Skip to content
cyber security breaches survey

What the Cyber Security Breaches Survey 2025/26 reveals about UK cyber risk

The latest Cyber Security Breaches Survey from the Department for Science, Innovation and Technology remains one of the most useful benchmarks for understanding how UK organisations are managing cyber risk. 

Several figures are worth paying attention to: 

  • 43% of UK businesses and 28% of charities reported a cyber breach or attack in the past 12 months 
  • This rises to 65% of medium-sized businesses and 69% of large organisations 
  • Phishing remains the most common attack type by a significant margin 

These are not outliers. They reflect what many organisations are dealing with on a regular basis. And they only account for incidents that have actually been identified. 

Breaches are now part of normal operations 

For medium and large organisations, experiencing a cyber incident within a 12-month period is increasingly likely. 

That changes how you need to think about cyber security. The focus cannot just be on having policies in place or meeting baseline compliance requirements. You need confidence that your controls are working as intended, that weaknesses are being identified early, and that your environment has been tested in a way that reflects how attackers actually operate. 

What this means for you: 

  • Cyber risk should be managed alongside other core business risks 
  • Incident response needs to be planned and practiced 
  • Regular testing and assurance activities are essential 
  • Visibility across systems and users is critical to identifying issues early 

Phishing and credential attacks continue to succeed 

Phishing remains the most common attack method, often leading directly to compromised accounts. 

What is notable is how persistent the underlying weaknesses are. Only around 40% of businesses report using multi-factor authentication, despite it being one of the most effective ways to prevent unauthorised access. 

Attackers are not relying on new techniques here. They are taking advantage of controls that are either missing or inconsistently applied. 

What this means for you: 

  • Multi-factor authentication should be standard across critical systems 
  • Technical controls need to support user awareness, not depend on it 
  • Monitoring for unusual login activity should be part of your baseline capability 
  • Training staff to identify phishing attempts and then reporting them is a frontline defence 

The impact of incidents is often underestimated 

The survey reports an average cost of £1,600 for the most disruptive breach, rising to £8,260 where there is a direct financial impact. 

In reality, the cost is rarely limited to this. Time spent responding, operational disruption, regulatory reporting and reputational impact can quickly outweigh the initial figures. 

Even relatively contained incidents can become complex once they involve customers, regulators or third parties. 

What this means for you: 

  • The true cost of an incident is broader than immediate financial loss 
  • Faster, more coordinated response reduces overall impact 
  • Preparation has a direct effect on how disruptive an incident becomes 

Governance still makes the difference 

Only around a quarter of businesses have a clear board-level responsibility for cyber security. Where that ownership is missing, gaps tend to follow. 

Organisations with weak governance typically underinvest in prevention, delay testing, and struggle to respond effectively when incidents occur. Cyber security is still too often treated as a technical hygiene task rather than a core business risk. 

This is not about turning boards into technical experts. It is about ensuring there is clear accountability, appropriate challenge and visibility of risk. 

What this means for you: 

  • Cyber security needs defined ownership at senior level 
  • Reporting should focus on risk and business impact 
  • Leadership involvement improves both preparedness and response 

Testing is where many organisations fall short 

A consistent theme is that organisations believe controls are in place but have limited evidence of how effective they are. This disconnect usually exists because controls are not being tested from an attacker’s perspective. 

Penetration testing plays a critical role here. Unlike compliance checklists or policy reviews, pentesting answers a simple question: can someone actually break in? 

At C3IA, common findings in penetration testing for our clients include: 

  • Internet-facing systems that are more exposed than expected 
  • Weak segmentation that allows movement between systems 
  • Outdated or vulnerable software still in use 
  • Third-party access routes that are not fully controlled 

Crucially, penetration testing provides evidence. It allows your organisation to prioritise fixes based on real risk, not assumptions. 

Where to focus your efforts 

The survey reinforces the importance of executing well in a few key areas rather than trying to do everything at once. 

 Focus on: 

  • Clear senior accountability for cyber risk 
  • Consistent implementation of core controls such as MFA and patching 
  • Independent validation of control effectiveness 
  • A tested and understood incident response capability 
  • Better visibility and management of third-party risk 

How C3IA can support you 

C3IA works with organisations across the UK to help turn insight into practical action. 

This includes: 

  • Penetration testing to identify real-world vulnerabilities 
  • Independent assurance over the effectiveness of controls 
  • Support in developing and testing incident response 
  • Helping leadership teams understand and prioritise risk 

Whether you are looking to validate existing controls, meet regulatory expectations, or simply gain clarity on your true risk position, independent testing and expert insight are essential. 

If the findings in the Cyber Security Breaches Survey feel uncomfortably familiar, now is the time to act. 

Speak to C3IA to understand where your organisation could be exposed and what good looks like in practice. 

Back To Top