exists outside the security team

People are routinely described as the "weakest link" in cyber security, but that description can be too simplistic. If employees haven't been trained properly, systems are difficult to use securely, or business processes push people to work around controls, the problem is organisational rather than individual.

This is another area where stated priority and actual practice diverge. Only 19% of UK businesses reported providing cyber security training or awareness activities in the previous 12 months, though the figure rises to 84% among large businesses.

A stronger security culture goes beyond an annual phishing test. Developers, finance teams, administrators, executives, customer-service staff and new starters don't necessarily need the same training, and the stronger organisations make secure behaviour part of normal operations rather than an annual compliance exercise.

5. The organisation has practised what happens after an attack

A security incident is a bad time to establish who has decision-making authority. Who shuts a critical system down? Who contacts customers, insurers or regulators? Which services need restoring first, and how does the business operate while systems are unavailable? Those questions need answers before the incident, not during it.

Only a quarter of UK businesses currently report having a formal cyber incident response plan. Among large organisations the figure is much stronger, at 76%, but that still doesn't tell us whether those plans have actually been rehearsed.

The NCSC recommends defined incident responsibilities, clear escalation processes and preparation for recovery as part of effective cyber governance. A plan stored somewhere on SharePoint is not resilience. The organisation needs to know whether it can actually use it.

6. Suppliers are treated as part of the security perimeter

Organisations increasingly rely on cloud platforms, software providers, consultancies and outsourced partners, which means somebody else's weakness can quickly become your problem.

Despite this, only 15% of UK businesses said they formally reviewed cyber risks from their immediate suppliers, and just 6% reviewed risks further into their supply chain. Even among large businesses, only 48% reviewed immediate suppliers and 24% considered the wider supply chain.

Taking information security seriously means understanding which third parties could materially affect your organisation. Useful questions include:

  • What information can the supplier access, and which systems can they connect to?
  • What happens if their service becomes unavailable?
  • What security standards do they follow, and when must they notify you of an incident?
  • Can you operate without them, and what happens to your information when the relationship ends?

Supplier security can't stop at a questionnaire completed during procurement.

7. The organisation has the capability to do what its policies promise

Security strategies don't implement themselves, which is where the people question becomes important.

The Government's UK cyber security labour-market research estimates that 49% of businesses have a basic technical cyber security skills gap, around 30% have an advanced technical skills gap, and 32% lack the confidence to deal with a cyber security incident without outsourcing that capability.

That distinction matters. The issue isn't simply whether the UK has enough people working in cyber security, a workforce the same research estimates at around 143,000. The harder question is whether each organisation has the right combination of skills, experience and authority for its particular risk profile. A business might need stronger:

  • security architecture
  • governance, risk and compliance capability
  • identity and access management
  • cloud security
  • vulnerability management
  • incident response and security operations
  • penetration testing
  • data protection and supplier assurance

Hiring more people without understanding the capability gap won't necessarily improve security.

8. Security leadership has authority, not just responsibility

There is a final difference between organisations that take security seriously and those that simply employ somebody with "security" in their title: authority.

A Head of Information Security or CISO can identify risks, recommend controls and build a strategy, but they cannot create organisational commitment on their own. Strong security leaders need access to senior decision-makers, clarity over their mandate, and the ability to challenge business decisions when the risk justifies it.

A CISO becomes particularly relevant where an organisation is facing:

  • increasing regulatory scrutiny
  • significant customer or investor expectations
  • complex technology or supplier environments
  • rapid cloud, digital or AI adoption
  • repeated security incidents or fragmented responsibility across teams
  • a need for clearer cyber governance
  • major transformation or acquisition activity

The best CISO isn't simply the most technical candidate available. The role increasingly requires someone who can translate complex security problems into decisions that executives can understand and act on. That's one reason senior information security hiring can be difficult: businesses sometimes search for technical breadth, regulatory knowledge, leadership, incident experience, commercial judgement and board communication in one person, without first deciding which problem they actually need that person to solve.

Need to strengthen your cyber security team? Explore TRIA's technology recruitment solutions.

Signs your organisation may not be taking security seriously

Individual weaknesses don't automatically indicate a poor security culture; priorities vary according to risk, size and resources. Patterns are more revealing. Warning signs include:

  • Security only becomes urgent after an incident. Known weaknesses remain unresolved until something goes wrong.
  • The board receives activity rather than risk information. Reports focus on blocked attacks and phishing statistics but can't explain business exposure.
  • Nobody can explain the organisation's risk appetite. Risks are being accepted by default rather than through conscious decisions.
  • The security team hears about technology decisions too late. New suppliers, platforms and systems are introduced before security implications are considered.
  • Temporary exceptions never expire. Vulnerabilities remain because a migration, upgrade or replacement is always coming "next quarter".
  • Compliance is treated as the objective. Passing an audit becomes more important than understanding whether controls genuinely work.
  • Incident response has never been tested. The first proper exercise will therefore be a real attack.
  • Responsibility sits with one overstretched individual. The organisation has technically filled the security role without building the capability around them.

The frustration behind these problems is visible in security communities too. Practitioners regularly describe raising the same vulnerability repeatedly, only to see it deferred because another upgrade or migration is supposedly around the corner. That's anecdotal rather than a measure of the wider market, but it illustrates exactly the organisational behaviour that stronger governance is designed to prevent.

A 10-question information security reality check

If you want to understand how seriously your organisation treats information security, start with ten questions:

  1. Which board member is accountable for cyber risk?
  2. When did we last conduct a meaningful cyber risk assessment?
  3. Which systems, services and information are genuinely business-critical?
  4. Which cyber risks are currently above our agreed risk appetite?
  5. Who has formally accepted unresolved security risks?
  6. When did we last test our incident response and recovery capability?
  7. How quickly could we restore our most important services?
  8. Which suppliers could materially disrupt us if they were compromised?
  9. Do we have the skills and leadership needed to manage our current exposure?
  10. What security decision does the board currently need to make?

If the organisation can't answer most of those questions confidently, buying another security product is unlikely to be the first problem worth solving. Governance probably is.

Information security is ultimately a leadership question

There will always be vulnerabilities. There will always be new technology, new attackers, and decisions where stronger security conflicts with cost, speed or convenience. Taking information security seriously isn't about refusing those trade-offs; it's about making them consciously.

The strongest organisations know what matters, understand where they're exposed, assign accountability, build the right capability and test whether their plans actually work. They also give security leaders enough authority to influence the business, rather than leaving them to document problems that nobody intends to resolve.

That's when information security stops being something an organisation says is important, and becomes something visible in the way it actually operates.

Frequently asked questions

What is information security? Information security is the practice of protecting an organisation's information from unauthorised access, alteration, loss or disruption. It includes technology, but also covers people, processes, governance, physical security and how information is handled throughout the organisation.

What is the difference between information security and cyber security? The terms overlap but aren't identical. Cyber security focuses primarily on protecting digital systems, networks and data against cyber threats. Information security is broader and covers information regardless of whether it's digital, physical or communicated in another form.

Who should be responsible for cyber security? Operational responsibility may sit with a CISO, Head of Information Security, CIO, CTO or another technology leader, depending on the organisation. Ultimate governance of material cyber risk should involve senior leadership and the board; the NCSC specifically identifies cyber security governance as a responsibility requiring board-level ownership.

Written By:
Harriet K copy
Harriet Kirkpatrick

As a founder of TRIA, Harriet is proud of the company's impact in transforming recruitment through strategic insight and deep market understanding. Her leadership style is characterised by a focus on sustainable growth and the development of long-term client relationships.

Connect on LinkedIn
Blog
Share this article:

Actions speak louder than words when it comes to ED&I and we’re proud to let ours do the talking for us. TRIA have a majority female workforce from director level down and to keep building on this, we embody a commitment to keep TRIA a safe, prejudice-free environment.

TRIA Consulting is dedicated to delivering end-to-end services that unlock potential and maximise value. Unlike traditional recruitment, we focus on providing comprehensive consultancy solutions tailored to your organisation's unique objectives.

TEL 0117 332 7000 | POST 14th Floor, Colston Tower, Colston St, Bristol BS1 4XE