Data explained simply

Useful cyber figures for business decisions.

One chart is shown at a time. Move through the deck, pause on any chart, and use the figures as helpful context—not a reason to panic.

A practical view

Understand the pattern, then focus on what you can improve.

Most small and medium businesses do not need a large internal cyber department to make progress. Stronger sign-in, updates, backups, clear responsibilities and safer digital services are sensible places to begin.

Read the figures carefully: the charts describe different questions, groups and time periods. They should not be added together or treated as the exact chance that one business will be attacked.

See sources and survey context

United Kingdom businesses • 2025/2026
43%of businesses

Forty-three percent identified a breach or attack.

The survey counts incidents businesses were able to identify and willing to report, so the true level may be higher.

Source details and context

Business size
42%Micro46%Small65%Medium69%Large

No business size is outside the picture.

Reported rates were forty-two percent for micro businesses, forty-six percent for small businesses, sixty-five percent for medium businesses and sixty-nine percent for large businesses.

Source details and context

Phishing messages
38%of businesses

Phishing remained the most common reported attack route.

Phishing means deceptive messages or websites designed to make someone click, sign in, share information or approve a payment.

69%of affected businesses called phishing the most disruptive type

Source details and context

How often affected businesses saw incidents
Weekly or more29%Once a month22%Less than monthly27%Only once19%

For some affected businesses, incidents were repeated.

Among businesses that identified a breach or attack, twenty-nine percent experienced one at least weekly and twenty-two percent around once a month.

Source details and context

Safer sign-in
47%of businesses

Less than half required two-step sign-in.

Forty-seven percent of businesses required two-factor authentication. This means a second check is needed as well as a password.

Source details and context

Security updates
Policy within 14 days34%No such policy reported66%

Timely software updates are not yet standard everywhere.

Thirty-four percent of businesses had a policy to apply software security updates within fourteen days. The second bar is the remaining share of the survey result.

Source details and context

Incident preparation
25%of businesses

Formal response plans remain limited.

Twenty-five percent had a formal incident response plan, while forty-five percent had none of the response measures listed by the survey.

45%had none of the listed response measures

Source details and context

Buying software
Considered to a large extent22%Not a major concern38%Not considered at all12%

Security is often not central when software is purchased.

Only twenty-two percent considered cyber security to a large extent when buying new software. This is why secure planning should begin before a website or application is built.

Source details and context

Wider United Kingdom threat environment
2023–2024892024–2025204Bar lengths show 89 as 43.6% of 204.

Nationally significant incidents more than doubled.

The National Cyber Security Centre handled two hundred and four nationally significant incidents, compared with eighty-nine the year before. This is not the total number of United Kingdom attacks, but it shows increasing pressure at the serious end of the threat landscape.

Source details and context

What this means in practice

Start with manageable improvements.

Useful security work can begin with a clear review, a prioritised plan and better decisions around accounts, updates, backups and the way websites or applications are designed.

Check the basics

Review important accounts, two-step sign-in, devices, backups and who has access.

Prepare before pressure

Write down who to contact, what must continue and where reliable backups are held.

Build carefully

Plan data, permissions, secure forms, updates and recovery before a digital service goes live.

General statistics are useful. Your own risk picture is more useful.

A Cyber Health Check turns broad guidance into a practical list for your business.

Start a conversation