The Cyber Security Breaches Survey 2025/2026, Read Properly
The Cyber Security Breaches Survey 2025/2026 was published by the Department for Science, Innovation and Technology and the Home Office on 30 April 2026. It drew on 2,112 UK businesses and 1,085 charities, run by the independent research firm Ipsos between August and December 2025. It is weighted to be statistically representative of the UK business population, which makes it the single most reliable dataset on UK cyber hygiene currently available.
Most coverage of it recycles three headline numbers: 43% of businesses breached, 31% board-level responsibility, 5% Cyber Essentials adoption. All accurate. None of them tell you what’s actually happening underneath.
The Certification Gap Is Not a Security Gap
Start with the number that gets the most attention: only 5% of UK businesses hold Cyber Essentials certification, though that’s up from 3% the year before.
Read in isolation, that looks like a country of businesses with no basic controls in place. It isn’t. 24% of businesses report having technical controls across all five required Cyber Essentials areas: boundary firewalls, secure configuration, user access controls, malware protection, and patch management. That’s roughly a fifth of the UK business population doing the underlying work without holding the paper that proves it.
The gap is closing, and it’s closing fastest exactly where you’d expect: procurement pressure. Small business Cyber Essentials certification jumped from 5% to 12% in a single year. Large business certification rose from 21% to 35%. That’s not a sudden outbreak of security consciousness. That’s insurers, clients, and tender requirements starting to ask for evidence rather than assurances.
The Control That Everyone Skips
If you want to know where UK businesses are genuinely weak, don’t look at certification. Look at the individual technical controls, ranked by adoption.
Malware protection sits at 81%. Cloud backup at 74%. Password policy at 74%. Network firewalls at 74%. Restricted admin rights at 73%. All comfortably majority practice.
Then it falls off a cliff. Two-factor authentication: 47%. VPN for remote staff: 36%. A policy to apply software security updates within 14 days: 34%. User activity monitoring: 33%.
That 14-day patching figure deserves particular attention, because it’s the technical area most directly tied to how attackers actually get in. Automated scanners hunt for known, unpatched vulnerabilities as a matter of course. A business with excellent firewalls and an out-of-date VPN appliance is still an easy target. Patch management is unglamorous, invisible when it works, and the single weakest link in the Cyber Essentials chain for two years running.
Board Engagement Is Recovering, Unevenly
Board-level responsibility for cyber security rose from 27% to 31% this year, reversing a downward trend that had run since 2020/2021. That’s a genuinely positive movement, and it’s worth taking at face value rather than dismissing.
But the sector breakdown tells the real story. Finance or insurance leads at 54% board ownership. Information and communication follows at 51%. Professional, scientific or technical services sits at 41%. At the other end: transport or storage at 17%, retail or wholesale at 20%, construction at 24%.
If your business sits in one of those low-ownership sectors, the survey isn’t describing an anomaly when nobody at board level owns cyber risk. It’s describing the norm for your industry, which is precisely why it’s worth being the exception.
Incident Response Remains the Weakest Link
Only 25% of businesses have a formal incident response plan, though the more granular breakdown is more useful than that single figure. 39% have assigned roles or responsibilities to specific individuals. 34% have written guidance on who to notify. 32% have guidance on when to report externally.
In other words, most of the fragments of an incident response plan exist in more businesses than the complete plan does. That suggests the barrier isn’t knowledge, it’s assembly. Businesses know who should be in the room; they simply haven’t written it down as a single, retrievable document.
What the Trend Data Actually Shows
Compared with 2024/2025, small businesses saw a reversal on several measures: cyber security risk assessments fell from 48% to 41%, formal policies covering cyber risk fell from 59% to 52%, and business continuity plans covering cyber security fell from 53% to 44%. All three returned roughly to 2023/2024 levels.
Micro businesses moved the opposite direction: two-factor authentication adoption rose from 35% to 43%, device restriction rose from 58% to 64%, and external provider usage rose from 39% to 44%.
Read together, that’s a genuinely mixed picture. Larger small businesses appear to be treading water or slipping slightly on formal governance measures, while the smallest businesses are quietly picking up ground on practical technical controls. Neither trend supports a simple headline in either direction, which is exactly why the raw data matters more than the summary.
How to Turn This Into a Competitive Advantage
Knowing precisely where the UK average sits on each control lets a business benchmark itself with real numbers rather than guesswork. A business that can say “we have all five Cyber Essentials technical controls, unlike 76% of UK businesses” has a specific, evidence-backed claim, not a vague reassurance.
How to Sell This to Your Board
Three data points that land with a board used to seeing figures, not adjectives:
Patch management within 14 days sits at just 34% nationally. If your business is above that, say so explicitly in any client-facing security statement. If it’s below, that’s your cheapest, fastest fix.
Board-level cyber ownership rose to 31% this year, the first increase in five years. Getting ahead of that trend now, rather than catching up later, is the difference between leading a sector shift and reacting to one.
The gap between having Cyber Essentials-equivalent controls (24%) and holding the certificate (5%) shows that most of the hard work of certification is technical, not administrative. For businesses already close to the five-area baseline, certification cost is largely the assessment fee, not a remediation project.
What This Means for Your Business
-
Benchmark your own five Cyber Essentials areas against the national averages above. You’ll immediately see whether you’re ahead of or behind the typical UK business in each specific control.
-
Prioritise patch management if it’s not already formalised. At 34% national adoption, it’s simultaneously the weakest control and one of the cheapest to fix with a documented 14-day policy.
-
If you’re in a low board-ownership sector (transport, retail, construction), use that as leverage. Being the exception in your industry is a genuine differentiator with clients and insurers.
-
Assemble your incident response fragments into one document. If you already know who calls the insurer and who talks to customers, you’re most of the way to the 25% who have a formal plan.