What the UK Government’s 2026 Cyber Security Breaches Survey Means for Businesses
Think your business is too small for cyber criminals to bother with? The reality is that businesses of all sizes are increasingly being targeted, making robust cyber security essential for protecting data, operations and customer trust. Recent statistics highlight just how widespread the threat has become.
The UK Government’s Cyber Security Breaches Survey 2025/26, published on 30 April 2026, found that 43% of businesses identified a cyber security breach or attack during the previous 12 months. Among small businesses it was 46%, rising to 65% of medium-sized businesses and 69% of large firms.
So no, cyber security isn’t just a “big company problem”.
If your business uses email, stores customer information, takes payments, uses cloud software or connects devices to the internet, there is something worth protecting.
What does the 2026 Cyber Security Breaches Survey tell us?
First, an important caveat.
These figures relate to UK organisations, rather than specifically to Isle of Man businesses, but they offer a useful indication of the threats facing organisations operating in a very similar digital environment and a few findings stand out.
43% of businesses identified a breach or attack
That is more than four in ten businesses. The Government estimates this equates to approximately 612,000 UK businesses identifying a cyber breach or attack over 12 months, and these are only the attacks businesses detected.
The survey itself notes that breaches can go unidentified, meaning the real level of activity may be higher.
Small Businesses are very much on the list
The breakdown by size is worth looking at:
- Micro businesses: 42%
- Small businesses: 46%
- Medium businesses: 65%
- Large businesses: 69%
Larger businesses may have more systems, people and data to attack, but being small clearly doesn’t make you invisible.
The NCSC makes the same point in its guidance for smaller organisations, warning businesses against assuming they are too small to attract cyber criminals.
Phishing is Still the Big One
No dramatic Hollywood-style hacking scene required, a convincing email can do the job.
Phishing was by far the most common attack identified in the survey, affecting 38% of all businesses. Among businesses that had identified some form of attack or breach, 88% had experienced phishing and that’s important because phishing targets something every business has, people.
Someone receives what looks like an email from Microsoft, or their bank, or their boss asking them to make an urgent payment.
One click, password or payment can be enough.
Technology security matters, but your people need to know what suspicious activity looks like and what to do when they spot it.
The small-business numbers that should get more attention
There was some good news in the survey, more micro businesses were using two-factor authentication and company-owned devices, for example.
But among small businesses, several important measures went backwards.
- The proportion carrying out cyber security risk assessments dropped from 48% to 41%.
- Those with a formal cyber security policy fell from 59% to 52%.
- And those with a business continuity plan covering cyber security fell from 53% to 44%.
That’s concerning because cyber security isn’t just about stopping attacks, it’s also about knowing what happens when something gets through.
- Who makes the decisions?
- How do you restore systems?
- How do employees work?
- Who contacts customers?
- How quickly can you recover?
Finding out the answers while an incident is happening isn’t ideal.
“But most attacks don’t cost much, do they?”
The 2026 survey shows why headline financial figures need context.
Many businesses reported little or no direct financial cost from their most disruptive breach, but a smaller group experienced substantially higher costs, with the top 5% reaching £4,000 among micro and small businesses and £10,000 among medium and large businesses.
Among businesses that experienced an attack or breach, the survey also found other impacts including additional staff time, disrupted day-to-day work, recovery costs, lost revenue, customer complaints and reputational damage.
That’s the bit a simple “cost of attack” figure can miss.
So, is your Business Cyber Secure?
Start with these questions:
Do you use multi-factor authentication?
Particularly on email, administrator accounts and important cloud systems.
Are devices and software kept up to date?
Security updates exist for a reason.
Are old accounts removed quickly?
Someone who left two years ago shouldn’t still have access “just in case”.
Are your backups reliable and tested?
Having a backup and knowing you can successfully restore from it are different things.
Does your team receive cyber awareness training?
Especially around phishing, suspicious links, password theft and payment requests.
Do you know what you would do after an attack?
You need an incident and business continuity plan before you need it.
These areas align closely with the practical cyber-security controls recommended by the National Cyber Security Centre. Cyber Essentials, for example, focuses on firewalls, secure configuration, security update management, user access control and malware protection.
Cyber security doesn’t need to become another full-time job
Most small business owners aren’t interested in becoming cyber-security experts, nor should they have to, but someone needs to be paying attention.
At Noventre, we help businesses understand where their vulnerabilities are, put sensible protections in place and manage cyber security as an ongoing business risk rather than an annual box-ticking exercise.
FAQs
Are small businesses really targeted by cyber-attacks?
Yes. The 2026 Government survey found 46% of small UK businesses identified a breach or attack during the previous 12 months.
What is the most common cyber-attack against businesses?
Phishing. It was identified by 38% of all businesses surveyed and accounted for the overwhelming majority of attacks experienced by businesses that reported one.
What is Cyber Essentials?
Cyber Essentials is the UK Government-recommended minimum cyber-security standard for organisations. It covers five core technical controls designed to protect against common online threats.