UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber Security

UK SME Cyber Attacks 2026: The Real Frequency & Cost

Servnet Editorial · IT infrastructure analysis7 min read
Share

National headlines say 43% of UK businesses were breached or attacked in the last 12 months, an estimated 612,000 organisations — but that average hides a sharper mid-market story. Government survey data shows medium-sized firms are hit far more often than micro businesses, while phishing remains the entry point in the overwhelming majority of cases. This data study pulls together the 2025/2026 Cyber Security Breaches Survey, AMVIA's SME-specific research and secondary analysis to answer the question national statistics avoid: how often is a business your size actually attacked, by what, and what does it really cost when the invoice lands? See our cyber security services for how these findings translate into practical controls.

UK breach or attack rate by business size (2025/2026 survey)
70%53%35%18%0%42%Micro46%Small65%Medium69%LargeBreach or attack rate
View the data behind this chart
UK breach or attack rate by business size (2025/2026 survey)
MicroSmallMediumLarge
Breach or attack rate%42%46%65%69

The Stark Reality: UK SME Cyber Attacks in 2026

The Cyber Security Breaches Survey 2025/2026, published by GOV.UK on 30 April 2026, found that 43% of UK businesses experienced a breach or attack in the previous 12 months — an estimated 612,000 businesses nationally. Phishing was the single most common attack type, affecting 38% of businesses, and among organisations that had been breached, phishing was rated the most disruptive incident type in 69% of cases.

But the 43% figure is an average across every business size, and averages flatten exactly the picture SMEs need. Segment data from the same survey period shows 65% of medium businesses and 69% of large businesses reported a breach or attack, compared with 46% of small businesses and 42% of micro businesses. In other words, a 20-person firm sits in a materially lower-reported-incidence band than a 150-person firm — but as AMVIA's dedicated SME research shows below, 'lower incidence' does not mean 'low risk'.

Illustration: UK SME Cyber Attacks 2026: The Real Frequency & Cost

Why Mid-Market Firms Are Different From the National Average

A common misconception is that cyber criminals only chase large enterprises with deep pockets. The segment data complicates that: medium businesses (65%) and large businesses (69%) report breaches at rates well above small (46%) and micro (42%) firms in the 2025/2026 survey. That gap likely reflects a mix of factors — larger attack surfaces, more employees clicking more emails, and better detection capability meaning more incidents get noticed and counted in the first place.

Separately, AMVIA's 2026 research into 1,200 UK businesses with 10 to 250 employees — a band spanning small through medium — found two-thirds were hit in 2025. That is a materially higher incidence than the government's small-business figure (46%), a reminder that survey methodology and sample composition change what 'typical' looks like. For a UK SME owner, the safest planning assumption is that incidence rises with headcount and complexity, not that smaller means safer.

The Threats Actually Hitting UK SMEs in 2026

Phishing dominates. It affected 38% of UK businesses in the 2025/2026 survey, was rated the most disruptive attack type in 69% of breached organisations, and 51% of businesses that experienced any breach or attack reported phishing as the only type involved — meaning for over half of affected firms, a single phishing incident was the entire story. If you fund one control category first, email and identity should be it; see what is ransomware for how phishing typically leads into more serious follow-on attacks.

Ransomware, by contrast, continued its decline: 1% of businesses reported ransomware in the 2025/2026 survey, down from 3% in both 2024/2025 and 2023/2024. That does not mean ransomware risk has disappeared for SMEs — a single ransomware event remains far more disruptive than a typical phishing attempt — but it does mean phishing, not ransomware, is the volume problem UK SMEs face day to day. For firms wanting to understand how ransomware tactics have shifted even as headline incidence falls, our analysis of ransomware attack trends and dedicated ransomware protection strategies covers the specifics.

Beyond the Numbers: What an Attack Actually Costs a UK SME

Cost data in this space is genuinely inconsistent, and it matters to keep the different measures separate rather than blend them. The government survey's median perceived cost of cyber-facilitated fraud across all businesses was just £500, with most reported costs falling between £150 and £5,000 — a fraud-specific figure, not a whole-breach cost. Separately, the median perceived cost of the most disruptive breach or attack overall was £0, rising to only £30 for medium and large businesses specifically, according to secondary analysis of the same survey coverage — a reflection of how many incidents are low-impact phishing attempts that get caught before real damage occurs.

AMVIA's SME-specific research tells a different story because it measures a different thing: an average breach cost of £6,400 across its 1,200-business, 10-250 employee sample, built from downtime, recovery work, regulatory costs and customer churn combined — not just the direct fraud loss. Worked through for a typical 20-person UK SME: a successful phishing attack compromises one mailbox, IT support spends days on containment and password resets, the business loses productive hours across the team while systems are checked, a handful of customers ask questions about data safety, and — in a minority of cases — there's a regulatory notification cost on top. That combination is what AMVIA's £6,400 average is measuring, and it is why the government's £500 median fraud figure and AMVIA's £6,400 average breach figure are not contradictory — they are measuring different scopes of cost. Separately, the survey found the proportion of businesses reporting a loss of revenue or share value after a breach rose from 2% to 5% year on year, and reputational damage reports rose from 1% to 3% — both still minority outcomes, but both growing. Use our calculate downtime costs tool to model what an equivalent outage would mean for your own headcount and revenue.

Your 2026 Cyber Security Checklist: 7 Steps That Matter Most

Given that phishing accounts for the majority of disruptive incidents, the highest-return controls for a UK SME cluster around email, identity and recovery — not exotic technology. The following order reflects where the data above points first.

  • Multi-factor authentication on every email account, remote access tool and admin login — the single control most likely to stop a phishing credential theft turning into a full account takeover.
  • Email security filtering with DMARC, DKIM and SPF properly configured, plus link and attachment sandboxing, to reduce the 38% phishing exposure rate before it reaches an inbox.
  • Regular, tested, offline backups so that even if an attacker gets in, recovery does not depend on paying anyone or rebuilding from nothing.
  • Ongoing staff phishing awareness with simulated test emails, refreshed at least quarterly — since 51% of breached businesses reported phishing as the only attack type involved, staff vigilance is doing most of the defensive work.
  • A patch and vulnerability management routine so known software flaws are closed before they become the entry point.
  • Managed detection & response cover for out-of-hours monitoring, since most SMEs lack a 24/7 internal security team; see managed detection & response for what this typically covers.
  • Cyber Essentials certification as a baseline framework that forces the above controls into a documented, auditable state — increasingly expected by insurers, customers and public-sector procurement; see UK Cyber Essentials certification.
UK businesses reporting ransomware by survey year
322102023/20242024/20252025/2026Survey yearBusinesses reporting…Ransomware incidence
View the data behind this chart
UK businesses reporting ransomware by survey year
Businesses reporting…2023/20242024/20252025/2026
Ransomware incidence331

Building Resilience: A Simple Incident Response Plan Template

Most UK SMEs do not need a lengthy incident response document; they need a one-page plan that survives contact with a real, stressful morning. Fill in the blanks below with your own details and keep a printed copy — not just a digital one, since a ransomware or account compromise may take down the system where it's stored.

Who declares an incident: [named role/person] and their deputy [named role/person]. First actions within 1 hour: isolate the affected device or account, change the affected passwords, notify [IT provider/internal lead]. Who to call: internal IT contact, external IT/security provider, cyber insurance provider, and — where personal data may be involved — your Data Protection Officer or equivalent. Communication plan: who tells staff, who tells affected customers, and who is authorised to speak to the press. Recovery checklist: restore from the last verified clean backup, confirm the entry point has been closed, and run a short lessons-learned review within two weeks. Keeping this plan simple, printed and rehearsed at least once a year matters more than making it comprehensive.

Looking Ahead: AI Threats, Regulation and Insurance

Two forces are reshaping how UK SMEs need to think about cyber risk in 2026. First, the attack techniques behind that 38% phishing figure are evolving as attackers use more convincing, faster-to-produce lures — which is exactly why static, once-a-year staff training is no longer sufficient on its own, and why layered controls (MFA plus email filtering plus ongoing simulated testing, not any single measure) matter more than ever. A zero trust approach — verifying every access request rather than trusting anything inside the network by default — gives SMEs a structural defence that does not depend entirely on staff spotting a well-crafted fake email every time.

Second, UK data protection and incident-reporting expectations continue to shape what 'good enough' security looks like for SMEs, particularly around how quickly a breach involving personal data must be assessed and, where required, reported. Combined with insurers increasingly asking for evidence of MFA, backups and a documented incident response plan before offering cover, the practical effect for SMEs is the same: the controls in the checklist above are no longer optional extras but the baseline expected by regulators, insurers and customers alike.

Conclusion: Taking Control of Your SME's Cyber Future

The 2026 data is clear on three points: phishing is the dominant threat by volume and disruption, medium-sized firms report materially higher breach rates than small and micro firms, and the true cost of an incident depends heavily on what you count — a £500 median fraud figure and a £6,400 average SME breach cost are both correct, for different scopes. For a UK SME, the practical response is not to chase every emerging threat but to lock down the handful of controls proven to stop the majority of real-world incidents, and to have a simple response plan ready before, not after, the first suspicious email lands.

Sources

Every figure in this article traces to the sources below.

  • GOV.UK — Cyber Security Breaches Survey 2025/2026 (breach incidence, phishing prevalence, fraud costs)
  • AMVIA — UK SME Cybersecurity Report 2026 (SME breach incidence and average breach cost)
  • Blackswan Cyber — analysis of Cyber Security Breaches Survey 2025/2026 by business size
  • The Small Business Cyber Security Guy — reaction to DSIT breaches survey 2025/2026
Why UK cyber attack cost figures differ by scope
Cost MeasureValueWhat It CoversMedian cyber fraud…Median cyber fraud cost£500Fraud losses onlyFraud cost typical…Fraud cost typical range£150-£5,00025th-75th percentileAMVIA average breach…AMVIA average breach cost£6,400Downtime, recovery…Median disruptive…Median disruptive breach…£0Most disruptive incident…Median disruptive…Median disruptive breach…£30Most disruptive incident…
View the data behind this chart
Why UK cyber attack cost figures differ by scope
Cost MeasureValueWhat It Covers
Median cyber fraud…Median cyber fraud cost£500Fraud losses only
Fraud cost typical…Fraud cost typical range£150-£5,00025th-75th percentile
AMVIA average breach…AMVIA average breach cost£6,400Downtime, recovery…
Median disruptive…Median disruptive breach…£0Most disruptive incident…
Median disruptive…Median disruptive breach…£30Most disruptive incident…
Open data

The 10 verified data points behind this study are free to download and reuse with attribution (CC BY 4.0).

Cite as: Servnet Research, “UK SME Cyber Attacks 2026: The Real Frequency & Cost”, servnetuk.com, 2026.

Share
Key takeaways
  • 43% of UK businesses reported a breach or attack in the 2025/2026 survey period, an estimated 612,000 businesses — but medium (65%) and large (69%) firms report far higher rates than small (46%) and micro (42%) firms.
  • Phishing affected 38% of UK businesses and was the most disruptive attack type in 69% of breached organisations; 51% of breached businesses faced phishing alone.
  • Ransomware incidence fell to 1% in 2025/2026, down from 3% in the two prior survey years — a volume decline, not a severity signal.
  • Cost figures vary by definition: £500 median for cyber-facilitated fraud specifically, versus AMVIA's £6,400 average SME breach cost including downtime, recovery, regulatory costs and churn.
  • Revenue/share-value loss reporting rose from 2% to 5% year on year, and reputational damage reporting rose from 1% to 3% — both still minority outcomes but trending upward.
  • MFA, email filtering, tested backups, staff phishing simulation, patching, managed monitoring and Cyber Essentials certification form the highest-return control set for UK SMEs in 2026.
Frequently asked

FAQs — UK SME Cyber Attacks 2026

What percentage of UK SMEs experienced a cyber attack in 2026?

The government's 2025/2026 survey found 43% of UK businesses overall had a breach or attack, but this varies sharply by size: 46% of small and 42% of micro businesses, versus 65% of medium and 69% of large firms. AMVIA's SME-specific research (10-250 employees) found two-thirds were hit in 2025.

What is the most common way UK SMEs get attacked?

Phishing, by a clear margin. It affected 38% of UK businesses, was rated the most disruptive attack type in 69% of breached organisations, and was the only attack type reported by 51% of affected businesses — making email and identity controls the priority investment.

How much does a cyber attack cost a UK SME?

It depends what's counted. The government survey found a £500 median cost for cyber-facilitated fraud specifically (typically £150-£5,000). AMVIA's separate SME research found a £6,400 average breach cost across downtime, recovery, regulatory costs and customer churn combined.

Are medium-sized businesses more at risk than small businesses in the UK?

Reported incidence is higher: 65% of medium businesses and 69% of large businesses reported a breach or attack in 2025/2026, compared with 46% of small and 42% of micro businesses. This likely reflects larger attack surfaces and better detection, not necessarily lower actual risk for smaller firms.

Is ransomware still a major threat to UK SMEs?

Reported incidence has fallen to 1% of UK businesses in 2025/2026, down from 3% in the previous two survey years. It remains far more disruptive per incident than phishing, but by volume, phishing is now the dominant day-to-day threat for UK SMEs.

Should a UK SME get Cyber Essentials certified?

Given phishing drives most disruptive incidents and insurers increasingly expect documented baseline controls, Cyber Essentials certification is a practical, low-cost way for SMEs to formalise MFA, patching and access controls into an auditable framework.

Related

Continue reading

More in Research

Got a question this study didn't answer?

One conversation with an engineer who's done this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111