The UK government publishes its Cyber Security Breaches Survey every year, and the 2025/2026 edition has landed with numbers that deserve more attention than they are getting. Around 612,000 UK businesses experienced a cyberattack or breach in the last twelve months. That is 43 percent of all businesses. The proportion of breaches that resulted in lost revenue or share value has more than doubled, rising from 2 percent to 5 percent in a single year.
These are not estimates from a vendor trying to sell security software. This is the government’s own data, collected from businesses of all sizes across every sector.
The phishing problem has not gone away
The most common attack type in the survey is phishing. It affected 38 percent of businesses that experienced a cyber incident, and 69 percent of breach victims described phishing as their most disruptive incident. The reason phishing remains so effective is that it targets people, not systems. It does not matter how good your firewall is if someone clicks a fraudulent link in a well-crafted email.
What makes 2026 different is that AI is now in the hands of criminals as well as defenders. The National Cyber Security Centre flagged a significant rise in credential-harvesting campaigns impersonating HMRC, major banks and NHS digital services. These are not the obvious spelling-mistake emails of five years ago. They are polished, personalised and designed to look exactly like communications your staff would expect to receive.
Phishing awareness training is not enough on its own. Multi-factor authentication on every account that matters — email, cloud storage, accounting software, your online banking portal — is now the minimum viable defence.
The supplier risk most SMEs are ignoring
One of the more striking findings in the survey involves the supply chain. Just 15 percent of UK businesses formally review the cyber posture of their immediate suppliers. Only 6 percent look at the wider supply chain. Compare that with large enterprises, where almost half review their immediate suppliers regularly.
This gap matters because your security is only as strong as the weakest link in your supply chain. If your IT support provider, your payroll bureau, your cloud hosting company or your accounts software vendor is compromised, the attacker can reach you through them — even if your own systems are well-maintained.
The DragonForce ransomware incidents that hit M&S, Co-op and Harrods in early 2026 exposed exactly this dynamic. Attackers compromised tools used by managed service providers and moved laterally into their clients’ systems. You may have never heard of the specific software involved, but your IT provider might use it on your behalf.
AI adoption is outpacing security readiness
The survey includes a new section on AI for the first time, and the findings are uncomfortable. AI use among businesses is growing quickly, but only around a quarter of organisations that are using, adopting or considering AI say they have security practices in place to manage the risks.
That gap represents real exposure. Employees using AI tools to draft communications, process data or summarise customer information may be doing so through services that were not reviewed by anyone in the business before sign-up. Data entered into unapproved AI tools could leave the organisation entirely, with no audit trail.
If you are adopting AI tools in your business — and most SMEs are, knowingly or otherwise — it is worth getting a proper assessment done. KeepSafe monitors for cyber incidents and emerging threats targeting UK businesses, and can help you understand what your current exposure actually looks like before an incident forces the issue.
The minimum you should do this week
The survey data is a useful prompt to do a quick self-assessment. Check whether multi-factor authentication is active on all your key business accounts. Ask your IT provider which third-party tools they use to manage your systems, and whether they have been security-reviewed. Make sure you know exactly where your business data lives — which cloud services, which devices, which providers — because you cannot protect what you cannot see.
The businesses that get breached are rarely the ones with the worst intentions. They are the ones that kept meaning to get around to it.