The UK Government's 2025/2026 Cyber Security Breaches Survey reveals that 43% of UK businesses reported a cyber breach or attack in the last year, equating to roughly 612,000 organizations.
The survey also identifies around 5.19 million cybercrime incidents during this period, with incidents leading to revenue loss or dips in share value more than doubling from 2% to 5% since previous reports. These findings signify that cyber threats continue to be a major issue, with many businesses urged to boost their resilience against such attacks.
National Awareness Initiatives
Despite numerous initiatives such as boardroom briefings, regulatory warnings, and national awareness campaigns, the UK is yet to break its cycle of acknowledging but inadequately managing risks. Businesses are aware of the threats but often lack structured and reliable strategies for managing these threats before they manifest into breaches.
The survey highlights that only 31% of businesses assign board-level responsibility for cybersecurity
The survey highlights that only 31% of businesses assign board-level responsibility for cybersecurity. Just 15% review risks from their immediate suppliers, and a mere 6% extend this review to their broader supply chain, indicating a decline in fundamental preparedness, particularly among smaller enterprises.
Challenges for Smaller Businesses
For small and medium-sized enterprises (SMEs), cybersecurity is often seen as a technical issue confined to IT departments rather than a structural concern needing oversight and accountability. Many SMEs operate with limited internal resources and rely heavily on external suppliers, creating a distinct risk profile compared to larger businesses.
The necessity of having comprehensive visibility of data, affected systems, involved suppliers, and existing controls is critical for effective incident response. Without pre-established information, responding to breaches becomes less efficient and more costly, highlighting the need for practical governance measures.
Supply Chain Risks and Accountability
The survey shows that a small number of organizations evaluate their supplier risks
Today’s businesses depend on external software providers, outsourced IT partners, and various other service platforms, making comprehensive supply chain risk assessment crucial. The survey shows that a small number of organizations evaluate their supplier risks, highlighting a gap in overall cybersecurity strategies.
In the UK, there is a shift towards enforcing cybersecurity resilience as a standard rather than a recommended practice. Demonstrating adequate control requires evidence, ownership, and up-to-date information, correlating cybersecurity risk with compliance, operations, and leadership.
Improving Governance Practices
Although organizational awareness of cyber threats is widespread, many lack the governance discipline necessary for proactive protection against cyber incidents. To enhance resilience, organizations must document control measures, integrate suppliers into risk assessments, and provide leadership with a comprehensive view of cyber resilience ahead of potential threats.
The survey indicates that progress in cybersecurity remains sluggish due to fragmented and inadequate governance approaches. To truly advance, businesses need to establish evidence-driven governance frameworks that connect controls to risks and move away from reactive practices, ensuring compliance is an ongoing posture rather than a sporadic activity.
The latest Cyber Security Breaches Survey makes for uncomfortable reading for UK businesses. According to the Government’s 2025/2026 report, 43% experienced a breach or attack in the last 12 months – that’s around 612,000 organizations. The findings also estimate approximately 5.19 million cybercrimes over the same period, while the proportion of breaches or attacks resulting in lost revenue or share value has more than doubled, rising from 2% to 5%.
On a surface level, the story is familiar – cyber attacks remain widespread, phishing continues to dominate and businesses are once again being urged to improve resilience. Experts have already described the findings as depressingly familiar, and it’s not difficult to see why. The numbers move slightly from year to year, but the underlying pattern remains largely unchanged, which is the real concern here.
National awareness campaigns
After years of major incidents, boardroom briefings, regulatory warnings and national awareness campaigns, the UK is still stuck in a cycle where risk is recognized, but not consistently governed. Businesses know threat exists, but many still lack the ability to demonstrate, in a structured and reliable way, how that threat is being managed before something goes wrong.
A breach shows the visible outcome of decisions, controls, gaps and assumptions that existed long before the incident itself. By the time a breach appears in a survey, the more important questions have already been missed: Were the right controls in place and were they being reviewed? Was there clear ownership? The answers to these determine whether an organization is genuinely resilient or simply fortunate.
Some areas of basic preparedness
The survey tells us a great deal about the scale of cybercrime and reveals too many companies are still measuring risk at the point of failure rather than at the point of control.
Only 31% of businesses have board-level responsibility for cyber security, just 15% review the risks posed by their immediate suppliers and only 6% look at the wider supply chain. The survey also points to small businesses going backwards in some areas of basic preparedness.
Cyber security is still too often treated as a technical function, owned somewhere inside IT and discussed seriously only when an incident takes place. Yet most of the weaknesses exposed by modern incidents are structural, with no clear accountability, no consistent control framework, no live view of risk and no board-level visibility until they are already under pressure.
Customer assurance process
Smaller businesses are often told to adopt better cyber hygiene. Whilst this advice is valid, it can also oversimplify the challenge. SMEs typically operate with less internal capacity, fewer dedicated roles, more informal processes and greater dependence on external suppliers, creating a very different kind risk profile from larger enterprises.
For many, cyber risk is managed through individual knowledge rather than institutional structure. One person knows where the policies are stored, one external provider understands the systems and one senior leader owns the customer assurance process, but that kind of system becomes fragile quickly.
Last-minute effort
The business needs clear visibility over the data it holds, the systems affected, the suppliers involved, the controls in place, what evidence exists and who is authorized to make decisions. If that information has not been organized in advance, incident response becomes slower and more expensive. This is where governance needs to become more practical.
Smaller organizations don’t need the same level of bureaucracy as global enterprises, but they do need a clear way to map risks, assign ownership, manage controls, maintain evidence and show progress over time. Without that, cyber resilience remains dependent on goodwill, memory and last-minute effort.
Outsourced IT partners
Modern companies rely on software providers, outsourced IT partners, consultants, payment systems, logistics platforms, cloud environments and data processors, which means cyber risk rarely sits neatly within the four walls of their organization. A weakness in one supplier can quickly become a weakness in the business itself.
But as the survey shows, only a small minority of organizations are reviewing immediate supplier risk and even fewer are looking at the wider supply chain. Customers are already asking more detailed questions about security controls, investors are looking more closely at operational resilience, regulators are moving towards stronger expectations around supply chain accountability and insurers are becoming more interested in evidence. In that environment, “we trust the supplier” is not enough.
Supply chain accountability
The UK is moving away from a model where cyber security is largely treated as voluntary good practice and towards one where resilience must be demonstrated. The Bill is part of that shift.
Demonstrating that the right controls, oversight and processes were in place before a breach happened relies on evidence, ownership and current information. It requires cyber risk to be connected to compliance, operations, procurement and leadership.
This is where many organizations will feel the gap most sharply. They may be doing some of the right things, but if those activities are fragmented, undocumented or disconnected from recognized frameworks, they will struggle to prove it.
Evidence-led governance
The UK doesn’t have a cyber awareness problem in the traditional sense. Most business leaders understand that attacks can disrupt operations, damage trust and create financial loss.
But, businesses need to better understand which frameworks apply, which controls are in place, who owns them, when they were last reviewed and where the evidence sits. That means treating compliance as a live management discipline rather than a project that begins shortly before an audit or customer request. Frameworks such as ISO 27001, SOC 2 and Cyber Essentials are becoming more important because they give organizations a common structure for turning cyber intent into demonstrable control. They also help in moving away from reactive reassurance and towards evidence-led governance.
Clear view of resilience
The real value in the Cyber Security Breaches Survey is in showing why progress remains slow. Too many businesses are using an approach that creates the appearance of activity without the discipline of governance and, until that changes, the annual numbers will continue to look familiar.
To move ahead, businesses need to build the evidence first, connect controls to risk, bring suppliers into scope and give leadership a clear view of resilience before pressure hits. Compliance isn’t a report, it’s a posture – that’s what the latest survey is really telling us.