TechForge

August 20, 2025

  • UK security leaders warn AI tool DeepSeek poses major cyber risks.
  • 4 in 5 CISOs urge UK to regulate DeepSeek over breach fears.

Businesses are under pressure where trade disputes, high interest rates, and rising cyber threats make it harder to grow without taking on more risk. At the same time, artificial intelligence is spreading fast. AI offers benefits, from automation to cost savings, but also exposes companies to new threats – many of them hidden.

In the UK, AI use is now common at work. KPMG research showed that while 69% of employees use it, only 42% trust it. Just over half are comfortable with its wider use, and that gap between adoption and trust highlights the problem that businesses and regulators face.

National and regulatory pressures

AI has moved beyond office tasks and into international relations. In February 2025, UK Prime Minister Keir Starmer and US President Donald Trump unveiled a new deal centred on AI and advanced tech. Starmer said, “Instead of over-regulating these new technologies, we’re seizing the opportunities they offer.”

Domestically, the Artificial Intelligence Regulation Bill – first tabled in 2023 – has resurfaced, being reintroduced in March 2025. The Bill reflects concerns over governance, cyber risks, and privacy. For organisations, this means AI is back on the boardroom agenda, and security leaders are being challenged to demonstrate how it can be used safely.

Challenges for security leaders

The shift to hybrid and remote work has made IT estates more complex and vulnerable. Employees work on multiple devices, often outside corporate networks, and AI adds a further layer of risk. For CISOs, this means balancing new regulations, rising cyber threats, and pressure from leadership.

Key concerns include:

  • AI governance: Almost two-thirds of employees admit they use AI platforms of their choice, even if it means bypassing company policy. Security experts also warn of risks from AI tools, with 60% saying they expect more cyber-attacks because of their use. CISOs need clear governance frameworks, policies, and training programmes, according to KPMG’s paper.
  • Remote work security: Legislation has made flexible work a legal right in the UK, but 60% of CISOs say remote work has weakened their cyber resilience. Most agree prevention is not enough – they need better recovery plans, stronger endpoint security, and improved visibility in distributed networks.
  • Resilience against attacks: Ransomware remains the top threat. Half of organisations say they were hit in the past year, and 63% fear the financial loss would cripple them. CISOs say they need to embed resilience into strategies by increasing readiness, investing in recovery, and using AI for defence.

DeepSeek and the AI threat

While companies rush to adopt AI, platforms like DeepSeek raise alarms. Some governments have already banned it from state-owned devices, and businesses are also restricting its use,worried about data security and national security concerns.

Research found nearly two-thirds of employees use AI for tasks, even if it means breaking rules. Sixty per cent of security leaders believe DeepSeek, in particular, increases the chance of cyber-attacks, and the same number say they are rethinking privacy and governance policies as a result.

There is also a strong call for government action. Eight in ten respondents said the UK should regulate or restrict the technology, but many worry the UK is lagging behind the US and EU in cyber standards.

Mixed signals: Investment and skills

Despite concerns, many leaders see AI as a tool to close the skills gap in security. Seventy per cent say it helps fill shortages, and 84% are hiring AI specialists this year. Eight in ten organisations have already sent senior executives to AI training courses, though nearly half feel their security teams are still not prepared for AI-driven threats.

Budget remains a sticking point. While 82% of executives have taken resilience training, 39% of leaders feel their companies don’t give them enough funding to stay secure.

Remote work still a weak link

Remote working continues to complicate cyber defences. Eighty-four per cent of security leaders say it has increased pressure on their networks, and 62% identify remote devices as their weakest point. Most organisations have incident response protocols, but the majority still focus more on prevention than recovery.

Given new legislation that protects employees’ right to request flexible work from day one, companies must assume hybrid work is permanent. That makes it important for CISOs to secure endpoints, expand visibility, and prepare for recovery after a breach.

A resilience-first approach

CISOs feel personal pressure: nearly half say they worry about losing their jobs if a cyber-attack succeeds. With ransomware attacks rising and AI adding new risks, leaders say resilience should a significant part of cyber strategy.

That means:

  • Building readiness into plans.
  • Investing in staff training and defensive use of AI.
  • Balancing prevention with recovery.

Not all trends are negative. The UK government’s 2025 Cyber Security Breaches Survey showed a small drop in reported breaches. Cyber hygiene is also improving overall, with more businesses adopting risk assessments, cyber insurance, formal policies, and continuity planning. Seventy per cent of large businesses now have a cyber defence strategy, though only 57% of medium-sized firms can say the same.

What’s next for CISOs

The environment for security leaders remains tough: AI tools are widespread, ransomware is costly, and remote work creates new vulnerabilities. Yet there are signs that awareness and preparation are improving.

Want to learn more about cybersecurity and the cloud from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London.

Explore other upcoming enterprise technology events and webinars powered by TechForge here.

Author

  • As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

    View all posts

About the Author

Muhammad Zulhusni

As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

Related

September 3, 2026

August 24, 2026

August 11, 2026

August 10, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

12394 view(s)
11525 view(s)
7736 view(s)
5398 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.
Name(Required)