Nearly half of UK businesses were hit by a cyber security breach or attack in the past year, according to the government’s newest annual snapshot of the problem. The Cyber Security Breaches Survey 2025/2026, published by the Department for Science, Innovation and Technology (DSIT) on 30 April 2026, puts the figure at 43% of businesses and 28% of charities, a number that translates into roughly 612,000 firms and 57,000 charities dealing with an incident this year alone. Security researchers and trade bodies are now using the release to press small and mid-sized firms to close basic gaps before the next wave of phishing and ransomware campaigns lands.

The headline number matters less than what sits underneath it. Among the organisations that flagged a breach or attack, 44% of businesses and 49% of charities say they were the victim of an actual cyber crime, not just a blocked attempt or a suspicious email that got caught in a filter. That distinction, between an attack being logged and an attack actually landing, is where most of this year’s advice from industry commentators is focused.

What the Cyber Security Breaches Survey 2025/2026 actually found

The Cyber Security Breaches Survey is DSIT’s long-running annual research project, run in partnership with pollster Ipsos and academic partners, and it remains the most cited dataset on UK business cyber security because it samples thousands of organisations rather than relying on self-reported incident tickets from a single vendor. The 2025/2026 edition kept the same core question it has asked for years: has your organisation identified any cyber security breaches or attacks in the last 12 months?

This year’s answer: 43% of businesses said yes, alongside 28% of charities. Scaled against the UK’s business population, that works out to roughly 612,000 businesses and 57,000 charities. Those aren’t small numbers, and they aren’t new territory either. The survey has tracked incident rates in a similar range for several years running, which is arguably the more uncomfortable finding. Despite growing security budgets, wider MFA rollout, and years of government-backed awareness campaigns, the share of UK organisations reporting a breach has not fallen meaningfully.

UK Government data from the survey states plainly that “just over four in ten businesses (43%) reported having experienced any kind of cyber security breach or attack in the last 12 months,” a figure drawn directly from the official DSIT publication. The same release notes that “this equates to approximately 612,000 UK businesses that identified a cyber breach or attack in the past year,” giving a concrete scale to a statistic that often gets flattened into a single percentage in headlines.

Breach rate by business size and sector

The 43% top-line figure hides a wide spread once you break it down by company size. Larger organisations report far higher exposure, not necessarily because they’re worse at security, but because they have more attack surface, more staff to phish, and better detection tooling that actually surfaces incidents smaller firms might never notice. The survey states that “large firms were much more likely to report cyber breaches or attacks, with 69% affected,” a gap of more than 25 percentage points against the overall business average.

Organisation typeShare reporting a breach/attack (12 months)Share that became a confirmed cyber crime
All UK businesses43%44%
UK charities28%49%
Large firms69%Not broken out separately
Estimated businesses affected~612,000–
Estimated charities affected~57,000–

That charity figure deserves its own callout. Charities report a lower overall breach rate (28% versus 43% for businesses) but a higher conversion rate into actual crime once an incident is flagged (49% versus 44%). Charities typically run leaner IT teams and smaller security budgets relative to their size, which may explain why fewer incidents get caught at the attempted stage before they turn into something costlier.

Phishing remains the dominant entry point

If there’s one attack type UK security teams should assume is already hitting their inbox, it’s phishing. The DSIT dataset states that “among businesses that experienced a breach or attack, phishing was the most common type, affecting 38% of businesses,” a figure that lines up with what the survey has shown in prior years and with reporting from outlets covering the release, including HR News, which put the share of business incidents involving phishing at roughly 85% among businesses that experienced any breach at all.

Those two numbers aren’t contradictory once you separate the denominators. The 38% figure is phishing’s reach across all UK businesses surveyed. The 85% figure describes how dominant phishing is specifically among organisations that already identified some kind of breach, meaning that once an incident happens at all, there’s a very high chance phishing was involved somewhere in the chain. Put together, the picture is consistent: phishing isn’t one threat among many, it’s close to the default way most UK organisations get breached in the first place.

That pattern isn’t unique to the UK, and it isn’t unique to 2026. Credential theft and social engineering have topped breach-cause rankings in the Verizon Data Breach Investigations Report for years, and the UK figures released this spring reinforce that the human inbox, not a zero-day exploit, is still where most attacks start.

Historical context: a decade of roughly the same number

The Cyber Security Breaches Survey has run annually since 2016, and the headline breach rate has bounced within a fairly narrow band the whole time, generally somewhere between the high thirties and low fifties depending on the year and methodology tweaks. That consistency is worth sitting with. It means the UK’s overall cyber risk exposure at the business level hasn’t structurally improved even as awareness campaigns, cyber insurance uptake, and compliance requirements like GDPR enforcement have all expanded over the same period.

Part of the explanation is that threat volume has grown roughly in step with defensive investment. Every year that phishing kits get cheaper and easier to rent, and every year that generic off-the-shelf ransomware toolkits circulate more widely, defenders have to run just to stay in place. UK police forces have felt this directly: Dyfed-Powys Police disclosed an 11-day internal investigation into a cyber attack touching staff data earlier this year, a reminder that public-sector bodies sit inside the same exposure pool as private businesses.

Why nearly half of businesses still get hit

Security commentary responding to the survey has converged on a familiar but persistent set of root causes. Smaller firms in particular tend to under-invest in the unglamorous basics: patching cadence, access control, and staff training, in favour of point solutions that look better on a procurement slide. None of that is new, but the survey’s repeated 40-plus percent breach rate suggests the industry’s messaging isn’t closing the gap fast enough.

Large UK companies aren’t immune either, and their incidents tend to be more expensive precisely because of scale. Jaguar Land Rover’s cyber attack cost the company roughly £1.9 billion in production and recovery costs, an outlier in size but a useful illustration of how quickly a single incident can eclipse years of a smaller firm’s entire security budget. The same logic explains why the survey shows large firms reporting breaches at 69%, nearly double the SME rate: bigger attack surface plus better detection equals more logged incidents, even when the underlying security posture is stronger than average.

The measures being pushed in response to the 2025/2026 figures aren’t exotic. They’re the same controls security teams have recommended for years, which is itself part of the story: the fixes are known, the adoption gap is what’s driving the incident rate.

  • Security-awareness training for staff, aimed squarely at phishing recognition given its dominance as an entry vector
  • Multi-factor authentication across email, remote access, and admin accounts
  • Supplier-risk reviews, since third-party and vendor access remains a common route into otherwise well-defended networks
  • Regular risk assessments rather than one-off compliance exercises
  • Encryption of data at rest and in transit
  • Malware protection and firewalls kept current, not just installed once and forgotten
  • Strong password policies paired with restricted administrator access
  • A written incident-response plan that staff have actually rehearsed
  • Cloud backups isolated from the primary network
  • User-activity monitoring to catch lateral movement early

None of these are a silver bullet in isolation. The value is cumulative: an organisation running MFA, current backups, and basic staff training closes off most of the cheap, high-volume attacks that make up the bulk of the 43% breach rate, even if it can’t stop a determined, well-resourced adversary. Much of this list mirrors the baseline guidance published by the National Cyber Security Centre, the UK’s technical authority on cyber defence, which has pushed the same small set of controls for years precisely because they catch the bulk of real-world attacks. For a deeper walkthrough of why phishing keeps winning against these defences, see our explainer on how phishing attacks work and how to spot them, and our companion piece on what actually keeps accounts safe beyond just picking a longer password.

Market and insurance impact

A persistent 43% breach rate has knock-on effects well beyond the IT department. Cyber insurance underwriters use exactly this kind of survey data to price premiums and set minimum control requirements, and a flat incident rate year over year gives insurers little reason to loosen terms. Expect renewal conversations in the back half of 2026 to keep leaning on proof of MFA deployment and tested backups as a condition of coverage, rather than a nice-to-have.

There’s also a compliance angle. The UK’s data protection regulator, the Information Commissioner’s Office, continues to treat weak baseline controls as an aggravating factor when assessing fines after a breach is reported. A firm that can show it had MFA, encryption, and an incident-response plan in place going into an attack is in a materially different position, both financially and reputationally, than one that had none of the above. That gap is likely to widen as more UK breach settlements and enforcement actions reference the same DSIT survey data as a baseline for what “reasonable” security looks like. Business groups such as the Federation of Small Businesses have long argued that compliance costs land disproportionately on smaller firms, which is part of why adoption of the survey’s recommended controls tends to lag furthest among sole traders and micro-businesses.

Competitive and sector comparison

Comparing sectors within the survey shows the same story reflected at different scales. Finance and insurance firms typically report some of the highest breach identification rates of any sector, largely because they run more mature monitoring and are required to log more. Retail and hospitality tend to sit closer to the middle. Charities, as the 2025/2026 data shows, report fewer identified incidents overall but a higher share that escalate into confirmed cyber crime, a pattern consistent with thinner IT staffing rather than a lower level of targeting.

Recommended controlPrimary threat it addressesTypical adoption barrier for SMEs
Multi-factor authenticationCredential theft, phishing follow-throughPerceived friction for staff and customers
Security-awareness trainingPhishing (38-85% of incidents, depending on measure)Time and recurring cost
Supplier-risk reviewsThird-party and supply-chain compromiseLack of leverage over larger vendors
Cloud backups (isolated)RansomwareStorage cost and setup complexity
Incident-response planSlow, costly breach containmentRarely prioritised until after an incident

What security teams are watching next

The UK’s cyber security picture doesn’t exist in isolation from the wider threat landscape. Global reporting bodies, including the World Economic Forum, have flagged fraud and AI-assisted attacks as top concerns among security leaders heading into 2026, a trend covered in our look at the WEF Global Cybersecurity Outlook 2026, where 94% of surveyed executives cited AI-driven risk as a growing factor. Ransomware groups also aren’t slowing down: our coverage of the broader ransomware ecosystem found active ransomware groups up 49% year over year, with more than 8,000 victims logged in a single year. Both trends point toward the same conclusion the DSIT survey supports: attack volume and variety are increasing even where individual defences are improving.

Predictions for the rest of 2026 and into 2027

  • The overall UK business breach rate will likely stay in the low-to-mid 40s in next year’s survey, since the underlying drivers (cheap phishing kits, patchy MFA adoption among SMEs) haven’t shifted enough to move the number meaningfully.
  • Cyber insurers will keep tightening minimum-control requirements at renewal, pushing MFA and tested backups from recommended to effectively mandatory for coverage.
  • Expect more regulatory scrutiny tied directly to survey findings, with the ICO and sector regulators referencing DSIT data when arguing a breached organisation should have known better.
  • Charities and small nonprofits will remain a soft target, given the survey’s finding that a higher share of their incidents convert into actual cyber crime relative to businesses.
  • Supply-chain and third-party risk reviews will get more attention in 2027 planning cycles, following a string of high-profile breaches traced back to vendor access rather than a direct compromise.

What this means for small business owners right now

For an owner-operator running a firm with a handful of staff, the practical takeaway from the 2025/2026 survey isn’t complicated: assume phishing will reach an employee’s inbox, because the data says it very likely already has somewhere in the UK business population this year. The controls that matter most for a lean team are also the cheapest to deploy: MFA on email and any remote-access tools, a tested backup that sits outside the main network, and a plan (even a one-page one) for who does what in the first hour after a suspected breach.

None of that guarantees immunity. The 69% breach rate among large firms, many of which run far larger security budgets than any SME could match, is proof that no organisation gets to zero. What the basics do buy is a shorter, cheaper recovery, and often the difference between an incident that stays contained and one that turns into a multi-week outage.

Frequently asked questions

What percentage of UK businesses experienced a cyber breach in 2025/2026?
According to the DSIT Cyber Security Breaches Survey 2025/2026, published 30 April 2026, 43% of UK businesses and 28% of charities identified at least one cyber security breach or attack in the previous 12 months.

How many UK businesses does the 43% figure represent?
The survey estimates that roughly 612,000 businesses and 57,000 charities reported cyber incidents over the 12-month period covered.

What’s the most common way UK businesses get breached?
Phishing. The survey found phishing affected 38% of businesses overall, and reporting on the release put phishing’s involvement at roughly 85% of incidents among businesses that experienced any breach at all.

Are large companies more likely to be breached than small ones?
Large firms report a substantially higher breach identification rate, 69% according to the survey, largely because of bigger attack surfaces and more mature detection tooling that catches incidents smaller firms might miss entirely.

Do charities face the same cyber risk as businesses?
Charities report a lower overall breach rate (28%) than businesses (43%), but a higher share of their incidents, 49% versus 44%, escalate into confirmed cyber crime, likely reflecting thinner IT resourcing.

What security measures does the survey recommend?
Security-awareness training, multi-factor authentication, supplier-risk reviews, regular risk assessments, encryption, malware protection, firewalls, strong password policies, restricted admin access, incident-response plans, cloud backups, and user-activity monitoring.

Where can I read the full Cyber Security Breaches Survey 2025/2026?
The full release is published on gov.uk under DSIT’s official statistics section.

Has the UK business breach rate changed much over the years?
Not dramatically. The Cyber Security Breaches Survey has run annually since 2016 and has consistently shown a large share of UK businesses, generally in the 40-plus percent range, identifying at least one breach or attack each year, despite rising security investment industry-wide.