How to prevent the next Asos? Give businesses cybersecurity tax relief
With Asos just the latest big British retailer to be the victim of a cyber hack, it’s time for the government to start incentivising businesses to up their security, writes Matt Warman
On Tuesday, Asos customers across the UK were sent pop-up messages from its app that appeared to be from hackers.
The clothing giant will need time to figure out exactly what happened, but shoppers getting concerning messages through an app they trust will worry businesses, markets and our government.
And it should, because this story isn’t really about one retailer. Every few months we see another household name experiencing an attack: JLR and M&S for example. It isn’t just the private sector either: in July the Department for Education confirmed hackers had taken more than 600,000 records. Every time, we see it as an IT department issue when it’s a genuine economic problem. When systems go down, orders stop, services drop, shelves are empty and customers lose confidence.
To be fair to the government, its ambitions are the right ones as the Cyber Security and Resilience Bill, the Cyber Growth Action Plan and even cyber’s place in the Industrial Strategy all point in the right direction, building on cross-party work in Parliament in recent years. But calling something a priority without money behind it means very little.
When it comes to cybersecurity, there are three key things the government can do in the Budget which would genuinely make a difference.
How the government can back cyber
Firstly, we need to help businesses pay for protection before they’re targeted, and make it cheaper to buy. Right now, cybersecurity gets no direct tax relief and little in the way of incentives for UK businesses to invest more in it. Targeted relief or incentives on accredited products and services from UK providers would change that, and help the smaller firms who feel it’s too costly to try.
Secondly, we need to give small cyber firms a fair chance at public contracts as they make up 77 per cent of the whole cyber sector. They are also where some of the most innovative work in the UK is happening right now. The problem is that procurement still rewards whoever has the biggest bid team. We need to keep this in mind if we want to have a home-grown cyber industry, a key ambition of Burnham’s domestic supply chains.
Finally, we need to make sure there is support for organisations newly brought into scope by future legislation and regulation, so compliance costs don’t fall hardest on those least able to absorb them. Last month’s figures show 57 per cent of businesses now lack basic technical cyber skills, up from 49 per cent last year. Businesses cannot comply with rules nobody in the business understands. Funding for training and awareness alongside any new regulation and policy would make firms safer, and help them understand what’s being asked of them.
None of this is expensive by Budget standards, and it’s cheaper than the alternative. Last year’s attack on JLR cost the economy £1.9bn, needed a £1.5bn government loan guarantee and contributed to 4,000 job cuts. This won’t be a one-off. The National Cyber Security Centre (NCSC) was dealing with four nationally significant attacks a week last year, and expects AI to increase both the number and impact of attacks. Without action, more of that bill could land on taxpayers.
As we wait for more information to come out on Asos, the ask for the Chancellor is clear: we need to pay for resilience now to avoid paying a lot more later. Invest in resilience, not consequence.
Matt Warman is chair of the Cybersecurity Business Network (CBN) and former UK digital and cyber minister