The latest UK Cyber Security Breaches Survey shows that cyber risk remains a routine business challenge. We identify five practical actions West Midlands SMEs can take to improve resilience, strengthen basic controls and reduce exposure.
Contents
- Contents
- Cyber Security Breaches Survey 2026: Five Actions for West Midlands SMEs
- Key Takeaways
- Action One: Strengthen Account Security
- Action Two: Conduct a Practical Cyber Risk Assessment
- Action Three: Prepare for an Incident Before One Happens
- Action Four: Identify the Suppliers You Cannot Easily Operate Without
- Action Five: Put Basic Governance Around AI Adoption
- Cyber Essentials Can Provide Structure for the Technical Baseline
- Smaller Businesses Should Not Interpret Lower Detection as Lower Risk
- Cyber Crime Is Concentrated Among Some Businesses
- Security Controls Should Reflect Commercial Requirements
- Turning the Survey into an Improvement Plan
Cyber Security Breaches Survey 2026: Five Actions for West Midlands SMEs
The 2025/26 Cyber Security Breaches Survey provides one of the clearest current pictures of how UK organisations experience and manage cyber risk. Its central finding is not a dramatic increase in attacks, but persistence: 43% of businesses identified a cyber security breach or attack during the previous 12 months, unchanged from 2024/25 and representing an estimated 612,000 businesses nationally.
The survey also shows why headline breach rates need careful interpretation. Larger businesses reported substantially higher levels of identified breaches and attacks than smaller organisations, with 65% of medium-sized and 69% of large businesses affected, compared with 42% of microbusinesses and 46% of small businesses. DSIT cautions that this difference may partly reflect the greater ability of larger organisations to detect and record incidents, rather than smaller businesses necessarily experiencing much less malicious activity.
The originating analysis, The UK Cyber Security Breaches Survey 2025/26: Stagnation, Scale, and the Illusion of Progress, examined the wider implications of these findings. For West Midlands SMEs, however, the survey can also be translated into a more immediate question: which improvements are most likely to strengthen resilience without requiring a small business to build an enterprise-scale cyber programme?
Five priorities emerge particularly clearly from the evidence: protecting accounts, understanding risk, preparing for incidents, examining critical suppliers and introducing proportionate governance around AI.
Read the wider regional analysis. The West Midlands Cyber Cluster examines what the 2026 Cyber Security Breaches Survey reveals about the state of organisational cyber resilience and the wider implications for the West Midlands, in the companion article “Cyber Security Breaches Survey 2026: What Businesses Need to Know”.
Key Takeaways
- Multi-factor authentication remains one of the clearest areas for improvement: only 47% of businesses reported using it, despite phishing continuing to dominate identified attacks.
- Only 30% of businesses had conducted a cyber risk assessment during the previous year, so many organisations still lack a structured view of which systems, information and dependencies deserve the greatest protection.
- Incident preparedness remains limited, with only 25% of businesses maintaining a formal incident-response plan and 45% reporting none of the response measures tested by the survey.
- Supply-chain review is uncommon, particularly among smaller organisations, even though SMEs increasingly depend on cloud services, outsourced IT and other external providers.
- AI adoption is running ahead of AI-specific cyber governance: 31% of businesses were using, adopting or considering AI, but only 24% of that group reported relevant cyber-security practices.
Action One: Strengthen Account Security
Phishing remains the most widespread form of cyber attack identified by UK businesses.
In 2025/26, 38% of all businesses reported phishing attacks. Among businesses that experienced a breach or attack, phishing was also frequently the only type identified: 51% of affected businesses reported phishing alone, compared with 45% in the previous year.
For SMEs, this means that account security deserves particular attention.
Phishing can be used to steal passwords, compromise email accounts, impersonate staff or gain access to cloud services. Once an attacker controls a legitimate account, subsequent activity can appear to come from somebody the organisation already trusts.
Multi-factor authentication provides an additional barrier by requiring something beyond the password before access is granted. Yet only 47% of businesses in the survey reported using it.
The priority should be the accounts capable of causing the greatest damage if compromised. Email and Microsoft 365 or Google Workspace accounts are obvious candidates, but administrator accounts, cloud applications, financial systems and remote-access services may be equally important.
Businesses should also review whether former employees retain access, whether administrative privileges are unnecessarily widespread and whether important services still depend on shared accounts.
Training remains useful, but it should support technical controls rather than substitute for them. Phishing messages are increasingly convincing, and legitimate business processes create ample opportunities for impersonation. A payment request appearing to come from a senior colleague, supplier or customer can be difficult to distinguish from genuine correspondence when judged from the email alone.
Financial processes can therefore provide another layer of defence. Changes to supplier bank details, unusual payments or sensitive requests can be verified through a separate communication channel rather than relying solely on the message that initiated the transaction.
The objective is to design business processes on the assumption that an employee may eventually encounter a convincing malicious message.
Action Two: Conduct a Practical Cyber Risk Assessment
The survey found that 72% of businesses regarded cyber security as a high priority for senior management, but only 30% had conducted a cyber risk assessment during the previous 12 months.
For SMEs, that gap is important because cyber investment can otherwise become reactive.
A business hears about ransomware and buys a product. A customer requests certification and security becomes an urgent procurement exercise. An insurer asks about multi-factor authentication and controls are introduced during renewal. Each response may be sensible, but together they do not necessarily amount to a coherent understanding of risk.
A practical assessment begins with the business rather than with a catalogue of cyber threats.
Which systems are essential to trading? What information would create serious problems if disclosed or lost? Which accounts have powerful access? Which suppliers could interrupt operations? How quickly would important systems need to be recovered? What contractual or regulatory obligations apply to the information the organisation handles?
The answers allow security effort to be prioritised.
A small professional-services firm heavily dependent on cloud email and document storage may concentrate initially on identity, access and recoverable data. A manufacturer may need to consider production systems and remote supplier access alongside corporate IT. A technology business hosting customer information may have stronger requirements around application security, monitoring and incident management.
The assessment does not need to become an extensive consultancy exercise. For many SMEs, a structured discussion involving management and whoever is responsible for technology can establish the most significant dependencies and identify a manageable improvement plan.
External support becomes useful where the business cannot confidently assess those risks itself, but the objective remains the same: understand what could materially affect the organisation before deciding what to protect first.
Action Three: Prepare for an Incident Before One Happens
The 2025/26 survey found that only 25% of businesses had a formal incident-response plan. More strikingly, 45% reported none of the incident-response measures tested by the survey.
These figures suggest that prevention continues to receive more attention than preparation for failure.
For SMEs, a useful incident plan does not need to predict every possible attack. It needs to establish how the organisation will make decisions when normal systems or communications cannot be trusted.
Consider a compromised email administrator account. Staff may lose access to email at precisely the point when the business needs to coordinate a response. Customers may receive fraudulent messages. Password resets may be required across several services, while somebody needs to contact the technology provider, insurer or bank.
A written plan can establish responsibilities and alternative contact methods before those decisions become urgent.
Important information should also be accessible independently of the systems most likely to be affected. Contact details for IT support, insurers, key suppliers and relevant authorities are of limited value if they exist only inside an inaccessible mailbox.
Backups deserve similar scrutiny.
The survey found that 74% of businesses used cloud backups, but possessing a backup and having a workable recovery capability are different things. Businesses should understand what is being backed up, how frequently, who can delete or alter backups and how long restoration is likely to take.
Testing provides the strongest evidence.
Even a short tabletop exercise can expose assumptions about responsibilities, communications and recovery. A business can work through a realistic scenario with management and its technology provider and identify what information or capability is missing.
The purpose is not to create a sophisticated crisis-management function. It is to avoid making every important decision for the first time during the incident itself.
Action Four: Identify the Suppliers You Cannot Easily Operate Without
Modern SMEs depend extensively on external technology and services.
Cloud platforms, outsourced IT providers, accounting software, payment systems, customer-management applications, logistics services and specialist industry platforms can all become critical to normal operations.
Despite this dependency, supplier cyber review remains limited.
The survey found that 15% of businesses reviewed cyber risks associated with their immediate suppliers and only 6% examined their wider supply chains. The differences by business size were substantial: 12% of microbusinesses and 22% of small businesses reviewed immediate suppliers, compared with 30% of medium-sized and 48% of large businesses.
Smaller businesses generally cannot perform detailed security assessments across every supplier, nor would that necessarily be a sensible use of resources.
The more practical approach is to identify critical suppliers first.
A provider should receive greater attention if it stores sensitive information, has administrator access to systems, provides technology essential to daily operations or would be difficult to replace quickly.
An outsourced IT provider is an obvious example because it may hold powerful access across the organisation. Cloud productivity platforms can be similarly important because email, documents and identity services may depend on them simultaneously.
The assessment should also consider non-technology suppliers where prolonged disruption would affect the business materially.
Once critical suppliers have been identified, SMEs can ask more focused questions. What happens if the service is unavailable? How does the supplier communicate security incidents? Who controls privileged access? Can business data be recovered or exported? What alternative arrangements exist if the relationship ends unexpectedly?
The purpose is not to eliminate supplier risk. Outsourcing often allows SMEs to obtain considerably stronger technology and expertise than they could provide internally.
The objective is to understand where another organisation has become part of the business’s operational resilience.
Action Five: Put Basic Governance Around AI Adoption
Artificial intelligence is becoming part of ordinary business software faster than many organisations are developing policies for its use.
The survey found that 31% of businesses were using, adopting or considering AI. Among those organisations, only 24% reported cyber-security practices specifically addressing AI risks.
For many SMEs, the immediate risks do not require specialist knowledge of machine-learning security.
They arise from how employees use readily available tools.
Staff may enter commercially sensitive information, customer data, source code or internal documents into public AI services without understanding how that information is processed. AI capabilities may also appear inside software the organisation already uses, meaning adoption can occur without a separate technology project.
A proportionate starting point is to establish simple rules.
Businesses should decide which AI services employees may use for work, what categories of information must not be submitted, whether generated material requires human verification and who is responsible for approving new applications where sensitive data or important business processes are involved.
Organisations developing or deploying AI more extensively will require stronger controls, but basic governance can address many immediate risks.
The underlying principle is familiar from previous waves of cloud and software adoption: convenience can cause technology to become operationally important before the organisation has consciously considered the dependency it creates.
Introducing lightweight governance early is generally easier than attempting to reconstruct how information and processes are being used after adoption has become widespread.
Cyber Essentials Can Provide Structure for the Technical Baseline
The five actions above are not intended to create another security framework for SMEs.
Businesses looking for an established technical baseline can use Cyber Essentials, which covers controls intended to reduce exposure to common internet-based attacks.
The 2025/26 survey recorded an increase in certification. Five per cent of businesses reported holding Cyber Essentials, compared with 3% previously. Among small businesses, adoption increased from 5% to 12%, while 35% of large businesses reported certification, compared with 21% in the previous year.
Certification can be useful for two reasons.
First, it gives businesses a defined set of technical requirements against which they can assess basic security. Second, customers and procurement processes increasingly recognise Cyber Essentials as evidence of a minimum security baseline.
It should not be treated as proof that every cyber risk has been resolved.
A manufacturer with operational technology, a software company processing sensitive customer information or a managed service provider with privileged access to clients may require controls beyond the scheme’s scope.
For many SMEs, however, the discipline of establishing a recognised baseline is preferable to selecting controls without an organising structure.
Smaller Businesses Should Not Interpret Lower Detection as Lower Risk
The survey’s findings by business size require particular caution.
Only 42% of microbusinesses identified a breach or attack, compared with 69% of large businesses. It would be tempting to conclude that smaller organisations face substantially less cyber risk.
Detection capability complicates that interpretation.
Large organisations are more likely to operate security monitoring, maintain specialist teams, record incidents formally and possess systems capable of identifying malicious activity. A smaller business may experience credential attacks, scanning or suspicious activity without recognising or recording them as security incidents.
This creates a visibility problem.
An SME should therefore avoid using the absence of known incidents as its principal measure of security effectiveness.
More useful indicators include whether important accounts are protected, systems remain supported and updated, backups can be restored, privileged access is controlled and unusual activity can be investigated.
This distinction also explains why security maturity can sometimes make an organisation appear to experience more attacks: better detection reveals activity that previously went unseen.
Cyber Crime Is Concentrated Among Some Businesses
The survey estimated that 19% of businesses experienced cyber crime during the previous year. Across UK businesses, DSIT estimated approximately 5.19 million cyber crimes, although the report cautions that this total has a wide margin of uncertainty because some respondents reported very high numbers of incidents.
The distribution is more informative than the headline total.
Among businesses experiencing cyber crime, the median number of events was three while the mean was 19. One third reported a single cyber crime, but 20% experienced between 11 and 99 and 5% reported 100 or more.
This indicates substantial repeat victimisation among part of the business population.
For SMEs, repeated incidents should trigger investigation rather than simply repeated recovery.
If the same account is continually targeted, if impersonation attempts repeatedly exploit the same business process or if compromise returns after systems have been restored, the organisation needs to establish whether an underlying weakness remains.
An incident is therefore also a source of information.
The most useful post-incident question is not only whether operations have been restored, but whether the organisation understands what needs to change to reduce the likelihood or consequence of recurrence.
Security Controls Should Reflect Commercial Requirements
Cyber security increasingly affects business relationships as well as internal resilience.
Larger customers may ask suppliers to demonstrate security controls, hold Cyber Essentials certification or respond to assurance questionnaires. Businesses operating in regulated or sensitive sectors can face more extensive requirements.
For SMEs, this means that cyber improvement can support commercial readiness.
A business planning to enter new supply chains should investigate likely customer requirements before a tender is under way. If certification, specific controls or documented policies are likely to be required, they can then be developed systematically rather than under procurement pressure.
This is particularly relevant in the West Midlands, where many smaller businesses operate within industrial, technology and professional supply chains.
The appropriate level of security remains proportionate to the organisation. A ten-person supplier should not be expected to reproduce the security department of a multinational customer.
It should, however, be able to explain how it protects the systems and information on which the commercial relationship depends.
Turning the Survey into an Improvement Plan
The Cyber Security Breaches Survey is valuable because it provides national evidence about where organisations are improving and where capability remains uneven. Its findings should not be converted into a generic checklist without considering the circumstances of the individual business.
For an SME deciding what to do next, the five priorities provide a practical sequence.
Strengthening important accounts reduces exposure to one of the most persistent routes of compromise. A basic risk assessment identifies where limited time and money should be concentrated. Incident preparation reduces dependence on improvisation when disruption occurs. Critical-supplier review extends resilience beyond the organisation’s own systems, while basic AI governance addresses a rapidly growing source of digital dependency.
Some businesses will already have these foundations and should progress towards more sophisticated controls. Others may discover that several remain incomplete.
The West Midlands Cyber Hub can help regional businesses navigate available support, understand relevant programmes and connect with cyber expertise where additional assistance is required. The purpose is not to turn every SME into a cyber specialist, but to help businesses establish the level of capability appropriate to their operations, customers and dependencies.
The latest survey shows that cyber risk has become persistent rather than exceptional. For smaller businesses, the rational response is equally persistent: a manageable programme of improvement that strengthens the organisation as its technology, suppliers and commercial requirements change.