UK SME Cybersecurity: The 2026 Data Briefing
What the published UK data actually shows on attack rates, costs and preparedness - drawn from the DSIT Cyber Security Breaches Surveys 2025 and 2025/26, the DSIT cyber skills research, the Verizon DBIR, Sophos and IBM, and read specifically for businesses with 10–250 staff.
Key Findings from the Published Data
Steady at 43% across the 2025 and 2025/26 editions, down from 50% in 2024 (DSIT).
Excluding businesses reporting no cost; £1,600 including them (DSIT 2025).
Up from 23% in the 2025 edition (DSIT Cyber Security Breaches Survey 2025/26).
Steady at 1% across the last two survey editions (DSIT) - rare, but existential when it lands; the NCSC advises against paying.
What the Published UK Data Shows, Year on Year
Sources and method
This briefing is AMVIA's reading of the primary published UK evidence, not a proprietary survey. The figures come from named sources: the DSIT Cyber Security Breaches Survey 2025/26 and its 2025 predecessor (the government's official measure), the DSIT Cyber security skills in the UK labour market reports (2024 and 2025 editions), the Verizon 2025 Data Breach Investigations Report (global), the Sophos State of Ransomware 2025 (global, vendor research), and IBM's Cost of a Data Breach 2025 (UK sample). Where a figure is global rather than UK-specific, it is labelled as such. Every statistic on this page carries its source; nothing here is estimated by AMVIA.
What the threat data shows
Phishing remains the dominant attack type - 85% of businesses that identified a breach reported phishing (DSIT 2025), and among incidents meeting the legal definition of cyber crime, 93% were phishing-based. In the 2025/26 edition, phishing remained the most prevalent attack type - experienced by 38% of all businesses - and was rated the most disruptive by 69% of those attacked. Ransomware, while rarer, sat at 1% of all businesses in each of the last two survey years (DSIT 2025 and 2025/26). Globally, stolen credentials were the initial attack vector in 22% of breaches, and 30% of breaches involved a third party (Verizon DBIR 2025) - the supply chain is now a mainstream route in.
Financial impact
The government's survey puts the average cost of the single most disruptive breach at £3,550 for UK businesses (£1,600 when businesses reporting no cost are included), and the average annual cost of cyber crime at £990 per affected business - £1,970 excluding phishing-only cases (DSIT 2025). At the severe end, IBM's Cost of a Data Breach 2025 puts the average UK data breach at £3.29 million - a different methodology measuring major incidents, quoted here for scale. Globally, the median ransom demand was about $1.32 million (~£1.04m) in 2025, down 34% year on year (Sophos), while Verizon puts global BEC losses at around $6.3 billion for the year with a median of roughly $50,000 per incident.
The MFA gap
Only 47% of UK businesses have any two-factor authentication in place (DSIT 2025/26) - despite Microsoft's long-standing finding that MFA blocks over 99.9% of automated credential attacks. That gap between a proven, cheap control and actual adoption is the single largest addressable weakness in the UK SME market, which is why it tops the action list on this page.
Preparedness and skills
Only 25% of UK businesses have a formal incident response plan (DSIT 2025/26; the 2025 edition put it at 23%, rising to 53% of medium and 75% of large businesses) - and just 15% formally review the cyber risks posed by their immediate suppliers. The skills picture explains much of this: DSIT's cyber skills research found a basic technical skills gap at around half of UK businesses (44% in the 2024 report, 49% in the 2025 report). Most SMEs cannot staff this internally, which is why managed detection and response has become the default route to 24/7 coverage.
Reading the data for a 10–250 person business
Three practical conclusions follow from the published evidence. First, the controls with the strongest evidence base - MFA, tested backups, patching, and staff phishing awareness - map directly onto the Cyber Essentials five, and most SMEs have not finished deploying them. Second, the cost asymmetry is stark: prevention is priced in pounds per user per month, while DSIT's £3,550 most-disruptive-breach average understates severe cases by orders of magnitude. Third, response capability now matters as much as prevention - with only 23% holding a formal incident response plan, the fastest differentiation available to an SME is simply having one, testing it, and knowing who acts in the first hour.
Turn the Data into Security Action
AMVIA's security assessment translates the published benchmarks in this briefing into a personalised gap analysis for your business - delivered in 48 hours.
Frequently Asked Questions
There is no single right percentage - UK government guidance focuses on outcome-based controls (the Cyber Essentials five) rather than budget shares. As an anchor: the average most disruptive breach costs £3,550 (DSIT 2025), severe incidents run far higher, and managed protection is priced in pounds per user per month - AMVIA managed cybersecurity starts at £5 per user. Prevention is consistently a fraction of breach cost.
Only 15% of UK businesses formally review cyber risks from their immediate suppliers (DSIT 2025/26). 30% of global data breaches in 2025 involved a third party (Verizon DBIR 2025).
BEC is a type of fraud where attackers impersonate executives or suppliers to trick employees into transferring funds or sharing sensitive data. Verizon's DBIR 2025 puts global BEC losses at around $6.3 billion for the year, with a median loss of roughly $50,000 per incident (global figures).
Phishing is the most common attack type, identified by 85% of businesses that experienced a breach (DSIT 2025). Among incidents meeting the legal definition of cyber crime, 93% were phishing-based (DSIT 2025).