Hiscox published its 2026 Cyber Readiness Report this month, surveying nearly 7,000 small firms across multiple countries, and the headline number should stop any UK business owner in their tracks: 38% of UK small firms say they suffered a successful cyberattack in the past year, against a 29% global average. That’s not a marginal difference. Britain came out worst of every market in the survey, worse than the US, worse than every European country included. If you run a small business here, statistically you’re more likely to be successfully hacked than a comparable business almost anywhere else in the world.
The report puts a price on it too: the average cost of a successful attack on a UK small firm now exceeds £25,000. And yet only around four in ten small UK firms carry any form of cyber insurance, compared with roughly 63% of medium-sized firms and seven in ten FTSE 100 companies. Nearly a third of UK SMEs have no cybersecurity protections in place at all. Put those numbers together and you get a country full of small businesses that are simultaneously the most likely to be hit and among the least prepared for it.
Why the UK specifically
Nothing in the report suggests UK small firms are being deliberately targeted more than others; the more likely explanation is a mix of high digital adoption without matching security investment, and phishing remaining by far the most common way in, hitting 38% of businesses surveyed. Small firms increasingly run their operations through cloud tools, accept online payments, and hold customer data digitally, but security spending and staff training haven’t kept pace with that shift. Criminals don’t need to work harder when the door’s already open.
Where to actually start
If you don’t already know your business’s real exposure, the fix isn’t necessarily buying a security product; it’s understanding what you’d lose and how you’d know if something had already gone wrong. Two practical steps:
- Get a genuine, current picture of your risk. Not a generic checklist, but an honest look at what data you hold, what systems would hurt to lose, and whether anyone would notice a breach quickly enough to limit the damage. This is precisely the gap between “we have antivirus” and “we’re actually monitored,” and it’s where most of that 32% with zero protection are sitting today without realising it.
- Put ongoing monitoring in place, not just a one-off audit. A point-in-time security review tells you about today; it says nothing about the phishing email that lands next Tuesday. KeepSafe’s cyber incident monitoring is built for exactly this: UK SMEs that need to know quickly when something’s wrong, rather than finding out weeks later from a customer or, worse, a regulator.
The insurance question
With average breach costs above £25,000 and most small firms uninsured, it’s also worth an honest conversation with your broker this month, even if the answer ends up being that your current setup is adequate. Being underinsured against a cost that size isn’t a risk most small businesses can absorb comfortably, and many policies also require evidence of basic security controls before they’ll pay out, which is another reason the monitoring question above isn’t one to leave until later.
The takeaway
The UK isn’t just at risk of the average cyberattack story you hear about large companies; on these numbers, small UK firms are the most exposed businesses of their size anywhere in the survey. If your last real look at your cyber exposure was more than a year ago, or never happened at all, this report is the reason to do it this month rather than after you become part of next year’s statistic.