Data explained simply

UK cyber security figures, explained for business decisions.

One chart is shown at a time. Move through the deck, pause on any chart, and use the figures as helpful context rather than a reason to panic.

A practical view

Understand the pattern, then focus on what you can improve.

Most small and medium businesses do not need a large internal cyber department to make progress. Stronger sign-in, updates, backups, clear responsibilities and safer digital services are sensible places to begin.

Read the figures carefully: these charts describe different questions, different groups and different time periods. They should not be added together, and they are not the exact chance that any one business will be attacked.

See sources and survey context

United Kingdom businesses • 2025/2026

Forty-three percent identified a breach or attack.

The survey counts the incidents businesses were able to identify and were willing to report, so the true level may well be higher.

Source details and context

What this means in practice

Start with manageable improvements.

Useful security work can begin with a clear review, a prioritised plan, and better decisions about accounts, updates, backups and the way websites or applications are designed.

Check the basics

Review important accounts, two-step sign-in, devices, backups and who has access.

Prepare before the pressure

Write down who to contact, what must keep running, and where reliable backups are held.

Build carefully

Plan data, permissions, secure forms, updates and recovery before a digital service goes live.

General statistics are useful. Your own risk picture is more useful.

A Cyber Health Check turns broad guidance into a practical list for your business.

Start a conversation