GCS Insights
UK Threat Landscape

Half of UK Businesses Had a Breach Last Year. Most Still Don't Know Why.

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
February 2026 · 4 min read

The DSIT Cyber Security Breaches Survey 2025 is out. The headline number is 50% of UK businesses reported a breach or attack in the last 12 months. For large enterprises, that rises to 74%.

Most people see that number and nod. They've seen versions of it before. What most organisations don't do is read it properly, past the headline, into what it's actually telling you about where the failure is.

50%
of UK businesses reported a breach in 12 months
74%
of breaches involved a human element
85%
of cases, phishing was the entry point
£20M
ICO maximum fine per governance failure

The Number That Should Be in Every Board Pack

74% of breaches involved a human element. Not a zero-day exploit. Not an advanced persistent threat. A process failure, a misconfiguration, a phishing email that should have been caught.

That number matters because it shifts the diagnosis. Most organisations, when they think about security investment, think about technology. New tools, new platforms, better detection. But if three in four breaches come from human failure, the gap isn't in your tooling. It's in your architecture: the people, processes, and governance that sit around the tools.

"The ICO fine on British Airways was £20 million, for a single governance failure. In most organisations I speak to, that number still hasn't made it into board discussions."

What the Breach Data Is Actually Telling You

Phishing remains the entry point in 85% of cases. Ransomware incidents doubled in 2025. The average cost of cyber-facilitated fraud per incident is £10,000, before downtime, reputational damage, and the regulatory conversations that follow.

The problem isn't a lack of awareness. Most leadership teams know they're exposed. The gap is between knowing and acting, and specifically, between acting and acting in a structured, deliberate way that produces a security posture that holds up under pressure.

Why Most Responses Miss the Point

The typical response to breach data is to buy something. A new endpoint product. A security awareness training platform. An additional monitoring layer. These aren't bad decisions in isolation. But without an architecture connecting them, and without people with the ownership and authority to make the architecture function day to day, they're expensive additions to a broken system.

The organisations that come through this period well are those that stopped treating security as a compliance exercise and started treating it as an operational priority. That means the right framework, the right people, and the governance to back both up. All three. In that order.

Is your security posture defensible?

A no-obligation conversation about where your organisation sits against the current threat landscape, and what to prioritise.

Start the Conversation →
Subscribe to GCS Insights

Sources: DSIT Cyber Security Breaches Survey 2025 · ICO Enforcement Register · IBM Cost of a Data Breach Report 2024

#UKCyber#CyberRisk#InfoSec#GDPR#NIS2#DataProtection