Enquire ↓

Business resilience

How Cyber Secure Is Your Small Business? Compare It With the 2026 UK Benchmark

UK government research found that 43% of businesses identified a cyber breach or attack in the previous 12 months. This scorecard turns the national statistics into a practical owner check.

Oct 6, 2026•10 min read

Cyber security can feel like an IT department problem until a small business loses access to email, files, customer data or an online account. The UK government's Cyber Security Breaches Survey 2025/2026 makes the scale of the issue difficult to dismiss.

Across the businesses surveyed, 43% said they had identified some kind of cyber security breach or attack in the previous 12 months. The figure was 42% among micro businesses and 46% among small businesses. The survey estimates that this equates to roughly 612,000 UK businesses identifying a breach or attack.

Phishing remained the most common type, reported by 38% of businesses overall. That matters for owner managed companies because the weak point is often not the website code itself. It is an email, reused password, compromised account or convincing impersonation attempt.

Compare your business with the national controls

The same survey asked businesses about basic security controls. 81% reported up-to-date malware protection, 74% secure cloud backups, 74% password policies, 74% network firewalls and 73% restricted admin rights. Only 47% required two-factor authentication.

Those figures give an owner a useful benchmark. They do not certify any individual business as secure, but they show which basic controls are common and where adoption is still weaker.

The seven point owner scorecard

Give yourself one point for each control you can verify today, not each one you assume somebody else has handled.

1. Important accounts use two-factor authentication, especially email, domain registrar, website administration and cloud storage.

2. Business data is backed up and somebody has checked that the backup can actually be restored.

3. Devices and software receive security updates rather than relying on staff to remember them indefinitely.

4. Administrator access is limited to people who genuinely need it.

5. Important passwords are unique and managed properly rather than reused across business systems.

6. The business knows who to contact if email, website, domain or cloud accounts are compromised.

7. There is a basic continuity plan for how the business would operate if a critical system became unavailable.

0 to 2 means the business is relying heavily on luck and informal habits. 3 to 5 means some useful controls exist but gaps remain. 6 to 7 means the basics are being treated as an operating responsibility rather than an afterthought.

Small businesses are not too small to be targeted

The survey found that 17% of micro businesses and 24% of small businesses experienced at least one cyber crime in the previous year. Smaller firms may also have less sophisticated monitoring, which means some incidents may never be identified.

The practical lesson is not to become paranoid. It is to stop assuming that cyber risk begins only when a company becomes large.

Recovery planning is still weak

Only 25% of businesses overall had a formal incident response plan. Among small businesses, 44% had a business continuity plan covering cyber security, down from 53% the previous year.

That creates a simple question for an owner: if the website, email or cloud files were unavailable tomorrow morning, who would do what first? If nobody knows, the recovery plan is being invented during the incident.

The website is only one account in the chain

Business owners sometimes focus on website security while overlooking the domain registrar, email account, cloud storage or social profiles that can be equally important. A stolen email account can be used to reset other passwords. A compromised domain account can affect where the website or email points.

Professional website management should therefore include clear responsibility for technical maintenance while leaving the business in control of the accounts and assets it appropriately owns.

Start with the boring controls

The National Cyber Security Centre's small organisation guidance emphasises practical basics such as backups and two-step verification. These controls are not exciting, but that is exactly why they are easy to neglect.

For a small business, resilience usually improves through a series of ordinary decisions: update the software, protect the accounts, back up the data, restrict unnecessary access and know who is responsible when something fails.

That is a better standard than assuming the website company, Microsoft, Google or somebody in the office has probably taken care of it.

Sources and method

These sources support the factual claims and benchmarks used above. Where a study is vendor produced, its sample and stated limitations are treated as part of the finding rather than as a national estimate.