The Government's 2025/2026 Cyber Security Breaches Survey makes for sobering reading: 43% of UK businesses — roughly 612,000 organisations — reported a cyber breach or attack in the past 12 months, with an estimated 5.19 million cybercrimes overall. Phishing remains by far the most common and most disruptive type of attack.
What stands out is how little the headline numbers move year to year. Awareness is high; consistent action is not.
The gaps the survey keeps finding
- Only around a third of businesses have board-level responsibility for cyber security.
- Just 15% review the risks posed by their immediate suppliers, and only 6% look at the wider supply chain.
- Smaller businesses are, in some areas, going backwards on the basics.
How not to become a statistic
- Get the fundamentals certified with Cyber Essentials — it stops the majority of common attacks.
- Train staff to spot phishing, and back it with phishing-resistant MFA.
- Assign clear ownership of cyber security at leadership level.
- Extend your security expectations to your suppliers.
The supply-chain blind spot
Two figures from the survey deserve more attention than they get: only around 15% of businesses review the security of their immediate suppliers, and just 6% look at the wider supply chain. Yet a growing share of breaches arrive not through an organisation’s own front door but through a trusted partner or platform. Combined with the finding that only about a third of businesses have board-level ownership of cyber security, it paints a picture of risk that is widely acknowledged but rarely governed. Closing that gap — extending your security expectations to suppliers and making cyber a leadership responsibility — is where much of the real progress now lies, and it is exactly the work we help clients put in place.
As a Cyber Essentials Plus certified provider, we help Greater Manchester businesses turn awareness into action. Get in touch.
Source: Nearly half of UK businesses experiencing cyber security breaches — HR News