deep dive · crime and safety

The state of UK cyber security

Britain faces an elevated and uneven cyber threat. Attacks reached 43 per cent of businesses and the great majority of universities in the last year; fraud against the public hit a record 4.2 million incidents; the NCSC handled more than four nationally significant incidents a week; and independent research commissioned by the government puts the cost of serious attacks on business at around 14.7 billion pounds a year. Yet the state's own systems remain exposed, with the spending watchdog calling the threat to government severe and advancing quickly.

Coverage: UK · Period: 2024 to 2026

Key figures

43%

of UK businesses identified a cyber breach or attack in the last 12 months

2025/2026 surveyDSIT and Home Office
£14.7bn

estimated annual cost of significant cyber attacks to UK businesses, about 0.5 per cent of GDP

2024 prices, published 2025KPMG, commissioned by DSIT
204

nationally significant incidents handled by the NCSC, up from 89 the year before

September 2024 to August 2025NCSC
4.2 million

fraud incidents against the public, the highest on record

year ending March 2025ONS

Businesses and charities

Businesses and charities under attack

The Cyber Security Breaches Survey asks organisations whether they have identified a breach or attack in the past 12 months. In the 2025/2026 edition, 43 per cent of businesses and 28 per cent of charities said yes. The risk climbs steeply with size: from 42 per cent of micro businesses to 69 per cent of large ones. Phishing dominates every breakdown, ransomware stays rare, and while board attention is slowly rising, supply chain checks remain very weak.

Businesses identifying a breach or attack, by size (per cent)

Micro (1 to 9 staff)42%
Small (10 to 49)46%
Medium (50 to 249)65%
Large (250+)69%

Source: DSIT and Home Office Cyber Security Breaches Survey 2025/2026.

Businesses identifying a breach or attack

43%

Down from 50 per cent of businesses in 2024, a fall concentrated among smaller firms. In the 2025 edition this was roughly 612,000 businesses.

Charities identifying a breach or attack

28%

Large businesses identifying a breach or attack

69%

Prevalence rises with size: 42 per cent micro, 46 per cent small, 65 per cent medium, 69 per cent large.

Businesses experiencing phishing attacks

38%

Phishing is the most common attack type by far. Among businesses that were breached in the 2025 edition, 85 per cent had faced phishing. The figure for all charities was 25 per cent.

Businesses experiencing ransomware

1%

Down from 3 per cent in each of the previous two years. Rare, but the survey treats ransomware as one of the most damaging attack types.

Median cost of the most disruptive breach

£0

The cost is heavily skewed: the median is zero, but the 95th percentile reaches 4,000 pounds for smaller firms and 10,000 pounds for medium and large ones. The 2025 edition put the mean at 1,600 pounds; DSIT has since stopped publishing a mean.

Businesses where cyber security is a high priority for senior management

72%

Businesses with a board member responsible for cyber security

31%

Up from 27 per cent the year before, and 68 per cent among large businesses.

Businesses that review cyber risks from their immediate suppliers

15%

Just 6 per cent review risks across their wider supply chain, even though supply chain compromise is a growing route of attack.

Businesses holding cyber insurance

47%

Businesses holding Cyber Essentials certification

5%

Only 17 per cent of businesses are even aware of the government backed Cyber Essentials scheme.

The hardest hit

Schools, colleges and universities

Education is the most heavily targeted part of the survey. The share identifying a breach or attack rises sharply through the system, reaching the great majority of colleges and almost every university. Phishing is even more dominant here than in business.

Education institutions identifying a breach or attack (per cent)

Primary schools44%
Secondary schools60%
Further education colleges85%
Higher education (universities)91%

Source: DSIT and Home Office Cyber Security Breaches Survey 2025, education institutions findings.

Universities identifying a breach or attack

91%

Compared with 85 per cent of further education colleges, 60 per cent of secondary schools and 44 per cent of primary schools.

Further education colleges identifying a breach or attack

85%

Phishing among affected further and higher education

97%

Phishing reached 89 per cent of affected primary and secondary schools and 97 per cent of affected colleges and universities.

The threat to the public

Fraud and computer misuse against individuals

Fraud is now the single most common crime against the public and reached a record 4.2 million incidents in the year to March 2025, the only driver of the rise in overall crime. Survey measured computer misuse fell sharply, yet the offences people actually reported to Action Fraud rose by more than a third, a telling gap between crime experienced and crime reported. These figures cover England and Wales.

Computer misuse offences reported to Action Fraud

Year ending Mar 202326,604
Year ending Mar 202440,832
Year ending Mar 202555,576

Source: ONS Crime in England and Wales, Action Fraud and NFIB data, year ending March 2025.

Fraud incidents (England and Wales)

4.2 million

Up 31 per cent on the year before, the highest since fraud was first measured in 2017, and the single driver of the 7 per cent rise in total crime to 9.4 million incidents.

Bank and credit account fraud incidents

About 2.4 million

The largest single type of fraud. Consumer and retail fraud accounted for about 1.1 million more.

Computer misuse incidents (survey estimate)

692,000

Down 32 per cent on the previous year, which had risen to about 1 million. Of this, 564,000 incidents were unauthorised access to personal information.

Computer misuse offences reported to Action Fraud

55,576

Up 36 per cent on the year before, from 40,832. While the survey estimate of computer misuse fell, the number people reported rose.

year ending March 2025ONS, Action Fraud and NFIB

Total cost of fraud (England and Wales)

£14.4 billion

Made up of 9.2 billion pounds affecting individuals and 5.2 billion pounds affecting businesses. This is an official estimate of all fraud, not only cyber fraud.

Stolen through payment fraud (UK Finance members)

£1.28 billion

Up 4 per cent on the year. Of this, authorised push payment fraud accounted for 576.4 million pounds across 248,070 cases, with two thirds of cases starting online. UK Finance is a banking trade body, not an official statistician.

The cost

What it costs the economy

The Breaches Survey deliberately does not produce an economy wide cost: its producers warn the self reported figures cannot be scaled up reliably. To fill that gap the government commissioned independent economists, whose central estimate puts the cost of serious attacks on business at around 14.7 billion pounds a year. These are modelled, indicative figures.

Annual cost of significant cyber attacks to UK businesses

£14.7 billion

About 0.5 per cent of GDP. The research is government commissioned but independent, and the authors stress the total should be treated as indicative only, as it draws partly on overseas data.

2024 prices, published November 2025KPMG, commissioned by DSIT

Average cost of a significant cyber attack to a business

£194,729

A significant attack is defined as one costing at least 500 pounds. The average is heavily influenced by a small number of very costly attacks.

Annual loss from theft of intellectual property via cyber attacks

£1bn to £8.5bn

A wide range reflecting how hard it is to value stolen knowledge assets. A separate study put fraud enabled by data breaches at about 755 million pounds a year.

National defence

Defending the nation: the NCSC's year

The National Cyber Security Centre managed 429 cyber incidents in the year to August 2025. The number it judged nationally significant more than doubled to 204, continuing a steep climb, and 18 were highly significant. At the same time its automated defences operate at vast scale, taking down malicious sites and handling tens of millions of public reports.

Nationally significant incidents handled by the NCSC

Sep 2022 to Aug 202362
Sep 2023 to Aug 202489
Sep 2024 to Aug 2025204

Source: NCSC Annual Reviews 2023, 2024 and 2025.

Cyber incidents managed by the NCSC

429

From 1,727 reports received.

September 2024 to August 2025NCSC Annual Review 2025

Nationally significant incidents

204

About four every week, and up sharply from 89 the year before and 62 the year before that.

September 2024 to August 2025NCSC Annual Review 2025

Highly significant incidents

18

Up about 50 per cent on the year before.

September 2024 to August 2025NCSC Annual Review 2025

Public reports to the Suspicious Email Reporting Service

10.9 million

More than 45 million reports have been made since the service launched in 2020, the basis for taking down hundreds of thousands of malicious sites.

September 2024 to August 2025NCSC Annual Review 2025

Devices compromised by the China-linked Flax Typhoon botnet

260,000+

One of the cases highlighted in the review, affecting more than 260,000 devices worldwide.

On ransomware

The NCSC describes ransomware as the most immediate, disruptive threat to critical national infrastructure.

On state actors

The NCSC describes China as a highly sophisticated and capable threat actor, and Russia as a capable and irresponsible threat actor in cyberspace.

The state's own defences

Government's own resilience

The National Audit Office reviewed central government's cyber resilience in January 2025 and found it wanting. Government runs hundreds of ageing systems whose vulnerability it cannot fully assess, struggles to fill cyber roles, and will miss its own 2025 hardening target. The watchdog called the threat severe and advancing quickly.

Legacy IT systems across government

At least 228

Of these, 63 are rated high risk and 120 have no fully funded plan to fix them. The NAO notes government does not know how vulnerable many of these systems are.

Government cyber roles vacant or filled by temporary staff

1 in 3

Around 70 per cent of specialist security architects in post were temporary staff. Several departments had more than half of their cyber team roles vacant.

Government organisations meeting the minimum cyber standard

25%

Officials reported the cyber resilience risk to government as extremely high. The NAO concluded the 2025 target to be significantly hardened to attack will not be met.

2022 self-assessmentNational Audit Office

Data breaches reported by central government to the ICO

Up to 114

A 75 per cent rise on the year before, affecting the data of more than 100,000 people.

MoD payroll records put at risk in the 2024 contractor attack

About 270,000

Names and bank details, with some addresses and National Insurance numbers, held by an external payroll contractor.

NHS appointments and procedures postponed after the Synnovis attack

11,862

The ransomware attack on pathology provider Synnovis postponed 10,152 acute outpatient appointments and 1,710 elective procedures across south east London.

Directly attributable cost of the British Library attack

£600,000

The October 2023 Rhysida ransomware attack leaked about 600GB of data; the Library refused to pay the ransom and faced a long rebuild.

Capacity

The cyber skills gap

Nearly half of UK businesses lack the basic cyber skills to manage their own defences, and the advanced skills shortage, though smaller, still affects a third. Recruitment is not closing the gap: core cyber job postings fell sharply in 2024.

Businesses with a cyber skills gap (per cent)

Basic skills gap49%
Advanced skills gap30%

Source: DSIT Cyber security skills in the UK labour market 2025.

Businesses with a basic cyber skills gap

49%

The people responsible cannot carry out basic tasks such as setting up firewalls or detecting and removing malware.

Businesses with an advanced cyber skills gap

30%

29 per cent of charities also reported an advanced skills gap.

Core cyber job postings in 2024

32,370

Down 33 per cent on the year, even as the estimated workforce gap held at about 3,800 people.

Caveats & data notes

How to read these figures

  • The Cyber Security Breaches Survey is a survey of organisations based on self reporting. It counts breaches or attacks that organisations identified, not every incident that occurred, and its producers warn its cost figures cannot be scaled into an economy wide total.
  • The economy wide cost of 14.7 billion pounds comes from independent research commissioned by the government. Its authors describe it as indicative only, as it relies in part on overseas data and on modelling assumptions.
  • The ONS Crime Survey covers England and Wales only and produces survey estimates with margins of error. Large year on year movements should be read with caution, especially the fall in computer misuse, which follows a sharp rise the year before.
  • Survey measured computer misuse fell while offences reported to Action Fraud rose. The two measure different things, crime experienced versus crime reported, and both are shown here rather than choosing one.
  • Payment fraud loss figures come from UK Finance, a banking trade body, not an official statistician, and cover losses reported by its members.
  • The NCSC, NAO and survey figures count different things over different periods and for different populations, so they are not directly additive or comparable.

Sources

Data provenance