TL;DR:

  • The DSIT Cyber Security Breaches Survey 2026 found that 50% of UK businesses experienced a cyber incident or breach in the past year, with phishing remaining the most common attack type
  • Small businesses continue to lag behind larger organisations on basic controls: fewer than one in three have completed a formal risk assessment in the past twelve months
  • The average cost of a disruptive cyber incident for a small business was estimated at around £1,600 — but that figure masks a long tail of higher-impact incidents that skew the real risk considerably

Every year, the Department for Science, Innovation and Technology publishes the Cyber Security Breaches Survey, and every year the findings are simultaneously reassuring and alarming. Reassuring because we’ve known about most of these problems for a decade. Alarming because they haven’t gone away.

The 2026 edition, published in April, continues that tradition. If you’re running a small business in the UK and you haven’t looked at the report, here’s what’s actually worth your attention.

Phishing Is Still Winning

Phishing remains the most common type of attack reported by UK businesses, with around 84% of businesses that identified a breach saying that phishing was the vector. To be honest, that number has been stubbornly high for years, which either tells you that phishing is extremely effective or that it’s the easiest thing for businesses to identify and attribute.

What’s changed is the sophistication of what’s arriving in inboxes. The survey period aligns with the wider roll-out of AI-generated personalised phishing, and anecdotal evidence from incident responders suggests that the success rate of targeted phishing emails has increased as the quality of the messages has improved. We’re past the era of “Dear Customer, your account has been suspend.” The fake invoices and supplier impersonation emails that are arriving now are frequently indistinguishable from legitimate correspondence without checking the header metadata.

The practical implication for small businesses is that technical email filtering (SPF, DKIM, DMARC configured correctly — which they still frequently aren’t) is necessary but no longer sufficient. Staff recognition training that keeps up with the current look of phishing attempts, rather than teaching people to spot 2019-era scams, matters more than it did.

The Ransomware Picture

Ransomware incidents affecting smaller businesses are up. The survey shows a significant increase in reports of data being encrypted or held for ransom, and the £1,600 average cost figure significantly understates the true picture for businesses that suffered a complete encryption event rather than a partial one.

What the headline number doesn’t capture is the secondary costs: lost productivity during incident response, potential ICO notification obligations if personal data was involved, reputational impact with customers, and in some cases the permanent loss of data that hadn’t been backed up properly.

The good news, such as it is: the survey found that businesses with recent offline backups were dramatically more likely to recover without paying a ransom. Backups remain the single most impactful technical control for ransomware recovery. The bad news: a significant proportion of small businesses still don’t have tested offline backups.

Where Small Businesses Are Falling Behind

The survey identified several areas where smaller organisations consistently lag. Formal cyber risk assessments are one: only 31% of small businesses reported having conducted a formal review of their cyber security risks in the past twelve months. Without a risk assessment, it’s genuinely difficult to prioritise where to put limited resource.

Multi-factor authentication adoption is improving but uneven. Around 60% of businesses now use MFA on email, which is the highest-risk account for most organisations, but adoption on cloud storage, accounting software, and admin accounts is considerably lower. Given that compromised credentials are a significant initial access vector in UK SME incidents, this is a gap that’s costing organisations.

The survey also found that very few small businesses have any kind of formal incident response plan. When something does go wrong, they’re working it out as they go. That’s not a catastrophic failure in most cases — incidents often get contained and resolved without a formal plan — but it does mean initial response is slower and more expensive than it needs to be.

What Cyber Essentials Can Actually Do Here

One of the consistent findings across years of DSIT surveys is that businesses which hold Cyber Essentials certification have better outcomes. Not because Cyber Essentials is comprehensive — it isn’t, it covers five technical controls — but because the process of getting certified forces a review of the basics: firewall configuration, access control, patch management, malware protection, and secure configuration of devices.

The survey data shows that Cyber Essentials holders are less likely to report a successful breach and more likely to have the basic technical controls in place that prevent the most common attack types. The certification also provides modest protection under some business insurance policies, with several UK cyber insurers offering lower premiums or broader coverage to certified organisations.

If you haven’t looked at Cyber Essentials, the NCSC’s guided self-assessment is a reasonable starting point. The basic certification costs around £300-400 through an approved certification body. Cyber Essentials Plus (which includes a technical audit) costs more but provides stronger assurance.

The Actions That Would Actually Move the Needle

The survey’s recommendations section covers familiar ground, but it’s worth translating it into specific things a small business can realistically do this month.

Get email authentication in place. If your domain doesn’t have DMARC set to at least quarantine (not just monitor), anyone can send emails that look like they came from you. That’s both a way you can be impersonated and a hygiene issue that reputable email recipients increasingly check. Your IT support or web host can configure this.

Check your backups. Not whether they exist — whether they work. Restore something. A backup you’ve never tested is a hope, not a plan. If you don’t have offline or air-gapped backups, talk to your IT provider about adding them.

Enable MFA on everything that offers it. Email first, then cloud storage, then your accounting platform, then your domain registrar. These are ranked roughly by risk level.

Report incidents. The survey consistently shows that UK small businesses under-report. Action Fraud (0300 123 2040) accepts reports of cyber incidents, and reporting helps the NCSC build a picture of what’s actually happening. If personal data was involved, you may have an obligation to report to the ICO within 72 hours.

References