Third-party monitoring: Investment without context
Aside from CVEs, UK companies report that third-party exposures are what their organizations struggle to understand and prioritize the most, above cloud misconfigurations, critical infrastructure exposures, and exposed credentials.
While 43% of UK companies say they continuously monitor all third-party relationships—a higher rate than many global peers—many still struggle to make sense of the data. In today’s post-NIS landscape, continuous monitoring is no longer a competitive edge—it’s a compliance expectation. But without the intelligence to interpret what that data means for the business, it’s just noise. UK security teams need clarity, not complexity, to make confident decisions, and that starts with risk teams turning data into actionable insight.
Strategic priorities differ globally
Continuous monitoring was rated the number one security and risk initiative by the global respondent pool, but in the UK identity and access management and risk assessment topped the list. Continuous monitoring ranks third, while exposure management comes in sixth. Third-party risk management, however, is near the bottom.
This mismatch suggests that while threat awareness is increasing, strategic alignment around exposure visibility is lagging. As adversaries grow more sophisticated, this is a gap UK enterprises can no longer afford.
Which security and risk initiatives do you consider most urgent for the next year (2025)? Select top three
|
UK
|
Total
|
| Identity and access management |
32% |
29% |
| Security and risk assessment |
31% |
30% |
| Continuous monitoring |
29% |
31% |
| Vulnerability management |
28% |
29% |
| Software supply chain security |
26% |
24% |
| Exposure management / attack surface management |
25% |
21% |
| Compliance reporting and auditing |
21% |
18% |
| Endpoint management / endpoint detection and response |
19% |
25% |
| Security training |
19% |
22% |
| Third-party risk management |
19% |
16% |
| Application security |
18% |
16% |
| Incident response planning |
14% |
11% |
Board-level communication: A pivotal challenge
Perhaps the clearest indicator of this maturity gap lies in how risk is communicated at the board level. Over half of UK respondents (52%) report struggling to translate technical security data into business risk, far outpacing the global average. An equally common barrier is a lack of cybersecurity fluency among board members themselves.
These communication challenges undermine strategic alignment and weaken support for critical initiatives. To overcome them, organizations need cyber risk intelligence that bridges the gap between security operations and business outcomes.
The path forward: From visibility to action
Improving exposure visibility is not just about identifying more threats—it’s about equipping leaders with the context to act decisively. Cyber risk intelligence, when properly integrated, provides that context. It transforms raw data into prioritized, business-aligned insights that support smarter decisions, faster response, and reduced burnout.
For UK organizations and their global peers, the imperative is clear: move beyond surface-level monitoring and begin to build a comprehensive, context-driven approach to cyber risk.
Read the full 2025 State of Cyber Risk and Exposure report to explore how leading organizations are meeting this challenge—and what steps others can take to follow suit.