<?xml version="1.0" encoding="UTF-8"?><ns2:project xmlns:ns1="http://gtr.rcuk.ac.uk/gtr/api" xmlns:ns2="http://gtr.rcuk.ac.uk/gtr/api/project" xmlns:ns3="http://gtr.rcuk.ac.uk/gtr/api/fund" xmlns:ns4="http://gtr.rcuk.ac.uk/gtr/api/person" xmlns:ns5="http://gtr.rcuk.ac.uk/gtr/api/project/outcome" xmlns:ns6="http://gtr.rcuk.ac.uk/gtr/api/organisation" ns1:created="2026-08-26T13:36:10Z" ns1:href="http://gtr.ukri.org/gtr/api/projects/2D847953-6A70-4C4C-BB23-937A855EB1B0" ns1:id="2D847953-6A70-4C4C-BB23-937A855EB1B0"><ns1:links><ns1:link ns1:href="http://gtr.ukri.org/gtr/api/persons/BA1C3C7D-0950-4110-936C-EEAD374BF62A" ns1:rel="PM_PER"/><ns1:link ns1:href="http://gtr.ukri.org/gtr/api/organisations/53FD1D9C-F4AC-4657-9AC3-97F5A8E06CB3" ns1:rel="LEAD_ORG"/><ns1:link ns1:href="http://gtr.ukri.org/gtr/api/organisations/53FD1D9C-F4AC-4657-9AC3-97F5A8E06CB3" ns1:rel="PARTICIPANT_ORG"/><ns1:link ns1:end="2021-04-29T23:00:00Z" ns1:href="http://gtr.ukri.org/gtr/api/funds/91F4983C-CD58-4EEE-A11D-28EB490719F6" ns1:rel="FUND" ns1:start="2020-11-01T00:00:00Z"/></ns1:links><ns2:identifiers><ns2:identifier ns2:type="RCUK">85374</ns2:identifier></ns2:identifiers><ns2:title>Improving the cyber security of companies that allow distributed devices access to corporate networks to facilitate remote working resulting from the longer term COVID-19 response.</ns2:title><ns2:status>Closed</ns2:status><ns2:grantCategory>Collaborative R&amp;D</ns2:grantCategory><ns2:leadFunder>Innovate UK</ns2:leadFunder><ns2:abstractText>According to Gallagher, in 2019_: &amp;quot;1.4m UK SMES suffered a cyber-attack/significant security incident. This cost the economy &amp;pound;8.8bn with the average attack costing &amp;pound;6,500\. 17% spent \&amp;gt;&amp;pound;10k to combat an incident with 10% paying out \&amp;gt;&amp;pound;20k. 23% of SMEs couldn't survive for \&amp;gt; a month if unable to trade following an incident ... 57,000 SMEs could be at risk of collapse.&amp;quot;_

COVID-19 has dramatically increased these risks. Cyber-criminals are adapting their tactics and targeting endpoint vulnerabilities exposed by the surge in home working. In Q2, UK businesses reported a 92% increase in cyber-attacks (VMWare). ZNET identifies a 72% increase in file-encrypted malware in the last three months and notes that ransomware attacks are now focused on stealing data as well as encrypting it. As a recent example, on 17 July, the NCSC exposed Russian attacks on Covid-19 vaccine developers.

These risks are unlikely to reduce in a post-COVID environment. A recent Gartner poll shows that 48% of employees will likely work remotely at least part of the time after COVID-19 versus 30% before the pandemic.

SMEs are particularly vulnerable to remote working attacks as they typically lack the resources required to protect against cybercrime. Given the increased number of attacks, over 100,000 UK SMEs could now be at risk of collapse.

Per Aon &amp;quot;_Over the past few years, bring your own device (&amp;quot;BYOD&amp;quot;) programs have increased in popularity as organizations aim to increase employee mobility._ _In 2018, 45% of UK businesses allowed employees to use their own devices.&amp;quot;_ A July 2020 survey by CyberArk shows that 77% of remote employees are now using unmanaged, insecure BYOD to access corporate systems. Per Aon _&amp;quot;Ideally, entirely separate devices should exist for corporate and personal data. However,_ _most organizations that did not follow a policy of issuing employees separate corporate devices prior to the coronavirus outbreak are highly unlikely to incur the costs of doing so now._ _...**As a result, there is an increased risk of data leakage particularly if personal devices are shared between family members or insecure network connections are being used**._&amp;quot;

SMEs, while among the most vulnerable organisations, lack the specialists to assist them defend against the threat. Cyber risk management needs to be democratised to allow non-specialists to manage the basics of cyber defence.

The Innovation Focus is to extend and repurpose InsurTechnix's existing software to meet the needs that Aon and many others describe by:

**1\. Providing a means by which SMEs can ensure that laptops and phones, including BYOD, being used to access their networks meet the minimum security thresholds to defend against/avoid the substantial majority of threats;** and,

**2\. Characterising, quantifying and reporting the data held on distributed devices, including BYOD, so that the risk of a data breach can be minimised by reducing the nature and volume of data held in higher-risk environments.**</ns2:abstractText></ns2:project>