Countdown until the UK analogue phone switch-off on 31 January 2027.Is your business affected?
Data Briefing 2026

UK SME Cybersecurity: The 2026 Data Briefing

What the published UK data actually shows on attack rates, costs and preparedness - drawn from the DSIT Cyber Security Breaches Surveys 2025 and 2025/26, the DSIT cyber skills research, the Verizon DBIR, Sophos and IBM, and read specifically for businesses with 10–250 staff.

5primary published sources
Aug 2026last data review
10–250employee focus

Key Findings from the Published Data

43%of UK businesses identified a breach or attack in 2025

Steady at 43% across the 2025 and 2025/26 editions, down from 50% in 2024 (DSIT).

£3,550average cost of the most disruptive breach

Excluding businesses reporting no cost; £1,600 including them (DSIT 2025).

25%have a formal incident response plan

Up from 23% in the 2025 edition (DSIT Cyber Security Breaches Survey 2025/26).

1%of UK businesses hit by ransomware

Steady at 1% across the last two survey editions (DSIT) - rare, but existential when it lands; the NCSC advises against paying.

What the Published UK Data Shows, Year on Year

Identified a breach or attack (DSIT CSBS)43
Hit by ransomware (DSIT CSBS)1
Basic cyber skills gap (DSIT Cyber Skills reports)49
2025 (%)
2024 (%)

Sources and method

This briefing is AMVIA's reading of the primary published UK evidence, not a proprietary survey. The figures come from named sources: the DSIT Cyber Security Breaches Survey 2025/26 and its 2025 predecessor (the government's official measure), the DSIT Cyber security skills in the UK labour market reports (2024 and 2025 editions), the Verizon 2025 Data Breach Investigations Report (global), the Sophos State of Ransomware 2025 (global, vendor research), and IBM's Cost of a Data Breach 2025 (UK sample). Where a figure is global rather than UK-specific, it is labelled as such. Every statistic on this page carries its source; nothing here is estimated by AMVIA.

What the threat data shows

Phishing remains the dominant attack type - 85% of businesses that identified a breach reported phishing (DSIT 2025), and among incidents meeting the legal definition of cyber crime, 93% were phishing-based. In the 2025/26 edition, phishing remained the most prevalent attack type - experienced by 38% of all businesses - and was rated the most disruptive by 69% of those attacked. Ransomware, while rarer, sat at 1% of all businesses in each of the last two survey years (DSIT 2025 and 2025/26). Globally, stolen credentials were the initial attack vector in 22% of breaches, and 30% of breaches involved a third party (Verizon DBIR 2025) - the supply chain is now a mainstream route in.

Financial impact

The government's survey puts the average cost of the single most disruptive breach at £3,550 for UK businesses (£1,600 when businesses reporting no cost are included), and the average annual cost of cyber crime at £990 per affected business - £1,970 excluding phishing-only cases (DSIT 2025). At the severe end, IBM's Cost of a Data Breach 2025 puts the average UK data breach at £3.29 million - a different methodology measuring major incidents, quoted here for scale. Globally, the median ransom demand was about $1.32 million (~£1.04m) in 2025, down 34% year on year (Sophos), while Verizon puts global BEC losses at around $6.3 billion for the year with a median of roughly $50,000 per incident.

The MFA gap

Only 47% of UK businesses have any two-factor authentication in place (DSIT 2025/26) - despite Microsoft's long-standing finding that MFA blocks over 99.9% of automated credential attacks. That gap between a proven, cheap control and actual adoption is the single largest addressable weakness in the UK SME market, which is why it tops the action list on this page.

Preparedness and skills

Only 25% of UK businesses have a formal incident response plan (DSIT 2025/26; the 2025 edition put it at 23%, rising to 53% of medium and 75% of large businesses) - and just 15% formally review the cyber risks posed by their immediate suppliers. The skills picture explains much of this: DSIT's cyber skills research found a basic technical skills gap at around half of UK businesses (44% in the 2024 report, 49% in the 2025 report). Most SMEs cannot staff this internally, which is why managed detection and response has become the default route to 24/7 coverage.

Reading the data for a 10–250 person business

Three practical conclusions follow from the published evidence. First, the controls with the strongest evidence base - MFA, tested backups, patching, and staff phishing awareness - map directly onto the Cyber Essentials five, and most SMEs have not finished deploying them. Second, the cost asymmetry is stark: prevention is priced in pounds per user per month, while DSIT's £3,550 most-disruptive-breach average understates severe cases by orders of magnitude. Third, response capability now matters as much as prevention - with only 23% holding a formal incident response plan, the fastest differentiation available to an SME is simply having one, testing it, and knowing who acts in the first hour.

Turn the Data into Security Action

AMVIA's security assessment translates the published benchmarks in this briefing into a personalised gap analysis for your business - delivered in 48 hours.

Compiled from
DSIT Cyber Security Breaches Surveys 2025 & 2025/26
Verizon DBIR 2025
Sophos & IBM 2025 (vendor research)
Reviewed August 2026

Frequently Asked Questions