By Oliver Spence, Co-Founder and CEO, CybaVerse | October 2026
UK IT managers are spending nearly five hours a day managing security tools, and 73% have missed or ignored a critical alert because they simply ran out of time. This is not a technology problem. Most organisations already have an EDR, a firewall, M365 security, and a backup product. What they lack is the people and hours to run those tools every day and night, decide what matters, fix it, and prove they did.
This report ranks the ten cyber security challenges eating the most time in organisations of 50 to 2,000 staff, where security is part of the IT job rather than the responsibility of a dedicated SOC. Every number links to its source. Where I give a ranking or a judgement, I say so.
Ranking methodology: each challenge is scored on four factors: weekly time cost, consistency across independent surveys, how stubbornly it stays unsolved, and relevance to UK firms in the 50 to 2,000 staff range.
Key Takeaways
- Alert triage is the single biggest daily time sink: security staff spend an average 4 hours 43 minutes a day managing tools, and 73% have missed a critical alert
- Exploited vulnerabilities are now the top breach entry point (31% of incidents), yet only 26% of known-exploited flaws get fully fixed
- 83% of ransomware is deployed outside business hours, when most IT teams are not watching
- Teams spend 12 working weeks a year on compliance evidence and 9 weeks on vendor security reviews
- 49% of UK businesses have a basic cyber skills gap, and 70% already use an external provider but still feel exposed
- The thread running through all ten: these are not technology gaps. They are people and time gaps.
About this research: Sources span public surveys and reports from 2023 to 2026 (UK Government, NCSC, DSIT, ISC2, Verizon, Vanta, Kaseya, Datto, Coro, Heimdal, Veeam, CoreView, Nudge, Ivanti, ConnectSecure, Proofpoint), plus practitioner posts from Reddit. Many vendor-sponsored surveys are included where useful for spotting pain points; the UK Government sources (CSBS, DSIT, NCSC) serve as the independent anchor throughout. Where vendor surveys cover a different population from the UK 50 to 2,000 staff target, this is noted.
Before ranking the challenges, it helps to understand who carries the load. In UK medium businesses (50 to 249 staff), the person most responsible for cyber security is the IT director (13%) or an IT manager, technician or administrator (14%), according to the DSIT and Home Office Cyber Security Breaches Survey 2025/26. Security is not a specialist function. It sits with general IT people who are also running the helpdesk.
The numbers that frame the challenge:
The picture is clear: the threat is rising, the teams are small, and outsourcing alone is not solving it. DSIT's 2025 skills report found that 23% of businesses that outsource security cannot tell whether their provider is good value. That gap, outsourced but still not covered and unable to see the value, is where most of the ten challenges below take root.
|
Rank |
Challenge |
Headline evidence |
|---|---|---|
|
1 |
Alert triage and console overload |
4h 43m/day on security tools; 73% missed a critical alert |
|
2 |
Patching and vulnerability prioritisation |
Exploited vulns now #1 breach vector (31%); only 34% of UK firms patch within 14 days |
|
3 |
Skills gaps and no out-of-hours cover |
83% of ransomware lands outside business hours; 49% UK skills gap |
|
4 |
Compliance evidence, Cyber Essentials and insurance |
12 working weeks/year on compliance; 61% spend more time proving than improving |
|
5 |
Phishing, BEC and the user-reported email queue |
Phishing hits 38% of UK businesses; only 11.88% of user-reported emails are actually malicious |
|
6 |
Identity: joiners, movers, leavers and MFA gaps |
5 hours per leaver; 79% of ransomware now starts with identity techniques |
|
7 |
Tool sprawl and integration |
Average 11.55 security tools; 46% spend more time maintaining than defending |
|
8 |
Microsoft 365 config drift and SaaS sprawl |
10,000+ M365 settings; 38% detect tampering manually |
|
9 |
Backup and ransomware recovery readiness |
89% had backups targeted; only 10% recovered more than 90% of data |
|
10 |
Board reporting, budget justification and supplier assurance |
Board cyber updates fell from 78% to 70% in UK medium businesses |
Alert triage is the single biggest daily time sink for UK IT security teams. Security staff at mid-market firms spend an average of 4 hours 43 minutes a day managing security tools, and monitoring security platforms is the most time-consuming task for 52% of them, ahead of patching. The consequence: 73% have missed, ignored or failed to act on a critical alert, with lack of staff and lack of time the two most common reasons (Coro SME Security Workload Impact Report, n=500).
Every security tool raises alerts. EDR, M365 Defender, firewall, email filter, SIEM, backup: each has its own console and its own noise floor. In a 50 to 2,000 person firm, the person reviewing all of them is usually the same person running the helpdesk.
The alert volume data is consistent across independent sources:
"Every morning there is a wall of stuff that technically matches a detection rule and practically means nothing. The gap between those two things is where most of the workday disappears." (IT manager, r/ITManagers)
"The cycle you described is basically every mid-size company IT experience right now. The market just sold everyone on detection coverage without thinking about what happens when that coverage generates 900 alerts a day." (reply in the same thread)
Tuning takes time the team does not have, so noise grows, which leaves even less time to tune. Each new tool adds another alert stream. This is the tuning debt loop: the backlog compounds until teams triage only the loudest alerts and hope the rest are benign.
The fix is not more detection. It is someone who has already filtered the noise before it reaches the IT manager, and who acts on the real alerts without waiting to be asked.
Patching is the second most time-consuming security task in mid-market firms, and it is also where the consequences of falling behind are now most severe. Exploitation of vulnerabilities is the most common initial access vector for breaches at 31%, up from 20% the previous year (Verizon DBIR 2026). For EMEA breaches specifically, that figure rises to 47%.
The remediation numbers make the risk concrete:
The volume of findings is not the core issue. The inability to prioritise them is.
"Backlog is around 62k findings right now. Every scan cycle adds another few thousand, so even when teams close tickets the overall number barely moves. There are so many 'critical' findings sitting open that people stopped reacting to the label." (security team of five, Reddit)
Ivanti's 2025 risk-based patching report found that 39% of security professionals struggle to prioritise remediation and patch deployment, with 35% struggling to stay compliant as a result. When every finding is rated urgent, nothing is actually prioritised.
The volume of CVEs keeps rising, severity scores do not reflect real-world exploitation risk, patching requires downtime the business resists, and ownership is blurred between security and operations. In a 50 to 2,000 person firm, both hats sit on the same head.
The practical need is not a longer list of findings. It is a short weekly list: the ten things that are actively exploited in the wild, present on systems that matter, with a clear fix or workaround. That output also answers the Cyber Essentials auditor and the cyber insurance questionnaire simultaneously.
This is the structural problem underneath challenges 1 and 2. A small IT team covers 9 to 5. Attackers do not.
83% of ransomware binaries are deployed outside the victim's local business hours (Sophos Active Adversary Report 2025). The median time from initial breach to first attack on Active Directory is just 11 hours. The median time to data theft is just over three days. By the time the IT manager arrives on Monday morning, the damage is often already done.
The impact of an encrypting ransomware attack on the IT team itself is severe: 41% report increased anxiety, 40% increased pressure from leadership, and in the UK specifically, 43% report more workload and 24% saw their team's leadership replaced (Sophos 2026).
A 24/7 in-house security rota requires five or more skilled people. No 50 to 2,000 person organisation will fund that for security alone, and hiring is increasingly difficult even for those that try. The only realistic answer for this segment is external cover for the hours the internal team cannot staff.
"Outsource it. Let a 24/7 SOC monitor all your devices. They can do instant containment while you're sleeping." (advice given in a Reddit thread on alert fatigue)
"Mainly because I'm just on my own and it was felt that it would be nice for me to have some professional advice and guidance." (UK CSBS 2025/26 interview, medium wholesale business, on why they bought cyber insurance)
Compliance is no longer a once-a-year exercise. The volume of evidence requests, from insurers, customers, auditors and certification bodies, has grown to the point where it competes directly with actual security work for the IT manager's time.
Teams spend approximately 10 hours a week (12 working weeks a year) on compliance tasks such as evidence collection and policy reviews, plus a further 7 hours a week (9 working weeks a year) on vendor security reviews. 61% say they spend more time proving security than improving it; 77% say stakeholders now demand verified proof of compliance, up from 65% (Vanta State of Trust 2025, n=2,500 across UK, US and Australia).
The UK context makes this particularly acute:
"The questionnaire is forty pages now, up from a handful a few years ago, and it is no longer yes or no. Pulling clean evidence out of all of it is a week of screenshots that still look like a patchwork." (security lead, mid-size company, Reddit)
"Last year it was three checkboxes. This year it reads like an audit." (Reddit, on insurance renewal)
Evidence lives in many consoles, is gathered by hand once a year, and is out of date the day after. Each insurer, customer and framework asks the same questions in a different format. The work lands on the IT manager without extra time or budget to do it.
The opportunity here is straightforward: if monitoring and patching data is already being collected, it can also become the evidence pack. Dated, exportable reports showing MFA coverage, EDR coverage, patching status and backup health answer Cyber Essentials, insurance renewals and customer questionnaires from the same underlying data.
Phishing is the most common attack on UK businesses and the most disruptive when it succeeds. It is also one of the most labour-intensive to manage, because every user report has to be checked: the one you skip could be the one that is real.
Phishing affects 38% of UK businesses and is the most disruptive attack for 69% of those breached. Among breached businesses, 51% experienced only phishing, up from 45% the year before (CSBS 2025/26). Malicious email (26%) and phishing (24%) together account for half of all ransomware root causes globally (Sophos State of Ransomware 2026).
The triage burden is significant because most reports are harmless. In Microsoft's live sample of user-reported emails, only 11.88% were actually malicious (Microsoft Security Copilot phishing triage RCT, arXiv 2025). The remaining 88% still require a human to check them.
Additional data points:
AI is making phishing lures cleaner, cheaper and harder to distinguish from legitimate email. Every staff report has to be checked, because the one you ignore could be the start of a business email compromise. It is low-skill but endless work that interrupts everything else on the IT manager's list.
Identity is now the primary way attackers get in. 79% of ransomware attacks start with identity-based techniques (Sophos 2026 via DQ Channels). In Sophos incident response cases, attackers logged in rather than broke in 56% of the time, and MFA was missing in 63% of breached organisations (Sophos Active Adversary Report 2025).
Despite this, identity management remains largely manual, ticket-driven, and dependent on managers remembering what access their staff had.
"Supervisors and managers don't always remember everything their employee had access to. Verifying what someone actually has means logging into each platform individually to check." (IT lead at a 1,000 person, 30-site firm, Reddit)
Not every application is behind single sign-on (SSO tiers cost extra). HR does not always notify IT in time. Managers cannot recall what access people had. Access reviews are skipped because they take too long. The result is an identity surface that grows with every hire, every SaaS subscription, and every leaver who was not fully offboarded.
Mid-market security teams are not short of tools. They are drowning in them. The average mid-market firm runs 11.55 separate security tools, and it takes an average of 4.22 months to make a new tool operational. 53% deal with vendor updates to endpoint agents daily or weekly. 85% plan to consolidate (Coro SME Security Workload Impact Report).
The result is not better security. It is more maintenance work.
Tools are bought one incident or one audit at a time. Nobody owns the integration work. And removing a tool is risky and time-consuming in itself, so the stack grows and the swivel-chair work compounds.
The worst outcome is a new tool that technically covers everything but becomes one more console nobody has time to watch. (This is a direct quote from a Reddit thread on choosing MDR/XDR for a 400-endpoint firm, and it captures the trap precisely.)
Microsoft 365 has more than 10,000 configuration settings. They change when Microsoft releases updates. They drift when admins make one-off adjustments under pressure. And most mid-sized organisations have nobody whose job it is to watch them continuously.
The scale of the problem is significant:
At a 1,000-employee organisation, a new SaaS account is created roughly every 20 minutes (Nudge Security platform data). Each new application potentially adds new data exposure, new permissions, and new offboarding complexity. For smaller organisations the pace is slower but the oversight is typically weaker.
24% of security professionals report misconfigured systems as a direct consequence of skills shortages (ISC2 2025).
Microsoft changes settings and licences constantly. The admin surface spans multiple portals (Entra, Exchange, SharePoint, Intune, Defender, Purview). AI tools like Copilot expose years of loose sharing permissions that were never reviewed. Most mid-sized firms have no continuous watch on any of this.
Most organisations have a backup product. Fewer have a backup that will actually work when ransomware hits. The gap between having backups and being able to recover from them is one of the most dangerous false assurances in security.
89% of organisations hit by ransomware had their backup repositories targeted, with an average 34% of backup data modified or deleted. Only 10% recovered more than 90% of their data; 57% recovered less than half. Only 44% of ransomware playbooks include backup verification (Veeam Ransomware Trends 2025, n=1,300).
UK-specific data from Sophos tells a stark story:
"Require quarterly test restores. 3-2-1 means nothing until you've actually restored something." (advice to a new security manager, Reddit)
Restore testing is the job that always slips. Backup is often owned by a different team or managed separately from security, so the two functions are not joined up. The playbook exists in theory; in practice, it has not been tested since it was written.
The final challenge is translating security into language that unlocks budget and satisfies the board, customers and insurers. IT managers are not trained to do this, and they rarely have the clean, regular data needed to do it well.
The UK data shows the gap is widening:
"Will he understand what I'm telling him? Probably not." (IT lead, medium transport business, CSBS 2025/26)
"I don't know that they think about cyber security. They just want to tell clients we are secure." (small professional services business, CSBS 2025/26)
"Leadership ignores the security team's recommendations for months, then the insurer asks the same question and suddenly the budget appears." (Reddit)
IT managers are not trained to translate risk into financial terms, and they have no regular, clean data to report from. External triggers (an insurer's question, a customer security questionnaire, a high-profile incident in the news) are what actually unlock budget. The implication is that security conversations with boards and budget holders should be timed around those triggers, not around the IT team's internal calendar.
These are not mainly technology gaps. Most organisations in the 50 to 2,000 staff range already own decent tools: an EDR, M365 security, a firewall, a backup product. What they lack is the people and hours to run those tools every day and night, decide what matters, fix it, and prove they did.
The independent UK data confirms this. 70% of UK medium businesses already use an external cyber security provider (CSBS 2025/26), yet 49% still have a basic skills gap. 23% of businesses that outsource cannot tell whether their provider is good value (DSIT 2025).
Outsourcing alone is not the answer. The question is whether the external provider actually covers the hours and decisions the internal team cannot, and whether it produces evidence the IT manager can show to insurers, customers and the board.
The three challenges that matter most for most organisations, in order:
Challenges 5 and 6 (email and identity) are close behind, and the 2026 data is clear that these are now the primary ransomware entry routes. Any security programme that covers 24/7 monitoring without also covering Microsoft 365 identities and email is leaving the main door open.