deep dive · crime and safety
The state of UK cyber security
Britain faces an elevated and uneven cyber threat. Attacks reached 43 per cent of businesses and the great majority of universities in the last year; fraud against the public hit a record 4.2 million incidents; the NCSC handled more than four nationally significant incidents a week; and independent research commissioned by the government puts the cost of serious attacks on business at around 14.7 billion pounds a year. Yet the state's own systems remain exposed, with the spending watchdog calling the threat to government severe and advancing quickly.
Coverage: UK · Period: 2024 to 2026
Key figures
of UK businesses identified a cyber breach or attack in the last 12 months
estimated annual cost of significant cyber attacks to UK businesses, about 0.5 per cent of GDP
nationally significant incidents handled by the NCSC, up from 89 the year before
Businesses and charities
Businesses and charities under attack
The Cyber Security Breaches Survey asks organisations whether they have identified a breach or attack in the past 12 months. In the 2025/2026 edition, 43 per cent of businesses and 28 per cent of charities said yes. The risk climbs steeply with size: from 42 per cent of micro businesses to 69 per cent of large ones. Phishing dominates every breakdown, ransomware stays rare, and while board attention is slowly rising, supply chain checks remain very weak.
Businesses identifying a breach or attack, by size (per cent)
Source: DSIT and Home Office Cyber Security Breaches Survey 2025/2026.
Businesses identifying a breach or attack
Down from 50 per cent of businesses in 2024, a fall concentrated among smaller firms. In the 2025 edition this was roughly 612,000 businesses.
Charities identifying a breach or attack
Large businesses identifying a breach or attack
Prevalence rises with size: 42 per cent micro, 46 per cent small, 65 per cent medium, 69 per cent large.
Businesses experiencing phishing attacks
Phishing is the most common attack type by far. Among businesses that were breached in the 2025 edition, 85 per cent had faced phishing. The figure for all charities was 25 per cent.
Businesses experiencing ransomware
Down from 3 per cent in each of the previous two years. Rare, but the survey treats ransomware as one of the most damaging attack types.
Median cost of the most disruptive breach
The cost is heavily skewed: the median is zero, but the 95th percentile reaches 4,000 pounds for smaller firms and 10,000 pounds for medium and large ones. The 2025 edition put the mean at 1,600 pounds; DSIT has since stopped publishing a mean.
Businesses where cyber security is a high priority for senior management
Businesses with a board member responsible for cyber security
Up from 27 per cent the year before, and 68 per cent among large businesses.
Businesses that review cyber risks from their immediate suppliers
Just 6 per cent review risks across their wider supply chain, even though supply chain compromise is a growing route of attack.
Businesses holding cyber insurance
Businesses holding Cyber Essentials certification
Only 17 per cent of businesses are even aware of the government backed Cyber Essentials scheme.
The hardest hit
Schools, colleges and universities
Education is the most heavily targeted part of the survey. The share identifying a breach or attack rises sharply through the system, reaching the great majority of colleges and almost every university. Phishing is even more dominant here than in business.
Education institutions identifying a breach or attack (per cent)
Source: DSIT and Home Office Cyber Security Breaches Survey 2025, education institutions findings.
Universities identifying a breach or attack
Compared with 85 per cent of further education colleges, 60 per cent of secondary schools and 44 per cent of primary schools.
Further education colleges identifying a breach or attack
Phishing among affected further and higher education
Phishing reached 89 per cent of affected primary and secondary schools and 97 per cent of affected colleges and universities.
The threat to the public
Fraud and computer misuse against individuals
Fraud is now the single most common crime against the public and reached a record 4.2 million incidents in the year to March 2025, the only driver of the rise in overall crime. Survey measured computer misuse fell sharply, yet the offences people actually reported to Action Fraud rose by more than a third, a telling gap between crime experienced and crime reported. These figures cover England and Wales.
Computer misuse offences reported to Action Fraud
Source: ONS Crime in England and Wales, Action Fraud and NFIB data, year ending March 2025.
Fraud incidents (England and Wales)
Up 31 per cent on the year before, the highest since fraud was first measured in 2017, and the single driver of the 7 per cent rise in total crime to 9.4 million incidents.
Bank and credit account fraud incidents
The largest single type of fraud. Consumer and retail fraud accounted for about 1.1 million more.
Computer misuse incidents (survey estimate)
Down 32 per cent on the previous year, which had risen to about 1 million. Of this, 564,000 incidents were unauthorised access to personal information.
Computer misuse offences reported to Action Fraud
Up 36 per cent on the year before, from 40,832. While the survey estimate of computer misuse fell, the number people reported rose.
Total cost of fraud (England and Wales)
Made up of 9.2 billion pounds affecting individuals and 5.2 billion pounds affecting businesses. This is an official estimate of all fraud, not only cyber fraud.
Stolen through payment fraud (UK Finance members)
Up 4 per cent on the year. Of this, authorised push payment fraud accounted for 576.4 million pounds across 248,070 cases, with two thirds of cases starting online. UK Finance is a banking trade body, not an official statistician.
The cost
What it costs the economy
The Breaches Survey deliberately does not produce an economy wide cost: its producers warn the self reported figures cannot be scaled up reliably. To fill that gap the government commissioned independent economists, whose central estimate puts the cost of serious attacks on business at around 14.7 billion pounds a year. These are modelled, indicative figures.
Annual cost of significant cyber attacks to UK businesses
About 0.5 per cent of GDP. The research is government commissioned but independent, and the authors stress the total should be treated as indicative only, as it draws partly on overseas data.
Average cost of a significant cyber attack to a business
A significant attack is defined as one costing at least 500 pounds. The average is heavily influenced by a small number of very costly attacks.
Annual loss from theft of intellectual property via cyber attacks
A wide range reflecting how hard it is to value stolen knowledge assets. A separate study put fraud enabled by data breaches at about 755 million pounds a year.
National defence
Defending the nation: the NCSC's year
The National Cyber Security Centre managed 429 cyber incidents in the year to August 2025. The number it judged nationally significant more than doubled to 204, continuing a steep climb, and 18 were highly significant. At the same time its automated defences operate at vast scale, taking down malicious sites and handling tens of millions of public reports.
Nationally significant incidents handled by the NCSC
Source: NCSC Annual Reviews 2023, 2024 and 2025.
Cyber incidents managed by the NCSC
From 1,727 reports received.
Nationally significant incidents
About four every week, and up sharply from 89 the year before and 62 the year before that.
Highly significant incidents
Up about 50 per cent on the year before.
Public reports to the Suspicious Email Reporting Service
More than 45 million reports have been made since the service launched in 2020, the basis for taking down hundreds of thousands of malicious sites.
Devices compromised by the China-linked Flax Typhoon botnet
One of the cases highlighted in the review, affecting more than 260,000 devices worldwide.
On ransomware
The NCSC describes ransomware as the most immediate, disruptive threat to critical national infrastructure.
On state actors
The NCSC describes China as a highly sophisticated and capable threat actor, and Russia as a capable and irresponsible threat actor in cyberspace.
The state's own defences
Government's own resilience
The National Audit Office reviewed central government's cyber resilience in January 2025 and found it wanting. Government runs hundreds of ageing systems whose vulnerability it cannot fully assess, struggles to fill cyber roles, and will miss its own 2025 hardening target. The watchdog called the threat severe and advancing quickly.
Legacy IT systems across government
Of these, 63 are rated high risk and 120 have no fully funded plan to fix them. The NAO notes government does not know how vulnerable many of these systems are.
Government cyber roles vacant or filled by temporary staff
Around 70 per cent of specialist security architects in post were temporary staff. Several departments had more than half of their cyber team roles vacant.
Government organisations meeting the minimum cyber standard
Officials reported the cyber resilience risk to government as extremely high. The NAO concluded the 2025 target to be significantly hardened to attack will not be met.
Data breaches reported by central government to the ICO
A 75 per cent rise on the year before, affecting the data of more than 100,000 people.
MoD payroll records put at risk in the 2024 contractor attack
Names and bank details, with some addresses and National Insurance numbers, held by an external payroll contractor.
NHS appointments and procedures postponed after the Synnovis attack
The ransomware attack on pathology provider Synnovis postponed 10,152 acute outpatient appointments and 1,710 elective procedures across south east London.
Directly attributable cost of the British Library attack
The October 2023 Rhysida ransomware attack leaked about 600GB of data; the Library refused to pay the ransom and faced a long rebuild.
Capacity
The cyber skills gap
Nearly half of UK businesses lack the basic cyber skills to manage their own defences, and the advanced skills shortage, though smaller, still affects a third. Recruitment is not closing the gap: core cyber job postings fell sharply in 2024.
Businesses with a cyber skills gap (per cent)
Source: DSIT Cyber security skills in the UK labour market 2025.
Businesses with a basic cyber skills gap
The people responsible cannot carry out basic tasks such as setting up firewalls or detecting and removing malware.
Businesses with an advanced cyber skills gap
29 per cent of charities also reported an advanced skills gap.
Core cyber job postings in 2024
Down 33 per cent on the year, even as the estimated workforce gap held at about 3,800 people.
Caveats & data notes
How to read these figures
- The Cyber Security Breaches Survey is a survey of organisations based on self reporting. It counts breaches or attacks that organisations identified, not every incident that occurred, and its producers warn its cost figures cannot be scaled into an economy wide total.
- The economy wide cost of 14.7 billion pounds comes from independent research commissioned by the government. Its authors describe it as indicative only, as it relies in part on overseas data and on modelling assumptions.
- The ONS Crime Survey covers England and Wales only and produces survey estimates with margins of error. Large year on year movements should be read with caution, especially the fall in computer misuse, which follows a sharp rise the year before.
- Survey measured computer misuse fell while offences reported to Action Fraud rose. The two measure different things, crime experienced versus crime reported, and both are shown here rather than choosing one.
- Payment fraud loss figures come from UK Finance, a banking trade body, not an official statistician, and cover losses reported by its members.
- The NCSC, NAO and survey figures count different things over different periods and for different populations, so they are not directly additive or comparable.
Sources
Data provenance
- Cyber Security Breaches Survey 2025/2026 ↗· DSIT and Home Office· Published April 2026
- Cyber Security Breaches Survey 2025, including education institutions findings ↗· DSIT and Home Office· Published April 2025
- Crime in England and Wales, year ending March 2025 ↗· Office for National Statistics· Fraud and computer misuse figures
- The economic and social costs of fraud ↗· Home Office· Year ending March 2024 estimate
- Annual Fraud Report 2026 ↗· UK Finance (industry body)· 2025 data
- Independent research on the economic impact of cyber attacks on the UK ↗· KPMG, Alma Economics and Frontier Economics, commissioned by DSIT· Published November 2025
- NCSC Annual Review 2025 ↗· National Cyber Security Centre· Published October 2025
- Government cyber resilience ↗· National Audit Office· Published January 2025
- Cyber security skills in the UK labour market 2025 ↗· DSIT· Published September 2025
Every figure on this page traces to its official source. Share it as it stands.
Keep going
Related deep dives
Every offence recorded by police from 2012/13 to 2024/25: what gets recorded, what has gone up and down, and where rates are highest by force area.
An estimated 3.8 million adults, 7.8 per cent, experienced domestic abuse in England and Wales in the year to March 2025, against 816,493 police recorded crimes, with separate non-comparable totals for Scotland and Northern Ireland and just 7.3 per cent of recorded crimes ending in a charge.
What share of crimes end in a charge, how that varies by offence type and police force, and why so many are closed with no suspect identified.
The monthly reading
Get the next one by email
One email a month: the national resilience score, what moved, and the newest analyses like this one, plus The Quarterly Record four times a year. Every figure traced to its official source.