Boxphish's review of the 2026 Cyber Security Breaches Survey has landed. Last years survey felt like a warning and that feeling has certainly developed with this years release.
The headline: Cyber risk is now business-as-usual
43% of UK businesses reported a cyber breach or attack in the last 12 months, an unchanged statistic from last year.
At first glance, that might sound like stability... It isn’t, it’s saturation.
Cyber attacks are no longer “rising” in the traditional sense. They’ve plateaued at a level where nearly half of organisations are consistently affected. The threat isn’t growing. It's embedded.
Phishing still dominates the threat landscape

Phishing continues to be the primary attack vector, involved in around 88% of breaches affecting UK businesses, making this a human problem, not a technical one.
Despite years of awareness campaigns, phishing remains the easiest door to push open. Attackers are getting smarter, using more tools like AI to craft more convincing and personalised emails that are increasingly more difficult to distinguish from legitimate ones. The traditional red flags, such as; poor grammar, odd formatting and suspicious urgency, are rarely used now. These stats also show that the methods they're using are now consistently effective.
For a growing proportion of UK businesses, phishing is no longer one risk among many, it’s the only attack they experience.
612,000 UK businesses reported a phishing attack in the last 12 months.
That is not a headline about one sector or one type of organisation. It is the operating reality for businesses across every industry.
For a growing proportion of UK organisations, phishing is no longer one risk among many, it is the only attack they experience.
And the pressure is persistent as the survey doesn't describe sporadic incidents. It describes a constant, low level threat that test organisations' resilience continuously, not just in the moments when something goes visibly wrong.
Attacks are evolving beyond phishing
While phishing remains dominant, other attack types are climbing:
Impersonation attacks
68% in 2025 → 79% in 2026 (within the higher education sector).
Malware and spyware
42% in 2025 → 51% in 2026.
Distributed denial of service attacks (DDoS)
36% in 2025 → 49% in 2026.
The pattern is clear and attackers are diversifying. Organisations focused solely on phishing prevention may find themselves exposed as the threat landscape continues to broaden.
Governance is improving… Slowly
There are signs of progress:
- More organisations are embedding cyber into governance structures.
- Board-level engagement is increasing in some sectors.
- Threat intelligence adoption is rising (e.g. universities up to 92%).
But progress is uneven and the gaps are still significant... Cyber governance needs to become a priority for UK organisations, not a box-ticking exercise.

Only 15% of businesses currently assess their supply chain cyber risk and even fewer look at their wider ecosystem. Attackers are very aware of this blind spot and actively exploit it.
The real shift: From prevention to resilience
The most important insight in this year’s survey isn’t a statistic, but the mindset shift...
Cyber security is no longer about stopping every attack but about continuing to operate when attacks succeed.
Building a resilient and positive cyber culture is a now must-have for UK organisations. The businesses navigating this most successfully are not necessarily the ones with the most sophisticated tools, but the ones that have made cyber a business wide discipline rather than an IT department problem and that invest in their people's awareness just as much as their infrastructure.
What this means
If last year was about awareness, this year is about maturity.
The data does not call for more tools or a bigger IT budget; it calls for a shift in how organisations think about cyber risk. Treating it as a leadership concern, measuring progress beyond compliance tick-boxes and recognising that human behaviour is as critical to protect as any technical system. That is a lot harder of a change to make than buying a new piece of software, but it is the one that makes the difference.
Final thought
The survey doesn’t tell a story of escalation, but a story of normalisation.
Cyber attacks are no longer exceptional events but operational realities. The organisations that adapt to this mindset change the fastest, will be the ones best positioned to handle what comes next.


