43%
of UK businesses were breached or attacked in the last year
£0
median cost of the most disruptive breach, but it’s a lottery
38%
experienced phishing – far ahead of anything else
19%
ran any staff training or awareness activity
Every spring, the government publishes a snapshot of UK cyber security: the Cyber Security Breaches Survey, commissioned by the Department for Science, Innovation and Technology and the Home Office, and carried out independently by Ipsos with over 2,100 businesses.
The 2025/2026 edition was published on 30 April 2026, based on data from late 2025.
Most coverage of it recycles the same headline. I want to do something more useful: pull out what the data actually says about businesses like yours, and what I think it means.
I have spent thirty years in IT governance and security, most of it helping smaller organisations, and several findings this year deserve more attention than they are getting.
In This Article
The headline: 43% of businesses were breached or attacked
Just over four in ten UK businesses (43%) experienced a cyber security breach or attack in the last twelve months. That equates to roughly 612,000 businesses. The rate rises with size: 42% of micro businesses, 46% of small businesses, 65% of medium businesses, and 69% of large businesses.
Two things worth knowing before you file that number away in the recycle bin of your mind. First, the survey only counts what organisations detected and were willing to report. The report itself acknowledges that the true figure is likely higher because many attacks go unnoticed.
If a company like South Staffordshire Water can host intruders for 20 months without spotting them, plenty of small firms are in the 43% without knowing it.
Second, “breach or attack” includes attempts. That is not a reason to relax. It is a reason to read on, because the impact data is where this year’s survey gets interesting.
The cost picture: usually nothing, occasionally serious
Breach costs are usually framed as being business-ending events, and they can be, but the vast majority are not.
Here is the finding that surprises me the most: the median cost of the most disruptive breach was £0. Most businesses that experienced an attack shrugged it off with no measurable financial hit.
So is the whole thing overblown?
No, and the reason is in the detail that follows.
For the worst 5% of cases, costs reached £4,000 for the average business and £10,000 for medium and large firms. For cybercrime other than phishing, the median cost among those who actually paid anything was £750, with the top end reaching £7,500.
And the proportion of breached businesses reporting a loss of revenue or share value more than doubled this year, from 2% to 5%, with reputational damage rising from 1% to 3%.
Cyber risk for a small business is not a steady tax. It’s a lottery ticket you did not choose to buy: most draws cost you nothing, but the wrong draw hurts. You do not need to outspend the threat. You need to not be the easy draw.
The businesses experiencing real losses are a growing share. This is exactly the sort of risk that proportionate, right-sized controls are built for.
Phishing is nearly the whole game
Phishing was experienced by 38% of businesses, far ahead of any other, and 69% of affected organisations rated it as their most disruptive attack type.
Among businesses that were breached, more than half (51%) experienced only phishing. Ransomware, for all its headlines, hit just 1% of businesses this year, down from 3%.
For a small business, this simplifies your priorities enormously. The attack most likely to reach you arrives via email, targeting a person rather than a firewall. Which makes the next finding harder to excuse: only 19% of businesses ran any staff training or awareness activity in the past year, a figure that has not moved.
Meanwhile, 58% have an agreed process for staff to follow when they spot a fraudulent email, which means four in ten have nothing at all.
Repeat victimisation compounds this. Among businesses experiencing cybercrime, the median number of incidents was 3 per year, and the mean was 19. Attackers return to what works.
Small businesses went backwards this year
To me, this is the most important finding in the report, and almost nobody is covering it.
Last year’s survey showed small businesses (10 to 49 staff) improving across several fundamentals. This year those gains evaporated. All back to where they were two years ago:
- Risk assessments covering cyber security fell from 48% to 41%
- Formal cyber security policies fell from 59% to 52%
- Business continuity plans covering cyber fell from 53% to 44%
The qualitative interviews point to the culprit: economic pressure.
When budgets tighten, security work that feels optional gets cut. I understand the logic, and I think it is exactly backwards.
A risk assessment is not the expensive part of security. It is the thinking part, the piece that tells you where the cheap wins are. Cutting it does not save money; it just means whatever you do spend is spent blind. It’s fundamental to any security governance and to just knowing what you are facing.
Curiously, micro businesses moved the other way, with two-factor authentication up from 35% to 43% and more of them engaging external security providers. The smallest firms are quietly getting more serious while their slightly larger neighbours slip.
Almost nobody is checking their suppliers, and that is about to matter
Only 15% of businesses formally review the cyber risks posed by their immediate suppliers, and just 6% look at their wider supply chain. But looking at the size split: 30% of medium businesses and nearly half of large businesses (48%) do review their suppliers. Okay, so they can afford resources to do it, but can you afford not to?
Now put that alongside the direction of travel in regulation. The Cyber Security and Resilience Bill currently moving through UK Parliament will require regulated organisations to manage risk across their supply chains. Those medium and large firms reviewing suppliers today are your customers, and their questionnaires will only get longer.
The survey shows the squeeze forming: the organisations above you in the chain are increasingly obliged to ask, while most firms below them cannot yet answer.
If you sell to bigger organisations, being able to evidence your security is shifting from a nice-to-have into the price of admission to tenders. The businesses that prepare before the questionnaire lands will win work from the ones that scramble after it.
ISO 27001 helps you identify, evaluate and manage your suppliers (with respect to security), and is a critical and notable part of the controls of the standard. You cannot afford to shrug your shoulders and go ‘hey, they look ok to me’. That’s not an evaluation. An evaluation involves finding out where your data is stored, what safeguards are in place around it, and what contractual obligations you’ve signed up for.
The certification signal hiding in the data
Two findings sit oddly together. Only 5% of businesses hold Cyber Essentials certification. Yet 24% already have technical controls across all five required areas. In other words, a fifth of UK businesses are essentially doing the work without receiving the credit.
And the credit is starting to move: Cyber Essentials certification among small businesses jumped from 5% to 12% in a single year, and among large businesses from 21% to 35%. That is not businesses suddenly discovering security. That is, businesses responding to requests from customers, insurers and tenders. Certification is becoming the receipt that procurement teams want to see.
The same logic applies further up the assurance ladder with ISO 27001. If you are already doing much of the work, the gap between where you are and something you can evidence is often smaller than you think. The waste is doing the work and being unable to prove it.
Incident response remains the weakest link
Only 25% of businesses have a formal incident response plan. Among micro businesses, it is 21%, compared with 76% for large firms.
Most organisations will find out how they respond to an incident during the incident. That’s crazy.
A response plan for a small business does not need to be a thick document; A page covering who decides, who you call, where the backups are and how you communicate while email is down covers most of it.
The NCSC’s free Exercise in a Box service even lets you rehearse it at no cost. Given that phishing targets your staff daily and repeat victimisation is the norm, this is the highest-value document most small businesses lack.
How this squares with the scarier headlines
If you read other security reports, you’ll notice numbers that seem to contradict this survey. Verizon’s Data Breach Investigations Report found ransomware present in 48% of the breaches it analysed, while the CSBS puts ransomware at 1% of UK businesses.
Both are right; they measure different things. The CSBS asks a representative sample of all businesses whether anything happened to them. The DBIR dissects confirmed, serious breach incidents. So ransomware rarely reaches an ordinary small business, but when a breach does turn serious, it’s very often the payload. Low frequency, high severity.
The severity end of that scale now has a British benchmark. The Cyber Monitoring Centre assessed the Jaguar Land Rover attack at around £1.9 billion in economic impact, the costliest cyber event in UK history, with the disruption cascading across more than 5,000 supply-chain organisations, most of which were never the target. Meanwhile, the DBIR offers a rare piece of good news: the median ransom paid has fallen to around $140,000 and 69% of victims now refuse to pay, evidence that decent backups and rehearsed response plans are shifting the economics against attackers.
Read together, the reports tell one story. Most lottery draws cost nothing. The losing tickets are getting more expensive. And the businesses that shrug off a losing ticket are the ones that did the unglamorous preparation beforehand.
What I take from all this
Strip out the noise, and the survey says something quite clean. The threat that will actually reach you is a phishing attempt targeting someone in your team. The cost of failure is usually small but occasionally serious, and the number of serious cases is growing. The fundamentals that protect you are being cut at exactly the moment customer and regulatory scrutiny is rising. And the gap between doing security and proving it is where small businesses are leaving money on the table.
None of the fixes is exotic:
- A genuine risk assessment
- Two-factor authentication everywhere it matters
- A trained, slightly suspicious team
- A one-page response plan you have rehearsed
- A way of evidencing all of it when a customer asks
That is proportionate security: enough, done properly, and provable.
If you want to see how your business measures up against a recognised framework, my free ISO 27001 gap analysis tool walks through it in plain English.
And if you would rather talk it through, I offer a genuinely free 30-minute discovery call.
Source: Cyber Security Breaches Survey 2025/2026, Department for Science, Innovation and Technology and the Home Office, published 30 April 2026. Contains public sector information licensed under the Open Government Licence v3.0.
See how you measure up,
in plain English.
My free ISO 27001 gap analysis walks through a recognised framework step by step. Or book a genuinely free 30-minute discovery call.
Author Background
This article was written by Alan Parker, an ISO 27001 consultant and founder of Iseo Blue Limited. He helps UK SMEs achieve certification in 90 days or less, often without a dedicated security team or a large budget.
With over 30 years in IT governance and information security, Alan works with software companies, IT service providers, managed service providers, and professional services firms across the UK, Europe, and internationally.
Qualifications: Certified ISO 27001 Lead Auditor (ANAB-accredited certification),
ITIL v3 Expert, ITIL v4 Bridge, PRINCE2 Practitioner. Named IT Project Expert of the Year (2024, UK). Alan writes in plain English for busy teams who need to get things done.
Connect on LinkedIn or Bluesky, or explore his free ISO 27001 tools and templates at iseoblue.com. B.Sc (Hons) Information Systems, CISMP certified.
