Collection

Cyber security longitudinal survey

An ongoing study looking at the cyber security behaviours of organisations.

The Cyber Security Longitudinal Survey (CSLS) helps us better understand cyber security policies and processes within medium and large businesses and high-income charities. It explores the links over time between these policies and processes and the likelihood and impact of a cyber incident.

  • The first wave of fieldwork was carried out during 2021, with the report published on 27 January 2022.
  • The second wave of fieldwork was carried out during 2022, with the report published on 9 December 2022.
  • The third wave of fieldwork was carried out during 2023, with the report published on 20 March 2024.
  • The fourth wave of fieldwork was carried out during 2024, with the report published on 6 February 2025.

This research is part of the government’s work to improve UK cyber defences also informs the government’s work to improve the cyber resilience of organisations across the UK economy.

For more information on the cyber security behaviours of organisations, please see the annual Cyber Security Breaches Survey.

Documents

Updates to this page

Published 28 January 2022
Last updated 6 February 2025 + show all updates
  1. The results from wave four of the survey have been added to the page.

  2. Wave three results added to the collection.

  3. Added the wave two results report.

  4. First published.