TL;DR:
- 612,000 UK businesses were breached in the past 12 months — 43% overall, 46% of small businesses
- Phishing was involved in 85% of all breaches and named the most disruptive attack by 69% of victims
- The proportion of breached businesses reporting revenue or share value loss rose from 2% to 5% in one year
- The average cost of a ransomware incident for a UK SME now exceeds £200,000 when downtime and recovery are included
- Only about a quarter of organisations using AI have security practices in place for it
The UK government publishes the Cyber Security Breaches Survey annually through DSIT (Department for Science, Innovation and Technology). The 2025/2026 edition is the most detailed yet on the business impact of breaches, and it makes uncomfortable reading for any small business owner who has treated cybersecurity as someone else’s problem.
Here is what the survey found, translated into terms that matter for a business without a dedicated IT team.
The Scale: Nearly Half of Small Businesses Were Breached
43% of all UK businesses experienced a cyber security breach or attack in the 12 months covered by the survey — a figure DSIT translates to approximately 612,000 businesses across the country.
The figure is not dominated by large enterprise targets. Small businesses (10-49 employees) experienced breaches at a rate of 46%, higher than the overall average. Medium businesses (50-249 employees) were hit at 65%; large organisations at 69%. The higher rates for larger businesses partly reflect better detection — they are more likely to notice an intrusion — but they also reflect the higher attractiveness of larger targets to organised ransomware operations.
For micro businesses (fewer than 10 employees), the figure was 42%. The near-parity with small and medium businesses is striking. Attackers are not selectively targeting mid-market companies. Automated attacks — phishing campaigns, credential stuffing, exploitation of unpatched software — hit any accessible target regardless of size.
What’s Actually Hitting Businesses: Phishing, Still Phishing
Phishing was the most common attack in the survey, experienced by 38% of all UK businesses. Among the businesses that were actually breached (not just targeted), 85% reported phishing was involved.
This figure has remained stubbornly high despite years of phishing awareness training programmes. The 2025/2026 survey notes a specific reason: AI tooling has made phishing materially easier to execute. Attackers can now generate convincing, personalised phishing emails at scale without the grammatical errors and generic content that characterised earlier campaigns. The survey describes this as a “key emerging factor” in the continued prevalence of phishing.
What does a modern phishing attack look like? Not a message from a Nigerian prince. Instead:
- A realistic invoice from what appears to be a supplier you actually use, with correct logos and a plausible email domain
- A message from what appears to be HMRC with your actual business name, noting an outstanding compliance issue and a link to resolve it
- A WhatsApp message from what appears to be your CEO or business owner asking for an urgent bank transfer
The 2025/2026 survey found 69% of breach victims named phishing as the most disruptive attack they experienced — meaning even when other attack types occurred, phishing caused the most operational damage.
The Money: Revenue Impact Is Doubling
The most significant change in the 2025/2026 survey compared to prior years is in reported financial impact. Among businesses that experienced breaches:
- The proportion reporting loss of revenue or share value rose from 2% to 5%
- The proportion reporting reputational damage rose from 1% to 3%
These are percentage point increases that sound small but represent a meaningful trend — breaches are increasingly resulting in tangible business consequences rather than just IT cleanup costs.
For ransomware specifically, the DSIT data aligns with broader UK SME incident response data: the average total cost of a ransomware incident for a UK SME, including downtime, recovery, potential regulatory fines, and reputational impact, now exceeds £200,000. That figure encompasses businesses that paid ransoms and those that did not — recovery costs without payment can exceed the ransom itself when operational downtime extends over days or weeks.
A critical clarification: cyber insurance does not automatically cover this. Many SME cyber insurance policies have sub-limits for ransomware, require specific security controls to have been in place as a condition of coverage, and exclude costs incurred during the period between the attack and notification. Understanding your policy’s actual coverage before an incident is essential.
The AI Risk No One Is Managing
One of the newer findings in the 2025/2026 survey is specific to AI adoption. Approximately a quarter of organisations that are already using, adopting, or considering AI have security practices in place to manage the risks that come with it.
For small businesses, AI risk is not abstract. If your team is entering client data into public AI tools like ChatGPT or Copilot, that data may be used for model training. If you’re using AI for customer service, there are new phishing vectors — attackers who feed prompts to your AI that cause it to expose information or behave unexpectedly. If you’re using AI coding tools to write software for your business, those tools can introduce security vulnerabilities into your code.
The survey’s finding that only 25% of AI-using organisations have any security practices in place for AI creates a significant blind spot that attackers are already exploiting.
Five Actions Based on the Survey’s Findings
The DSIT survey is not just a collection of statistics — it identifies what differentiates breached from unbreached businesses. Here are five actions with clear evidence behind them:
1. Deploy multi-factor authentication on everything external. Email accounts, accounting software, banking portals, cloud storage. MFA stops the credential stuffing and phishing attacks that account for the majority of initial access. The survey consistently finds MFA adoption is the single highest-impact low-cost control.
2. Patch software within 24-48 hours of critical vulnerability announcements. Automated patching for operating systems and major applications, manual review for business-critical software. Breaches caused by unpatched known vulnerabilities are preventable by definition.
3. Run a phishing simulation at least quarterly. Not a one-time awareness training tick-box. Regular simulations with immediate feedback identify which staff are most susceptible and maintain vigilance over time. Many providers offer SME-appropriate pricing for small-team simulations.
4. Review your cloud storage and email permissions. Overshared files and misconfigured sharing settings are consistently in the top causes of data breaches for small businesses. Audit who has access to what in your Google Workspace or Microsoft 365, and revoke access for former employees and unnecessary third-party apps.
5. Write down what you’d do if your email was compromised tomorrow morning. A one-page incident response plan — who you’d call, what accounts you’d lock, how you’d notify clients, where your backups are — is worth more than any security tool if you’ve never done it. NCSC’s Cyber Incident Response guidance is free and calibrated for small organisations.
The 2025/2026 survey’s message is not that cyberattacks are inevitable. It’s that the gap between breached and unbreached organisations maps closely to whether basic controls are in place. For small businesses without dedicated security staff, the controls above are achievable this quarter.
Sources
- Cyber Security Breaches Survey 2025/2026 — GOV.UK
- UK Government: 612,000 Businesses Breached, Revenue Impact Doubles — Cloudswitched
- UK Cyber Security Breaches Survey 2026: Revenue Impact Doubles for SMEs — Meridian Micro
- DSIT Breaches Survey 2025/2026 UK SMB Analysis — The Small Business Cybersecurity Guy