More than four in ten (43%) UK businesses have been hit by a cyber breach or attack in the past 12 months, according to the latest data from the UK government.
The Department for Science, Innovation and Technology released their 2025/26 Cyber Security Breaches Survey, which showed that 69% of large firms suffered a cyber breach or attack in the past 12 months, with 29% of firms experiencing a breach or attack at least once a week.
The astounding figures show that the cyber threats in the UK are paramount and myriad; the high-profile attacks against UK retail giants last Spring and the Jaguar Land Rover attack – one of the most costly ever in the UK – are just the ones that hit the headlines as cyber incidents permeate across UK enterprise, becoming commonplace.
According to the survey, about 612,000 UK businesses reported a cyber incident in the past 12 months.
The survey also reveals a gap in security posture, starting at the board, with only 31% of businesses having board-level responsibility for cybersecurity. Further, only a quarter (25%) of businesses have a formal incident response plan, increasing the potential damage of attacks.
Despite calls for staff training and increased understanding of the threat, phishing remains the most common type of attack, accounting for 38% of breaches.
Cyber security minister Liz Lloyd has written to CEOs and Chairs of over 180 UK businesses urging them to sign up to the new Cyber Resilience Pledge to improve their security posture amid the torrent of threats.
trols.
Recommended reading
- Report: Cyber Breaches Are Tanking Share Prices
- Negligence Stirring Rise in Cyber Incidents
- Inside the Aftermath: What Really Happens When You Get Hacked
- Report: 93% of Data Breaches Expose Financial Records
The pledge would require businesses to take three actions: making cyber a board-level responsibility; signing up to the Early Warning service from the National Cyber Security Centre; and earning a Cyber Essentials certification across their operations and supply chain.
“These figures are a stark reminder of the importance of having robust cyber security measures. All business leaders should be gripping this issue and taking action now, especially as AI is making the threat more acute. Quite simply, firms cannot afford not to take these steps,” Lloyd said.
“Businesses are not powerless. Practical steps such as using the NCSC’s free guidance, signing up to their Early Warning service and adopting Cyber Essentials can significantly strengthen defences and help keep businesses, customers and the wider economy safe.”





