Home » UK Cyber Security Breaches Survey 2026: The Threats Hitting Small Businesses Hardest

UK Cyber Security Breaches Survey 2026: The Threats Hitting Small Businesses Hardest

What the DSIT Cyber Security Breaches Survey 2026/2027 means for UK SMEs, the threats hitting small businesses hardest, and the tools to fix them.

Hooded person at computer screens in dark room illustrating cyber security breaches survey threats to small businesses

The cyber security breaches survey is the closest thing the UK has to an official weather report for online crime, and every year it tells small business owners roughly the same uncomfortable story: the attacks are common, the basics are often missing, and the firms that get hit hardest are usually the ones that assumed they were too small to bother with. The latest edition, produced under DSIT research (the Department for Science, Innovation and Technology) alongside the Home Office, continues that annual tracking of how UK businesses and charities experience cyber attacks.

If you run a shop, a trades firm, an agency or an online store, here is the direct answer to the question the survey implicitly asks: the threats most likely to hit you are phishing emails, followed by impersonation and fraudulent payment requests, and the single biggest weakness is not fancy hacking but weak passwords, unpatched software and staff who have never been trained to spot a scam, a gap that widens once teams quietly adopt unapproved AI tools that can leak company data. The good news is that the fixes are cheap, well documented and mostly within reach of a business with no IT department at all, and affordable tools like Malwarebytes arriving on the Microsoft Store make covering the basics easier.

What the Cyber Security Breaches Survey actually is

The Cyber Security Breaches Survey is an annual official statistic. Government researchers interview thousands of UK businesses and charities about the attacks they have seen in the previous 12 months, what those attacks cost, and what defences they have in place. Because it runs every year, the value is in the trend: it shows whether small firms are getting better or worse at protecting themselves, and where the gaps sit.

For a small business owner it is worth ten minutes of your time because it is UK-specific, free, and not trying to sell you anything. It also underpins policy: the survey feeds into how the National Cyber Security Centre (NCSC) shapes its free guidance and how schemes like Cyber Essentials are promoted.

The threats hitting small businesses hardest

Year after year, the pattern for smaller organisations is consistent. Sophisticated, targeted hacking is rare against a five-person firm. Opportunistic, high-volume attacks are not.

  • Phishing. Fake emails and texts designed to trick someone into handing over a password or clicking a malicious link. This is comfortably the most common threat reported by small businesses, and it is getting more convincing as attackers use AI to write cleaner, better-targeted messages. The same tools create internal exposure too, as our guide to the hidden risk of staff using unapproved AI tools explains.
  • Impersonation and invoice fraud. A criminal poses as a supplier, a director or your bank and asks for a payment or a change of bank details. For a business that pays invoices by bank transfer, one successful attempt can cost thousands.
  • Malware and ransomware. Software that locks or steals your files, often demanding payment. Affordable protection helps here, which is why Malwarebytes arriving on the Microsoft Store matters for SME security. Less common than phishing but far more damaging when it lands. Keeping affordable antivirus such as Malwarebytes on the Microsoft Store current is a cheap defence.
  • Account takeover. Reused or weak passwords let attackers into email, cloud storage or your online banking, often quietly, and use that access to launch the frauds above.

The uncomfortable finding the survey tends to repeat is that many small firms cannot say for certain whether they have been breached at all, because they have no logging, no alerts and no one whose job it is to look. If you cannot detect a problem, you cannot report it or fix it.

Why small firms are the soft target

It is rarely because a business owner does not care. It is because cyber security competes with everything else on a busy week and loses. The survey consistently shows smaller organisations are less likely to have written policies, staff training, tested backups or an incident plan than larger ones.

There is also a supply-chain angle worth understanding. Attackers target small firms not only for what they hold but for who they connect to. A compromised supplier email account is a superb launchpad for invoice fraud against that supplier’s larger customers. This is one reason bigger clients increasingly ask their SME suppliers to prove they have basic protections in place, often by holding Cyber Essentials certification.

The defences that give you the most protection for the money

You do not need an enterprise budget. The NCSC’s own advice for small businesses focuses on a handful of controls that block the majority of common attacks. In plain English:

  • Turn on multi-factor authentication (MFA) everywhere you can, especially email and banking. This is a second check, usually a code or app tap, on top of your password. It is free and it stops most account takeovers dead.
  • Use a password manager so every account has a long, unique password nobody has to remember.
  • Keep everything updated. Turn on automatic updates for laptops, phones and software so security patches install themselves.
  • Back up your data to a separate location and test that you can actually restore it.
  • Train your people to spot a dodgy email, because your staff are both your biggest risk and your best line of defence.

On that last point, our write-up of why KnowBe4 says SMEs must protect both people and machines is worth reading, because AI now sits on both sides of the fight: it writes better phishing and it powers better filtering.

Tools an SME would actually shortlist

Naming names matters here, so you know where to look. The table below compares categories a small UK business would realistically buy, with the sort of tools worth a quote. Prices move, so treat these as indicative rather than exact, and always check current UK pricing on the vendor’s own site.

Need Tools to consider Rough UK cost Notes
Password manager Bitwarden, 1Password, NordPass Free to around £3 to £6 per user a month Bitwarden is open source with a usable free tier; 1Password is polished for teams.
Antivirus / endpoint protection Malwarebytes, Sophos, Bitdefender, ESET Around £30 to £60 per device a year Sophos is UK-founded (Abingdon) and strong for small teams; Malwarebytes is now on the Microsoft Store.
Email security / anti-phishing Egress, Mimecast Varies; typically a few pounds per user a month Egress is a UK firm focused on stopping inbound phishing and outbound data leaks.
Backup Backblaze, Acronis From around £6 per device a month Automate it and test restores; a backup you have never tested is a hope, not a plan.
Cyber Essentials help CyberSmart, plus IASME-accredited assessors Certification from around £300 to £500 plus support fees CyberSmart is a UK challenger that guides small firms through certification and monitors compliance.

The two names most owners overlook are worth a second look: Egress, a British email-security specialist, and CyberSmart, a UK company built specifically to get SMEs through Cyber Essentials without hiring a consultant. Our recent piece on Malwarebytes arriving on the Microsoft Store explains why easier distribution matters for firms with no IT team, and if you are still assembling your wider toolkit, our guide to the software every UK owner should consider in 2026 puts security in context alongside the rest.

The cost of getting it wrong

A breach is rarely just the money stolen. There is the time spent recovering, the customers you have to notify, and the possible reporting duty to the Information Commissioner’s Office if personal data is exposed. That is why cyber insurance now appears on so many renewal quotes. It is worth reading it alongside your other cover; our overview of the business insurance a UK small business must have explains where cyber sits and what it typically excludes if you have ignored basic protections.

Frequently asked questions

When is the Cyber Security Breaches Survey published?

DSIT publishes it annually, usually in the spring, on gov.uk. Each edition covers the previous 12 months, so the latest reporting reflects the experiences businesses had over the preceding year.

Does this survey apply to sole traders and micro businesses?

Yes. The research covers organisations of all sizes, and the smallest firms are precisely where the biggest gaps in basic protection tend to show. The advice scales down: even a one-person business benefits from MFA, a password manager and backups.

Do I legally have to do anything about cyber security?

You are not required to buy any specific product, but if you hold personal data you have obligations under UK data protection law to keep it secure, and you must report certain breaches to the ICO. Some larger clients and public sector contracts also require Cyber Essentials before they will work with you.

What is Cyber Essentials and is it worth it?

Cyber Essentials is a government-backed certification covering five basic technical controls. For many SMEs it is worth it both for the protection and because it opens doors with customers who insist on it. Providers like CyberSmart and IASME-accredited assessors can guide you through it.

Will AI make phishing worse for small businesses?

It already is making scam messages cleaner and more targeted, which is why staff training and technical filters both matter more than before. The flip side is that AI is also improving the tools that catch these attacks.

What to do next

  • Turn on multi-factor authentication today for your email and online banking. It is free and it is the single highest-impact step you can take this week.
  • Roll out a password manager such as Bitwarden, 1Password or NordPass across everyone in the business, and get rid of reused passwords.
  • Set up and test one backup. Choose a tool like Backblaze or Acronis, automate it, then actually restore a file to prove it works.
  • Book Cyber Essentials through a provider like CyberSmart if you sell to larger clients or the public sector, and read the latest survey on gov.uk to see where your gaps line up with the national picture.