Thursday, 1 October 2026

Where technology leaders come to think out loud

The BriefCybersecurity

Half of surveyed security providers refer to UK security codes

Government-commissioned research maps a supply side made up mostly of micro and small firms, where penetration testing dominates and services for securing AI after deployment are still patchy

The facts
  • DSIT’s 2026 sectoral analysis counted 1,141 software security and 111 AI security providers in the UK
  • Researchers contacted 1,906 software and 127 AI security providers to reach their sample
  • Almost two in five (39%) software security providers do not use AI or machine learning in their services
  • Seven in 10 AI security providers say substantially more client demand would encourage them to offer more services
What to do now

Security leaders can use the software code as a buying tool: put its principles into supplier questionnaires and renewal terms, and ask any provider to show which principles each service covers rather than accepting a pen test report as proof. For AI systems already in production, ask what the provider offers for monitoring and retirement before signing. With smaller suppliers, check capacity and continuity as closely as skills.

“providers perceive that security is often not a priority for clients”Pye Tait Consulting, report for the Department for Science, Innovation and Technology

Around half of surveyed software and AI security providers refer to the government’s security codes of practice when creating or selling services, according to research for the Department for Science, Innovation and Technology (DSIT) published on 10 July 2026. The figure was 48% among software security providers and 50% among AI security providers.

Pye Tait Consulting surveyed 200 software security providers and 50 AI security providers between November 2025 and January 2026. The codes in question are the Software Security Code of Practice, written with industry and the National Cyber Security Centre (NCSC) to set baseline principles for software suppliers, and the AI Security Code of Practice, on which the European Telecommunications Standards Institute (ETSI) global standard EN 304 223 builds. Awareness is high: 81% of software security providers know their code, and 92% of AI security providers know theirs.

Just over half (51%) of the software security providers employ fewer than 10 people and a further 34% are small firms with 10 to 49 staff. Penetration testing ranks in the top three under every theme of both codes except communication with customers. Coverage is thinnest on the AI side for deployment, maintenance and end of life, where the report finds no single service listed by more than a handful of providers. More than half of providers (55% in software, 51% in AI) say legislation would encourage them to widen what they offer.

Sources
  1. Department for Science, Innovation and Technology (Pye Tait Consulting), “Mapping of the AI and software security services market”, research, 10 July 2026. https://www.gov.uk/government/publications/mapping-of-the-ai-and-software-security-services-market/mapping-of-the-ai-and-software-security-services-market
  2. GOV.UK, “Mapping of the AI and software security services market”, publication page, 10 July 2026. https://www.gov.uk/government/publications/mapping-of-the-ai-and-software-security-services-market
AdvertisementZoomInfo
More from The BriefAll briefs
Datel

Evergreen’s Pine Services Group buys Sage partner Datel

Office for National Statistics

ONS finds a third of UK firms with 10 or more staff use AI

Claranet

Claranet buys rival MSP Six Degrees through an administrators’ sale

Information Commissioner’s Office

UK organizations now need a data protection complaints process

Get the briefs every week in The VETTDD Briefing.