A decade of government data shows that cyber threats have become a persistent part of doing business. We look at what has changed, what has not, and the practical lessons smaller organisations can take from ten years of UK cyber security evidence.
Contents
- Contents
- Ten Years of Cyber Breaches: What West Midlands SMEs Can Learn
- Key Takeaways
- The Long-Term Evidence Shows Persistence Rather Than Resolution
- Familiar Attack Methods Continue to Work
- Basic Controls Have Improved, but Coverage Remains Uneven
- Leadership Attention Has Not Always Become Operational Preparedness
- Incident Planning Remains a Significant Weakness
- The Cost of an Incident Is Not Captured by a Single Average
- Repeat Victimisation Deserves More Attention
- Suppliers Have Become Part of the Security Boundary
- Cyber Security Is Increasingly Connected with Customer Requirements
- AI Creates a New Version of a Familiar Governance Problem
- A Practical SME Baseline Is More Useful Than an Enterprise Wish List
- Ten Years of Evidence Point Towards Sustained Capability
Ten Years of Cyber Breaches: What West Midlands SMEs Can Learn
Ten years of the UK Cyber Security Breaches Survey provide a useful perspective on how business cyber risk has developed. The picture is not one of attacks steadily disappearing as organisations have become more security-aware. Instead, cyber incidents remain a persistent feature of doing business, while improvements in basic controls and senior-level awareness have been accompanied by continuing weaknesses in risk assessment, incident planning and supply-chain security.
The historical evidence needs to be interpreted carefully. Changes to survey questions and methodology mean that breach-prevalence percentages cannot be treated as one perfectly comparable ten-year time series. In particular, the current prevalence measure is directly comparable only with the 2023/24 and 2024/25 surveys. The longer record is nevertheless valuable for examining how attack methods, business practices and organisational responses have changed.
The originating analysis, A Decade of the UK Cyber Security Breaches Survey: Trends, Plateaus, and What Actually Changed, examined that longer history and concluded that increased awareness has not produced an equivalent improvement in organisational capability. For West Midlands SMEs, the practical lesson is not that security controls have failed, but that cyber resilience requires sustained implementation rather than a one-off programme of improvement. The source corpus identifies the article as the decade-long component of a three-part Breaches Survey analysis, alongside the current-state survey and examination of the gap between observed and actual exposure.
Read the wider regional analysis. The West Midlands Cyber Cluster examines what a decade of UK Cyber Security Breaches Surveys tells us about changing threats, persistent weaknesses and the limits of apparent progress, in the companion article “A Decade of UK Cyber Breaches: What Has Actually Changed?”.
Key Takeaways
- Breach prevalence has remained substantial despite improvements in awareness and basic controls, although methodology changes mean headline percentages should not be treated as a single directly comparable decade-long series.
- Phishing has become increasingly dominant, while the persistence of relatively familiar attack methods suggests that everyday controls and user-facing processes remain central to SME security.
- Leadership attention has improved more than formal preparedness: in 2025/26, 72% of businesses considered cyber a high senior-management priority, but only 30% had conducted a recent risk assessment and 25% had a formal incident-response plan.
- Smaller businesses should prioritise a manageable set of controls around accounts, updates, backups, critical suppliers and incident preparation rather than attempting to reproduce an enterprise security programme.
- Cyber resilience increasingly has a commercial dimension because customers and supply-chain partners may expect businesses to demonstrate proportionate security as a condition of doing business.
The Long-Term Evidence Shows Persistence Rather Than Resolution
One of the most useful lessons from the survey’s history is that cyber risk has not followed a simple downward trajectory.
Earlier editions recorded substantial proportions of businesses identifying breaches or attacks: 46% in 2017, 43% in 2018, 32% in 2019, 46% in 2020 and 39% in 2021. These historical figures help establish the persistence of the problem, but methodological changes mean they should not be placed uncritically alongside the latest results as though every percentage measured precisely the same thing.
The latest survey provides a more defensible short-term comparison. In 2025/26, 43% of businesses identified a breach or attack during the previous 12 months, unchanged from 2024/25 and compared with 50% in 2023/24. DSIT estimates that the latest figure represents approximately 612,000 UK businesses.
There is another reason to treat prevalence carefully. Detection capability varies between organisations.
The latest survey found that 42% of microbusinesses and 46% of small businesses identified breaches or attacks, compared with 65% of medium-sized and 69% of large businesses. Larger organisations may genuinely face greater exposure, but they also tend to possess better monitoring, governance and security capability, making them more likely to recognise activity that a smaller organisation might never detect.
For SMEs, a low number of known incidents should therefore not be interpreted automatically as evidence of low exposure.
The more useful question is whether the business has enough visibility to recognise the forms of attack that would materially affect it.
Familiar Attack Methods Continue to Work
The changing composition of attacks provides another important long-term lesson.
Phishing was already the most common form of breach or attack among affected businesses in 2017, when 72% reported fraudulent emails or attempts to direct staff towards malicious websites. By 2021, the corresponding proportion had risen to 83%.
Over the same period, some other forms of attack became less prominent in the survey. Malware among affected businesses fell from 33% in 2017 to 9% in 2021, while ransomware declined from 17% to 7%.
The latest survey continues to show the importance of phishing. In 2025/26, 38% of all businesses identified phishing attacks, and among businesses that had experienced breaches or attacks, 51% reported phishing as the only type identified, compared with 45% in the previous year.
The persistence of phishing is instructive because it demonstrates that attackers do not need sophisticated technical methods when ordinary business processes continue to provide effective opportunities.
Email remains embedded in customer relationships, invoicing, procurement, recruitment and internal communication. Attackers can exploit those legitimate activities through credential theft, impersonation and fraudulent requests.
This makes phishing a business-process problem as well as an awareness problem.
Staff training has value, but expecting employees to identify every convincing message is an unreliable primary defence. Multi-factor authentication can reduce the consequences of stolen passwords. Payment-verification processes can make impersonation fraud harder. Appropriate email security can reduce malicious messages reaching users, while clear internal reporting allows suspicious activity to be investigated quickly.
The historical evidence therefore supports a layered approach rather than continued dependence on employees simply becoming better at spotting increasingly convincing attacks.
Basic Controls Have Improved, but Coverage Remains Uneven
The survey history also shows genuine improvement in some areas of business security.
Between 2016 and 2020, the proportion of businesses reporting that they never updated software fell from 26% to 17%. Board-level responsibility for cyber security increased from 28% to 37%, while the proportion conducting cyber risk assessments rose from 23% to 35%. Written cyber policies increased from 29% to 38%.
These changes demonstrate that cyber security became more established within ordinary organisational governance during the survey’s early years.
The latest data presents a mixed picture.
In 2025/26, 81% of businesses reported malware protection, while 74% used cloud backups, 74% had password policies and 74% had network firewalls. Seventy-three per cent restricted administrative rights.
More demanding or organisationally dependent controls were less widespread. Multi-factor authentication was reported by 47% of businesses, virtual private networks by 36% and user monitoring by 30%.
For an SME, the practical conclusion is not that every available technical control should be implemented immediately. Businesses differ considerably in their systems and exposure.
The stronger lesson is that security should be built in layers. If a password is compromised, another control should make account takeover harder. If a device fails or data is encrypted, recovery should not depend on that device remaining available. If an employee has no business reason to administer systems, their account should not possess administrative privileges.
Basic controls remain useful precisely because common attacks continue to exploit common weaknesses.
Leadership Attention Has Not Always Become Operational Preparedness
One of the more persistent tensions in the survey evidence is the difference between recognising cyber security as important and building the organisational mechanisms required to manage it.
In 2025/26, 72% of businesses described cyber security as a high priority for senior management. Yet only 30% had conducted a cyber risk assessment during the previous 12 months, 31% had a board member or trustee responsible for cyber security, and 25% had a formal incident-response plan.
The gap is particularly important for SMEs because senior responsibility is often concentrated among a small number of people.
A managing director may understand that cyber security matters without having the time or expertise to translate that concern into a structured programme. An outsourced IT provider may manage systems effectively without necessarily owning the business’s wider cyber risk. Insurance may provide financial protection without establishing how operations will continue during an incident.
The practical starting point is therefore to assign responsibility and create a manageable review process.
That need not involve extensive governance. A smaller business can periodically review its important systems, the information it holds, its critical suppliers, access arrangements and recovery capability. The output should identify a small number of actions with named owners rather than produce a large risk document that is rarely revisited.
The distinction between concern and capability has remained visible across the survey series. SMEs can close that gap by making cyber security part of ordinary business management rather than treating it as an occasional technical project.
Incident Planning Remains a Significant Weakness
The persistence of cyber incidents makes preparation for disruption as important as prevention.
Only 25% of businesses in the 2025/26 survey had a formal incident-response plan, while 45% had none of the response measures tested by the survey.
For smaller businesses, incident planning does not need to begin with a complicated technical playbook. It should begin with decisions that become difficult when normal systems are unavailable.
Who has authority to make decisions? How will staff communicate if email cannot be trusted? Who contacts the IT provider, insurer, bank, customers or relevant authorities? Where are important contact details stored? How will the business determine whether backups are safe to restore? Which activities need to resume first?
A short exercise can reveal weaknesses more effectively than simply writing a policy.
Consider an SME whose Microsoft 365 administrator account has been compromised, whose email is inaccessible and whose customers are receiving fraudulent payment instructions. The technical response matters, but so do communications, customer management, banking controls and leadership decisions.
A manufacturer might face a different scenario involving loss of access to production-management systems. A professional-services firm could lose access to client files. An online retailer may be unable to process orders.
The incident differs, but the planning principle is consistent: recovery needs to reflect how the business actually operates.
The Cost of an Incident Is Not Captured by a Single Average
Cyber-cost statistics can be difficult for SMEs to interpret because the distribution of losses is highly uneven.
The 2025/26 survey found a median perceived cost of zero for the most disruptive breach or attack. That does not mean incidents are generally costless. Many detected attempts are blocked or create little measurable financial consequence, while a much smaller proportion produce substantially larger losses.
At the 95th percentile, the estimated cost of the most disruptive breach reached approximately £4,000 among businesses overall and micro and small businesses, rising to around £10,000 among medium and large businesses.
Direct financial estimates also capture only part of the consequence.
An SME may experience management time, delayed orders, lost productivity, customer communications, professional fees or reputational effects that are difficult to quantify precisely. For a company operating on narrow margins, even a relatively short interruption can be significant.
This distribution explains why using the “average cost of a cyber attack” as a general sales statistic is often unhelpful.
Businesses should instead assess consequence in relation to their own operations.
The useful questions concern how long the organisation could operate without an important system, what contractual commitments could be affected, whether customer information could be exposed and what recovery resources would be available.
That produces a more meaningful basis for security investment than an abstract national average.
Repeat Victimisation Deserves More Attention
The latest survey’s cyber-crime estimates also reveal that incidents are not distributed evenly between organisations.
Approximately 19% of businesses experienced cyber crime during the previous 12 months. DSIT estimates around 5.19 million cyber crimes across UK businesses, although the survey explicitly cautions that the total has a wide confidence interval because a relatively small number of organisations report very high volumes.
Among businesses experiencing cyber crime, 33% reported a single event, while 20% experienced between 11 and 99 and 5% reported 100 or more. The median was three incidents, compared with a mean of 19.
The difference between median and mean demonstrates how heavily repeated activity affects the overall estimate.
For an SME, repeated attacks can indicate something different from a one-off malicious email. Persistent credential attacks, repeated impersonation attempts or recurring compromise may reveal an exposed account, process or technical weakness that has not been addressed.
Incident response should therefore include learning.
After an event, the business should establish what happened, which control failed or was absent, whether similar exposure exists elsewhere and what change would reduce recurrence.
Without that feedback loop, an organisation can recover operationally while leaving the original weakness intact.
Suppliers Have Become Part of the Security Boundary
One of the most important changes in business technology over the past decade is the extent to which organisations now depend on external digital services.
SMEs routinely use cloud accounting, customer-management systems, online payments, outsourced IT, managed security, file sharing, communications platforms and specialist software. This allows small organisations to obtain capability that would previously have required substantial internal infrastructure.
It also changes where risk sits.
The 2025/26 survey found that only 15% of businesses reviewed cyber risks associated with their immediate suppliers and 6% considered the wider supply chain. Among small businesses, 22% reviewed immediate supplier risks, compared with 30% of medium-sized and 48% of large businesses.
An SME does not need to perform sophisticated security audits across every supplier.
It does need to distinguish between ordinary vendors and critical dependencies.
A provider hosting essential business data deserves more attention than a supplier whose service could be replaced immediately. An IT company holding administrator credentials creates a different risk from a vendor with no access to systems. A specialist supplier whose failure could stop production warrants consideration even if it holds no sensitive data.
Supplier management can therefore begin with classification rather than bureaucracy.
Identify the providers whose compromise or prolonged unavailability would materially affect the business, then understand the security and recovery arrangements associated with those relationships.
Cyber Security Is Increasingly Connected with Customer Requirements
The growing importance of supply-chain security has another consequence for SMEs: customers may expect evidence of cyber maturity.
Cyber Essentials certification remains far from universal, but adoption is increasing. In 2025/26, 5% of businesses reported holding Cyber Essentials, compared with 3% previously. Among small businesses, certification increased from 5% to 12%.
Certification is not a complete measure of organisational resilience, but it provides a recognised baseline and can help businesses respond to customer or procurement requirements.
The broader commercial trend is more important than any individual scheme.
An SME seeking work with larger businesses, government organisations or regulated sectors may encounter security questionnaires, contractual requirements, insurance conditions or requests for certification. Waiting until a tender is under way before addressing these requirements can create unnecessary pressure.
Businesses can instead treat cyber maturity as part of commercial readiness.
That means understanding what target customers are likely to require, establishing proportionate controls and retaining evidence that those controls are actually in place.
For many West Midlands SMEs operating within manufacturing, engineering, technology and professional supply chains, this connection between security and market access is likely to become increasingly relevant.
AI Creates a New Version of a Familiar Governance Problem
Artificial intelligence introduces new technical questions, but it also illustrates a recurring lesson from the survey’s history: organisations frequently adopt technology faster than they adapt governance around it.
In 2025/26, 31% of businesses were using, adopting or considering AI. Among that group, only 24% reported having cyber-security practices specifically addressing AI risks.
For SMEs, the immediate concerns are often straightforward.
Employees may enter customer, commercial or personal information into public AI services. AI functionality may be introduced through existing software without a separate procurement decision. Businesses may depend on generated outputs without understanding how they should be checked or where sensitive data is processed.
The appropriate response is not necessarily an extensive AI-security framework.
A smaller organisation can begin by deciding which tools are approved, what information must not be entered into external systems, who is responsible for evaluating new services and where human review remains necessary.
This is consistent with the broader ten-year lesson. Technology changes, but organisations repeatedly face the same governance problem: understanding a new dependency early enough to manage it deliberately rather than discovering its significance after an incident.
A Practical SME Baseline Is More Useful Than an Enterprise Wish List
The decade of survey evidence does not support the idea that SMEs need increasingly elaborate security programmes simply because cyber risk persists.
It supports prioritisation.
For many smaller organisations, a practical baseline includes securing important accounts with multi-factor authentication, maintaining supported and updated systems, restricting unnecessary administrative access, protecting recoverable backups, understanding critical suppliers and preparing a basic incident-response process.
Cyber Essentials can provide structure around several of these technical foundations.
Businesses with greater exposure should progress further. A manufacturer with connected production systems, a managed service provider with privileged customer access or a company handling particularly sensitive information may need specialist assessment and stronger governance.
The appropriate level of security therefore depends on dependency and consequence rather than company size alone.
West Midlands SMEs that are uncertain about where to begin do not need to navigate the support landscape unaided. The West Midlands Cyber Hub can help businesses identify appropriate regional and national support, understand available programmes and connect with relevant expertise.
The important step is to begin from the business’s actual operating environment rather than from an assumption that every organisation requires the same cyber programme.
Ten Years of Evidence Point Towards Sustained Capability
A decade of Cyber Security Breaches Surveys does not show that UK businesses have made no progress. Basic controls have improved in several areas, senior leaders are more likely to recognise cyber security as an organisational priority, and schemes such as Cyber Essentials have become more established.
Neither does the evidence support complacency.
Cyber incidents remain common, phishing continues to exploit ordinary business processes, formal incident preparation is limited and supplier dependencies have become more significant as businesses have digitised. New technologies such as AI are creating additional governance requirements before many organisations have fully addressed existing ones.
For SMEs, the most defensible conclusion from the decade is that cyber resilience is cumulative.
A business does not become secure through one training course, one software purchase or one certification. Capability develops when sensible controls are maintained, responsibilities remain clear, incidents lead to improvement and security adapts as the organisation changes.
That approach is less dramatic than responding periodically to the latest threat, but the survey history suggests it is considerably closer to the problem businesses actually need to solve.