BLOG

Review of the 2026 Cyber Security Breaches Survey

Aug 5, 2026

Boxphish's review of the 2026 Cyber Security Breaches Survey has landed. Last years survey felt like a warning and that feeling has certainly developed with this years release.  

The headline: Cyber risk is now business-as-usual 

43% of UK businesses reported a cyber breach or attack in the last 12 months, an unchanged statistic from last year.

At first glance, that might sound like stability... It isn’t, it’s saturation.  

Cyber attacks are no longer “rising” in the traditional sense. They’ve plateaued at a level where nearly half of organisations are consistently affected. The threat isn’t growing. It's embedded. 

Phishing still dominates the threat landscape 

Phishing continues to be the primary attack vector, involved in around 88% of breaches affecting UK businesses, making this a human problem, not a technical one.

Despite years of awareness campaigns, phishing remains the easiest door to push open. Attackers are getting smarter, using more tools like AI to craft more convincing and personalised emails that are increasingly more difficult to distinguish from legitimate ones. The traditional red flags, such as; poor grammar, odd formatting and suspicious urgency, are rarely used now. These stats also show that the methods they're using are now consistently effective. 

For a growing proportion of UK businesses, phishing is no longer one risk among many, it’s the only attack they experience.  

612,000 UK businesses reported a phishing attack in the last 12 months.

That is not a headline about one sector or one type of organisation. It is the operating reality for businesses across every industry.

For a growing proportion of UK organisations, phishing is no longer one risk among many, it is the only attack they experience.

And the pressure is persistent as the survey doesn't describe sporadic incidents. It describes a constant, low level threat that test organisations' resilience continuously, not just in the moments when something goes visibly wrong.

Attacks are evolving beyond phishing 

While phishing remains dominant, other attack types are climbing: 



The pattern is clear and attackers are diversifying. Organisations focused solely on phishing prevention may find themselves exposed as the threat landscape continues to broaden. 

Governance is improving… Slowly 

There are signs of progress: 

  • More organisations are embedding cyber into governance structures. 
  • Board-level engagement is increasing in some sectors. 
  • Threat intelligence adoption is rising (e.g. universities up to 92%). 

But progress is uneven and the gaps are still significant... Cyber governance needs to become a priority for UK organisations, not a box-ticking exercise.

Only 15% of businesses currently assess their supply chain cyber risk and even fewer look at their wider ecosystem. Attackers are very aware of this blind spot and actively exploit it.  

The real shift: From prevention to resilience 

The most important insight in this year’s survey isn’t a statistic, but the mindset shift... 

Cyber security is no longer about stopping every attack but about continuing to operate when attacks succeed.  

Building a resilient and positive cyber culture is a now must-have for UK organisations. The businesses navigating this most successfully are not necessarily the ones with the most sophisticated tools, but the ones that have made cyber a business wide discipline rather than an IT department problem and that invest in their people's awareness just as much as their infrastructure. 

What this means 

If last year was about awareness, this year is about maturity.  

The data does not call for more tools or a bigger IT budget; it calls for a shift in how organisations think about cyber risk. Treating it as a leadership concern, measuring progress beyond compliance tick-boxes and recognising that human behaviour is as critical to protect as any technical system. That is a lot harder of a change to make than buying a new piece of software, but it is the one that makes the difference. 

Final thought 

The survey doesn’t tell a story of escalation, but a story of normalisation. 

Cyber attacks are no longer exceptional events but operational realities. The organisations that adapt to this mindset change the fastest, will be the ones best positioned to handle what comes next. 

Ready to transform your cyber culture? Book a demo today!

Latest insights

Employees using cyber awareness training

Aug 11, 2026

How to get employees to engage with security training

Aug 14, 2026

Your checklist for the 2026 Cyber Security Breaches Survey

Aug 14, 2026

Your guide to the 2026 Cyber Security Breaches Survey