What Is a Cyber Breach and What Should You Do?
A cyber breach is any incident where an unauthorised party accesses, steals, corrupts, or disrupts your business data or systems. It is what happens when an attack succeeds.
Quick answer
A cyber breach is any incident where an unauthorised party accesses, steals, corrupts, or disrupts your business data or systems. It is what happens when an attack succeeds. In the UK, 43% of businesses suffered a breach or attack in the past year — and the firms that recover fastest are the ones with a plan and a single accountable security provider before it happens.
Key Points
What you need to know.
The Short Answer
A concise overview of what you need to know.
For UK Businesses
How this applies specifically in the UK context.
Cost Considerations
What to expect in terms of investment and ongoing costs.
Next Steps
What you should do with this information.
Quick Comparison
| Feature | Option A | Option B |
|---|
What counts as a cyber breach, exactly?
A breach is the moment unauthorised access actually occurs — data is read, copied, encrypted, deleted, or systems are taken offline. It is distinct from an attempt. If a phishing email is blocked, that is a thwarted attack; if someone clicks, hands over credentials, and a criminal logs into your mailbox, that is a breach.
The distinction is not academic. Breaches involving personal data trigger legal reporting duties, insurance claims, and regulatory scrutiny that mere attempts do not. According to the UK government's Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cyber breach or attack in the previous 12 months. Common breach types include:
- Account takeover — stolen credentials used to log into email, finance, or cloud systems
- Ransomware — files encrypted and held to ransom (see what is ransomware)
- Data exfiltration — customer, employee, or commercial data copied out
- Business email compromise — a hijacked or spoofed inbox used to redirect payments
- System disruption — services knocked offline, often to extort or distract
If your data or systems were touched without permission, treat it as a breach and work back to the parent topic on our managed cybersecurity pillar to understand the controls that prevent it.
How do cyber breaches actually happen?
Most breaches are not sophisticated. They exploit predictable gaps: a reused password, an unpatched server, a convincing email. The Cyber Security Breaches Survey 2025 found phishing was the most common vector, identified by 85% of businesses that suffered a breach.
That single statistic should shape where you spend. The headline-grabbing nation-state attack is rare; the email that tricks an accounts clerk into resetting a password is daily. The most frequent breach paths for UK SMEs are:
| Breach path | Typical trigger | Primary control |
|---|---|---|
| Phishing | Staff click a malicious link or attachment | Email filtering + phishing protection and training |
| Credential theft | Reused or weak passwords | Multi-factor authentication everywhere |
| Unpatched software | Known vulnerability left open | Routine patching and vulnerability management |
| Misconfigured cloud | Open storage, weak M365 defaults | Hardening and configuration review |
| Insider error | Data sent or shared by mistake | Access controls and data loss prevention |
The pattern is consistent: foundational controls stop the overwhelming majority of incidents. The NCSC makes the same point — basic cyber hygiene, applied consistently, defeats most attacks before they become breaches.
What is the difference between a cyber breach and a cyber attack?
A cyber attack is any attempt to compromise your systems, including the unsuccessful ones. A cyber breach is what you have when an attack succeeds and unauthorised access, theft, or disruption actually occurs. Every breach starts as an attack; not every attack becomes a breach.
This matters for three reasons. First, reporting: only a breach involving personal data starts the regulatory clock. Second, insurance: insurers distinguish blocked attempts from realised losses. Third, response: an attack you stopped needs review, while a breach needs containment, notification, and recovery. The 43% headline figure from the Cyber Security Breaches Survey 2025 covers both breaches and attacks combined — which is why your own logging needs to tell the two apart.
What should you do immediately after a cyber breach?
Move fast and in order. Contain first, then preserve evidence, then notify. The first hour shapes the cost and the recovery. Do not wipe machines, do not pay anything, and do not stay silent — get the right people involved straight away.
The immediate steps, in sequence:
1. Isolate affected systems — disconnect compromised devices from the network without powering them off, to preserve forensic evidence. 2. Contact your IT or security provider — escalate to whoever owns incident response. Our incident response team works this exact runbook. 3. Change credentials — reset passwords and revoke sessions for affected and connected accounts; enforce MFA. 4. Report to Action Fraud — the UK's national reporting centre for cyber crime, at actionfraud.police.uk. 5. Notify the ICO within 72 hours — if personal data was compromised (see below). 6. Preserve logs and timeline — record what was seen, when, and by whom for insurers and regulators.
For the full recovery playbook, read our guide on what to do after a cyber breach. Continuous detection through managed detection and response is what turns a six-figure incident into a contained one — because the breach is caught in minutes, not discovered in months.
Are you legally required to report a cyber breach in the UK?
If a breach involves personal data, UK GDPR requires you to notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it. You must also tell affected individuals where the breach poses a high risk to their rights and freedoms. Reporting is not optional.
The penalties are significant: under UK GDPR, fines can reach up to £17.5 million or 4% of annual global turnover, whichever is higher. That regulatory exposure sits on top of the direct incident cost. The Cyber Security Breaches Survey 2025 puts the average cost of the most disruptive breach at £3,550, rising to £8,260 where data or money was actually lost — and those figures exclude fines, legal fees, and lost custom.
What does a cyber breach actually cost a UK business?
The measurable cost is only part of it. The Cyber Security Breaches Survey 2025 reports an average of £3,550 for the most disruptive breach, climbing to £8,260 where data or finances were lost. For most SMEs, the harder costs are downtime, lost customer trust, and the management hours consumed by clean-up.
- Direct costs — incident response, recovery, replacement hardware or software
- Regulatory costs — ICO fines up to £17.5 million or 4% of turnover for serious breaches
- Operational costs — downtime, lost orders, staff diverted from their day jobs
- Reputational costs — customers and partners who walk after a public incident
Prevention is consistently cheaper than recovery. One provider that owns your security, runs Microsoft-certified controls, and monitors round the clock costs a fraction of a single serious breach.
Frequently Asked Questions
Phishing is the leading cause: 85% of UK businesses that suffered a breach identified it as the attack vector (Cyber Security Breaches Survey 2025). Other frequent causes include stolen credentials, unpatched software, and misconfigured cloud services. Most breaches exploit basic gaps, which is why MFA and patching prevent the majority of incidents.
If a breach involves personal data, UK GDPR requires notification to the ICO within 72 hours of becoming aware of it, and you must inform affected individuals where there is a high risk to their rights. Failure to report can attract fines of up to £17.5 million or 4% of annual turnover. Regulatory penalties can far exceed the direct incident cost.
A cyber attack is any attempt to compromise your systems, including unsuccessful ones. A cyber breach occurs when an attack succeeds and unauthorised access, data theft, or disruption actually happens. With 43% of UK businesses experiencing a breach or attack in 2025, the distinction matters for incident reporting, insurance claims, and regulatory duties.
Aim to contain within the first hour. Isolate affected systems from the network without powering them off, reset credentials, and escalate to your security provider immediately. The speed of containment is the single biggest factor in how much a breach ultimately costs, because it limits how far an attacker can move.
Yes. Smaller firms are frequently targeted precisely because their defences are thinner, and the Cyber Security Breaches Survey 2025 shows breaches are common across all business sizes. Attackers automate phishing and credential attacks at scale, so being small offers no protection. Foundational controls and continuous monitoring close the gap.
It depends on your policy and whether you met its conditions, which increasingly require MFA, patching, and documented incident response. Insurers distinguish blocked attempts from realised losses, so accurate logging matters. Keeping evidence — affected systems, timelines, and actions taken — is essential to support any claim after a breach.
Related Questions
What Is Ransomware?
Ransomware is the most financially damaging type of cyber breach — how it works and how to prevent it.
What Is Phishing?
Phishing is the most common cause of cyber breaches in UK businesses.
Cybersecurity Guide for UK SMEs
The controls that reduce your likelihood of a breach and your recovery time if one occurs.
Protect your business → Get Cybersecurity Assessment