Read the official breach statistics the way most coverage read them and you get an alarming number. Just over four in ten UK businesses, 43%, identified a cyber security breach or attack in the last twelve months. Scaled to the wider business population that is roughly 612,000 firms.
Read one page further and you get a much stranger number. The median perceived cost of the most disruptive breach those businesses suffered was £0.
Both come from the same publication: the Cyber Security Breaches Survey 2025/2026, produced by the Department for Science, Innovation and Technology with the Home Office and published on 30 April. They are not in tension, and the gap between them is the most commercially useful thing in the report. Cyber risk in the UK is not a steady tax on trading. It is a long-tailed distribution, and most firms budget for it as though it were an average.
What the survey actually measured
The 43% headline covers any identified breach or attack, from a phishing email that nobody clicked to a full compromise. It has been broadly flat for a year, after falling from 50% in 2023/2024. The rate climbs steeply with size: 42% of micro businesses and 46% of small ones, against 65% of medium and 69% of large firms. That gradient is unsurprising, since a larger organisation has more staff to target, more systems to expose and more people paid to notice when something happens.
The cost figures are self-reported estimates of the most disruptive single incident, which is why the survey calls them perceived costs. The middle half of businesses, the 25th to 75th percentile, put that cost somewhere between £0 and £200. Only for medium and large firms does the median rise above zero at all, and then only to £30.
Taken alone, those numbers would justify spending almost nothing. That is precisely the trap.
The average is the wrong statistic
At the 95th percentile the picture changes completely. The top 5% of cases cost £4,000 for businesses overall and for micro and small firms, rising to £10,000 for medium and large businesses. Narrow the sample to incidents that produced an actual outcome, or to firms that reported any material financial cost at all, and the figures rise again. For non-phishing cyber crime specifically, the median perceived cost was £560.
This is the shape of the problem. A typical year for a typical firm costs nothing, which is why the typical firm concludes it is adequately protected. The evidence for that conclusion is real, and it is also the evidence a business would see in the years immediately before a serious incident. Nothing about a quiet decade tells you where you sit in the distribution.
The survey also recorded a rise in the consequences that do not show up as a direct invoice. Businesses reporting that a breach cost them revenue or share value rose from 2% to 5%, and those reporting reputational damage rose from 1% to 3%. Small proportions, but both more than doubled in a year.
Almost all of it is phishing
For most firms there is really only one threat, and it arrives by email. Phishing was involved in 38% of business breaches, by far the most prevalent type, and 69% of affected businesses named it the most disruptive thing that happened to them.
More striking is the concentration. Among businesses that suffered any incident at all, the share that experienced phishing and nothing else rose from 45% to 51%. For a slim majority of affected firms, phishing is now the entire threat landscape. Interviewees told the survey they believed phishing had become easier to carry out and was arriving in greater volume.
Ransomware moved the other way, falling to 1% of businesses from 3% in each of the previous two years. That is a genuine decline in frequency, though it says nothing about severity, and ransomware sits firmly in the tail the median cannot see.
The practical consequence is that the highest-return security spending for a small firm is unglamorous and cheap. Multi-factor authentication, a tested process for verifying payment-detail changes, and staff who feel able to query an unusual instruction from a director will address the large majority of what the data says will actually happen.
Small firms went backwards on the basics
Last year’s survey recorded small businesses improving across a range of cyber hygiene measures. This year that reversed, with several measures returning to 2023/2024 levels. The proportion of small businesses with a formal policy covering cyber security risks fell from 59% to 52%. Those with a business continuity plan covering cyber fell from 53% to 44%. Cyber security risk assessments among the same group fell from 48% to 41%.
The reversal fits a wider pattern. UK small business confidence has been running at record lows, and documentation is the kind of overhead that quietly lapses when a management team is stretched. Micro businesses were the exception, showing some increases, including in restricting access to company-owned devices.
Formal incident response plans remain the clearest dividing line by size. Just 25% of businesses have one: 21% of micro firms against 57% of medium and 76% of large. Cheaper partial measures are more common, with 39% assigning roles and responsibilities to named individuals and 34% holding written guidance on who to notify. Those are worth having, but they are not the same as having decided in advance who makes the call to take a system offline.
Two blind spots worth naming
The first is the supply chain. Only 15% of businesses formally review the cyber risk posed by their immediate suppliers, and just 6% look at the wider supply chain. For firms that have outsourced payroll, bookkeeping, hosting or customer data to a third party, that is the largest piece of the risk sitting entirely unexamined.
The second is artificial intelligence. Around 31% of businesses are using AI, adopting it or actively considering it. Of that group, only 24% reported having any practices or processes in place to manage the risks arising from it. As we reported when the adoption figures landed, UK AI adoption is broad but shallow, and governance is trailing well behind deployment.
What this means for a budget
Cyber insurance is now held in some form by 47% of businesses, rising to 55% of small and 61% of medium firms. Adoption of the government-backed Cyber Essentials certification remains low in absolute terms at 5%, but it is growing quickly, from 21% to 35% among large businesses and from 5% to 12% among small ones. Awareness of the scheme is still only 17%, while 24% of businesses already have the technical controls it asks for across all five areas: firewalls, secure configuration, security update management, user access control and malware protection. A meaningful number of firms are close to certification without knowing it.
Board attention is rising too. Cyber security is treated as a high priority by senior management in 72% of businesses, and board-level responsibility sits at 31%, up from 27% and reversing a long decline.
The budgeting question that follows from this data is not how much a breach costs. On the median it costs nothing, and any calculation built on that number will conclude that spending is not warranted. The question is what a bad outcome would cost this specific business, and whether the firm could absorb it. For most companies the honest answer involves a handful of low-cost controls that block the 38% case, and one clear-eyed decision about whether the 5% case is survivable.


More Stories
Late Payments Now Cost £11bn and One in Five Firms Just Writes Them Off
Mountain Warehouse Passed £500m and Its Founder Handed Over the Same Week
Britain Built Half as Many Commercial Vehicles as It Did a Year Ago