SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
Cisco warns UK firms unready for 24-hour cyber rule

Cisco warns UK firms unready for 24-hour cyber rule

Wed, 30th Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Cisco has published research suggesting many UK organisations are not prepared to meet a proposed 24-hour cyber incident reporting deadline, as the Cyber Security and Resilience Bill moves through Parliament.

Its UK data shows that 64% of respondents could not update security controls within 24 hours of a new threat being identified. Under the proposed legislation, organisations would have to notify regulators and the National Cyber Security Centre within 24 hours of a significant cyber incident, followed by a fuller report within 72 hours.

The study is part of Cisco's Relentless Defence Report, which surveyed 8,000 security professionals across 30 markets. The global average score in Cisco's assessment was 64 out of 100, compared with 67 for the UK.

In the UK, 91% of organisations suffered a material, business-disrupting cyber incident in the past 12 months. More than one in three of those incidents involved an AI-enhanced attack.

AI concerns

The research suggests AI is adding to the pressure on security teams while creating new concerns about governance and oversight. Nearly nine in 10 UK organisations, or 88%, cited at least one significant AI-related security concern.

The leading concerns were systems being compromised or manipulated by attackers, cited by 47%, and sensitive data exposure through AI use, cited by 45%. Cisco also found that fewer than half of UK organisations, 47%, consistently apply comprehensive security controls to non-human entities such as AI agents, service accounts and automated systems.

That gap is matched by limited confidence in responding to compromised automated systems. Across the wider findings, only 54% said they were very confident they could detect and respond to a compromised AI agent.

AI adoption in security operations also remains uneven. Just 39% of UK organisations said they had extensively deployed AI for security investigations, while only one-third had extensively deployed AI agents in security operations.

Operational friction

Cisco's report argues that organisational barriers, rather than a lack of security tools, are often the main obstacle to faster cyber defence. Around six in 10 practitioners who said they were struggling pointed to internal issues such as coordination, approvals and access to data as the changes most likely to improve their defences.

In the UK, 47% said security and network or infrastructure teams operate as a single coordinated team with shared visibility and tools. While that was above the global figure of 41%, it still suggests that more than half of organisations lack that level of integration.

Communication with senior leadership remains another weak point. Cisco found that 39% of UK organisations said their security metrics were too technical to influence executive decision-making.

Elsewhere in the broader survey, 43% said what they measure is too technical to persuade executives, 36% said they struggle to translate business metrics into information that can influence decision-making, and 27% said they have no consistent way to measure security performance.

Data handling also emerged as a recurring problem. Four in 10 respondents said they spend more time collecting and correlating data across systems than addressing the threat itself, while 39% said critical insights are missed because data is out of reach.

Best performers

Cisco identified a top-performing group it calls Relentless Defenders, representing 8% globally and 12% in the UK. These organisations were more likely to combine broad protection, faster response times and closer coordination across teams.

Among organisations that increased security spending, those in this top group were nearly twice as likely to report a fall in incidents, at 71% versus 39% for others. The report also found that 83% of these higher-performing organisations operate as a single coordinated security team with shared visibility and tools across security, network and infrastructure, compared with 37% of other defenders.

They were also more likely to apply consistent controls to AI agents and non-human identities. Cisco found that 86% of the top group did so, compared with 37% of all other defenders, while 77% said they were very confident they could detect and respond to a compromised AI agent, versus 51% for others.

The study also found stronger use of AI in operations among this group. A quarter reported that AI had improved threat-detection speed by more than 100%, compared with 7% of other respondents.

The results point to a gap between the speed expected by lawmakers and regulators and the operational reality inside many organisations. If the proposed reporting timetable becomes law, companies may face pressure not only to detect incidents faster, but also to align internal teams, gain approvals and assemble reliable information within a much narrower window.

"Boards have stopped asking whether AI will deliver. They are asking whether their organisation is secure enough to use it. Regulation accelerated that shift, but it will not finish it. Organisations treating security as a compliance exercise will struggle. Those building it into how they operate are already ahead," said Chintan Patel, Chief Technology Officer, EMEA, Cisco.