Thursday, 1 October 2026

Where technology leaders come to think out loud

AnalysisCybersecurity

Small firms slip on cyber basics as phishing tightens its grip

The government’s annual breach survey finds attack rates flat and micro firms improving. But small businesses have lost last year’s gains in planning, just as officials warn AI is speeding up attackers

VETTDD cybersecurity section card
Image: VETTDD
In brief
  • Only a quarter of businesses have a formal incident response plan, against 76% of large firms.
  • Phishing is crowding out other attacks, and more breached firms report lost revenue, while fewer micro firms recover within a day.
  • Large customers are far more likely to demand supplier accreditation than a year ago, making Cyber Essentials increasingly a condition of trade for small suppliers.

Small UK businesses have lost most of last year’s gains in cybersecurity planning. The Cyber Security Breaches Survey 2025/2026, commissioned by the Department for Science, Innovation and Technology (DSIT) and the Home Office and published on 30 April, finds that the share of small firms (10 to 49 employees) carrying out a cyber risk assessment fell from 48% to 41% in a year. Those with a formal policy covering cyber risk dropped from 59% to 52%, and those with a business continuity plan that covers cyber from 53% to 44%.

The headline rate of attack barely moved. Just over four in 10 businesses (43%) identified a breach or attack in the previous 12 months, about 612,000 firms, in line with the year before. Medium (65%) and large (69%) businesses were more likely to report one than micro (42%) and small (46%) firms. The survey was carried out by Ipsos, mainly by telephone, between August and December 2025, and covers 2,112 businesses and 1,085 charities.

The question for security leaders is why small firms went backward – and what happens to organizations whose defenses stop at the basics now that officials say AI is making attackers faster.

A flat line that hides harder hits

Phishing remains the dominant threat. It was experienced by 38% of businesses and named by 69% of those that suffered a breach as the attack that caused them most disruption. Among breached businesses, the share hit by phishing and nothing else rose from 45% to 51%. Ransomware fell to 1% of businesses, from 3% in each of the previous two years.

The damage, though, is getting worse for some. Among businesses that identified a breach, the share reporting lost revenue or share value rose from 2% to 5%, and reputational damage from 1% to 3%. Among micro businesses, the proportion able to recover within a day from the breach that hit them hardest fell from 92% to 86%. Most firms still report little cost: the median perceived cost of the worst breach was £0. But the top 5% of cases cost £4,000 or more for micro and small firms and £10,000 or more for medium and large ones.

The report’s authors are blunt about the lack of movement. They write that “cyber security prioritisation and action has not moved substantially, with long-standing issues like the resilience gap between large firms and SMEs persisting.” Only 25% of businesses have a formal incident response plan, falling to 21% of micro businesses, against 57% of medium and 76% of large firms.

Where smaller firms are improving

The picture is not uniformly poor. Micro businesses (one to nine employees) increased their use of two-factor authentication from 35% to 43% and of company-owned devices only from 58% to 64%. The share of micro firms with an external cybersecurity provider rose from 39% to 44%. Outsourcing is highest among small (64%) and medium (70%) businesses.

Cyber Essentials, the government-backed certification for basic controls, is spreading from a low base. The proportion of businesses holding it rose from 3% to 5%, driven by large firms (21% to 35%) and small firms (5% to 12%). Prompted awareness of the scheme stands at 17%, though 24% of businesses say they have controls in all five of its technical areas. Board-level responsibility for cybersecurity rose from 27% to 31% of businesses, reversing a decline earlier in the decade.

Supply chains are where the pressure on smaller firms is likely to come from. Only 15% of businesses review the cyber risks posed by their immediate suppliers, rising to 48% of large firms. But 41% of large businesses now require suppliers to hold a security standard or accreditation, up from 21%, and 26% require Cyber Essentials specifically, up from 10%. For a small supplier to a large customer, certification is increasingly becoming a condition of trade.

Why AI raises the stakes

The survey landed two weeks after an open letter to business leaders from Liz Kendall, the science, innovation and technology secretary, and Dan Jarvis, the security minister. Dated 15 April, it says the AI Security Institute assesses that frontier model capabilities are now doubling every four months, compared with every eight months previously. The letter argues that “the steps organisations should take to protect against AI-driven cyber threats are the same cyber hygiene measures recommended for traditional cyber threats.” It points smaller businesses to the National Cyber Security Centre’s (NCSC) Cyber Action Toolkit and notes that free cyber insurance is available to small organizations that obtain Cyber Essentials.

The NCSC made a similar point around its CYBERUK conference in Glasgow. In a release on 21 April, the NCSC said its chief executive, Dr Richard Horne, would warn in a speech there the next day that “frontier AI is rapidly enabling discovery and exploitation of existing vulnerabilities at scale, illustrating how quickly it will expose where fundamentals of cyber security are still to be addressed.” The release also said Horne would describe the number of incidents the NCSC handles as “fairly steady”.

The NCSC’s other CYBERUK announcement speaks directly to the phishing problem. On 23 April it said it no longer recommends that individuals use passwords where passkeys are available, and that businesses should offer passkeys to consumers as the default, citing a technical report that found passkeys at least as secure as the strongest password paired with two-step verification. The survey shows that only 47% of businesses require two-factor authentication at all. AI is also arriving inside the organizations being attacked: 31% of businesses are using, adopting or considering AI, and only around a quarter of those (24%) have cybersecurity practices to manage its risks.

What to do now

If attackers can find and exploit weaknesses faster, the gap the survey describes between firms that plan and firms that react is likely to widen. Small businesses that let risk assessments and continuity plans lapse are likely to be the most exposed.

The priorities follow from the data. Write and rehearse an incident response plan, since three-quarters of businesses have none. Move staff and administrator accounts to phishing-resistant sign-in, using passkeys where services support them and two-factor authentication everywhere else. Firms that sell to larger organizations should get Cyber Essentials before a customer asks for it. Medium-sized firms should restore regular reporting to senior management: the proportion whose senior managers are updated on cyber at least once a year fell from 78% to 70%. None of this is new advice. What has changed is how long organizations can afford to ignore it.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, official statistics, 30 April 2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
  2. DSIT and Cabinet Office, “AI cyber threats: open letter to business leaders”, 15 April 2026. https://www.gov.uk/government/publications/ai-cyber-threats-open-letter-to-business-leaders/ai-cyber-threats-open-letter-to-business-leaders-html
  3. NCSC, “Cyber chief: UK faces ‘perfect storm’ for cyber security”, news release, 21 April 2026. https://www.ncsc.gov.uk/news/cyber-chief-uk-faces-perfect-storm-for-cyber-security
  4. NCSC, “NCSC: Leave passwords in the past – passkeys are the future”, news release, 23 April 2026. https://www.ncsc.gov.uk/news/ncsc-leave-passwords-in-the-past-passkeys-are-the-future
About the author

Editor

The VETTDD editorial desk. Interviews, analysis, columns and news on the decisions shaping UK B2B technology.

More from Editor →