SecBriefs
← Industry Reports
UK GovernmentUK Government
INDUSTRY REPORTRegulation & Policy7 min read

Cyber Security Breaches Survey 2025/2026

The UK survey finds 19% of businesses and 14% of charities experienced cyber crime, with phishing dominating reported cases and larger organizations facing materially greater exposure.

UK Government
2026

Cyber Security Breaches Survey 2025/2026

REGULATION & POLICY · SECBRIEFS ANALYSIS
THE SHORT VERSION

Executive Takeaway

The UK Government’s 2025/2026 survey shows cyber crime remaining persistent rather than uniformly escalating. Nineteen percent of businesses and 14% of charities reported at least one cyber crime, while phishing accounted for the overwhelming majority of organizations that experienced one.

The leadership implication is that scale and repeat targeting matter. Larger organizations report substantially higher exposure, and a minority of victims experience dozens or hundreds of events. Basic controls must therefore be reliable under repeated pressure, not merely documented.

Key Findings

  1. 01

    Nineteen percent of businesses and 14% of charities reported at least one cyber crime in the previous 12 months.

  2. 02

    The estimates represent approximately 267,000 businesses and 28,000 registered charities.

  3. 03

    Among organizations experiencing cyber crime, 93% of businesses and charities experienced phishing-related crime.

  4. 04

    Forty-eight percent of large businesses experienced cyber crime, compared with 17% of micro businesses.

  5. 05

    Among victim businesses, 20% experienced between 11 and 99 cyber crimes and 5% experienced 100 or more.

  6. 06

    Ransomware affected 1% of all surveyed businesses and charities, subject to the survey’s sampling uncertainty.

What the Data Says

19%

Businesses affected

The survey estimates that almost one in five UK businesses experienced at least one cyber crime in the prior 12 months.

14%

Charities affected

The estimated prevalence among registered charities remained significant, with exposure increasing among higher-income organizations.

93%

Phishing among victims

Phishing was by far the most common cyber-crime type among businesses and charities that experienced cyber crime.

What It Doesn’t Say / Limitations

This is survey-based evidence and is subject to sampling error, respondent recall and differences in how organizations identify and classify events. Undetected incidents cannot be represented.

The results describe UK businesses, charities and educational institutions and should not be generalized directly to other countries. Percentage changes in low-frequency categories such as ransomware require particular care.

Why It Matters

The survey provides a useful counterweight to incident-response and vendor telemetry because it measures organizational experience across a broad population. It also shows how exposure rises with organizational size.

For leaders, the repeat-victimization finding is important: controls and response processes must withstand sustained social engineering, not just a single annual test. Smaller organizations and charities may need simpler, affordable defensive measures and external support.

Who Should Care

  • UK business and charity leaders
  • CISOs and security managers
  • Fraud and finance teams
  • Public-policy and regulatory teams
  • Education-sector leaders
  • Boards and trustees
SECBRIEFS VIEW

SecBriefs Assessment

The survey is strongest as a national resilience benchmark rather than a technical threat report. Its official methodology and broad organizational scope add context that vendor datasets cannot provide.

The main operational message is persistence: phishing remains dominant, larger organizations face greater exposure and some victims are repeatedly targeted. Organizations should compare their own reporting and detection maturity before interpreting lower reported prevalence as lower risk.

What To Do Now

  1. Use phishing-resistant authentication for administrators, finance staff and other high-impact roles.
  2. Harden account-recovery, supplier-payment and executive-impersonation workflows against social engineering.
  3. Track repeat incidents and recurring control failures, not only the number of unique attack types.
  4. Give smaller business units and suppliers a minimum-control package with clear support routes.
  5. Test ransomware and non-phishing cyber-crime reporting so low-frequency events are not missed.
  6. Compare internal incident rates with sector and organization-size benchmarks rather than the national average alone.
ORIGINAL REPORT

Cyber Security Breaches Survey 2025/2026

Publisher
UK Government
Published
URL
https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026
View on publisher site(opens in a new tab)

Get the next SecBriefs report analysis

Clear analysis of major cybersecurity reports, delivered by SecBriefs.