Addressing the UK’s trust gap in cyber risk management

CyXcel's research reveals that a lack of trust in third-party vendors leaves UK businesses exposed to escalating digital threats.

  • Thursday, 17th July 2025 Posted 11 months ago in by Aaron Sandhu

New research by CyXcel, a global cybersecurity consultancy, has highlighted a worrying gap in the UK's digital risk landscape. Nearly three in ten UK risk managers claim insufficient trust in third-party vendors, escalating their risk factors and threatening their business stability.

This trust deficit is both a vendor and a visibility issue. According to CyXcel, over a quarter of UK respondents are unaware of the risks they manage, complicating vendor evaluations. As companies increasingly outsource areas like cyber incident response (26%), AI adoption (20%), and geopolitical risk management (21%), they must confront a fragile risk stance without trusted partners or internal clarity.

The challenge intensifies with converging threats: AI-driven attacks, geopolitical instability, and sophisticated cybercrime. These conditions demand more than mere contracts or one-time vendor reviews. Instead, businesses need intelligence-led, validated partnerships, alongside systems for real-time assessment, questioning, and course correction.

Compounding this, organisations investing £75,000 to £100,000 yearly in risk tools remain unsure of their effectiveness. One in four risk managers feels overwhelmed by the complexities they face. It's crucial to evaluate whether outsourcing is strategic or stems from inadequate internal risk comprehension.

CyXel's Digital Risk Management (DRM) platform addresses these challenges by offering insights into AI-related risks across all sectors, regardless of organisation size. The DRM platform aids in identifying risks and formulating appropriate policies and governance. Notably, it brings together cyber, legal, technical, and strategic insights, developed from decades of experience.

This platform provides real-time vendor assurance and remediation, assuring organisations of their third-party integrity. In light of rising supply chain attacks and stringent third-party oversight regulations, CyXcel’s DRM is shifting organisations from a reactive to a resilient posture.

Jamf survey highlights emerging challenges as AI adoption deepens across organisations, underscoring the growing need for effective governance to...
Smartsheet integrates AI capabilities with major platforms, supporting enterprise teams in work management and data-driven insights.

Understanding the evolving landscape of cyber threats

Posted 4 days ago by Sophie Milburn
The latest insights from Check Point Software highlight the persistent cybersecurity challenges faced globally, amid evolving threats and...

Inforcer expands with Threat Detection and Response

Posted 1 week ago by Sophie Milburn
inforcer launches its latest solution to provide complete threat detection and response, aiming to strengthen security for Managed Service Providers.
Keepit earns top marks in SaaS backup and recovery, helping demonstrate customer satisfaction and secure data handling globally.
CyberSmart's latest findings reveal an increasing focus on third-party risk, with MSPs facing new challenges amid regulatory changes.
New capability aims to improve visibility, monitoring, and control of AI agents in enterprise environments as organisations increasingly adopt...
Hack The Box and Semperis form an alliance to strengthen cybersecurity through hands-on skills development and identity security strategies.