Question
What percentage of UK businesses experienced a cyber security breach or attack in 2025?
50% of UK businesses and 32% of charities reported experiencing cyber security breaches or attacks in the past 12 months.
Question
What is the most common type of cyber attack affecting UK organisations?
Phishing attacks remain the most common threat, accounting for 84% of all cyber security incidents reported by businesses.
Question
What is the average cost of a cyber security breach for UK businesses?
The average cost is £15,300 for businesses and £3,230 for charities, with larger organisations facing significantly higher costs.
Question
What percentage of businesses have cyber security policies in place?
Only 31% of businesses have a formal cyber security strategy documented, highlighting a significant gap in organisational preparedness.
Question
Which sector experiences the highest rate of cyber attacks?
The finance and insurance sector reports the highest rate at 77%, followed by information and communications at 69%.
Question
What is the primary barrier to improving cyber security?
Lack of budget and resources is cited by 42% of businesses, followed by lack of expertise (38%) and senior management engagement (29%).
Question
How often should staff receive cyber security training?
Best practice recommends at least annual training, but only 54% of businesses provide regular security awareness training to employees.
Question
What percentage of breaches are caused by human error?
Approximately 88% of data breaches are caused by employee mistakes, emphasising the critical importance of security awareness training.
Question
What is ransomware and how prevalent is it?
Ransomware is malicious software that encrypts data and demands payment. It affected 17% of businesses in 2025, with attacks increasing by 13%.
Question
What are the top three cyber security priorities for 2026?
1) Implementing multi-factor authentication (MFA), 2) Regular security updates and patching, 3) Comprehensive staff training and awareness programs.
Question
What is the role of ISO 27001 in cyber security?
ISO 27001 is an international standard for information security management systems, providing a framework for protecting sensitive data and managing security risks.
Question
How can CyberGP help your organisation?
CyberGP offers ISO 27001 audits, security assessments, OSINT evaluations, phishing campaigns, and comprehensive training to strengthen your cyber security posture.