Technology

43% of UK businesses had a cyber breach last year. Most weren't big companies.

4 min read

Every year, the Department for Science, Innovation and Technology and the Home Office publish the Cyber Security Breaches Survey — official statistics on how many UK organisations experienced a cyber breach or attack, and what it cost them. The 2025/2026 edition, published on 30 April 2026, found that 43% of businesses identified a breach or attack in the past 12 months.

It’s easy to read a statistic like that and picture large corporates with dedicated security teams. The reality is closer to the opposite: small and micro businesses make up the overwhelming majority of UK companies, and they’re rarely the ones with a security team at all.

Why this matters more for small businesses, not less

Larger businesses tend to have dedicated IT and security staff, tested backup procedures, and budget set aside for incident response. Most small businesses don’t — which means a breach isn’t just more likely to happen, it’s more likely to actually hurt when it does. A few days of lost access to your booking system, your card payment terminal, or your customer records lands very differently on a five-person business than a five-hundred-person one.

The survey also found that 72% of businesses consider cyber security a high priority for senior management — which suggests awareness isn’t really the gap. The gap is usually time, budget, and knowing where to start.

What actually causes most breaches

The overwhelming majority of reported breaches and attacks aren’t sophisticated, targeted operations. They’re phishing emails, weak or reused passwords, and out-of-date software with known vulnerabilities — all of which are addressable without a big security budget:

Keep software and systems updated, including the boring stuff — router firmware, POS software, the operating system on the office PC nobody thinks about.

Use a password manager and multi-factor authentication on anything that touches money, customer data, or your website — email accounts especially, since a compromised inbox is often step one of a bigger breach.

Back up properly, and actually test the restore — a backup you’ve never tried to recover from isn’t a backup you can rely on in an emergency.

Know who to call before you need them. If something does go wrong, the businesses that recover fastest are usually the ones who already had a plan and a point of contact, not the ones improvising on the day.

Where this fits with the rest of your business

Cyber security often gets treated as a separate, technical problem — something to worry about later, or hand off entirely. In practice it sits alongside the other infrastructure decisions a growing business makes: what software you run, who hosts it, and whether it’s actually built and maintained by people who are accountable when something breaks.

That’s the thinking behind our apps and web development service — we don’t just build the software, EPOS systems and websites businesses run on, we host and manage the database behind them too, so there’s one team responsible for the whole stack rather than a chain of vendors to chase when something needs fixing.

Source: GOV.UK, Cyber Security Breaches Survey 2025/2026, Department for Science, Innovation and Technology and Home Office, published 30 April 2026.

Contingency fee — no saving, no charge

Let's find out what you're overpaying.

A free review takes a few minutes and puts no obligation on you. If we can't find you a saving, it costs you nothing.