The government’s annual survey of cyber security skills, published on 29 September, comes with a headline that writes itself. As The Register puts it, more than half of UK businesses lack confidence in basic cyber skills: 57 per cent, or about 808,000 firms, up from 49 per cent, about 699,000, a year earlier.

It is a real finding and worth taking seriously. It is also easy to read wrongly, and the wrong reading leads to the wrong fix. So here is what the survey measures, what it found task by task, and why I think the answer for most small businesses is a better set of defaults rather than a training course.

What the number measures

Ipsos and Perspective Economics ran the research for the Department for Science, Innovation and Technology, the latest in an annual series going back to 2018. The survey asked the person responsible for cyber security in each organisation how confident they, or anyone else in a cyber role, would be at carrying out nine basic tasks, a mix of the technical areas Cyber Essentials covers and other basics. Not confident counts as a gap, and a task the organisation has handed to an outside provider does not.

The 57 per cent is the share of businesses not confident in at least one of the nine. A firm not confident in one task counts the same as a firm not confident in any, so the headline is driven by the few tasks where confidence is lowest. The fieldwork ran from August to October 2025, and the margin of error on the business figure is four percentage points either way.

The nine tasks, in order

For businesses, from the largest gap to the smallest: detecting and removing malware (38 per cent not confident), storing or transferring personal data securely (31), restricting the software that runs on devices (28) and setting up configured firewalls (26). Then the gaps narrow sharply: choosing secure settings for devices or software (15), setting up automatic updates (11), setting up new user accounts and authentication securely (10), controlling who has admin rights (9) and creating back-ups (7).

Charities are less confident than businesses on most of the list, and 47 per cent of them are not confident about malware. The public sector is more confident on every task, although its overall gap has nearly doubled in a year, from 14 to 27 per cent. Large businesses do far better than small ones, with a gap of 24 per cent.

Why the rise may be good news

The researchers say the increase “may be due to higher awareness of organisations’ cyber security posture rather than a decline in perceived capabilities”. One cyber lead at a large business put it plainly in the interviews: “I don’t think there’s significantly more attacks, but it’s been a lot more public,” before naming Marks and Spencer, Co-op, Harrods and JLR.

The biggest movements are consistent with that reading. The share of businesses not confident about malware rose from 23 to 38 per cent in a year, and about personal data from 25 to 31. Those are the two areas a board would start asking about after watching well-known retailers’ systems go down for weeks.

A fall in confidence after a year like that is what you would hope to see. Confidence measures what people think they know, and the respondent to worry about is the confident one who should not be. A business that has just discovered it is unsure how it would remove malware is in a better position than one that has never asked.

The basics should not need a specialist

Look again at the top four. Detecting and removing malware, handling personal data, controlling which software runs and configuring firewalls are the tasks where the part-time IT lead in a twelve-person firm is least likely to be confident, and they are also the tasks that should least depend on that person’s confidence.

Malware in 2026 is a job for a product and a service: modern endpoint protection, with somebody watching its alerts who can act on them. Businesses that outsource already treat it that way, and among those that outsource anything, detecting and removing malware is the task they hand over most often, at 84 per cent. Firewall configuration and application control belong in the same bracket: set them once, properly, on the business-grade versions of the platforms you already pay for, and let them hold.

The bottom of the list is the encouraging part. Automatic updates, admin rights and back-ups have some of the smallest gaps, and they are also where modern platforms do most of the work by default. The survey does not measure defaults, but my reading is that where the secure option is the default, the gap shrinks, and that is the lesson to scale up.

The survey points at the checklist itself, since the nine tasks sit largely on ground Cyber Essentials covers, which is why I keep recommending it as the place to start. I have written about the five controls that do most of the work and about what certification actually costs, and neither needs a security specialist on the payroll, although a good IT provider helps.

The gap that matters more

The same survey has a number that worries me more than the 57 per cent. Among businesses and charities that have not handed incident response to anyone else, 47 per cent of cyber leads in each are not confident they could deal with a breach or attack. Asked separately about writing an incident response plan, 49 per cent of business cyber leads said they were not confident.

The report also cites the government’s Cyber Security Breaches Survey, which found that only a quarter of businesses have a formal incident response plan. That is the gap that turns a bad day into a bad month, and it is the easiest of all to close, because a first plan fits on one page: who decides, who you call, how you reach them if email is down, where the back-ups are and how long a restore takes. I set out how to write one in incident response planning for a small business.

Help is closer than most people think. In England, Wales and Northern Ireland, Report Fraud, which replaced Action Fraud, takes calls from organisations under cyber attack on 0300 123 2040; in Scotland, call Police Scotland on 101. The police-led Cyber Resilience Centres across England and Wales offer free and affordable help to smaller organisations.

Four questions for the owner

For a small business owner or a charity trustee, the survey boils down to four questions. Which of the nine tasks could we do confidently today, and which have we given to someone else? If someone else, is anyone actually watching the alerts?

Is automatic updating switched on everywhere, including the equipment nobody thinks about? And do we have the one-page plan, and has anyone read it since it was written?

The point

The survey measures confidence, and confidence falling after the attacks of 2025 is less alarming than the headline suggests. The fix is not to turn every office manager into a malware analyst.

It is to make the secure option the default, hand the specialist jobs to specialists, and write down what happens on the bad day. That is how a small business gets its good mornings back.