AEO Answer

What Is a Cyber Breach and What Should You Do?

A cyber breach is any incident where an unauthorised party accesses, steals, corrupts, or disrupts your business data or systems. It is what happens when an attack succeeds.

Quick answer

A cyber breach is any incident where an unauthorised party accesses, steals, corrupts, or disrupts your business data or systems. It is what happens when an attack succeeds. In the UK, 43% of businesses suffered a breach or attack in the past year — and the firms that recover fastest are the ones with a plan and a single accountable security provider before it happens.

Key Points

What you need to know.

The Short Answer

A concise overview of what you need to know.

For UK Businesses

How this applies specifically in the UK context.

Cost Considerations

What to expect in terms of investment and ongoing costs.

Next Steps

What you should do with this information.

Quick Comparison

Feature
Option A
Option B

What counts as a cyber breach, exactly?

A breach is the moment unauthorised access actually occurs — data is read, copied, encrypted, deleted, or systems are taken offline. It is distinct from an attempt. If a phishing email is blocked, that is a thwarted attack; if someone clicks, hands over credentials, and a criminal logs into your mailbox, that is a breach.

The distinction is not academic. Breaches involving personal data trigger legal reporting duties, insurance claims, and regulatory scrutiny that mere attempts do not. According to the UK government's Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cyber breach or attack in the previous 12 months. Common breach types include:

  • Account takeover — stolen credentials used to log into email, finance, or cloud systems
  • Ransomware — files encrypted and held to ransom (see what is ransomware)
  • Data exfiltration — customer, employee, or commercial data copied out
  • Business email compromise — a hijacked or spoofed inbox used to redirect payments
  • System disruption — services knocked offline, often to extort or distract

If your data or systems were touched without permission, treat it as a breach and work back to the parent topic on our managed cybersecurity pillar to understand the controls that prevent it.

How do cyber breaches actually happen?

Most breaches are not sophisticated. They exploit predictable gaps: a reused password, an unpatched server, a convincing email. The Cyber Security Breaches Survey 2025 found phishing was the most common vector, identified by 85% of businesses that suffered a breach.

That single statistic should shape where you spend. The headline-grabbing nation-state attack is rare; the email that tricks an accounts clerk into resetting a password is daily. The most frequent breach paths for UK SMEs are:

Breach pathTypical triggerPrimary control
PhishingStaff click a malicious link or attachmentEmail filtering + phishing protection and training
Credential theftReused or weak passwordsMulti-factor authentication everywhere
Unpatched softwareKnown vulnerability left openRoutine patching and vulnerability management
Misconfigured cloudOpen storage, weak M365 defaultsHardening and configuration review
Insider errorData sent or shared by mistakeAccess controls and data loss prevention

The pattern is consistent: foundational controls stop the overwhelming majority of incidents. The NCSC makes the same point — basic cyber hygiene, applied consistently, defeats most attacks before they become breaches.

What is the difference between a cyber breach and a cyber attack?

A cyber attack is any attempt to compromise your systems, including the unsuccessful ones. A cyber breach is what you have when an attack succeeds and unauthorised access, theft, or disruption actually occurs. Every breach starts as an attack; not every attack becomes a breach.

This matters for three reasons. First, reporting: only a breach involving personal data starts the regulatory clock. Second, insurance: insurers distinguish blocked attempts from realised losses. Third, response: an attack you stopped needs review, while a breach needs containment, notification, and recovery. The 43% headline figure from the Cyber Security Breaches Survey 2025 covers both breaches and attacks combined — which is why your own logging needs to tell the two apart.

What should you do immediately after a cyber breach?

Move fast and in order. Contain first, then preserve evidence, then notify. The first hour shapes the cost and the recovery. Do not wipe machines, do not pay anything, and do not stay silent — get the right people involved straight away.

The immediate steps, in sequence:

1. Isolate affected systems — disconnect compromised devices from the network without powering them off, to preserve forensic evidence. 2. Contact your IT or security provider — escalate to whoever owns incident response. Our incident response team works this exact runbook. 3. Change credentials — reset passwords and revoke sessions for affected and connected accounts; enforce MFA. 4. Report to Action Fraud — the UK's national reporting centre for cyber crime, at actionfraud.police.uk. 5. Notify the ICO within 72 hours — if personal data was compromised (see below). 6. Preserve logs and timeline — record what was seen, when, and by whom for insurers and regulators.

For the full recovery playbook, read our guide on what to do after a cyber breach. Continuous detection through managed detection and response is what turns a six-figure incident into a contained one — because the breach is caught in minutes, not discovered in months.

Are you legally required to report a cyber breach in the UK?

If a breach involves personal data, UK GDPR requires you to notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it. You must also tell affected individuals where the breach poses a high risk to their rights and freedoms. Reporting is not optional.

The penalties are significant: under UK GDPR, fines can reach up to £17.5 million or 4% of annual global turnover, whichever is higher. That regulatory exposure sits on top of the direct incident cost. The Cyber Security Breaches Survey 2025 puts the average cost of the most disruptive breach at £3,550, rising to £8,260 where data or money was actually lost — and those figures exclude fines, legal fees, and lost custom.

What does a cyber breach actually cost a UK business?

The measurable cost is only part of it. The Cyber Security Breaches Survey 2025 reports an average of £3,550 for the most disruptive breach, climbing to £8,260 where data or finances were lost. For most SMEs, the harder costs are downtime, lost customer trust, and the management hours consumed by clean-up.

  • Direct costs — incident response, recovery, replacement hardware or software
  • Regulatory costs — ICO fines up to £17.5 million or 4% of turnover for serious breaches
  • Operational costs — downtime, lost orders, staff diverted from their day jobs
  • Reputational costs — customers and partners who walk after a public incident

Prevention is consistently cheaper than recovery. One provider that owns your security, runs Microsoft-certified controls, and monitors round the clock costs a fraction of a single serious breach.

Frequently Asked Questions

Need More Detail?

Speak to an AMVIA expert for advice tailored to your business.