Security

    43% of UK Businesses Were Breached Last Year. Phishing Did Most of It

    The government's Cyber Security Breaches Survey 2025 puts breaches at 43% of UK businesses — roughly 612,000 firms — down from 50% a year earlier. Phishing accounted for 85% of them.

    Written by

    Diogo Marques

    Co-Founder & CTO

    16 Feb 2026 · 6 min read

    Market: United Kingdom

    Key figures

    43%
    of UK businesses breached or attacked in 12 months
    Source: DSIT
    612,000
    UK businesses affected, down from 718,000
    Source: DSIT
    85%
    of affected businesses hit by phishing
    Source: DSIT

    The Cyber Security Breaches Survey 2025, published by DSIT and the Home Office, reports that just over four in ten businesses (43%) experienced a cyber security breach or attack in the previous twelve months — approximately 612,000 UK businesses. That is down from 50%, or around 718,000 businesses, in 2024.

    Two things are true at once in that figure. The direction of travel is good, and the absolute number is still enormous. If you employ people in the UK, a breach attempt against your business this year is closer to the base case than to the exception.

    The composition matters more than the headline. Among businesses and charities that were breached, phishing remains the most prevalent and most disruptive category — experienced by 85% of affected businesses and 86% of affected charities. This is not a story about sophisticated intrusion. It is a story about a convincing email reaching a person who has no system-level reason to doubt it.

    That has a direct consequence for how you spend. Perimeter tooling does very little against a credential handed over willingly. What reduces exposure is unglamorous: multi-factor authentication on every account that touches money or customer data, a named internal route for staff to report a suspicious message without embarrassment, and payment-change requests verified out of band as a standing rule rather than a judgement call. The NCSC's phishing guidance is explicit that layered defences beat any single control, precisely because some messages will always get through.

    There is a commercial dimension that boards under-weight. Enterprise procurement in the UK now routinely asks for evidence of controls before signing. When a mid-market supplier cannot answer basic questions about access control or incident response, the deal slows or moves. Security posture has quietly become a sales asset, and the businesses treating it that way get paid back twice.

    Our position is that cyber hygiene belongs in the same conversation as CRM and website work, not in a separate annual IT review. Every connected system you add is another door, and the door is usually opened by a person rather than forced. Design for that, and the 43% becomes a number that describes other companies.

    Sources

    1. 1.Cyber Security Breaches Survey 2025Department for Science, Innovation and Technology & Home Office · 2025
    2. 2.Phishing attacks: defending your organisationNational Cyber Security Centre · 2025

    Apply it

    Score your growth system

    Ten questions, a stage-by-stage score and your three highest-value priorities.
    Get your free Growth Audit