This is for you if

  • You need sourced figures for a board paper, a budget case or an insurer conversation
  • You run a small or medium-sized business and want to see where your controls sit against the UK figures
  • Someone has asked about your incident response plan, Cyber Essentials or supplier checks, and you want to know how unusual your answer is

Security budgets are hard to argue without a benchmark, and most figures in circulation have no method behind them. The official numbers are clearer and less comfortable: 43% of UK businesses reported a breach or attack in the last 12 months, and 25% had a formal incident response plan.

Eleven figures on how often UK businesses are breached or attacked, how that changes with size, and how prepared they are, from the government's Cyber Security Breaches Survey 2025/2026 and the NCSC Annual Review 2025. Each one is quoted in the publisher's own words, with the source on the tile.

The figures are in the two bands above. Below, the same measures as tick boxes, with the UK business figure beside each line, so you can see where your business sits in a few minutes. The wording of every figure was re-checked against its source on 5 October 2026.

How do you compare?

Tick each line only if you could show it to a customer or an insurer today. The UK business figure is beside every line.

1. Who owns it

  • Someone at board level is responsible for cyber security (UK businesses: 31%; large businesses: 68%)
  • We know where we would go for outside guidance, and have used it in the last year (UK businesses: 44%)

2. When it happens

  • We have a formal incident response plan, written down (UK businesses: 25%; medium: 57%; large: 76%)
  • We are insured against cyber security risks in some way, and know what the policy expects of us (UK businesses: 47%)

3. The controls behind it

  • We hold Cyber Essentials, or know what would fail it today (UK businesses holding it: 5%)
  • We have reviewed the cyber risks posed by our immediate suppliers (UK businesses: 15%; wider supply chain: 6%)
  • We have security practices in place for the AI tools we use or are considering (31% of those businesses have no plans to)
  • We would know about a phishing attempt that got through, and what was clicked (38% of businesses experienced phishing in the year)

What your ticks add up to

  • All 8 ticked

    On these measures you are ahead of most UK businesses the survey counted. Keep the evidence for each tick somewhere a customer or insurer could be shown it.

  • Five to seven ticked

    Better than the UK figure on most lines. In the survey the two least common are a supplier review (15%) and a formal incident response plan (25%), so check those two first.

  • Four or fewer ticked

    You are where most UK businesses are, and 43% of them reported a breach or attack last year. Start with ownership at board level and a written incident response plan.

  • Not sure how to answer a line

    Treat it as unticked. A control nobody can confirm is the one that turns out not to be there on the day.

Cyber Essentials, in the NCSC's words

Five per cent of businesses hold Cyber Essentials, up from three per cent. The NCSC Annual Review 2025 adds two lines worth knowing: "data from the Cyber Essentials Insurance company tells us that organisations with Cyber Essentials are 92% less likely to make a claim on their insurance." And: "In recent years this has accelerated, with certification rates increasing by over 17% in the last year." Systech holds Cyber Essentials and helps clients prepare for it; we are not a certification body.

Sources

  1. 1DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, published 30 April 2026. www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
  2. 2NCSC, NCSC Annual Review 2025: incident management, published 14 October 2025. www.ncsc.gov.uk/collection/ncsc-annual-review-2025/chapter-01-cyber-threat-to-the-uk/incident-management
  3. 3NCSC, NCSC Annual Review 2025: NCSC tools and services, published 14 October 2025. www.ncsc.gov.uk/collection/ncsc-annual-review-2025/chapter-02-resilience-at-scale/empowering-organisations-ncsc-tools-services

Every figure is quoted in the publisher’s own words. The wording and numbers were re-checked against each source on 5 October 2026.

Where this leaves you

If the comparison left more lines unticked than you expected, the security posture review checks identity, endpoints, email and backup against what attacks actually exploit, and tells you plainly whether you would pass Cyber Essentials today. You keep the written summary whether or not you engage us. Our Microsoft security posture service is the longer version of the same work.

This is one of a set. The rest, covering virtual desktops, security, cost, compliance and device management in the same format, are listed on all our free resources.

Frequently asked

Where do these UK cyber security figures come from?

Two official sources. The Cyber Security Breaches Survey 2025/2026, official statistics from the Department for Science, Innovation and Technology and the Home Office published on 30 April 2026, and the NCSC Annual Review 2025, published on 14 October 2025 and covering 1 September 2024 to 31 August 2025. Every figure on this page is quoted in the publisher's own words, with the source beside it.

What counts as a small or medium business in the survey?

The survey splits businesses into micro (1 to 9 employees), small (10 to 49), medium (50 to 249) and large (250 or more). It matters because the averages hide the spread: 42% of micro businesses reported a breach or attack in the last 12 months, against 65% of medium-sized businesses.