01543 524594  ·  hello@initialit.co.uk
CYBER ESSENTIALS · MICROSOFT PARTNER · UK HELPDESK · 5.0 ★ GOOGLE
HomeBlog › Cyber Security

Is data security really your top priority?

Most business owners say data security matters most. Far fewer could prove it in an audit. Here is how to close that gap.

Andy Price · Founder15 June 2026 · 6 min read

There is an interesting disconnect in business right now, and it is worth knowing which side of it you are on.

Research suggests around seven in ten IT leaders rank data security as their top concern, yet only about a third feel confident they would pass their next audit. If you are not completely sure where all your sensitive data lives or who can access it, you are in the majority. The good news is that this is fixable, and it starts with understanding your own setup well enough to trust it.

Most firms say data security is the top priority but few could pass an audit, explained by Initial IT in Lichfield

Key takeaways

  • Around seven in ten IT leaders say data security is their top priority, but only about a third feel confident they would pass an audit.
  • Most businesses are quietly running hybrid setups: cloud apps added over the years, plus older systems still in place.
  • When data lives in many places, simple questions get hard: who can access what, where sensitive data sits, and whether permissions are reviewed.
  • Adding AI on weak data foundations amplifies the problem, because AI depends on clean, well-governed data.
  • Good security is understanding your environment well enough to trust it, and that starts with a data and access review.

What is the confidence gap?

Most IT leaders will tell you data security is their number one priority when upgrading or modernising. Far fewer say they feel extremely confident they would pass a regulatory audit. That gap between what we know matters and what we can actually prove is the real issue.

You might not describe what you are doing as modernising hybrid infrastructure, but that is effectively what has happened in most companies over time.

You are probably running hybrid IT already

Over the years you have added cloud software: Microsoft 365, cloud accounting, a CRM, file sharing. At the same time, you may still rely on an older system or server that has been in place for a long time.

That mix is completely normal. It is also where things get complicated, because your data no longer lives in one tidy place.

The questions that get hard to answer

When data is spread across many systems, some simple questions become surprisingly tricky:

  • Who has access to what, and does that still match what people actually need?
  • How does information move between your systems?
  • Are any old platforms still holding sensitive data?
  • Are access permissions reviewed regularly, or set once and forgotten?

None of this feels dramatic day to day. Everything works, the team logs in, files get shared. But under the surface, complexity quietly builds up, and many businesses are also stretched to find people with the right skills to stay on top of it.

Where AI makes it riskier

Lots of businesses are exploring AI to improve efficiency, and that can be a positive step. But AI depends on clean, well-managed, accessible data. If your foundations are not solid, adding AI can amplify the problem rather than fix it.

There is also the everyday risk of staff pasting confidential information into public AI tools like ChatGPT. Good data governance is what keeps that in check.

How to close the gap

The fix is not ripping everything out. It is usually a review followed by a few targeted improvements: mapping where your sensitive data actually lives, tightening access so people only have what they need, switching on multi-factor authentication, encrypting devices, and securing or retiring old systems. Cyber Essentials then gives you a clear baseline and evidence you can show clients and insurers.

This matters even more for the law firms and accountancy practices we work with, who carry SRA or regulatory duties on top of GDPR. We handle all of this as part of managed cyber security, with dedicated support for law firms and accountants across Lichfield and Staffordshire. Done properly, an audit feels manageable rather than stressful.

Frequently asked questions

What counts as a data security audit?

It could be a Cyber Essentials assessment, a questionnaire from a client or insurer, or a regulatory review such as the ICO or SRA. They all get a lot easier once your foundations are in place and you can show how data is protected.

Where do most small businesses go wrong?

Usually over-broad access, old accounts left active after someone leaves, permissions that are never reviewed, and sensitive data scattered across too many places. None are dramatic on their own, but together they add up.

Do we need to rip everything out and start again?

No. In most cases it is a review plus targeted fixes, not a rebuild. The aim is to understand and tidy what you already have so you can trust it.

How does Cyber Essentials help?

It gives you a recognised baseline of sensible controls and the evidence to prove it. That reassures clients and insurers, and it forces the basics to be done properly.

Can you assess our setup?

Yes. We run a data and access review as part of managed cyber security, then give you a clear, plain-English plan. Give us a ring on 01543 524594 or get in touch.

– Andy Price, Founder & MD, Initial IT · 01543 524594 · hello@initialit.co.uk