Every year the Department for Science, Innovation and Technology asks a couple of thousand UK businesses what actually happened to them. The 2025/2026 survey was published on 30 April 2026. Forty-three per cent had a breach or attack in the previous twelve months.

That figure gets quoted a great deal. On its own it does not tell you much. The useful part is underneath it.

Phishing is the method, not one of several

Phishing was involved for 38% of the businesses reporting something. Nothing else comes close. And for 69% of the organisations affected, phishing was the most disruptive thing that happened to them all year.

That is worth sitting with. The most damaging attack on most businesses is not a technical break-in. It is a message that asks.

Being small does not keep you out of it

There is a comfortable idea that attackers only go after big organisations. The survey does not support it. 42% of micro businesses and 46% of small businesses reported a breach or attack, against 65% of medium and 69% of large.

The gap is real, but it is nothing like the gap people imagine. A twenty-person firm holds much the same kind of client data as a large one. It is simply less likely to have anyone whose only job is to notice trouble.

The real gap is in what happens next

Two findings stood out to us more than any of the breach figures. Only 25% of businesses have a formal incident response plan. Only 15% formally review the cyber risk their immediate suppliers bring.

Prevention gets all the attention. But nobody prevents everything, and the difference between a bad morning and a bad quarter is usually whether anyone knew what to do at nine o’clock.

Four things worth doing

  • Turn on multi-factor authentication everywhere, not only on email. Attackers go where it is not.
  • Agree that bank details never change over email. If an invoice asks you to update payment details, someone rings a number you already had. Payment redirection is the expensive one.
  • Write the plan on one page. Who is called, in what order, and who can authorise stopping something. One page that exists beats ten pages that do not.
  • Make reporting safe. Most people who click a bad link know within about a minute. Whether they tell anyone is a culture question, not a technical one.

What we take from it

None of this is new, and none of it requires frightening anybody. The survey has been broadly saying the same thing for several years. The attacks are ordinary, they arrive by email, and the businesses that come out of them well are the ones who decided in advance what they would do.

Multi-factor authentication, monitored backups and staff training are part of our support, not a separate purchase. If you would like someone to look at where you stand, that is a conversation rather than an audit.

Sources

  1. Department for Science, Innovation and Technology and Home Office, Cyber security breaches survey 2025/2026, published 30 April 2026. Carried out independently by Ipsos.
  2. ICAEW, Phishing most prevalent cyber attack, confirms UK survey.
  3. NCC Group, News reaction: UK Cyber Security Breaches Survey 2025/2026.
  4. Alston & Bird, UK Cyber Security Breaches Survey 2025/2026: key takeaways.

Back to the blog

Let’s Talk

Want to know how Trunnion can help your business?

Tell us what is getting in the way. We will have a proper conversation about it, with no obligation and no sales script.