Cyber Security Breaches Survey 2025 Reveals Key Risks and Lessons for UK Organisations

The Department for Science, Innovation & Technology (DSIT) has released its much-anticipated Cyber Security Breaches Survey 2025. Serving as the UK’s annual benchmark for digital resilience, the survey examines the cybersecurity landscape across businesses and charities, offering vital insights into preparedness, attack trends, cost implications, and key actions to improve security posture.

 

Key Findings from the 2025 Survey

1. Prevalence of Cyber Attacks Remains High

Over the past 12 months, 43% of UK businesses and 30% of charities experienced a cybersecurity breach or attack. That translates to approximately 612,000 businesses and 61,000 charities facing some form of digital disruption annually. Phishing remains the most common and disruptive attack, cited by 85% of affected businesses and 86% of charities. Increasingly, these attacks are being fuelled by sophisticated tools such as AI impersonation.

2. Cyber Hygiene is Improving Among Small Businesses

Compared to 2024, small businesses have made encouraging progress:

  • 48% now conduct cyber risk assessments (up from 41%)
  • 62% have cyber insurance (up from 49%)
  • 59% maintain formal cyber policies (up from 51%)
  • 53% include cybersecurity in business continuity plans (up from 44%)

However, some larger charities are slipping backwards. For instance, fewer are identifying risks or reviewing supplier vulnerabilities than in previous years.

3. Risk Management Practices Still Need Strengthening

While progress has been made, gaps remain:

  • Only 14% of businesses and 9% of charities review risks from immediate suppliers
  • Just 7% of businesses and 4% of charities assess the wider supply chain
  • Only 21% of organisations consider cybersecurity a high priority when buying new software

This highlights a significant opportunity to embed cyber risk assessment into procurement and supply chain processes.

4. Governance and Board Involvement is Declining

Despite cyber threats becoming more complex, only 27% of businesses report having a board member responsible for cybersecurity — a drop from 38% in 2021. This points to a worrying lack of top-level engagement, particularly among smaller businesses. In contrast, 96% of large businesses say cybersecurity is a board-level priority.

5. Disruption and Costs are on the Rise

More organisations are now reporting service disruptions as a direct result of cyber incidents:

  • 7% of businesses temporarily lost access to files or networks (up from 4%)
  • 5% of charities lost access to third-party services (up from 1%)

The average cost of a breach has also risen:

  • £1,600 for the most disruptive business breaches
  • £3,550 average cost for businesses with financial losses
  • £8,690 average cost for charities with losses

For sectors like health and social care, where service disruption can have critical consequences, these numbers highlight the importance of a solid incident response strategy.

6. Incident Response Planning is More Common in Health and Care Sectors

Encouragingly, 66% of health and social care organisations have incident response plans in place. This compares favourably to just 23% of businesses overall, indicating that some sectors are leading the way in preparedness.

 

What This Means for Your Organisation

The survey reinforces the message that cybersecurity is no longer a “nice-to-have”  it’s essential. As threats evolve, so must your defences. Here are some practical steps based on the DSIT findings:

  • Train Your Team: Human error remains a major vulnerability. Regular phishing simulations and staff training are vital.
  • Review Your Policies: Ensure you have formalised cyber risk management plans and policies in place.
  • Assess Your Supply Chain: Don’t overlook third-party risk. Evaluate your suppliers’ cybersecurity standards.
  • Upgrade Technical Defences: Adopt advanced tools like multi-factor authentication, endpoint detection, and secure VPNs.
  • Insure Against Risk: Consider a dedicated cyber insurance policy, not just one bundled within broader business cover.

 

Final Thoughts

The Cyber Security Breaches Survey 2025 serves as a timely reminder: cyber resilience requires constant attention. While progress is being made especially among smaller businesses the threat landscape continues to evolve. Proactive planning, education, and investment in the right tools are all critical.

Our cybersecurity specialists can help you assess where your organisation stands today and what steps you need to take next.

Contact the experts at Kalamazoo IT today for a free cybersecurity audit and start strengthening your defences.