The Department for Science, Innovation and Technology published the Cyber Security Breaches Survey 2025/2026 in April 2026. The headline figure of 43 percent of businesses reporting a breach or attack is large. What the report is more careful about stating plainly is that the equivalent figures for the two previous years were 50 percent in 2024 and 32 percent in 2023. The apparent decline masks a more complex picture that the technical annex makes clear: improved detection has increased reporting accuracy and the 2023 figure likely underrepresented actual breach rates. The honest reading is that the baseline has not moved.
The survey estimates 5.19 million cybercrime incidents during the period. The proportion of incidents resulting in lost revenue or a fall in share value has more than doubled from 2 percent to 5 percent since the previous survey. This financial impact figure is almost certainly an undercount because it only captures impacts that organisations were able to quantify and willing to report.
Phishing was the attack vector in 85 percent of business incidents and 86 percent of charity incidents among those that experienced any breach at all. This is not a marginal finding. It means that the dominant mechanism through which UK organisations are compromised in 2026 is not zero-day exploitation, supply chain poisoning or sophisticated persistent threat activity. It is an email that tricks someone into clicking a link or entering credentials on a fake page.
Breach Rates Across Sectors and Organisation Sizes
The distribution of breach rates across organisation types reveals a pattern that should concentrate minds at the leadership level of every medium and large organisation in the UK. The chart below shows the percentage of each organisation type reporting a breach or attack in the past twelve months.

Chart 1: Percentage of UK organisations reporting a cyber breach or attack by type, DSIT Breaches Survey 2025/2026
The Education Sector Figures Deserve Separate Attention
Ninety one percent of universities and 85 percent of further education colleges reported a breach or attack. These are not organisations that lack awareness of the threat. They are organisations with structural characteristics that make them extremely difficult to defend: large, decentralised user populations with minimal central IT control, high volumes of research data that is valuable to state-sponsored actors and chronic underfunding of security functions relative to the scale of the challenge.
The university breach rate has remained above 85 percent for four consecutive years. This is not a problem that awareness campaigns or Cyber Essentials certification will solve at the structural level. It requires investment in centralised identity and access management, network segmentation and endpoint visibility of a kind that most UK universities have not been funded to implement.
Why the Numbers Have Not Improved
The 2025/2026 survey is frank about the reasons for the persistent baseline. Governance approaches remain fragmented and inadequate. Compliance is treated as a sporadic activity rather than an ongoing posture. The evidence driven connection between specific controls and specific risks that characterises genuinely effective security programmes is absent in the majority of organisations surveyed.
There is also a resources dimension that the survey acknowledges without fully quantifying. Small businesses account for a disproportionate share of UK economic activity and employment. The survey shows their breach rate at 38 percent, lower than larger organisations but still representing hundreds of thousands of businesses. Most of these organisations have no dedicated security resource. The government’s Cyber Essentials scheme provides a baseline but its take-up remains low outside sectors where it is mandated.
Where Organisations Should Focus Limited Resources
| Defensive Measure | Why It Has the Highest Impact | Implementation Complexity |
| Multi-factor authentication on email and remote access | Phishing drives 85 percent of breaches and MFA stops most credential-based follow-on access | Low. Most cloud email platforms include MFA at no additional cost |
| Simulated phishing exercises | Staff who have experienced a realistic phishing test are measurably less likely to fall for real attacks | Low to medium. Multiple providers offer automated programmes at modest cost |
| Patching critical vulnerabilities within 14 days | Exploited vulnerabilities are the second most common initial access vector after phishing | Medium. Requires patch management process and testing discipline |
| Cyber Essentials certification | Addresses the five controls that mitigate the majority of commodity attacks; now required for government contracts | Low to medium. Self-assessed or independently verified |
| Offline backup testing | The difference between recovering from ransomware and paying a ransom is almost always a tested offline backup | Medium. Requires scheduled testing not just backup creation |
Table 1: Highest-impact security measures for UK organisations based on DSIT breach survey findings and NCSC guidance

Leave a Reply