
The Cyber Security and Resilience Bill outlined in this year’s King’s Speech sends a clear signal about how the UK views cyber risk. Cyber resilience is increasingly being treated as a matter of economic stability, business continuity and national security, reflecting the growing impact that cyber incidents can have on organisations, supply chains and critical services.
That shift in thinking comes at a critical moment. New research from ManageEngine found that 77% of UK organisations suffered a cyber incident in the past 12 months, the highest rate among the five European countries surveyed and 11 percentage points above the European average. At the same time, AI-powered attacks have emerged as the threat businesses fear most over the next year.
The findings point to a changing reality for security leaders. The challenge is beyond identifying threats but maintaining operational resilience in an environment where attacks are becoming faster, more sophisticated and increasingly automated.
AI-powered threats
AI is reshaping cybersecurity on both sides of the equation. Organisations are adopting AI to improve threat detection, automate security operations and accelerate decision-making. Attackers are doing exactly the same.
According to our recent research, 43% of UK organisations believe AI-powered attacks will represent their biggest cyber risk over the next 12 months, ahead of ransomware, phishing and data breaches. Investment priorities mirror that concern, with 41% identifying AI and advanced threat preparedness as their leading cybersecurity spending priority over the next two years.
This reflects a growing recognition that AI is reducing the barriers to launching sophisticated attacks. Techniques that once required significant expertise can now be automated, scaled and refined at speed. AI-generated phishing campaigns can be tailored with greater accuracy, while malicious actors can use automation to probe systems continuously for vulnerabilities.
For organisations, this creates a race between defensive capabilities and increasingly intelligent attack methods.
Detection has improved
One of the most striking findings from the research is the gap between how quickly organisations identify cyber incidents and how long it takes them to recover.
Nearly all UK organisations surveyed (94%) said they can detect a cyber incident within 24 hours. On the surface, this suggests significant progress. Investments in monitoring tools, security operations and visibility platforms are clearly delivering results.
Recovery tells a different story
Despite this, lLess than half of organisations (49%) recover within 10 days of an incident. More than a quarter (26%) reported recovery periods extending beyond 10 days, while 6% said recovery can take longer than 20 days.
This distinction matters because business impact is rarely determined by detection alone. Extended recovery periods increase operational disruption, financial losses and reputational damage. A ransomware attack that is identified quickly can still cause significant harm if systems remain unavailable for weeks.
The King’s Speech highlighted the need for stronger resilience across the UK’s digital infrastructure. The survey findings reinforce why that focus is necessary. Organisations have become increasingly effective at identifying incidents; many continue to struggle with restoring operations at the pace modern business demands.
Operational pressure and security risk
Technology alone is not driving the resilience gap.
We found that 46% of UK organisations see the cybersecurity skills gap as their primary operational challenge, the highest rate among the countries surveyed. Meanwhile, 60% reported increased operational pressure on IT and security teams over the past year.
The strain is becoming increasingly visible. Team fatigue and burnout were cited by 29% of respondents, again the highest figure recorded across Europe. The same proportion pointed to insufficient management support as a significant challenge.
These findings highlight an often-overlooked aspect of cyber resilience. Security programmes ultimately depend on people. Even organisations with advanced technologies can struggle when teams are stretched across incident response, compliance obligations, infrastructure management and growing threat volumes.
Board engagement needs to move beyond crisis response
The UK demonstrated some of the strongest governance indicators in the study. Around 67% of organisations have implemented a formal resilience methodology, while 96% conduct formal reviews following cyber incidents.
However, executive engagement often remains tied to specific events rather than ongoing oversight.
Almost one quarter of respondents described board involvement as limited or non-existent, and only one-third reported very high and continuous leadership engagement. While 83% implemented some form of cybersecurity improvement after an incident, only 37% introduced broader long-term changes.
This suggests many organisations still approach resilience as a response function rather than an operational discipline embedded across the business.
The direction outlined by policymakers and regulators increasingly points towards a different model. Cyber resilience is becoming a board-level responsibility, closely linked to operational continuity, risk management and organisational performance.
Building resilience
The UK’s cyber landscape presents a paradox. Organisations face the highest cyber incident rate among the European countries surveyed, yet they also demonstrate some of the strongest governance structures, resilience frameworks and detection capabilities.
The next stage of maturity will depend on closing the gap between awareness and operational readiness.
As AI-powered threats continue to evolve, resilience will be determined by an organisation’s ability to combine visibility, skilled personnel, governance and recovery capabilities into a coordinated strategy. Faster detection remains essential, but the organisations best positioned for the future will be those capable of sustaining operations, recovering quickly and adapting continuously as the threat landscape changes.
