612,000 Breached Businesses and Nobody's Talking About the Real Reason Why

Opinion

612,000 Breached Businesses and Nobody's Talking About the Real Reason Why

The government published its own survey this year. Forty-three per cent of UK businesses, an estimated 612,000 of them, reported a cyber security breach or attack in the last twelve months. Phishing caused 38% of those breaches and was named the most disruptive type by 69% of the businesses it hit. Ransomware, meanwhile, fell to just 1% of businesses, down from 3% in each of the two preceding years.

Read that again. The boring thing is what’s actually happening to you. The dramatic thing is comparatively rare. And yet walk into any industry conference, read any vendor’s marketing email, and you’d think the entire UK business population was one click away from a hooded criminal personally targeting their firewall.

The Industry Sells Fear About the Wrong Threat

This isn’t an accident. Fear about rare, catastrophic events is a genuinely effective sales tool. It’s easier to frighten a business owner with a story about a criminal syndicate holding their entire company hostage than it is to get them excited about enforcing multi-factor authentication on their email, even though the second thing is what would actually have stopped 38% of this year’s breaches.

The survey data itself flags something worth sitting with: the share of breach victims experiencing phishing only, no other type of breach involved, rose from 45% to 51% year on year. Qualitative interviews behind the survey found that AI tooling has made phishing “easier for attackers to commit,” producing higher volumes and more convincing attacks. That’s the actual trend line. Not a wave of sophisticated ransomware gangs. A steadily improving volume attack against the same weak point businesses have had for a decade: people opening emails.

Where the Real Money Is Going Now

Here’s the twist that should worry every small business owner even more than the headline figures. Among businesses that did experience a breach, the share reporting a loss of revenue or share value rose from 2% to 5% year on year, and reputational damage reports rose from 1% to 3%. The financial cost is going up even as the ransomware headline figure goes down, because the boring, high-volume attacks are getting more effective at doing real damage, not less.

And that survey’s fieldwork closed in December 2025, before the widely reported Easter 2025 ransomware wave that hit M&S, Co-op and Harrods, estimated by the UK Cyber Monitoring Centre at £270 million to £440 million across affected parties. So the true cost picture for the year is almost certainly worse than the headline figures suggest, not because ransomware suddenly became common again, but because a small number of catastrophic, high-cost outliers sit alongside a much larger volume of grinding, everyday phishing losses that the median statistic simply doesn’t capture.

What Small Businesses Should Actually Take From This

If you run a business with fewer than fifty people, the lesson isn’t “buy armour against a rare, dramatic threat.” It’s “enforce multi-factor authentication, train your staff to spot a convincing email, and keep tested backups,” because that’s what stops the thing that’s actually most likely to hit you. It’s less exciting to say out loud, and it doesn’t fill a conference hall. It also happens to be true, and it’s considerably cheaper than the alternative.

A Fair Counterpoint

To be fair to the industry, ransomware remains the most financially destructive category per incident even at 1% prevalence, and City of London Police data separately puts average reported ransomware losses at around £270,000 per incident for the year to March 2026. Rare and catastrophic isn’t the same as irrelevant. The point isn’t to ignore ransomware. It’s to stop letting the rare, dramatic threat crowd out attention and budget for the boring, likely one that’s doing most of the actual damage.

How to Turn This Into a Competitive Advantage

Businesses that can point to evidence-based security decisions, grounded in what’s actually happening to businesses their size, look materially more credible to clients and insurers than businesses reciting vendor talking points about the latest headline threat.

How to Sell This to Your Board

  1. The government’s own data supports prioritising phishing defence and MFA first. This isn’t a hunch, it’s the highest-volume, most disruptive category in the national survey.
  2. Basic controls are cheaper than the fear-driven alternative. Enforcing MFA and training staff costs a fraction of the products typically pitched against rare, dramatic threats.
  3. The financial impact trend is worsening even as ransomware prevalence falls, meaning this isn’t a moment to relax, just a moment to redirect focus correctly.

What This Means for Your Business

  1. Prioritise phishing defence and MFA enforcement first, since that’s what the national data shows is actually hitting businesses your size.
  2. Treat any vendor pitch grounded purely in dramatic, rare-threat fear with scepticism. Ask specifically how it addresses the boring, likely risk instead.
  3. Keep tested backups regardless, since the rare catastrophic event, while less common, remains genuinely business-ending when it lands.
SourceArticle
GOV.UKCyber Security Breaches Survey 2025/2026
City of London PoliceRansomware warning: more than 320 businesses affected last year
Computer WeeklyM&S, Co-op attacks a ‘Category 2 cyber hurricane’

Filed under

  • smb-security
  • uk-business
  • business-risk
  • social-engineering
  • compliance-failure