NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 13 of 32
Don't wait for the breach: why don't organisations act earlier?

The role of leadership, culture, and behavioural science in encouraging proactive approaches to cyber security.
Cyber security needs to be a boardroom issue. It affects financial performance, operational continuity, and corporate reputation. Yet, despite the rising frequency and severity of cyber incidents, many organisations still do not act until after a breach has occurred. The consequences – legal, financial, and reputational – can be devastating, as seen in several high-profile attacks this year.
This delay is not simply a matter of oversight. It reflects a complex mix of behavioural, cultural, and financial dynamics that shape how organisations perceive and respond to cyber risk. Drawing on behavioural science theory and recent research into cyber security culture, this article explores why action is often deferred, and what senior leaders can do to change that.
At a basic level, the lack of preventative action can be explained by not having a full understanding of:
- the likelihood of a cyber attack happening to them
- the possible impact this could have on their business
- their ability to prevent (or recover from) a cyber attack
Furthermore, research suggests that individuals are more likely to act when they:
- feel positively about the action
- believe others expect them to do it
- feel confident in their ability to follow through
Therefore, a focus on understanding the true cyber risk facing organisations, the impact breaches could have and the actions that could be taken will help organisations take action before they are victims of a cyber attack.
Understanding and communicating cyber risk
A common barrier to proactive cyber risk management is the belief that their organisation is unlikely to be targeted. Smaller organisations, or leaders in sectors such as healthcare, manufacturing, or education might ask “Why would cyber criminals attack us?” This reflects a behavioural theory called optimism bias – the assumption that negative events are unlikely to happen to them. It’s reinforced by a lack of visible threats and limited understanding of how cyber attackers operate. Cyber criminal attackers target vulnerabilities, not sectors, so every organisation with digital assets is a potential target.
Since most organisations rely on digital technology to function, cyber is another risk – like financial or legal risk – that the board needs to manage. The Cyber Governance Code of Practice help boards and directors manage digital risks so they can protect their organisations from cyber attacks.
A key challenge here is ensuring board members can communicate effectively about cyber risk. Unlike financial or legal risk, cyber risk is not always on the board’s agenda. Leaders are fluent in the language of revenue, liability, and shareholder value, but cyber security is often framed in technical terms that feels disconnected from business strategy. To address this problem, the NCSC published guidance on ‘Engaging with Boards to improve the management of cyber security risk' , which helps CISOs to communicate more effectively with board members.
As the guidance explains, cyber risk must be translated into business risk, so that board members can approve necessary mitigations. For example, what happens if the factory comes to a grinding halt or the website goes offline? These impacts could affect share price, customer trust, and regulatory standing. By acknowledging this, it becomes far easier to prioritise and govern cyber security effectively.
The cost of inaction
Like any other business risk, cyber security will be competing for limited resources - both in terms of money and, crucially, space within the board’s agenda. Without a visible threat, investment in prevention is frequently deferred. As a result, cyber security remains underfunded—until a breach occurs. Only then do attitudes shift, public scrutiny intensifies, and urgency becomes unavoidable.
IBM’s X-Force 2025 Threat Intelligence Index notes that UK is the most targeted European country for cyber attacks. In the UK, businesses have lost billions of pounds to cyber attacks over five years. Many of these losses could have been prevented through basic cyber hygiene and cultural change.
Boards must recognise that investing in cyber resilience today protects long-term value and reduces the likelihood of costly disruption.
Once risk and impact are better understood, organisations can then consider what preventative action they will take. While this article can’t cover every element of this, one overarching theme we urge all organisations to consider is their approach to ‘cyber security culture’, as this can be the springboard for a whole range of good cyber security behaviours and practice.
Building a positive cyber security culture
Research shows that any efforts to improve the cyber security of an organisation will only ever be effective if they are supported by a culture that encourages this improvement. An organisation’s culture influences how cyber security is approached, for example how decisions are made, how incidents are managed and people’s attitudes towards it.
What is cyber security culture?
Cyber security culture is the collective understanding of what is normal and valued in the workplace with respect to cyber security. It sets expectations on behaviour and relationships, influencing people's ability for collaboration, trust, and learning.
Leaders have a vital role to play in setting the tone for their organisation's culture. While some goals can be achieved by the cyber security team, significant and sustained impact needs leadership buy-in and advocacy
This year, the NCSC published its Cyber Security Culture Principles, outlining what good culture looks like and how to shift perceptions and behaviours. Applying the principles will help you tackle the behavioural barriers identified in this article and provide a foundation for change. To support implementation, the NPSA launched the Security Culture Tool, helping organisations assess and shape their entire security culture.
Improving cyber risk culture is not a technical issue – it’s a leadership issue. Boards must set the tone from the top and embed cyber resilience into the organisation’s DNA.
Don’t wait for the breach
Cyber incidents often act as powerful cues to increase cyber security but by then, the damage is done. The cost of inaction is rising, and the window for preparation is narrowing. Organisations must move from reactive to proactive approaches to cyber security. This means challenging assumptions, quantifying risk, investing in prevention, and embedding a culture of cyber resilience at every level. The question is no longer if your organisation will face a cyber incident, but when. The time to act is now.