National headlines say 43% of UK businesses were breached or attacked in the last 12 months, an estimated 612,000 organisations — but that average hides a sharper mid-market story. Government survey data shows medium-sized firms are hit far more often than micro businesses, while phishing remains the entry point in the overwhelming majority of cases. This data study pulls together the 2025/2026 Cyber Security Breaches Survey, AMVIA's SME-specific research and secondary analysis to answer the question national statistics avoid: how often is a business your size actually attacked, by what, and what does it really cost when the invoice lands? See our cyber security services for how these findings translate into practical controls.
View the data behind this chart
| Micro | Small | Medium | Large | |
|---|---|---|---|---|
| Breach or attack rate | %42 | %46 | %65 | %69 |
The Stark Reality: UK SME Cyber Attacks in 2026
The Cyber Security Breaches Survey 2025/2026, published by GOV.UK on 30 April 2026, found that 43% of UK businesses experienced a breach or attack in the previous 12 months — an estimated 612,000 businesses nationally. Phishing was the single most common attack type, affecting 38% of businesses, and among organisations that had been breached, phishing was rated the most disruptive incident type in 69% of cases.
But the 43% figure is an average across every business size, and averages flatten exactly the picture SMEs need. Segment data from the same survey period shows 65% of medium businesses and 69% of large businesses reported a breach or attack, compared with 46% of small businesses and 42% of micro businesses. In other words, a 20-person firm sits in a materially lower-reported-incidence band than a 150-person firm — but as AMVIA's dedicated SME research shows below, 'lower incidence' does not mean 'low risk'.

Why Mid-Market Firms Are Different From the National Average
A common misconception is that cyber criminals only chase large enterprises with deep pockets. The segment data complicates that: medium businesses (65%) and large businesses (69%) report breaches at rates well above small (46%) and micro (42%) firms in the 2025/2026 survey. That gap likely reflects a mix of factors — larger attack surfaces, more employees clicking more emails, and better detection capability meaning more incidents get noticed and counted in the first place.
Separately, AMVIA's 2026 research into 1,200 UK businesses with 10 to 250 employees — a band spanning small through medium — found two-thirds were hit in 2025. That is a materially higher incidence than the government's small-business figure (46%), a reminder that survey methodology and sample composition change what 'typical' looks like. For a UK SME owner, the safest planning assumption is that incidence rises with headcount and complexity, not that smaller means safer.
The Threats Actually Hitting UK SMEs in 2026
Phishing dominates. It affected 38% of UK businesses in the 2025/2026 survey, was rated the most disruptive attack type in 69% of breached organisations, and 51% of businesses that experienced any breach or attack reported phishing as the only type involved — meaning for over half of affected firms, a single phishing incident was the entire story. If you fund one control category first, email and identity should be it; see what is ransomware for how phishing typically leads into more serious follow-on attacks.
Ransomware, by contrast, continued its decline: 1% of businesses reported ransomware in the 2025/2026 survey, down from 3% in both 2024/2025 and 2023/2024. That does not mean ransomware risk has disappeared for SMEs — a single ransomware event remains far more disruptive than a typical phishing attempt — but it does mean phishing, not ransomware, is the volume problem UK SMEs face day to day. For firms wanting to understand how ransomware tactics have shifted even as headline incidence falls, our analysis of ransomware attack trends and dedicated ransomware protection strategies covers the specifics.
Beyond the Numbers: What an Attack Actually Costs a UK SME
Cost data in this space is genuinely inconsistent, and it matters to keep the different measures separate rather than blend them. The government survey's median perceived cost of cyber-facilitated fraud across all businesses was just £500, with most reported costs falling between £150 and £5,000 — a fraud-specific figure, not a whole-breach cost. Separately, the median perceived cost of the most disruptive breach or attack overall was £0, rising to only £30 for medium and large businesses specifically, according to secondary analysis of the same survey coverage — a reflection of how many incidents are low-impact phishing attempts that get caught before real damage occurs.
AMVIA's SME-specific research tells a different story because it measures a different thing: an average breach cost of £6,400 across its 1,200-business, 10-250 employee sample, built from downtime, recovery work, regulatory costs and customer churn combined — not just the direct fraud loss. Worked through for a typical 20-person UK SME: a successful phishing attack compromises one mailbox, IT support spends days on containment and password resets, the business loses productive hours across the team while systems are checked, a handful of customers ask questions about data safety, and — in a minority of cases — there's a regulatory notification cost on top. That combination is what AMVIA's £6,400 average is measuring, and it is why the government's £500 median fraud figure and AMVIA's £6,400 average breach figure are not contradictory — they are measuring different scopes of cost. Separately, the survey found the proportion of businesses reporting a loss of revenue or share value after a breach rose from 2% to 5% year on year, and reputational damage reports rose from 1% to 3% — both still minority outcomes, but both growing. Use our calculate downtime costs tool to model what an equivalent outage would mean for your own headcount and revenue.
Your 2026 Cyber Security Checklist: 7 Steps That Matter Most
Given that phishing accounts for the majority of disruptive incidents, the highest-return controls for a UK SME cluster around email, identity and recovery — not exotic technology. The following order reflects where the data above points first.
- •Multi-factor authentication on every email account, remote access tool and admin login — the single control most likely to stop a phishing credential theft turning into a full account takeover.
- •Email security filtering with DMARC, DKIM and SPF properly configured, plus link and attachment sandboxing, to reduce the 38% phishing exposure rate before it reaches an inbox.
- •Regular, tested, offline backups so that even if an attacker gets in, recovery does not depend on paying anyone or rebuilding from nothing.
- •Ongoing staff phishing awareness with simulated test emails, refreshed at least quarterly — since 51% of breached businesses reported phishing as the only attack type involved, staff vigilance is doing most of the defensive work.
- •A patch and vulnerability management routine so known software flaws are closed before they become the entry point.
- •Managed detection & response cover for out-of-hours monitoring, since most SMEs lack a 24/7 internal security team; see managed detection & response for what this typically covers.
- •Cyber Essentials certification as a baseline framework that forces the above controls into a documented, auditable state — increasingly expected by insurers, customers and public-sector procurement; see UK Cyber Essentials certification.
View the data behind this chart
| Businesses reporting… | 2023/2024 | 2024/2025 | 2025/2026 |
|---|---|---|---|
| Ransomware incidence | 3 | 3 | 1 |
Building Resilience: A Simple Incident Response Plan Template
Most UK SMEs do not need a lengthy incident response document; they need a one-page plan that survives contact with a real, stressful morning. Fill in the blanks below with your own details and keep a printed copy — not just a digital one, since a ransomware or account compromise may take down the system where it's stored.
Who declares an incident: [named role/person] and their deputy [named role/person]. First actions within 1 hour: isolate the affected device or account, change the affected passwords, notify [IT provider/internal lead]. Who to call: internal IT contact, external IT/security provider, cyber insurance provider, and — where personal data may be involved — your Data Protection Officer or equivalent. Communication plan: who tells staff, who tells affected customers, and who is authorised to speak to the press. Recovery checklist: restore from the last verified clean backup, confirm the entry point has been closed, and run a short lessons-learned review within two weeks. Keeping this plan simple, printed and rehearsed at least once a year matters more than making it comprehensive.
Looking Ahead: AI Threats, Regulation and Insurance
Two forces are reshaping how UK SMEs need to think about cyber risk in 2026. First, the attack techniques behind that 38% phishing figure are evolving as attackers use more convincing, faster-to-produce lures — which is exactly why static, once-a-year staff training is no longer sufficient on its own, and why layered controls (MFA plus email filtering plus ongoing simulated testing, not any single measure) matter more than ever. A zero trust approach — verifying every access request rather than trusting anything inside the network by default — gives SMEs a structural defence that does not depend entirely on staff spotting a well-crafted fake email every time.
Second, UK data protection and incident-reporting expectations continue to shape what 'good enough' security looks like for SMEs, particularly around how quickly a breach involving personal data must be assessed and, where required, reported. Combined with insurers increasingly asking for evidence of MFA, backups and a documented incident response plan before offering cover, the practical effect for SMEs is the same: the controls in the checklist above are no longer optional extras but the baseline expected by regulators, insurers and customers alike.
Conclusion: Taking Control of Your SME's Cyber Future
The 2026 data is clear on three points: phishing is the dominant threat by volume and disruption, medium-sized firms report materially higher breach rates than small and micro firms, and the true cost of an incident depends heavily on what you count — a £500 median fraud figure and a £6,400 average SME breach cost are both correct, for different scopes. For a UK SME, the practical response is not to chase every emerging threat but to lock down the handful of controls proven to stop the majority of real-world incidents, and to have a simple response plan ready before, not after, the first suspicious email lands.
Sources
Every figure in this article traces to the sources below.
- •GOV.UK — Cyber Security Breaches Survey 2025/2026 (breach incidence, phishing prevalence, fraud costs)
- •AMVIA — UK SME Cybersecurity Report 2026 (SME breach incidence and average breach cost)
- •Blackswan Cyber — analysis of Cyber Security Breaches Survey 2025/2026 by business size
- •The Small Business Cyber Security Guy — reaction to DSIT breaches survey 2025/2026
View the data behind this chart
| Cost Measure | Value | What It Covers | |
|---|---|---|---|
| Median cyber fraud… | Median cyber fraud cost | £500 | Fraud losses only |
| Fraud cost typical… | Fraud cost typical range | £150-£5,000 | 25th-75th percentile |
| AMVIA average breach… | AMVIA average breach cost | £6,400 | Downtime, recovery… |
| Median disruptive… | Median disruptive breach… | £0 | Most disruptive incident… |
| Median disruptive… | Median disruptive breach… | £30 | Most disruptive incident… |
The 10 verified data points behind this study are free to download and reuse with attribution (CC BY 4.0).
Cite as: Servnet Research, “UK SME Cyber Attacks 2026: The Real Frequency & Cost”, servnetuk.com, 2026.
