More than four in ten businesses (43%) and three in ten charities (30%) reported experiencing any kind of cybersecurity breach or attack in the past year, new government statistics reveal.
The UK government released data from its cybersecurity breaches survey, which revealed a decrease in the number of cyber-attacks faced by UK businesses in the past 12 months.
UK businesses faced about 612,000 cyber-attacks or breaches, while UK charities faced about 61,000. This is a marked decrease from the 2024 data, which showed that 50% of UK businesses faced an attack or breach, equating to 718,000.
The survey said the decrease was mainly driven by fewer micro and small businesses identifying phishing attacks, though the prevalence of breaches and attacks in medium and large businesses remain high and on par with 2024 figures.
Of the businesses and charities that experienced a breach in the past 12 months, phishing attacks remain the most prevalent, the survey found, experienced by 85% of businesses and 86% of charities.
Businesses reported an increase in temporary loss of access to files or networks from last year (7% vs 4%), while charities experienced a rise in loss of access to third-party services (5% vs 1% in 2024).
Cyber Hygiene
The UK government survey found a mixed bag when it comes to cyber hygiene across businesses and charities of various sizes.
The survey found that small businesses are encouragingly showing improvement in many cyber hygiene practices, including increased uptake of cybersecurity risk assessments, cyber insurance, formal cybersecurity policy covering cybersecurity risks, and business continuity plans that address cybersecurity.
Conversely, high-income charities showed a decline in several of these areas compared to last year, including in identifying cyber risks, reviewing supplier risks, and having a formal cybersecurity strategy in place.
Still the majority of businesses and charities have implemented basic technical controls, like malware protection, password policies, network firewalls, backing up data securely, and restricted admin rights.
However, other measures have lower rates of adoption, such as two-factor authentication, virtual private networks for staff, and user monitoring.
Risk Management and Supply Chains
The survey revealed a troubling trend as relatively few businesses or charities are taking steps to review the risks posed by their immediate suppliers and wider supply chain.
Just over one in ten businesses said they reviewed the risks posed by their immediate suppliers (14%) and under one in ten were looking at the wider supply chain (7%). Among charities, the respective figures were slightly lower (9% at their immediate suppliers, and 4% at their wider supply chain).
This varied by size, possibly reflecting a more complex supply chain, with around a third of medium businesses (32%) and nearly half of large businesses (45%) reviewing the cybersecurity risks posed by their immediate suppliers, in comparison to 22% of micro businesses and 21% of small businesses.
Recommended reading
- UK Cybersecurity Budgets Set to Surge Over 30% in 2025
- UK Cybersecurity Revenue Grows 12%, Reaches £13.2BN
- Cyber Leaders Reveal Compliance and Boardroom Struggles
Board Engagement
While cybersecurity remains a high priority for the majority of businesses (72%) and charities (68%), a trend emerged that board-level responsibility for cybersecurity has steadily declined among businesses since 2021.
Larger organisations to have a higher prioritisation of cybersecurity (92%) compared to businesses overall (72%).
Cyber-crime
According to the government, some cyber breaches and attacks do not count as cyber-crimes according to the law, so the survey presented some separate statistics for this phenomenon.
20% of businesses and 14% of charities have been victims of at least one cyber-crime in the past year, the data found. This means that just under half of businesses identifying a breach or attack ended up being victims of a cyber-crime.
The larger the business, the more likely they were to experience a cyber-crime, the survey found, with 52% of all crimes being reported by large organisations. The same pattern was found among charities based on relative income.
While the level of overall crime remained static, the prevalence of ransomware among businesses increased from less than 0.5% in 2024 to 1% in 2025.
UK businesses experienced approximately 8.58 million cyber-crimes of all types in the last 12 months, which includes non-phishing crimes and fraud. Charities in the UK experienced around 435,000 cyber-crimes in the same time span.





