Resources

10 Biggest Cyber Security Challenges for UK IT Managers in 2026

Written by Oliver Spence | Oct 6, 2026, 8:16:52 AM

By Oliver Spence, Co-Founder and CEO, CybaVerse | October 2026

UK IT managers are spending nearly five hours a day managing security tools, and 73% have missed or ignored a critical alert because they simply ran out of time. This is not a technology problem. Most organisations already have an EDR, a firewall, M365 security, and a backup product. What they lack is the people and hours to run those tools every day and night, decide what matters, fix it, and prove they did.

This report ranks the ten cyber security challenges eating the most time in organisations of 50 to 2,000 staff, where security is part of the IT job rather than the responsibility of a dedicated SOC. Every number links to its source. Where I give a ranking or a judgement, I say so.

Ranking methodology: each challenge is scored on four factors: weekly time cost, consistency across independent surveys, how stubbornly it stays unsolved, and relevance to UK firms in the 50 to 2,000 staff range.

Key Takeaways

  • Alert triage is the single biggest daily time sink: security staff spend an average 4 hours 43 minutes a day managing tools, and 73% have missed a critical alert
  • Exploited vulnerabilities are now the top breach entry point (31% of incidents), yet only 26% of known-exploited flaws get fully fixed
  • 83% of ransomware is deployed outside business hours, when most IT teams are not watching
  • Teams spend 12 working weeks a year on compliance evidence and 9 weeks on vendor security reviews
  • 49% of UK businesses have a basic cyber skills gap, and 70% already use an external provider but still feel exposed
  • The thread running through all ten: these are not technology gaps. They are people and time gaps.

About this research: Sources span public surveys and reports from 2023 to 2026 (UK Government, NCSC, DSIT, ISC2, Verizon, Vanta, Kaseya, Datto, Coro, Heimdal, Veeam, CoreView, Nudge, Ivanti, ConnectSecure, Proofpoint), plus practitioner posts from Reddit. Many vendor-sponsored surveys are included where useful for spotting pain points; the UK Government sources (CSBS, DSIT, NCSC) serve as the independent anchor throughout. Where vendor surveys cover a different population from the UK 50 to 2,000 staff target, this is noted.

Who Is Actually Doing This Work?

Before ranking the challenges, it helps to understand who carries the load. In UK medium businesses (50 to 249 staff), the person most responsible for cyber security is the IT director (13%) or an IT manager, technician or administrator (14%), according to the DSIT and Home Office Cyber Security Breaches Survey 2025/26. Security is not a specialist function. It sits with general IT people who are also running the helpdesk.

The numbers that frame the challenge:

  • 65% of UK medium businesses identified a breach or attack in the last year (69% of large businesses)
  • 70% of UK medium businesses already use an external cyber security provider, yet 49% still have a basic skills gap
  • 68% of IT teams globally have 25 or fewer IT staff; the share with fewer than five rose from 31% to 36% in a year (Kaseya Global IT Trends 2025)
  • 204 nationally significant cyber incidents were handled by the NCSC in the year to August 2025, up from 89 the year before

The picture is clear: the threat is rising, the teams are small, and outsourcing alone is not solving it. DSIT's 2025 skills report found that 23% of businesses that outsource security cannot tell whether their provider is good value. That gap, outsourced but still not covered and unable to see the value, is where most of the ten challenges below take root.

The 10 Biggest Cyber Security Challenges for UK IT Managers, Ranked

Rank

Challenge

Headline evidence

1

Alert triage and console overload

4h 43m/day on security tools; 73% missed a critical alert

2

Patching and vulnerability prioritisation

Exploited vulns now #1 breach vector (31%); only 34% of UK firms patch within 14 days

3

Skills gaps and no out-of-hours cover

83% of ransomware lands outside business hours; 49% UK skills gap

4

Compliance evidence, Cyber Essentials and insurance

12 working weeks/year on compliance; 61% spend more time proving than improving

5

Phishing, BEC and the user-reported email queue

Phishing hits 38% of UK businesses; only 11.88% of user-reported emails are actually malicious

6

Identity: joiners, movers, leavers and MFA gaps

5 hours per leaver; 79% of ransomware now starts with identity techniques

7

Tool sprawl and integration

Average 11.55 security tools; 46% spend more time maintaining than defending

8

Microsoft 365 config drift and SaaS sprawl

10,000+ M365 settings; 38% detect tampering manually

9

Backup and ransomware recovery readiness

89% had backups targeted; only 10% recovered more than 90% of data

10

Board reporting, budget justification and supplier assurance

Board cyber updates fell from 78% to 70% in UK medium businesses

1. Alert Triage and Watching the Consoles

Alert triage is the single biggest daily time sink for UK IT security teams. Security staff at mid-market firms spend an average of 4 hours 43 minutes a day managing security tools, and monitoring security platforms is the most time-consuming task for 52% of them, ahead of patching. The consequence: 73% have missed, ignored or failed to act on a critical alert, with lack of staff and lack of time the two most common reasons (Coro SME Security Workload Impact Report, n=500).

Every security tool raises alerts. EDR, M365 Defender, firewall, email filter, SIEM, backup: each has its own console and its own noise floor. In a 50 to 2,000 person firm, the person reviewing all of them is usually the same person running the helpdesk.

The scale of the noise problem

The alert volume data is consistent across independent sources:

  • 59% of security teams have too many alerts; 55% have too many false positives; 46% deal with alerts that lack context. Alerting is the most common source of SOC inefficiency, cited by 47% (Splunk State of Security 2025, n=2,058)
  • 56% of MSPs experience alert fatigue daily or weekly; roughly one in four alerts is a false positive, with some MSPs reporting rates as high as 70%. High false-positive rates triple the chance of missing a genuine incident (Heimdal / FutureSafe, 80 North American MSPs, 2025)
  • In the UK, only 32% of businesses used tools designed for security monitoring in the last year, against 81% with up-to-date malware protection (CSBS 2025/26)

What practitioners say

"Every morning there is a wall of stuff that technically matches a detection rule and practically means nothing. The gap between those two things is where most of the workday disappears." (IT manager, r/ITManagers)

"The cycle you described is basically every mid-size company IT experience right now. The market just sold everyone on detection coverage without thinking about what happens when that coverage generates 900 alerts a day." (reply in the same thread)

Why it stays unsolved

Tuning takes time the team does not have, so noise grows, which leaves even less time to tune. Each new tool adds another alert stream. This is the tuning debt loop: the backlog compounds until teams triage only the loudest alerts and hope the rest are benign.

The fix is not more detection. It is someone who has already filtered the noise before it reaches the IT manager, and who acts on the real alerts without waiting to be asked.

2. Patching and Vulnerability Prioritisation

Patching is the second most time-consuming security task in mid-market firms, and it is also where the consequences of falling behind are now most severe. Exploitation of vulnerabilities is the most common initial access vector for breaches at 31%, up from 20% the previous year (Verizon DBIR 2026). For EMEA breaches specifically, that figure rises to 47%.

The remediation numbers make the risk concrete:

  • Only 26% of CISA Known Exploited Vulnerabilities (KEV) were fully remediated in 2025, down from 38% the year before
  • Median time to full fix rose to 43 days from 32 days
  • Only 34% of UK businesses have a policy to apply security updates within 14 days, the lowest-adopted control in the CSBS 2025/26 survey. Fourteen-day patching of high and critical updates is a Cyber Essentials requirement, making this a direct certification blocker
  • Exploited vulnerabilities were the top technical root cause of UK ransomware attacks in 36% of cases (Sophos State of Ransomware in the UK 2025)

The prioritisation problem

The volume of findings is not the core issue. The inability to prioritise them is.

"Backlog is around 62k findings right now. Every scan cycle adds another few thousand, so even when teams close tickets the overall number barely moves. There are so many 'critical' findings sitting open that people stopped reacting to the label." (security team of five, Reddit)

Ivanti's 2025 risk-based patching report found that 39% of security professionals struggle to prioritise remediation and patch deployment, with 35% struggling to stay compliant as a result. When every finding is rated urgent, nothing is actually prioritised.

Why it stays unsolved

The volume of CVEs keeps rising, severity scores do not reflect real-world exploitation risk, patching requires downtime the business resists, and ownership is blurred between security and operations. In a 50 to 2,000 person firm, both hats sit on the same head.

The practical need is not a longer list of findings. It is a short weekly list: the ten things that are actively exploited in the wild, present on systems that matter, with a clear fix or workaround. That output also answers the Cyber Essentials auditor and the cyber insurance questionnaire simultaneously.

3. Not Enough Skilled People, and Nobody Watching Out of Hours

This is the structural problem underneath challenges 1 and 2. A small IT team covers 9 to 5. Attackers do not.

83% of ransomware binaries are deployed outside the victim's local business hours (Sophos Active Adversary Report 2025). The median time from initial breach to first attack on Active Directory is just 11 hours. The median time to data theft is just over three days. By the time the IT manager arrives on Monday morning, the damage is often already done.

The skills and staffing data

  • 58% of ransomware victims cite lack of people or skills as a contributing cause. Organisations with 100 to 250 staff are the most likely to say they did not have enough experts watching at the time (43%) (Sophos State of Ransomware 2026, n=2,158)
  • 42% of UK ransomware cases cited lack of expertise as the top operational cause (Sophos UK 2025)
  • 49% of UK businesses have a basic cyber skills gap (setting up firewalls, detecting malware, handling personal data securely); 30% have an advanced skills gap (DSIT 2025)
  • 88% of security professionals have experienced at least one significant security consequence because of a skills shortage (ISC2 2025 Workforce Study, n=16,029)

The human cost of getting it wrong

The impact of an encrypting ransomware attack on the IT team itself is severe: 41% report increased anxiety, 40% increased pressure from leadership, and in the UK specifically, 43% report more workload and 24% saw their team's leadership replaced (Sophos 2026).

Why it stays unsolved

A 24/7 in-house security rota requires five or more skilled people. No 50 to 2,000 person organisation will fund that for security alone, and hiring is increasingly difficult even for those that try. The only realistic answer for this segment is external cover for the hours the internal team cannot staff.

"Outsource it. Let a 24/7 SOC monitor all your devices. They can do instant containment while you're sleeping." (advice given in a Reddit thread on alert fatigue)

"Mainly because I'm just on my own and it was felt that it would be nice for me to have some professional advice and guidance." (UK CSBS 2025/26 interview, medium wholesale business, on why they bought cyber insurance)

4. Proving It: Compliance Evidence, Cyber Essentials, Insurance and Customer Questionnaires

Compliance is no longer a once-a-year exercise. The volume of evidence requests, from insurers, customers, auditors and certification bodies, has grown to the point where it competes directly with actual security work for the IT manager's time.

Teams spend approximately 10 hours a week (12 working weeks a year) on compliance tasks such as evidence collection and policy reviews, plus a further 7 hours a week (9 working weeks a year) on vendor security reviews. 61% say they spend more time proving security than improving it; 77% say stakeholders now demand verified proof of compliance, up from 65% (Vanta State of Trust 2025, n=2,500 across UK, US and Australia).

The UK compliance picture

The UK context makes this particularly acute:

  • Only 5% of UK businesses hold Cyber Essentials certification (35% of large businesses), yet moving towards certification was a top priority raised in CSBS interviews
  • 61% of UK medium businesses hold some cyber insurance, but 22% of businesses do not know whether they are insured (CSBS 2025/26)
  • Organisations with Cyber Essentials are 92% less likely to make a cyber insurance claim, according to data from the scheme's insurer published by the NCSC
  • 87.5% of MSPs deal with several cyber insurers for their clients; 29.2% call it unsustainable because of long questionnaires and differing proof requirements (ConnectSecure MSP survey, 2024)

What practitioners say

"The questionnaire is forty pages now, up from a handful a few years ago, and it is no longer yes or no. Pulling clean evidence out of all of it is a week of screenshots that still look like a patchwork." (security lead, mid-size company, Reddit)

"Last year it was three checkboxes. This year it reads like an audit." (Reddit, on insurance renewal)

Why it stays unsolved

Evidence lives in many consoles, is gathered by hand once a year, and is out of date the day after. Each insurer, customer and framework asks the same questions in a different format. The work lands on the IT manager without extra time or budget to do it.

The opportunity here is straightforward: if monitoring and patching data is already being collected, it can also become the evidence pack. Dated, exportable reports showing MFA coverage, EDR coverage, patching status and backup health answer Cyber Essentials, insurance renewals and customer questionnaires from the same underlying data.

5. Phishing, BEC and the User-Reported Email Queue

Phishing is the most common attack on UK businesses and the most disruptive when it succeeds. It is also one of the most labour-intensive to manage, because every user report has to be checked: the one you skip could be the one that is real.

Phishing affects 38% of UK businesses and is the most disruptive attack for 69% of those breached. Among breached businesses, 51% experienced only phishing, up from 45% the year before (CSBS 2025/26). Malicious email (26%) and phishing (24%) together account for half of all ransomware root causes globally (Sophos State of Ransomware 2026).

The false positive problem in user-reported email

The triage burden is significant because most reports are harmless. In Microsoft's live sample of user-reported emails, only 11.88% were actually malicious (Microsoft Security Copilot phishing triage RCT, arXiv 2025). The remaining 88% still require a human to check them.

Additional data points:

  • 49% of businesses were hit by phishing in the past year (Kaseya 2026 Cybersecurity Outlook)
  • 64% of MSPs say phishing is their clients' top security concern; 61% say BEC is (Datto State of the MSP 2025)
  • Only 19% of UK businesses ran any staff awareness training in the last year, though this rises to 54% for medium businesses and 84% for large (CSBS 2025/26)

Why it stays unsolved

AI is making phishing lures cleaner, cheaper and harder to distinguish from legitimate email. Every staff report has to be checked, because the one you ignore could be the start of a business email compromise. It is low-skill but endless work that interrupts everything else on the IT manager's list.

6. Identity and Access: Joiners, Movers, Leavers, MFA Gaps and Admin Accounts

Identity is now the primary way attackers get in. 79% of ransomware attacks start with identity-based techniques (Sophos 2026 via DQ Channels). In Sophos incident response cases, attackers logged in rather than broke in 56% of the time, and MFA was missing in 63% of breached organisations (Sophos Active Adversary Report 2025).

Despite this, identity management remains largely manual, ticket-driven, and dependent on managers remembering what access their staff had.

The numbers behind the identity gap

  • IT teams spend an average of 5 hours per leaver identifying and removing cloud and SaaS access; 69% use three or more sources to work out what someone had; 70% have suffered business disruption, security incidents or wasted spend from incomplete offboarding (Nudge Security, 375 US IT professionals at 50+ staff firms, 2023)
  • Where stolen credentials caused a breach, 97% of victims had MFA deployed in some form, suggesting coverage gaps or bypass techniques rather than absence of MFA entirely (Sophos 2026)
  • Only 47% of UK businesses require two-factor authentication, rising to 90% of large businesses (CSBS 2025/26)
  • Admin accounts are less protected than regular user accounts: full MFA on 55% of admin accounts versus 62% of standard users; 63% skip access reviews because they take too long (CoreView 2026, 279 leaders at 1,000+ employee firms)
  • Third parties were involved in 48% of breaches, up 60% year on year; SMB breaches involved a third party in 55% of cases (Verizon DBIR 2026)

What practitioners say

"Supervisors and managers don't always remember everything their employee had access to. Verifying what someone actually has means logging into each platform individually to check." (IT lead at a 1,000 person, 30-site firm, Reddit)

Why it stays unsolved

Not every application is behind single sign-on (SSO tiers cost extra). HR does not always notify IT in time. Managers cannot recall what access people had. Access reviews are skipped because they take too long. The result is an identity surface that grows with every hire, every SaaS subscription, and every leaver who was not fully offboarded.

7. Tool Sprawl and Integration

Mid-market security teams are not short of tools. They are drowning in them. The average mid-market firm runs 11.55 separate security tools, and it takes an average of 4.22 months to make a new tool operational. 53% deal with vendor updates to endpoint agents daily or weekly. 85% plan to consolidate (Coro SME Security Workload Impact Report).

The result is not better security. It is more maintenance work.

The integration and fatigue data

  • 46% spend more time maintaining their security tools than actually defending the organisation
  • 78% say their security tools are disconnected and dispersed; 57% lose investigation time to data gaps between tools (Splunk State of Security 2025, n=2,058)
  • 89% of MSPs struggle with tool integration; only 11% have seamless integration; MSPs running seven or more tools report nearly double the alert fatigue (Heimdal / FutureSafe 2025)
  • 95% of MSPs say integrating RMM, PSA and documentation tools is essential to their operation (Kaseya MSP Benchmark 2025)

Why it stays unsolved

Tools are bought one incident or one audit at a time. Nobody owns the integration work. And removing a tool is risky and time-consuming in itself, so the stack grows and the swivel-chair work compounds.

The worst outcome is a new tool that technically covers everything but becomes one more console nobody has time to watch. (This is a direct quote from a Reddit thread on choosing MDR/XDR for a 400-endpoint firm, and it captures the trap precisely.)

8. Microsoft 365 Configuration Drift and SaaS Sprawl

Microsoft 365 has more than 10,000 configuration settings. They change when Microsoft releases updates. They drift when admins make one-off adjustments under pressure. And most mid-sized organisations have nobody whose job it is to watch them continuously.

The scale of the problem is significant:

  • 38% of organisations detect M365 configuration tampering manually; 17% have no method at all
  • Only 17% back up their own M365 configuration; 37% incorrectly believe Microsoft does this for them
  • 66% delayed or cancelled a Microsoft Copilot rollout because of data exposure concerns
  • 14% cannot count the number of applications connected to their Entra ID tenant (CoreView 2026 State of Microsoft 365 Security, 279 leaders at 1,000+ employee firms, mostly US)

The SaaS sprawl dimension

At a 1,000-employee organisation, a new SaaS account is created roughly every 20 minutes (Nudge Security platform data). Each new application potentially adds new data exposure, new permissions, and new offboarding complexity. For smaller organisations the pace is slower but the oversight is typically weaker.

24% of security professionals report misconfigured systems as a direct consequence of skills shortages (ISC2 2025).

Why it stays unsolved

Microsoft changes settings and licences constantly. The admin surface spans multiple portals (Entra, Exchange, SharePoint, Intune, Defender, Purview). AI tools like Copilot expose years of loose sharing permissions that were never reviewed. Most mid-sized firms have no continuous watch on any of this.

9. Backup and Ransomware Recovery Readiness

Most organisations have a backup product. Fewer have a backup that will actually work when ransomware hits. The gap between having backups and being able to recover from them is one of the most dangerous false assurances in security.

89% of organisations hit by ransomware had their backup repositories targeted, with an average 34% of backup data modified or deleted. Only 10% recovered more than 90% of their data; 57% recovered less than half. Only 44% of ransomware playbooks include backup verification (Veeam Ransomware Trends 2025, n=1,300).

The UK recovery picture

UK-specific data from Sophos tells a stark story:

  • Only 39% of encrypted UK organisations recovered using backups in 2025, down from 48% the year before
  • 54% of UK ransomware victims paid the ransom (Sophos State of Ransomware in the UK 2025)
  • Only 25% of UK businesses have a formal incident response plan; only 33% have a business continuity plan that covers cyber (CSBS 2025/26)
  • 37% of businesses lost a full day or more to downtime after an incident (Kaseya 2026 Cybersecurity Outlook)

What practitioners say

"Require quarterly test restores. 3-2-1 means nothing until you've actually restored something." (advice to a new security manager, Reddit)

Why it stays unsolved

Restore testing is the job that always slips. Backup is often owned by a different team or managed separately from security, so the two functions are not joined up. The playbook exists in theory; in practice, it has not been tested since it was written.

10. Board Reporting, Budget Justification and Supplier Assurance

The final challenge is translating security into language that unlocks budget and satisfies the board, customers and insurers. IT managers are not trained to do this, and they rarely have the clean, regular data needed to do it well.

The UK data shows the gap is widening:

  • UK medium businesses giving senior managers cyber updates at least annually fell from 78% to 70% in a year
  • Only 31% of businesses have a board member responsible for cyber (52% of medium businesses)
  • Only 15% of UK businesses review risks from their immediate suppliers; only 6% review the wider supply chain (CSBS 2025/26)
  • Organisations spend 10% of IT budget on security, against what leaders see as a 17% ideal, with no improvement on 2024 (Vanta State of Trust 2025)
  • Only 64% of CISOs feel their board sees eye to eye with them on cyber, down from 84% (Proofpoint Voice of the CISO 2025). For IT managers in mid-market firms without a CISO, the disconnect is likely greater

What practitioners say

"Will he understand what I'm telling him? Probably not." (IT lead, medium transport business, CSBS 2025/26)

"I don't know that they think about cyber security. They just want to tell clients we are secure." (small professional services business, CSBS 2025/26)

"Leadership ignores the security team's recommendations for months, then the insurer asks the same question and suddenly the budget appears." (Reddit)

Why it stays unsolved

IT managers are not trained to translate risk into financial terms, and they have no regular, clean data to report from. External triggers (an insurer's question, a customer security questionnaire, a high-profile incident in the news) are what actually unlock budget. The implication is that security conversations with boards and budget holders should be timed around those triggers, not around the IT team's internal calendar.

The Thread Running Through All Ten

These are not mainly technology gaps. Most organisations in the 50 to 2,000 staff range already own decent tools: an EDR, M365 security, a firewall, a backup product. What they lack is the people and hours to run those tools every day and night, decide what matters, fix it, and prove they did.

The independent UK data confirms this. 70% of UK medium businesses already use an external cyber security provider (CSBS 2025/26), yet 49% still have a basic skills gap. 23% of businesses that outsource cannot tell whether their provider is good value (DSIT 2025).

Outsourcing alone is not the answer. The question is whether the external provider actually covers the hours and decisions the internal team cannot, and whether it produces evidence the IT manager can show to insurers, customers and the board.

The three challenges that matter most for most organisations, in order:

  1. 24/7 coverage of alerts and threats (challenges 1 and 3 combined): the 4h 43m daily time sink, the 73% who have missed a critical alert, the 83% of ransomware that lands outside business hours
  2. Prioritised vulnerability remediation (challenge 2): not a scanner, but a weekly short list of what is actively exploited, on systems that matter, with a fix attached
  3. An always-ready evidence pack (challenge 4): monitoring and patching data that doubles as Cyber Essentials evidence, insurance renewal documentation and customer assurance

Challenges 5 and 6 (email and identity) are close behind, and the 2026 data is clear that these are now the primary ransomware entry routes. Any security programme that covers 24/7 monitoring without also covering Microsoft 365 identities and email is leaving the main door open.