One in five Irish businesses, or approximately 50,000 companies, have no cyber security policy, according to research from Magnet+.
Almost one-third of Irish businesses, around 83,000 companies, allocated less than 10% of their IT budget to cyber security measures last year, which is unlikely to change much in 2022 despite several high profile breaches such as the ransomware attack on the HSE.
Some 38% of respondents to the survey said they had not increased their budget this year, with 37% admitting they have no idea if they increased their budget or not, while just 25% of companies said they have increased their cyber security budget for 2022.
In terms of responsibility for cyber security strategy, 30% said the business owner or office manager was responsible while 47% said the CTO or IT manager, and 13% said they either didn't know or that nobody was responsible.
Meanwhile, a quarter said they rely on social media or blogs/news sites for information on cyber threats and attacks, while the same amount (25%) read industry-specific websites or publications, 16% rely on a consulting firm, and 13% don't keep informed.
Almost one in four said email attachments posed the greatest cyber security threat to their business, but the survey found that 50% of businesses have not implemented an email security solution to prevent this.
"These figures are quite concerning to me. We live in a digital economy where the risk of a cyber-attack on a business is always increasing and usually these cyber hackers tend to be a step ahead," John Delves, managing director of Magnet+, said.
"For organisations with no cyber security system in place, the potential damage that could be caused from an attack may be irreversible. It’s also alarming to see that 28% of businesses say it’s difficult to make a business case for management to invest in cyber security when it should be a key focus of theirs.
"At the end of the day, it is the CEO’s responsibility to understand the core principles of cyber security and ensure an investment in cyber security is a top priority”.
The research comes as Magnet+ announces a new partnership with Exponential-e to add a full cyber security service to its offering, meaning Magnet+ customers can now get their connectivity and security requirements from one provider.
"We are really looking forward to working with Magnet+ and to bring our security expertise to their ever-growing network of experts," Simon Acott, director of business at Exponential-e, said.
"In the current climate we are seeing an increase in the number of cyber-attacks on a global scale and the reality is what we read about in the media is a very small per cent of the actual number of cyber-crimes happening as more often than not, it’s the SMEs and smaller companies that are being hit the most.
"The results from Magnet+’s survey indicate that there is an overall lack of awareness and understanding of the importance of cyber security for SMEs which is a bit unnerving given the world we are living in currently. Business owners need to prepare for the inevitable and start seeing investing in cyber security as an asset as opposed to a cost."
Photo: John Delves, Managing Director of Magnet+ and Simon Acott, Director of Business at Exponential-e. (Pic: Conor McCabe Photography)