The Cyber Security Breaches Survey is a research study for UK cyber-resilience, aligning with the UK Government’s National Cyber Strategy. The study explores the policies, processes and approach to cybersecurity, for businesses, charities and educational institutions.
It also considers the different cyber-attacks and cyber-crimes these organisations face, as well as how these organisations are impacted and respond.
For this latest release, the UK Government’s quantitative survey was carried out in winter 2023/24 and the qualitative element in early 2024.
Identification of Cybersecurity Breaches and Attacks
Cybersecurity breaches and attacks remain a common threat.
Half of businesses (50%) and around a third of charities (32%) report having experienced some form of cybersecurity breach or attack in the last 12 months. This is much higher for medium businesses (70%), large businesses (74%) and high-income charities with £500,000 or more in annual income (66%).
By far the most common type of breach or attack is phishing (84% of businesses and 83% of charities). This is followed, to a much lesser extent, by others impersonating organisations in emails or online (35% of businesses and 37% of charities) and then viruses or other malware (17% of businesses and 14% of charities).
Among those identifying any breaches or attacks, the survey estimates that the single most disruptive breach from the last 12 months cost each business, of any size, an average of approximately £1,205. For medium and large businesses, this was approximately £10,830. For charities, it was approximately £460.
Cyber-hygiene
The most common cyber-threats are relatively unsophisticated, so government guidance advises businesses and charities to protect themselves using a set of “cyber-hygiene” measures. A majority of businesses and charities have a broad range of these measures in place.
The most common are updated malware protection, password policies, cloud back-ups, restricted admin rights and network firewalls – each administered by at least seven in ten businesses and around half of charities or more. Compared to 2023, the deployment of various controls and procedures has risen slightly among businesses:
- Using up-to-date malware protection (up from 76% to 83%).
- Restricting admin rights (up from 67% to 73%).
- Network firewalls (up from 66% to 75%).
- Agreed processes for phishing emails (up from 48% to 54%).
These trends represent a partial reversal of the pattern seen in the previous three years of the survey, where some areas had seen consistent declines among businesses. The changes mainly reflect shifts in the micro business population and, to a lesser extent, small and medium businesses.
Risk Management and Supply Chains
Businesses are more likely than charities to take actions to identify cyber-risks. Larger businesses (defined as medium and large businesses as opposed to smaller business that cover micro and small business) are the most advanced in this regard.
31% of businesses and 26% of charities have undertaken cybersecurity risk assessments in the last year – rising to 63% of medium businesses and 72% of large businesses.
A third of businesses (33%) deployed security monitoring tools, rising to 63% of medium businesses and 71% of large businesses. The proportion was lower among charities (23%).
Around four in ten businesses (43%) and a third of charities (34%) report being insured against cybersecurity risks rising to 62% of medium businesses and 54% of large businesses (i.e. cyber insurance is more common in medium businesses than large ones). Compared to the 2023 survey, the proportion of businesses with some form of insurance has increased from 37% to 43%, while the proportion has remained stable among charities.
Just over one in ten businesses say they review the risks posed by their immediate suppliers (11%, vs. 9% of charities). More medium businesses (28%) and large businesses (48%) review immediate supplier risks.
Qualitative interviews suggest that organisations have an increasing awareness of the cybersecurity risks posed by supply chains. Despite this, organisations, particularly at the smaller end, tend to have limited formal procedures in place to manage cyber-risks from wider supply chains.
Board Engagement and Corporate Governance
Board engagement and corporate governance approaches towards cybersecurity tend to be more sophisticated in larger organisations. Levels of activity have remained stable compared with 2023.
Three-quarters of businesses (75%) and more than six in 10 charities (63%) report that cybersecurity is a high priority for their senior management. This proportion is higher among larger businesses (93% of medium businesses and 98% of large businesses, vs. 75% overall). The same is true for high-income charities (93% of those with income of £500,000 or more, vs. 63% overall).
The proportion that say cybersecurity is a high priority has remained stable since 2023, following an apparent decrease in prioritisation in 2023. The qualitative interviews suggest that, despite economic conditions, many organisations have continued to invest either the same amount or more in cybersecurity over the last 12 months. This is in part a response to the perceived increase in the number of cyber-attacks and their sophistication.
Three in ten businesses and charities (both 30%) have board members or trustees explicitly responsible for cybersecurity as part of their job role – rising to 51% of medium businesses and 63% of large businesses. There has been no change in the overall figures since 2023.
22% of medium businesses and 33% of large businesses have heard of the NCSC’s Board Toolkit rising from 11% and 22% respectively in 2020 (when it was introduced).
58% of medium businesses, 66% of large businesses and 47% of high-income charities have a formal cybersecurity strategy in place. The figures for both businesses and charities are higher than in 2023 with significant changes seen for medium businesses and charities.
Qualitative data shows a similar set of issues to previous years that prevent boards from engaging more in cybersecurity, including a lack of knowledge, training and time. It also highlights a contrast between more structured board engagement in larger organisations, compared with more informal approaches in smaller organisations, where responsibility was often passed onto external contractors.
Cyber-accreditations and Following Guidance
The proportion of businesses seeking external information or guidance on cybersecurity has fallen since 2023. In addition, a sizeable proportion of organisations, including larger organisations, continue to be unaware of government guidance such as the 10 Steps to Cyber Security, and the government-endorsed Cyber Essentials standard.
Linked to this, relatively few organisations at present are adhering to recognised standards or accreditations.
Four in ten businesses (41%) and charities (39%) report seeking information or guidance on cybersecurity from outside their organisation in the past year, most commonly from external cybersecurity consultants, IT consultants or IT service providers. The figure for businesses is lower than in 2023 (49%), while there has been no change among charities.
13% of businesses and 18% of charities are aware of the 10 Steps guidance – rising to 37% of medium businesses and 44% of large businesses. Nevertheless, 39% of businesses and 32% of charities have taken action on 5 or more of the 10 Steps. This is much more common in medium businesses (80%) and large businesses (91%). Just 3% of businesses and charities have enacted all 10 Steps, increasing to 14% of medium businesses and 27% of large businesses.
12% of businesses and 11% of charities are aware of the Cyber Essentials scheme, consistent with 2023 but representing a decline over last 2-3 years. Awareness is higher among medium businesses (43%) and large businesses (59%). Although only 3% of businesses and charities report adhering to Cyber Essentials, a higher proportion (22% of businesses and 14% of charities) report having technical controls in all five of the areas covered by Cyber Essentials.
Qualitative findings suggest the desire to seek external accreditation can be due to client demand, pressure from board members, a motivation to enforce a positive change in staff culture, and peace of mind for stakeholders.
Incident Response
While a large majority of organisations say that they will take several actions following a cyber-incident, in reality a minority have agreed processes already in place to support this. These findings are consistent with previous years.
The most common processes, mentioned by around a third of businesses and charities, are having specific roles and responsibilities assigned to individuals, having guidance on external reporting, and guidance on internal reporting.
Formal incident response plans are not widespread (22% of businesses and 19% of charities have them). This rises to 55% of medium-sized businesses, 73% of large businesses and 50% of high-income charities.
External reporting of breaches remains uncommon. Among those identifying breaches or attacks, 34% of businesses and 37% of charities reported their most disruptive breach outside their organisation. Many of these cases simply involve organisations reporting breaches to their external cybersecurity or IT providers and no one else.
The qualitative interviews highlighted several challenges organisations might face when dealing with cyber-incidents. In smaller organisations, there was a strong reliance on DSPs for incident response, such as IT providers and cloud storage providers. This was linked with a lack of in-house expertise or capacity. In larger organisations, the challenges were often more related to a disconnect between IT or cyber-teams and wider staff, including senior managers.
Cyber-crime
Some cybersecurity breaches and attacks do not constitute cyber-crimes under the Computer Misuse Act 1990 and the Home Office Counting Rules. Therefore, the statistics on prevalence and financial cost of cyber-crime differ from the equivalent estimates for all cybersecurity breaches or attacks (as described above). They should be considered as a distinct set of figures, specifically for crimes committed against organisations, so are a subset of all breaches and attacks.
This survey includes questions on cyber-crime and cyber-facilitated fraud. Changes to the questions were made in order to strengthen the reliability of the more experimental data from the 2023 survey. Due to these changes, it is not possible to make direct comparisons between 2023 and 2024. The new 2024 data should also still be considered experimental.
Recommended reading
- UK Gov to Link China to Electoral Commission Cyber-attack
- NCSC Releases Cyber Incident Response Guidance for CEOs
- Over 1 in 10 Business Leaders Don’t Know if They’ve Been Hacked
An estimated 22% of businesses and 14% of charities have experienced cyber-crime in the last 12 months, rising to 45% of medium businesses, 58% of large businesses and 37% of high-income charities. Looked at another way, among the 50% businesses and 32% of charities identifying any cybersecurity breaches or attacks, just over two-fifths (44% for businesses and 42% for charities) ended up being victims of cyber-crime.
A total of 3% of businesses and 1% of charities have been victims of fraud as a result of cyber-crime. The proportion is higher among large businesses (7%).
The survey estimates that UK businesses have experienced approximately 7.78 million cyber-crimes of all types and approximately 116,000 non-phishing cyber-crimes in the last 12 months. For UK charities, the estimate is approximately 924,000 cyber-crimes of all types in the last 12 months. It should be noted that these estimates of scale will have a relatively wide margin of error.
The average (mean) annual cost of cyber-crime for businesses is estimated at approximately £1,120 per victim (this excludes crimes where the only activity was phishing).





