Forty-three percent identified a breach or attack.
The survey counts incidents businesses were able to identify and willing to report, so the true level may be higher.
One chart is shown at a time. Move through the deck, pause on any chart, and use the figures as helpful context—not a reason to panic.
Most small and medium businesses do not need a large internal cyber department to make progress. Stronger sign-in, updates, backups, clear responsibilities and safer digital services are sensible places to begin.
The survey counts incidents businesses were able to identify and willing to report, so the true level may be higher.
Reported rates were forty-two percent for micro businesses, forty-six percent for small businesses, sixty-five percent for medium businesses and sixty-nine percent for large businesses.
Phishing means deceptive messages or websites designed to make someone click, sign in, share information or approve a payment.
Among businesses that identified a breach or attack, twenty-nine percent experienced one at least weekly and twenty-two percent around once a month.
Forty-seven percent of businesses required two-factor authentication. This means a second check is needed as well as a password.
Thirty-four percent of businesses had a policy to apply software security updates within fourteen days. The second bar is the remaining share of the survey result.
Twenty-five percent had a formal incident response plan, while forty-five percent had none of the response measures listed by the survey.
Only twenty-two percent considered cyber security to a large extent when buying new software. This is why secure planning should begin before a website or application is built.
The National Cyber Security Centre handled two hundred and four nationally significant incidents, compared with eighty-nine the year before. This is not the total number of United Kingdom attacks, but it shows increasing pressure at the serious end of the threat landscape.
Useful security work can begin with a clear review, a prioritised plan and better decisions around accounts, updates, backups and the way websites or applications are designed.
Review important accounts, two-step sign-in, devices, backups and who has access.
Write down who to contact, what must continue and where reliable backups are held.
Plan data, permissions, secure forms, updates and recovery before a digital service goes live.
A Cyber Health Check turns broad guidance into a practical list for your business.