The headline numbers
46% of small businesses (10–49 staff) reported experiencing a cyber security breach or attack in the past 12 months, compared with 42% of micro businesses (under 10 staff), 65% of medium businesses, and 69% of large organisations. Breach rates still climb with size — bigger businesses have a bigger attack surface and more to steal — but the gap in resilience between small and large organisations is the more important story in this year's data.
Phishing remains the dominant attack type by a wide margin, experienced by 38% of respondent businesses. It was also rated the most disruptive type of breach or attack by 69% of the businesses it hit, ahead of any technically sophisticated attack vector. Most UK businesses are not being brought down by zero-days. They're being brought down by a convincing email and a moment of inattention.
Small businesses are going backwards, not forwards
The uncomfortable finding in this year's survey is that small businesses had made modest gains in basic cyber hygiene the previous year — and those gains reversed. Fewer small businesses completed a cyber risk assessment. Fewer had a documented security policy. Fewer had a business continuity plan that accounted for a cyber incident. None of these are expensive or technically demanding to fix; they're organisational habits that slipped once the immediate pressure to build them eased off.
Awareness of government support is also low where it matters most. Only 30% of small businesses had heard of Cyber Aware, and just 23% were aware of the NCSC's 10 Steps to Cyber Security guidance — both of which are free. The barrier for most small businesses isn't a lack of available guidance, it's that the guidance never reaches the person who owns the decision.
Breach rate and disruption by business size
| Business size | Reported a breach in 12 months | Most disruptive attack type |
|---|---|---|
| Micro (under 10 staff) | 42% | Phishing |
| Small (10–49 staff) | 46% | Phishing |
| Medium (50–249 staff) | 65% | Phishing |
| Large (250+ staff) | 69% | Phishing |
The pattern holds across every size band: phishing is the entry point, and the organisations with the least formal process around identity, patching, and incident response are the ones for whom a single successful phish does the most damage.
The new variable: AI adoption is outpacing security review
Separately, AI adoption among UK SMEs has climbed sharply — from 23% in 2023 to roughly 54% running some form of AI tooling in 2026. That's a good thing for productivity, and we've written before about what's actually worth doing with AI as a UK SME. But almost none of that adoption has been matched by a parallel review of access control or data handling, and it shows up in the breaches survey as a widening blind spot around supply chain and third-party risk.
In practice this means: staff pasting customer records into an ungoverned AI chat tool to "summarise this for me", a new SaaS-with-AI-features added as a sub-processor without anyone checking its data residency or retention terms, or an AI agent given a live API key with far broader scope than the task requires. None of this shows up as a "cyber attack" in the survey data, but it's the same root cause — access granted faster than it's reviewed — that shows up as a breach a year later.
What actually moves the needle this quarter, in order:
Where a baseline stops being enough
Cyber Essentials and good hygiene habits close off the commodity attacks that phishing represents. They don't tell you whether your actual application — the SaaS product, the customer portal, the API your partners integrate against — has an exploitable flaw. That's a different exercise, and it's worth budgeting for separately once you're handling real customer data at scale. Our penetration testing cost guide covers current CREST day rates and how to tell a real test from a vulnerability scan wearing a report cover, and our web application security checklist walks through the OWASP Top 10 controls we build into every product by default.
If your product handles EU or UK personal data, the security conversation and the compliance conversation are really the same conversation. Our GDPR and data compliance guide covers lawful basis, sub-processor risk, and the AI vendor questions that data protection officers are now asking as standard.
AyTech note: Every product we ship goes through the same access-control and dependency review regardless of client size, because the breaches survey confirms what we see in client audits — the businesses that get hurt aren't the ones facing exotic attacks, they're the ones where a basic control quietly lapsed and nobody was watching for it.
Not sure where your biggest gap is?
AyTech can run a practical security and access review against your actual stack, then hand you a prioritised, costed fix list — no scare tactics, just what matters.
Cybersecurity services