Key Insights
The most significant IT security threats facing UK organisations in 2026 are:
- Unpatched software vulnerabilities,
- AI assisted phishing and social engineering,
- Ransomware and data extortion,
- Third party and supply chain compromise,
- Stolen credentials,
- And the rapid spread of unsanctioned "shadow AI" tools.
- Government figures show 43% of UK businesses identified a cyber breach or attack in the last 12 months, and phishing remains the single most common and most disruptive attack type.
- Most successful attacks still exploit basic gaps: missing multi factor authentication, slow patching, unreviewed suppliers and untrained staff.
Key statistics at a glance
| Metric | Figure | Source |
|---|---|---|
| UK businesses identifying a breach or attack (12 months) | 43%, roughly 612,000 organisations | DSIT Cyber Security Breaches Survey 2025/2026 |
| UK businesses hit by phishing | 38% | DSIT CSBS 2025/2026 |
| Estimated cyber crimes against UK businesses | 5.19 million in 12 months | DSIT CSBS 2025/2026 |
| Nationally significant UK cyber incidents | 204 in the year to August 2025, up from 89 | NCSC Annual Review 2025 |
| Top global initial access route | Vulnerability exploitation, 31% of breaches | Verizon DBIR 2026 |
| Global average cost of a data breach | $4.99 million, a record and up 12% | IBM Cost of a Data Breach 2026 |
| UK businesses with a formal incident response plan | 25% | DSIT CSBS 2025/2026 |
| UK businesses reviewing supplier cyber risk | 15% | DSIT CSBS 2025/2026 |
What are IT security threats?
IT security threats are any circumstance or actor with the potential to compromise the confidentiality, integrity or availability of your systems and data. In plain terms, they are the things that can steal your information, stop your business operating, or quietly sit inside your network until it suits an attacker to act.
It helps to separate three related ideas that often get blurred together:
- A threat is the potential source of harm, such as a ransomware group, a careless supplier or a disgruntled employee.
- A vulnerability is the weakness the threat exploits, such as an unpatched server, a reused password or an absent approval process for payments.
- A cyber incident is what happens when the two meet, whether or not data is actually lost.
Traditional threats to computer security fell into neat categories: viruses, worms, trojans, spyware and denial of service. Those still exist, but they no longer describe the real risk picture. Modern attacks are commercial operations. They target identity, trust and business process far more often than they target the technology itself. An attacker who convinces your IT service desk to reset a password has bypassed every firewall you own.
That shift matters for how you defend. Buying more tools rarely closes the gap. Fixing process, identity and patching almost always does.
The state of cyber incidents in the UK right now
The UK government's Cyber Security Breaches Survey 2025/2026, published on 30 April 2026 by DSIT and the Home Office, surveyed 2,112 businesses and 1,085 charities. Its headline findings:
- 43% of businesses and 28% of charities identified a breach or attack in the previous 12 months, equating to around 612,000 businesses and 57,000 charities.
- Exposure rises sharply with size: 42% of micro businesses and 46% of small businesses, against 65% of medium and 69% of large businesses.
- Phishing was experienced by 38% of businesses and was named the most disruptive attack type by 69% of those affected.
- Reported ransomware fell to 1% of businesses, down from 3% in each of the two previous years.
- Businesses reporting a loss of revenue or share value rose from 2% to 5%, and reputational damage rose from 1% to 3%.
- An estimated 5.19 million cyber crimes were committed against UK businesses over the year.
Two things stand out. First, headline breach volumes have plateaued while the consequences have got worse. Fewer organisations are reporting nothing more than nuisance, and more are reporting genuine commercial harm.
Second, preparedness is not keeping pace. Only 25% of businesses hold a formal incident response plan, 47% use any form of two factor authentication, 34% have a policy to apply security updates within 14 days, and just 15% formally review the cyber risk posed by their immediate suppliers. Small businesses actually went backwards this year, with risk assessments falling from 48% to 41% and cyber inclusive business continuity plans falling from 53% to 44%.
At the national level, the NCSC Annual Review 2025 recorded 429 incidents requiring direct support from 1,727 reports. Of those, 204 were classed as nationally significant, up from 89 the year before, a rise of roughly 130%. Eighteen were categorised as highly significant, a 50% year on year increase. That works out at about four nationally significant cyber incidents every week.
The biggest IT security threats in 2026
1. Unpatched vulnerabilities
This is the headline change of the year. The Verizon 2026 Data Breach Investigations Report, which analysed more than 22,000 confirmed breaches across 145 countries, found that exploitation of software vulnerabilities was the top initial access vector at 31% of breaches. It is the first time in the report's 19 year history that credential theft has been knocked off the top spot.
Worse, the gap is widening in the attacker's favour. Median time to patch rose from 32 days to 43 days, while AI assisted tooling has compressed the time from disclosure to working exploit from months to hours.
What to do: treat patching as a measured service level, not an aspiration. Aim for critical internet facing systems inside 14 days and ideally inside 72 hours for anything on the CISA Known Exploited Vulnerabilities list. Subscribe to the NCSC's free Early Warning service.
2. Phishing and AI assisted social engineering
Phishing remains the most common attack type in the UK and, according to IBM, the most common initial attack vector globally for the fourth consecutive year, accounting for 17% of breaches at an average cost of $5.9 million.
What has changed is quality and channel. Generative AI has removed the spelling errors and awkward phrasing that used to give phishing away. Attacks have also moved off email. Verizon found engagement rates for mobile based phishing simulations were 40% higher than traditional email simulations, with criminals increasingly using SMS, WhatsApp, social media and voice calls to reach staff who are mobile, distracted and more trusting.
Deepfake impersonation is now mainstream rather than novel. IBM's 2026 report found that one in four malicious breaches were AI enabled, a 56% year on year increase, with deepfake impersonation the single largest category. Those breaches cost around $6 million on average, roughly $1 million above the global average.
What to do: phishing resistant authentication beats phishing awareness training. Deploy passkeys or FIDO2 security keys for administrators and finance staff. Add a mandatory out of band verification step for any payment change or credential reset, and train the service desk specifically, because that is where the retail attacks of 2025 began.
3. Ransomware and data extortion
Ransomware remains what the NCSC calls the most pressing cyber threat to the UK. The economics are shifting slightly in defenders' favour: the DBIR recorded a median ransomware payment of $139,875, down from $150,000, with 69% of victims declining to pay. But IBM found 39% of breached organisations had suffered at least one ransomware attack over the past 12 months, up from 24% in 2023.
The bigger change is tactical. Many groups no longer bother encrypting. They exfiltrate data and threaten publication, which sidesteps your backups entirely and turns a technical problem into a regulatory and reputational one.
What to do: assume encryption is optional and exfiltration is likely. Segment your network, apply least privilege, monitor for large outbound transfers, and keep at least one immutable, offline backup copy that you have actually tested restoring from.
4. Supply chain and third party compromise
Verizon found third party involvement in breaches jumped 60% and now features in 48% of cases. This is the threat category where UK preparedness is weakest by a distance: only 15% of businesses review the cyber risk of immediate suppliers, and only 6% look at the wider supply chain.
The pattern is consistent. Attackers compromise a supplier with weaker controls and inherit the trust that supplier has been granted. Synnovis, Advanced, Capita and MOVEit all followed this shape, and so did the Stryker Medical incident that disrupted NHS supplies of defibrillators and other equipment in March 2026.
What to do: tier your suppliers by the damage they could cause, not by what you spend with them. For tier one suppliers, ask for Cyber Essentials Plus or ISO 27001, a recent penetration test summary and a contractual breach notification window. Then check what access they actually hold and remove what is not needed.
5. Stolen credentials and MFA bypass
Credential theft slipped to second place globally, but only because vulnerability exploitation surged. Infostealer malware continues to feed a vast market in valid logins, and attackers have adapted to multi factor authentication with MFA fatigue prompts, adversary in the middle proxy kits that steal session tokens, SIM swapping and help desk impersonation.
What to do: number matching or phishing resistant MFA everywhere, conditional access policies that flag impossible travel and unfamiliar devices, and short session lifetimes for privileged accounts. Dark web credential monitoring is genuinely worthwhile.
6. Shadow AI and unsecured AI systems
The fastest growing new category. Verizon found unsanctioned employee AI use tripled to feature in 45% of breaches. IBM put shadow AI in 43% of security incidents, more than double the previous year, with those incidents ending in data loss or compromise roughly half the time and around one in five drawing a regulatory fine.
The UK picture is equally uncomfortable. Around 31% of businesses are using, adopting or considering AI, but only 24% of that group have any cyber security practices in place to manage the resulting risk.
What to do: publish a short, permissive AI use policy that names approved tools rather than banning everything, which only drives usage underground. Provide a sanctioned enterprise option. Log and review AI tool usage, and treat prompt inputs as data egress.
7. Insider risk and human error
Verizon found the human element present in 62% of breaches, up slightly from 60%. The great majority is not malice. It is misdirected email, oversharing in cloud folders, weak passwords and staff trying to get their jobs done around inconvenient controls.
What to do: default to least privilege, enable data loss prevention on email and file sharing, review external sharing links quarterly, and run a genuine leavers process that revokes access on the last day.
8. Cloud misconfiguration and identity sprawl
As workloads moved to SaaS and cloud platforms, the perimeter became the identity. Overprivileged service accounts, dormant admin roles, public storage buckets and forgotten integrations are now among the most reliable threats to computer security in mid sized organisations, precisely because nobody owns them.
What to do: run a quarterly identity review covering every cloud tenancy. Remove dormant accounts, enforce MFA on every cloud service that supports it, and audit third party app integrations with OAuth access to your data.
9. Business email compromise and invoice fraud
Impersonation attacks were reported by 12% of UK businesses. Cyber facilitated fraud affected an estimated 3% of businesses, roughly 43,000 organisations, with the top 10% of cases costing £12,000 or more. For a small business, that is a serious loss with no technical breach to point at.
What to do: a hard rule that bank detail changes require verbal confirmation on a previously known number, dual authorisation above a threshold, and DMARC enforcement on your own domain so criminals cannot easily spoof you.
10. Unsupported and legacy technology
Every organisation carries some. An old line of business application on an unsupported operating system, a firewall past end of life, a machine tool controller nobody dares touch. These are the systems that turn a contained incident into a shutdown.
What to do: maintain an asset register with end of support dates. Where replacement is genuinely impossible, isolate the system on its own network segment with strictly controlled access, and document that decision as an accepted risk at board level.
Cyber attacks examples: what recent UK incidents actually teach us
Abstract statistics rarely change behaviour. Specific cyber attacks examples usually do.
Jaguar Land Rover, August 2025
The most economically damaging cyber event in UK history. The Cyber Monitoring Centre classified it a Category 3 systemic event and modelled the UK financial impact at £1.9 billion, within a range of £1.6 billion to £2.1 billion, affecting more than 5,000 UK organisations. Production halted for roughly five weeks across Solihull, Halewood and Wolverhampton, and full recovery ran into January 2026.
The lesson: the vast majority of that cost was lost manufacturing output, not stolen data. Operational disruption, not data theft, is the dominant financial risk for most businesses. Ask yourself what a fortnight offline would cost you before you ask what a data breach would cost.
Marks & Spencer and the Co-op, April 2025
The CMC assessed these as a single Category 2 systemic event with a combined financial impact of £270 million to £440 million. M&S guided to around £300 million of operating profit impact for 2025/26 and lost an estimated £1.3 million per day while online ordering was suspended for 46 days. Public reporting linked the initial M&S compromise to social engineering against a third party IT service desk.
The lesson: a password reset process, not a firewall, was the weak link. Your help desk is a security control and needs to be treated as one.
Synnovis, June 2024
The ransomware attack on this NHS pathology provider cost an estimated £32.7 million, disrupted five London trusts and delayed more than 11,000 appointments. It was cited repeatedly during parliamentary debate on the Cyber Security and Resilience Bill because, under the existing NIS Regulations, it did not trigger mandatory reporting obligations at all.
The lesson: when you outsource a process, you do not outsource the consequence.
How to prevent cyber attacks: a practical UK checklist
The honest answer to how to prevent cyber attacks is that you cannot prevent all of them. What you can do is make yourself a poor target, detect intrusions early, and recover quickly. The overwhelming majority of successful attacks exploit basics rather than sophistication, which is genuinely good news for smaller organisations.
Tier one: the non negotiables
- Multi factor authentication on every service that supports it. Only 47% of UK businesses use any 2FA. This is the single highest impact control available to you.
- Patch on a schedule you can evidence. Critical and internet facing systems inside 14 days.
- Tested, immutable backups. Follow 3-2-1: three copies, two media types, one offline or immutable. Restore something real every quarter.
- Restrict administrative rights. No day to day work from an admin account, ever.
- Up to date malware protection and correctly configured firewalls across the network and on individual devices.
Those five map directly onto Cyber Essentials, and only 24% of UK businesses currently have controls in place across all five areas.
Tier two: the material uplift
- Write and rehearse an incident response plan. Only 25% of businesses have one. Include who declares an incident, who calls the insurer, who talks to customers, and how you operate on paper for 72 hours.
- Formally review your suppliers. Tier them by potential damage and require evidence from the top tier.
- Train staff on what attacks now look like, including voice, SMS and messaging app approaches, not just suspicious emails.
- Enforce a payment verification process that cannot be overridden by urgency from someone claiming to be a director.
- Get Cyber Essentials certified. It is affordable, increasingly a procurement requirement, and forces the tier one work to actually happen.
Tier three: maturity
- Continuous monitoring and logging with alerting you actually read, whether in house or through a managed provider. Around 48% of UK businesses already use an external cyber security provider.
- Network segmentation so a single compromised device cannot reach everything.
- Governance at board level. Board responsibility rose to 31% this year, reversing years of decline. Use the Cyber Governance Code of Practice to structure the conversation.
- Encrypt sensitive data at rest and in transit. IBM found only 37% of breached organisations were doing both.
- Review your cyber insurance against realistic scenarios, particularly business interruption cover and supply chain dependencies.
One encouraging finding from IBM: organisations making extensive use of AI and automation in security operations cut breach costs by close to $2 million on average compared with those using none.
UK security and threats regulation: what changes in 2026
The compliance picture around security and threats is tightening considerably, and this is the year the direction of travel became unmistakable.
The Cyber Security and Resilience Bill
Introduced to the Commons on 12 November 2025, the Bill completed its Commons passage on 16 June 2026, was introduced in the Lords on 17 June and had its second reading there on 14 July 2026. Committee stage in the Lords is expected from September, with Royal Assent anticipated later in 2026 and phased implementation following through secondary legislation.
The Bill updates the NIS Regulations 2018 by widening scope to include managed service providers, data centres and designated critical suppliers, tightening incident reporting to a 24 hour early warning and a 72 hour full report, and giving regulators substantially stronger enforcement powers including a two tier penalty structure.
If you supply an operator of essential services, expect the requirements to reach you through your contracts well before they reach you through the law.
Ransomware payment policy
The Bill as drafted does not contain the ransomware measures the government consulted on. Those proposals, a targeted payment ban for public sector bodies and critical national infrastructure, a payment prevention regime requiring notification before any payment, and mandatory incident reporting, remain government policy and are expected to arrive through separate legislation. Plan on the assumption that paying will become harder and slower, and that your recovery capability is your only real option.
Cyber Essentials: the Danzell update
From 27 April 2026, new Cyber Essentials assessment accounts use version 3.3 of the requirements and the Danzell question set. The five core controls are unchanged, but enforcement has tightened significantly. Multi factor authentication is now mandatory on every cloud service where it is available, and its absence on a single service is an automatic fail. Patching requirements are stricter, and the verified self assessment must be finalised before Cyber Essentials Plus testing begins rather than adjusted in response to audit findings. The scheme has also moved to emphasise passwordless authentication and passkeys.
If you certified under the previous Willow question set, do not assume renewal will be straightforward.
A realistic 90 day plan
Days 1 to 30: see what you have. Build an asset register covering devices, cloud services and suppliers. Identify every account with administrative rights. List every cloud service and whether MFA is enforced. Confirm your backups exist and test one restore.
Days 31 to 60: close the obvious gaps. Enable MFA everywhere it is available, starting with email, finance systems and remote access. Remove dormant accounts and unnecessary admin rights. Agree and document a patching service level. Put a payment verification rule in writing and tell your finance team.
Days 61 to 90: prove it works. Write a one page incident response plan with named roles and contact details. Run a 90 minute tabletop exercise around a plausible scenario, such as ransomware in your finance system on a Friday afternoon. Tier your top ten suppliers and request evidence from the critical ones. Book your Cyber Essentials assessment.
None of that requires a large budget. Almost all of it requires someone to own it.
Frequently asked questions
What are the most common IT security threats for small businesses? Phishing by a wide margin, followed by impersonation and business email compromise. UK government data shows 38% of businesses experienced phishing, and phishing accounted for 93% of businesses that were victims of cyber crime. Ransomware receives more attention but was reported by only 1% of businesses, although its impact when it lands is disproportionately severe.
How much does a cyber attack cost a UK business? It depends enormously on scale. The median perceived cost of the most disruptive breach was effectively £0 for most UK businesses, rising to £4,000 at the 95th percentile and £10,000 for medium and large businesses. Globally, IBM puts the average data breach at $4.99 million. The genuine outliers are operational: the JLR attack modelled at £1.9 billion across the UK economy.
Are cyber incidents actually increasing? Volume has plateaued but severity has risen sharply. UK breach prevalence held steady at 43%, while nationally significant incidents handled by the NCSC rose 130% to 204 in the year to August 2025, and businesses reporting revenue or share value losses more than doubled from 2% to 5%.
Is AI making IT security threats worse? On balance, yes, for now. AI enabled breaches rose 56% year on year and cost around $1 million more than average. Shadow AI features in 43% to 45% of incidents depending on the dataset. But organisations using AI and automation defensively cut breach costs by close to $2 million, so the technology cuts both ways.
Do I need to report a cyber incident in the UK? If personal data is affected, you must notify the ICO within 72 hours where there is a risk to individuals. Under the Cyber Security and Resilience Bill, in scope organisations will additionally face a 24 hour early warning and 72 hour full report duty to their regulator and the NCSC. Only 40% of UK businesses currently report their most disruptive breach externally at all.
What is the single most effective thing I can do this week? Turn on multi factor authentication across your email and cloud services, and remove administrative rights from day to day user accounts. Those two actions block or contain a very large share of real world attacks.
Sources
- DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, 30 April 2026
- Verizon, 2026 Data Breach Investigations Report and findings summary, May 2026
- IBM, Cost of a Data Breach Report 2026 and press release, 29 July 2026
- NCSC, Annual Review 2025, October 2025
- Cyber Monitoring Centre, statement on the Jaguar Land Rover incident, October 2025
- Cyber Monitoring Centre, statement on retail sector ransomware incidents, June 2025
- UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill
- IASME, Changes to Cyber Essentials for April 2026
- NHS England, Stryker Medical cyber attack and associated supply disruption, March 2026




