Cybersecurity · Last updated

Cyber Security Breaches Survey 2025/26: Key Findings

43% of UK businesses hit, phishing at 38%, ransomware down to 1%, and preparedness among small firms falling. What the survey means in practice.

Nerdster Team

The Cyber Security Breaches Survey is the closest thing the UK has to a national baseline for how organisations actually behave on security, rather than how they say they intend to. It is produced for the Department for Science, Innovation and Technology and the Home Office, and this year’s edition contains several findings that are genuinely uncomfortable — including one that has moved in the wrong direction.

Here is what it found, and what each figure means if you run a small or mid-sized firm in London.

How the survey was done

The Cyber Security Breaches Survey 2025/26 was published on 30 April 2026. The fieldwork ran between August and December 2025: a random probability telephone and online survey of 2,112 UK businesses, 1,085 UK registered charities and 577 education institutions, followed by qualitative interviews.

Two things follow from that design and are worth holding onto while reading the numbers.

First, it is a representative sample of all UK organisations, which means it is dominated by very small ones. Findings about “businesses” describe the national picture, not the picture in a 40-person professional firm in the City.

Second, it measures what respondents identified and recalled. An organisation with no monitoring cannot report an incident it never noticed. Detection capability and reported incidence are not independent of each other, and the survey is explicit that these are perceived figures.

The headline findings

43% of businesses and 28% of charities reported experiencing any kind of cyber security breach or attack in the previous 12 months. That equates to approximately 612,000 UK businesses and 57,000 UK charities.

Using the mean number of incidents, the survey estimates UK businesses experienced approximately 5.19 million cyber crimes of all types in the year, including around 70,000 non-phishing cyber crimes. The great majority of that volume is phishing, which is the next finding and, this year, essentially the whole story.

Phishing at the centre of the problem

38% of businesses experienced phishing, making it by far the most common category. Among organisations that had any breach or attack, phishing was named as the most disruptive type by 69% of businesses and 69% of charities.

The trend underneath is the interesting part. Phishing has not risen — at 38% it is statistically level with last year and down from 42% two years ago. But among organisations that experienced anything at all, the proportion experiencing phishing and nothing else rose from 45% to 51%.

So the mix has narrowed. Other categories have thinned out while phishing has held, which means for most UK organisations “cyber security” and “email and identity security” are now very nearly the same subject. That has a practical consequence: the controls that address authentication and email — multi-factor authentication, mail filtering, domain authentication, and staff who know what to do with a suspicious message — cover a larger share of your real exposure than they did three years ago. Our note on anti-phishing testing covers what the human side of that looks like.

What the cost figures actually say

This is where most summaries of the survey go wrong, in both directions.

  • The median perceived cost of the most disruptive breach or attack was £0 for businesses, rising to £30 for medium and large businesses.
  • The range where most cases fell (25th to 75th percentile) was £0 to £200.
  • Excluding organisations that reported no cost at all, the median rises to £200 for businesses generally and £300 for medium and large ones.
  • For the top 5% of cases, the perceived cost was £4,000 for businesses generally, rising to £10,000 for medium and large businesses.

Read plainly: most incidents are absorbed. A phishing email is spotted, a password is reset, an afternoon is lost, and nothing appears on a ledger. Anyone quoting a large average UK breach cost is describing a different population from the one this survey samples.

The distribution is the point, though, not the median. What is changing is the severity of the tail. Businesses reporting that a breach or attack led to loss of revenue or share value rose from 2% to 5% in a single year, and those reporting reputational damage rose from 1% to 3%. The typical incident is getting no more expensive. The bad one is getting worse, and slightly more common.

For a professional firm holding client data, that tail is the whole risk. The cost that matters is not the IT bill; it is the week of disruption, the client notifications and the regulatory correspondence.

Notice that reported ransomware fell

Ransomware fell to 1% of businesses, down from 3% in each of the two previous years.

That will read oddly against everything else published this year, and it is worth handling honestly rather than quietly dropping. It is a real finding about a representative sample of UK organisations, and it sits alongside vendor research showing ransom demands and recovery costs rising. Both can be true: fewer UK organisations reporting ransomware, and a heavier outcome for those who do. We have worked that tension through in our guide to ransomware in 2026.

Face the finding that went backwards

Here is the one that deserves more attention than it got. Among small businesses, several measures returned to where they had been two years earlier:

  • Business continuity plans that address cyber security: 44%, down from 53%
  • Formal cyber security policies covering cyber security risks: 52%, down from 59%
  • Cyber security risk assessments: 41%, down from 48%

Last year’s improvement did not hold. There is no comfortable reading of that. The most likely explanation is that these are the activities that get done when someone has time, and they are the first to lapse when they do not — nobody decides to stop doing a risk assessment, it simply does not happen.

If you hold current versions of these three documents, you are now in a shrinking group, which is worth knowing when a client sends a due-diligence questionnaire or an insurer asks what you have.

The controls most organisations still lack

Basic technical controls are widespread. 81% of businesses have up-to-date malware protection, 74% back up to a cloud service, 74% have a password policy, 74% have network firewalls and 73% restrict admin rights. A further 48% back up by other means as well.

The gaps sit one level up:

  • Only 47% have any two-factor authentication. Given that phishing is the dominant attack and stolen credentials are what phishing is for, this is the single largest exposure in the survey. It is improving at the smallest end — among micro businesses, 2FA rose to 43% from 35% — but a control that stops most account-takeover attacks is still absent from more than half of UK businesses.
  • Only 25% have a formal incident response plan, rising to 57% of medium-sized businesses and 76% of large ones, and falling to 21% of micro businesses. By sector, finance or insurance leads at 53% and information and communication at 49%.
  • Only 19% ran staff training or awareness activity in the past year, unchanged from the year before.

The incident response figure is the one most worth acting on for a mid-sized firm. Writing the plan costs almost nothing, and it is the difference between a coordinated hour and a chaotic day. Ours are built around named roles, contact routes that work when email is down, and a rehearsal date — see our backup and disaster recovery checklist for the recovery half of the same exercise.

Who is responsible for cyber security

31% of businesses have board members or trustees with explicit responsibility for cyber security. That is up from 27%, and the survey notes it reverses a downward trend running since 2020/21 — one of the clearer pieces of good news in the report.

The variation by size and sector tracks what you would expect: 29% of micro businesses, 37% of small, 52% of medium and 68% of large. By sector, finance or insurance is highest at 54%, information and communication at 51%, and professional, scientific or technical at 41%.

Named ownership is the quiet variable behind most of the other figures. Risk assessments, response plans and training all belong to somebody in the organisations that keep them current.

Mind the supply chain

15% of businesses review the risks posed by their immediate suppliers, and 6% look at their wider supply chain. Only 3% require suppliers to hold Cyber Essentials specifically.

For most firms the practical exposure runs through a handful of systems: the practice management platform, the payroll bureau, the outsourced bookkeeper, the file-sharing tool. Knowing which of those hold your clients’ data, and what happens if one of them is unavailable for a week, is a short exercise that almost nobody has done.

Regulated firms are being pulled forward on this faster than everyone else, which usually means the questions arrive in general procurement a year or two later. Our page on FCA operational resilience covers where financial services has got to.

The Cyber Essentials evidence gap

Three figures sit next to each other and tell a story:

  • 5% of businesses hold Cyber Essentials, up from 3%.
  • 17% have even heard of it.
  • 24% report having the technical controls associated with the scheme in all five areas.

Roughly one business in four is already doing the work. One in twenty holds the certificate that would demonstrate it to a client, an insurer or a procurement team. For a firm that is already close, Cyber Essentials is mostly a matter of evidencing and tidying what exists rather than building something new — and the NCSC states that any UK organisation with a turnover under £20m achieving certification across their whole organisation is automatically entitled to Cyber Liability Insurance arranged by IASME, its delivery partner for the scheme.

What this means for your firm

Strip the survey down and it points at a short list, in this order:

  1. Get two-factor authentication onto everything, including the secondary systems — the practice management platform, the accounting package, the file-sharing tool. This is where the biggest gap and the biggest attack surface overlap.
  2. Prove you can recover. Backups are near-universal; a dated restore test with a recorded recovery time is not.
  3. Write the incident response plan, and put a rehearsal date in the diary. Three-quarters of UK businesses have not.
  4. Keep your documents current. Risk assessment, cyber policy, continuity plan. They are lapsing across the small-business population, which makes holding them a genuine differentiator.
  5. Ask about your suppliers. Which of them hold your clients’ data, and what is your position if one is offline for a week.

The survey also shows where firms turn for help: 44% of businesses actively sought external information or guidance on cyber security in the past year, and the most common single source, mentioned by 27%, was an external cyber security consultant, IT consultant or provider.

If working through that list would be useful, we are glad to help. Book a conversation and we will go through where you currently stand against these five points, what closing each one would involve, and what it would cost.

cyber securitybreachesphishingsmall businessUK statistics

FAQ

Cyber Security Breaches Survey 2025/26: your questions answered

What is the Cyber Security Breaches Survey?

It is an official statistic produced for the Department for Science, Innovation and Technology and the Home Office, and it is the main measure of cyber security behaviour among UK organisations. The 2025/26 edition was published on 30 April 2026 and is based on a random probability telephone and online survey of 2,112 UK businesses, 1,085 UK registered charities and 577 education institutions, carried out between August and December 2025, followed by qualitative interviews.

How many UK businesses experienced a breach or attack?

43% of businesses and 28% of charities reported experiencing any kind of cyber security breach or attack in the previous 12 months, which the survey estimates at approximately 612,000 UK businesses and 57,000 UK charities. Using the mean number of incidents, it estimates UK businesses experienced around 5.19 million cyber crimes of all types in the year, of which approximately 70,000 were non-phishing cyber crimes.

What does the survey say a breach costs?

Less than most headlines suggest, for the typical case, and more than most firms budget for in the worst case. The median perceived cost of the most disruptive breach or attack was £0 for businesses, rising to £30 for medium and large businesses, and the range where most cases fell was £0 to £200. For the top 5% of cases, the perceived cost was £4,000 for businesses generally and £10,000 for medium and large businesses. Excluding organisations reporting no cost at all, the median rises to £200. The wider damage is growing: businesses reporting that a breach cost them revenue or share value rose from 2% to 5% in a year.

Why did reported ransomware fall when ransomware is said to be getting worse?

Because two different things are being measured. The survey asks a representative sample of all UK organisations, most of them very small, whether they experienced ransomware, and that figure fell to 1% from 3% in each of the two previous years. Vendor research surveys organisations that had a ransomware incident and asks what it cost, and those costs have risen. Fewer UK organisations reporting ransomware and higher costs among those who suffer it are consistent findings, not contradictory ones. Our guide to ransomware in 2026 works through that in more detail.

What should a smaller firm do first, based on this survey?

Two-factor authentication, then a restore test, then a written incident response plan. The survey shows only 47% of businesses have any two-factor authentication, and phishing is both the most common attack at 38% and the most disruptive for 69% of those affected — so authentication is where the largest gap and the largest attack surface overlap. After that, the ability to recover and the ability to respond in an organised way are what separate a bad afternoon from a bad quarter.

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report