Many organizations sit below the “cyber poverty line”: they skip basics like two-factor authentication and timely patching, making it easier for attackers to breach them through phishing, stolen credentials, and by exploiting known vulnerabilities. For instance, the chart here shows the security practices of businesses and charities in the UK, from a nationally representative 2025/26 survey by the UK Department for Science, Innovation and Technology. Fewer than half of UK businesses and charities use any two-factor authentication, or have a policy to apply security updates within two weeks. A quarter of UK businesses do not have a firewall covering their whole network. 📷