Cybersecurity, data and
compliance
The fight for trust: the changing data and cyber landscape
This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.
The fight for trust: the changing data and cyber landscape
With the introduction of the Cyber Security and Resilience (Network and Information Systems) Bill, there has been a transformation in how organisations approach their cyber and data strategy. While the Bill directly impacts organisations involved in the delivery of critical services, elements of the legislation such as the expanded reporting requirements are indicative of wider cybersecurity trends and recognise the increasing complexity of cyber incidents.
Businesses have had to accept that it’s not a case of if there is a cyber incident, but when one will occur. While prevention measures remain the key protection, organisations now focus significant attention on their cybersecurity response framework and ensuring that teams have rehearsed breach response strategies in place.
Our research shows that over half of UK decision‑makers (53%) believe the government should prioritise data protection and cybersecurity as part of the country’s digital enablement agenda, and 61% of CEOs listed cybersecurity as their main concern when driving the adoption of a digital enablement strategy within their business.
These priorities reflect the reality facing businesses today: the risks are rising, the rules are tightening and expectations from regulators, partners and customers are only increasing.
The pressure is particularly visible in the compliance challenges that organisations report. Cybersecurity and data protection topped the list of challenges cited by our respondents, with many businesses still grappling with legacy technology, inconsistent governance and fast moving regulatory change.
As organisations build and rely on ever larger volumes of data, the importance of protecting that information while meeting legal duties under UK GDPR, the Data Protection Act and emerging AI related regulation, has never been higher. Businesses need to harness the power of data to maintain their competitive edge, but this can only be successful if that data is appropriately secured.
Cybersecurity threats are expected to grow significantly in the next one to two years, with 60% of respondents anticipating an increase. The UK’s National Cyber Security Centre’s 2025 Annual Report highlights how crowded the threat landscape has become, with attackers of varying motivations operating through sophisticated ecosystems designed to disrupt. At the same time, new technologies are lowering barriers to entry for cyber attackers and making attacks more targeted, quicker to implement, and harder to trace. New technologies are also introducing fresh regulatory considerations, with 53% expecting AI ethics and regulation to become more significant in the near term.
For UK organisations, compliance is no longer a back office issue. Data and cyber strategy now define organisational resilience.
Data and cyber hygiene has become a core differentiator. Demonstrating strong data governance, cyber readiness and responsible practices is increasingly essential for maintaining customer trust, attracting investment and meeting supply chain requirements. Trust has become a competitive advantage and consumer expectations are high surrounding protection of data and how businesses respond when that data is compromised. Timely detection, clear and prompt communication, and prompt decision making are core ingredients for an effective response.
Regulators are sharpening expectations around accountability, documentation and proactive risk management. We have seen from recent high profile data incidents that regulators judge organisations on their ability to respond appropriately to cyber incidents. Early decisive action (even if that means shutting down sections of the business) has been praised by the UK’s data protection regulator.
As digital operations expand, so too does exposure. Many organisations still rely on a mix of legacy systems, complex vendor arrangements and incomplete oversight of data flows. These challenges can create blind spots around security responsibilities, contractual risk and regulatory compliance, especially where cross‑border data, cloud infrastructure and third‑party technology providers are involved.
A significant proportion of cyber incidents are caused by third-party suppliers. Business operations are outsourced at great speed and scale, offering great efficiency to businesses but also enlarging the attack perimeter and taking it beyond control of the relevant organisation. Visibility and control are weakened once processes (and associated data) leave an organisation, and the interconnected nature of modern supplier frameworks means that a single supplier vulnerability quickly cascades into the wider ecosystem. Organisations that take a structured, legally informed approach to governance are best placed to navigate this changing landscape.
Although most businesses are accelerating digital initiatives, confidence in managing related risks is uneven. While 47% feel confident that their digital strategy aligns with regulatory and legal risk management, this still leaves a majority who remain uncertain. This uncertainty is often rooted in fragmented governance where IT, legal and operational teams are not fully aligned, and in gaps around monitoring, incident response and contractual risk.
With 60% expecting cyber threats to increase, the disconnect between ambition and readiness is becoming more pronounced. Attackers continue to exploit vulnerabilities in ageing systems, unpatched software and supply‑chain dependencies. For UK businesses, this raises not only operational risk, but also potential liability under data protection law and increasing scrutiny from regulators.
Cybersecurity and data protection emerge as the two most significant barriers to digital progress. These issues are closely linked: weak security can quickly enable a data breach, triggering breach notifications, regulatory investigations and potential fines.
Many organisations struggle with visibility – knowing what data they hold, where it sits, who has access and which third parties support key processes. This is particularly common with AI tools. Where customers are eager to adopt new technologies, essential data due diligence is often overlooked. This can undermine compliance with the UK GDPR principles of data minimisation, integrity, confidentiality and accountability. It also makes it harder to provide tangible evidence of compliance, which regulators increasingly expect.

Governance is becoming a defining differentiator.
Businesses with clear accountability models, regular risk assessments and integrated legal‑technical decision‑making are better equipped to adopt new technologies.
While 15% of respondents feel regulation is slowing them down, 27% see regulation as enabling.
The message from the data is clear: organisations that embed cybersecurity, data protection and ethical technology practices into their strategic planning are best placed to grow with confidence. UK businesses should take a proactive approach, moving from reactive compliance to anticipatory and holistic risk management.
Practical steps include strengthening incident response plans, improving visibility over data and third‑party suppliers and ensuring legal and technical teams work together on governance and procurement decisions. Regular data and cyber health checks, updated contractual protections and clear accountability structures are also essential foundations for compliance with UK data protection law and future AI regulation. Strong oversight of systems – covering transparency, fairness, and human oversight – will become increasingly important as the regulatory landscape evolves.