Addressing the UK’s trust gap in cyber risk management

CyXcel's research reveals that a lack of trust in third-party vendors leaves UK businesses exposed to escalating digital threats.

  • Thursday, 17th July 2025 Posted 6 months ago in by Aaron Sandhu

New research by CyXcel, a global cybersecurity consultancy, has highlighted a worrying gap in the UK's digital risk landscape. Nearly three in ten UK risk managers claim insufficient trust in third-party vendors, escalating their risk factors and threatening their business stability.

This trust deficit is both a vendor and a visibility issue. According to CyXcel, over a quarter of UK respondents are unaware of the risks they manage, complicating vendor evaluations. As companies increasingly outsource areas like cyber incident response (26%), AI adoption (20%), and geopolitical risk management (21%), they must confront a fragile risk stance without trusted partners or internal clarity.

The challenge intensifies with converging threats: AI-driven attacks, geopolitical instability, and sophisticated cybercrime. These conditions demand more than mere contracts or one-time vendor reviews. Instead, businesses need intelligence-led, validated partnerships, alongside systems for real-time assessment, questioning, and course correction.

Compounding this, organisations investing £75,000 to £100,000 yearly in risk tools remain unsure of their effectiveness. One in four risk managers feels overwhelmed by the complexities they face. It's crucial to evaluate whether outsourcing is strategic or stems from inadequate internal risk comprehension.

CyXel's Digital Risk Management (DRM) platform addresses these challenges by offering insights into AI-related risks across all sectors, regardless of organisation size. The DRM platform aids in identifying risks and formulating appropriate policies and governance. Notably, it brings together cyber, legal, technical, and strategic insights, developed from decades of experience.

This platform provides real-time vendor assurance and remediation, assuring organisations of their third-party integrity. In light of rising supply chain attacks and stringent third-party oversight regulations, CyXcel’s DRM is shifting organisations from a reactive to a resilient posture.

THE ICONIC uses Datadog to unify its observability, with the aim of supporting a more consistent shopping experience for its 2 million customers.
The MSP Channel Insights Roadshow returned to Manchester, uniting leaders, experts, and partners for a day of insight, strategy, and collaboration.
Guardz taps MSP veteran Rob Rae to guide its channel-focused cybersecurity strategy, helping MSPs protect SMBs amid a rising threat landscape.

The role of observability in the evolution of agentic AI

Posted 2 days ago by Sophie Milburn
A recent global study by Dynatrace highlights observability as crucial for successfully scaling agentic AI solutions.

Cameo Services reveals leadership restructure for 2026

Posted 2 days ago by Sophie Milburn
Cameo Services restructures senior leadership to support international growth following developments in 2025.
NCC Group partners with Delinea to provide cloud-native PAM solutions, helping organisations manage identities, access, and cyber risks in hybrid...
New research reveals UK businesses' evolving approach to resilience, highlighting reliance on AI and automation over traditional measures.
Netskope's report highlights the communication gaps faced by I&O leaders in enhancing AI capabilities.