← All articles
EXPLAINED

Half of UK SMEs were breached last year

Two major 2026 surveys agree: around half of UK small businesses had a cyber incident. The causes are ordinary, and fixable.

Sophia, HackRisk's AI security analyst, in a UK bakery showing the owner her HackRisk tablet, with the headline 'Half of UK SMEs were breached last year'

If you run a small or medium-sized business in the UK, there's roughly a coin-flip chance you had a cyber incident in the last year. That's not a scare headline. It's what two separate pieces of research published in 2026 found, and the reasons behind it are surprisingly ordinary.

The numbers

In September, ESET published a survey of 500 UK businesses with between 25 and 1,000 devices. 49% had experienced a cyber incident in the previous 12 months, and 13% of those had been hit more than once. On average, it took just over four weeks to identify and recover from each incident.

The government's own Cyber Security Breaches Survey 2025/26, published in April, puts the figure for all UK businesses at 43%, or around 612,000 businesses. The rate climbs with size: 42% of micro businesses, 46% of small businesses and 65% of medium-sized businesses reported a breach or attack.

The two surveys ask slightly different questions of slightly different businesses, but they point the same way. Being small doesn't keep you out of the numbers.

What actually got them

The most useful part of ESET's research is what caused the incidents. None of it involves Hollywood-style hacking.

Phishing: 27%

A convincing email, text or call that gets someone to click a link, hand over a password or approve a payment. The government survey found phishing affected 38% of businesses and was behind 69% of the breaches that actually disrupted them.

Unpatched vulnerabilities: 23%

Software with a known, published flaw that hadn't been updated. Websites, VPNs, firewalls and plugins are the usual culprits, because they face the internet and attackers scan for them constantly.

Weak passwords: 20%

Reused, guessable or already-leaked passwords, often on accounts without multi-factor authentication. Once a password has appeared in a breach elsewhere, attackers will try it everywhere.

Nobody watching: 20%

Insufficient monitoring meant problems weren't spotted until the damage was done. That's a big part of why recovery took a month.

Why four weeks hurts

For a large company, a month of disruption is painful. For a 20-person firm, it can mean missed invoices, lost customers and staff sitting idle. The cost of an incident isn't just the fix. It's everything that doesn't happen while you're fixing it.

The basics are known, but most businesses haven't done them

Cyber Essentials, the government-backed scheme for basic security controls, directly covers two of those four causes: keeping software updated and locking down passwords and accounts. Yet the government survey found only 17% of businesses had even heard of it, and just 5% hold the certification. The gap between knowing what to do and doing it is where most of these incidents happen.

What to do this week

Turn on multi-factor authentication for email, banking, cloud storage and any admin accounts. It stops most password attacks on its own.

Update anything that faces the internet. Your website, firewall, VPN and remote access tools come first. Switch on automatic updates wherever you can.

Check whether your passwords have already leaked. If staff work email addresses show up in known breaches, change those passwords now.

Test your team, don't just tell them. A short, realistic phishing test shows you who would click, so you can help them before a criminal finds out.

Decide who gets the alert. Make sure someone is responsible for spotting problems, and knows what to do when they do.

Sophia Says

“What strikes me about these numbers is how preventable they are. Half of UK businesses breached sounds overwhelming, but when you look at the causes, it's a phishing email, a missed update, a reused password and nobody watching. None of those need a big budget to fix. They need someone paying attention.”
“That's exactly what I do at HackRisk. I look at your business from the outside, the way an attacker would, and tell you in plain English what I've found and what to fix first. Not a 90-page report, just the three or four things that would have kept you out of these statistics.”
— Sophia, HackRisk AI Security Analyst

Where HackRisk fits

Each of the four causes has a HackRisk check against it:

Phishing: Phishing Simulations and Security Awareness Training show you who's likely to be caught out and help them spot the next one.

Unpatched vulnerabilities: Vulnerability Scan finds known weaknesses in your internet-facing systems, and Recon Scan finds the forgotten ones you didn't know you had.

Weak passwords: Dark Web Scan tells you when your business's email addresses and passwords turn up in leaked data.

Nobody watching: HackRisk monitors continuously, so you hear about problems in days, not after a month of disruption. It also helps you work towards Cyber Essentials, so the basics are covered and certified.

Find out if you're in the half

Get your free HackRisk report to see what an attacker can see about your business today. No installation, no card details.

Sources

ESET: UK SMBs still vulnerable to basic cyberattacks (September 2026)

GOV.UK: Cyber Security Breaches Survey 2025/2026 (April 2026)