{
  "title": "The state of UK cyber security",
  "standfirst": "Britain faces an elevated and uneven cyber threat. Attacks reached 43 per cent of businesses and the great majority of universities in the last year; fraud against the public hit a record 4.2 million incidents; the NCSC handled more than four nationally significant incidents a week; and independent research commissioned by the government puts the cost of serious attacks on business at around 14.7 billion pounds a year. Yet the state's own systems remain exposed, with the spending watchdog calling the threat to government severe and advancing quickly.",
  "period": "2024 to 2026",
  "headline": [
    {
      "value": "43%",
      "label": "of UK businesses identified a cyber breach or attack in the last 12 months",
      "period": "2025/2026 survey",
      "sourceOrg": "DSIT and Home Office",
      "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026"
    },
    {
      "value": "£14.7bn",
      "label": "estimated annual cost of significant cyber attacks to UK businesses, about 0.5 per cent of GDP",
      "period": "2024 prices, published 2025",
      "sourceOrg": "KPMG, commissioned by DSIT",
      "sourceUrl": "https://www.gov.uk/government/publications/independent-research-on-the-economic-impact-of-cyber-attacks-on-the-uk"
    },
    {
      "value": "204",
      "label": "nationally significant incidents handled by the NCSC, up from 89 the year before",
      "period": "September 2024 to August 2025",
      "sourceOrg": "NCSC",
      "sourceUrl": "https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025"
    },
    {
      "value": "4.2 million",
      "label": "fraud incidents against the public, the highest on record",
      "period": "year ending March 2025",
      "sourceOrg": "ONS",
      "sourceUrl": "https://www.ons.gov.uk/peoplepopulationandcommunity/crimeandjustice/bulletins/crimeinenglandandwales/yearendingmarch2025"
    }
  ],
  "sections": [
    {
      "key": "breaches",
      "eyebrow": "Businesses and charities",
      "title": "Businesses and charities under attack",
      "summary": "The Cyber Security Breaches Survey asks organisations whether they have identified a breach or attack in the past 12 months. In the 2025/2026 edition, 43 per cent of businesses and 28 per cent of charities said yes. The risk climbs steeply with size: from 42 per cent of micro businesses to 69 per cent of large ones. Phishing dominates every breakdown, ransomware stays rare, and while board attention is slowly rising, supply chain checks remain very weak.",
      "chart": {
        "caption": "Businesses identifying a breach or attack, by size",
        "unit": "per cent",
        "color": "accent",
        "source": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026.",
        "bars": [
          { "label": "Micro (1 to 9 staff)", "value": 42 },
          { "label": "Small (10 to 49)", "value": 46 },
          { "label": "Medium (50 to 249)", "value": 65 },
          { "label": "Large (250+)", "value": 69 }
        ]
      },
      "stats": [
        {
          "label": "Businesses identifying a breach or attack",
          "value": "43%",
          "period": "last 12 months, 2025/2026 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026",
          "note": "Down from 50 per cent of businesses in 2024, a fall concentrated among smaller firms. In the 2025 edition this was roughly 612,000 businesses."
        },
        {
          "label": "Charities identifying a breach or attack",
          "value": "28%",
          "period": "last 12 months, 2025/2026 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026"
        },
        {
          "label": "Large businesses identifying a breach or attack",
          "value": "69%",
          "period": "last 12 months, 2025/2026 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026",
          "note": "Prevalence rises with size: 42 per cent micro, 46 per cent small, 65 per cent medium, 69 per cent large."
        },
        {
          "label": "Businesses experiencing phishing attacks",
          "value": "38%",
          "period": "last 12 months, 2025/2026 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026",
          "note": "Phishing is the most common attack type by far. Among businesses that were breached in the 2025 edition, 85 per cent had faced phishing. The figure for all charities was 25 per cent."
        },
        {
          "label": "Businesses experiencing ransomware",
          "value": "1%",
          "period": "last 12 months, 2025/2026 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026",
          "note": "Down from 3 per cent in each of the previous two years. Rare, but the survey treats ransomware as one of the most damaging attack types."
        },
        {
          "label": "Median cost of the most disruptive breach",
          "value": "£0",
          "period": "2025/2026 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026",
          "note": "The cost is heavily skewed: the median is zero, but the 95th percentile reaches 4,000 pounds for smaller firms and 10,000 pounds for medium and large ones. The 2025 edition put the mean at 1,600 pounds; DSIT has since stopped publishing a mean."
        },
        {
          "label": "Businesses where cyber security is a high priority for senior management",
          "value": "72%",
          "period": "2025/2026 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026"
        },
        {
          "label": "Businesses with a board member responsible for cyber security",
          "value": "31%",
          "period": "2025/2026 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026",
          "note": "Up from 27 per cent the year before, and 68 per cent among large businesses."
        },
        {
          "label": "Businesses that review cyber risks from their immediate suppliers",
          "value": "15%",
          "period": "2025/2026 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026",
          "note": "Just 6 per cent review risks across their wider supply chain, even though supply chain compromise is a growing route of attack."
        },
        {
          "label": "Businesses holding cyber insurance",
          "value": "47%",
          "period": "2025/2026 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026"
        },
        {
          "label": "Businesses holding Cyber Essentials certification",
          "value": "5%",
          "period": "2025/2026 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025/2026",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026",
          "note": "Only 17 per cent of businesses are even aware of the government backed Cyber Essentials scheme."
        }
      ]
    },
    {
      "key": "education",
      "eyebrow": "The hardest hit",
      "title": "Schools, colleges and universities",
      "summary": "Education is the most heavily targeted part of the survey. The share identifying a breach or attack rises sharply through the system, reaching the great majority of colleges and almost every university. Phishing is even more dominant here than in business.",
      "chart": {
        "caption": "Education institutions identifying a breach or attack",
        "unit": "per cent",
        "color": "worsening",
        "source": "DSIT and Home Office Cyber Security Breaches Survey 2025, education institutions findings.",
        "bars": [
          { "label": "Primary schools", "value": 44 },
          { "label": "Secondary schools", "value": 60 },
          { "label": "Further education colleges", "value": 85 },
          { "label": "Higher education (universities)", "value": 91 }
        ]
      },
      "stats": [
        {
          "label": "Universities identifying a breach or attack",
          "value": "91%",
          "period": "last 12 months, 2025 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025, education findings",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025-education-institutions-findings",
          "note": "Compared with 85 per cent of further education colleges, 60 per cent of secondary schools and 44 per cent of primary schools."
        },
        {
          "label": "Further education colleges identifying a breach or attack",
          "value": "85%",
          "period": "last 12 months, 2025 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025, education findings",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025-education-institutions-findings"
        },
        {
          "label": "Phishing among affected further and higher education",
          "value": "97%",
          "period": "2025 survey",
          "sourceOrg": "DSIT and Home Office Cyber Security Breaches Survey 2025, education findings",
          "sourceUrl": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025-education-institutions-findings",
          "note": "Phishing reached 89 per cent of affected primary and secondary schools and 97 per cent of affected colleges and universities."
        }
      ]
    },
    {
      "key": "public",
      "eyebrow": "The threat to the public",
      "title": "Fraud and computer misuse against individuals",
      "summary": "Fraud is now the single most common crime against the public and reached a record 4.2 million incidents in the year to March 2025, the only driver of the rise in overall crime. Survey measured computer misuse fell sharply, yet the offences people actually reported to Action Fraud rose by more than a third, a telling gap between crime experienced and crime reported. These figures cover England and Wales.",
      "chart": {
        "caption": "Computer misuse offences reported to Action Fraud",
        "unit": "offences",
        "color": "worsening",
        "source": "ONS Crime in England and Wales, Action Fraud and NFIB data, year ending March 2025.",
        "bars": [
          { "label": "Year ending Mar 2023", "value": 26604 },
          { "label": "Year ending Mar 2024", "value": 40832 },
          { "label": "Year ending Mar 2025", "value": 55576 }
        ]
      },
      "stats": [
        {
          "label": "Fraud incidents (England and Wales)",
          "value": "4.2 million",
          "period": "year ending March 2025",
          "sourceOrg": "ONS Crime Survey for England and Wales",
          "sourceUrl": "https://www.ons.gov.uk/peoplepopulationandcommunity/crimeandjustice/bulletins/crimeinenglandandwales/yearendingmarch2025",
          "note": "Up 31 per cent on the year before, the highest since fraud was first measured in 2017, and the single driver of the 7 per cent rise in total crime to 9.4 million incidents."
        },
        {
          "label": "Bank and credit account fraud incidents",
          "value": "About 2.4 million",
          "period": "year ending March 2025",
          "sourceOrg": "ONS Crime Survey for England and Wales",
          "sourceUrl": "https://www.ons.gov.uk/peoplepopulationandcommunity/crimeandjustice/bulletins/crimeinenglandandwales/yearendingmarch2025",
          "note": "The largest single type of fraud. Consumer and retail fraud accounted for about 1.1 million more."
        },
        {
          "label": "Computer misuse incidents (survey estimate)",
          "value": "692,000",
          "period": "year ending March 2025",
          "sourceOrg": "ONS Crime Survey for England and Wales",
          "sourceUrl": "https://www.ons.gov.uk/peoplepopulationandcommunity/crimeandjustice/bulletins/crimeinenglandandwales/yearendingmarch2025",
          "note": "Down 32 per cent on the previous year, which had risen to about 1 million. Of this, 564,000 incidents were unauthorised access to personal information."
        },
        {
          "label": "Computer misuse offences reported to Action Fraud",
          "value": "55,576",
          "period": "year ending March 2025",
          "sourceOrg": "ONS, Action Fraud and NFIB",
          "sourceUrl": "https://www.ons.gov.uk/peoplepopulationandcommunity/crimeandjustice/articles/natureoffraudandcomputermisuseinenglandandwales/yearendingmarch2025",
          "note": "Up 36 per cent on the year before, from 40,832. While the survey estimate of computer misuse fell, the number people reported rose."
        },
        {
          "label": "Total cost of fraud (England and Wales)",
          "value": "£14.4 billion",
          "period": "year ending March 2024",
          "sourceOrg": "Home Office, Economic and Social Cost of Fraud",
          "sourceUrl": "https://www.gov.uk/government/publications/economic-and-social-cost-of-fraud-2023-to-2024",
          "note": "Made up of 9.2 billion pounds affecting individuals and 5.2 billion pounds affecting businesses. This is an official estimate of all fraud, not only cyber fraud."
        },
        {
          "label": "Stolen through payment fraud (UK Finance members)",
          "value": "£1.28 billion",
          "period": "2025",
          "sourceOrg": "UK Finance (industry body)",
          "sourceUrl": "https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2026-press-release",
          "note": "Up 4 per cent on the year. Of this, authorised push payment fraud accounted for 576.4 million pounds across 248,070 cases, with two thirds of cases starting online. UK Finance is a banking trade body, not an official statistician."
        }
      ]
    },
    {
      "key": "economy",
      "eyebrow": "The cost",
      "title": "What it costs the economy",
      "summary": "The Breaches Survey deliberately does not produce an economy wide cost: its producers warn the self reported figures cannot be scaled up reliably. To fill that gap the government commissioned independent economists, whose central estimate puts the cost of serious attacks on business at around 14.7 billion pounds a year. These are modelled, indicative figures.",
      "stats": [
        {
          "label": "Annual cost of significant cyber attacks to UK businesses",
          "value": "£14.7 billion",
          "period": "2024 prices, published November 2025",
          "sourceOrg": "KPMG, commissioned by DSIT",
          "sourceUrl": "https://www.gov.uk/government/publications/independent-research-on-the-economic-impact-of-cyber-attacks-on-the-uk",
          "note": "About 0.5 per cent of GDP. The research is government commissioned but independent, and the authors stress the total should be treated as indicative only, as it draws partly on overseas data."
        },
        {
          "label": "Average cost of a significant cyber attack to a business",
          "value": "£194,729",
          "period": "2024 prices",
          "sourceOrg": "KPMG, commissioned by DSIT",
          "sourceUrl": "https://www.gov.uk/government/publications/independent-research-on-the-economic-impact-of-cyber-attacks-on-the-uk",
          "note": "A significant attack is defined as one costing at least 500 pounds. The average is heavily influenced by a small number of very costly attacks."
        },
        {
          "label": "Annual loss from theft of intellectual property via cyber attacks",
          "value": "£1bn to £8.5bn",
          "period": "2024",
          "sourceOrg": "Alma Economics, commissioned by DSIT",
          "sourceUrl": "https://www.gov.uk/government/publications/independent-research-on-the-economic-impact-of-cyber-attacks-on-the-uk",
          "note": "A wide range reflecting how hard it is to value stolen knowledge assets. A separate study put fraud enabled by data breaches at about 755 million pounds a year."
        }
      ]
    },
    {
      "key": "ncsc",
      "eyebrow": "National defence",
      "title": "Defending the nation: the NCSC's year",
      "summary": "The National Cyber Security Centre managed 429 cyber incidents in the year to August 2025. The number it judged nationally significant more than doubled to 204, continuing a steep climb, and 18 were highly significant. At the same time its automated defences operate at vast scale, taking down malicious sites and handling tens of millions of public reports.",
      "chart": {
        "caption": "Nationally significant incidents handled by the NCSC",
        "unit": "incidents",
        "color": "worsening",
        "source": "NCSC Annual Reviews 2023, 2024 and 2025.",
        "bars": [
          { "label": "Sep 2022 to Aug 2023", "value": 62 },
          { "label": "Sep 2023 to Aug 2024", "value": 89 },
          { "label": "Sep 2024 to Aug 2025", "value": 204 }
        ]
      },
      "stats": [
        {
          "label": "Cyber incidents managed by the NCSC",
          "value": "429",
          "period": "September 2024 to August 2025",
          "sourceOrg": "NCSC Annual Review 2025",
          "sourceUrl": "https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025",
          "note": "From 1,727 reports received."
        },
        {
          "label": "Nationally significant incidents",
          "value": "204",
          "period": "September 2024 to August 2025",
          "sourceOrg": "NCSC Annual Review 2025",
          "sourceUrl": "https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025",
          "note": "About four every week, and up sharply from 89 the year before and 62 the year before that."
        },
        {
          "label": "Highly significant incidents",
          "value": "18",
          "period": "September 2024 to August 2025",
          "sourceOrg": "NCSC Annual Review 2025",
          "sourceUrl": "https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025",
          "note": "Up about 50 per cent on the year before."
        },
        {
          "label": "Public reports to the Suspicious Email Reporting Service",
          "value": "10.9 million",
          "period": "September 2024 to August 2025",
          "sourceOrg": "NCSC Annual Review 2025",
          "sourceUrl": "https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025",
          "note": "More than 45 million reports have been made since the service launched in 2020, the basis for taking down hundreds of thousands of malicious sites."
        },
        {
          "label": "Devices compromised by the China-linked Flax Typhoon botnet",
          "value": "260,000+",
          "period": "2024 to 2025",
          "sourceOrg": "NCSC Annual Review 2025",
          "sourceUrl": "https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025",
          "note": "One of the cases highlighted in the review, affecting more than 260,000 devices worldwide."
        }
      ],
      "qualitative": [
        {
          "label": "On ransomware",
          "quote": "The NCSC describes ransomware as the most immediate, disruptive threat to critical national infrastructure."
        },
        {
          "label": "On state actors",
          "quote": "The NCSC describes China as a highly sophisticated and capable threat actor, and Russia as a capable and irresponsible threat actor in cyberspace."
        }
      ]
    },
    {
      "key": "state",
      "eyebrow": "The state's own defences",
      "title": "Government's own resilience",
      "summary": "The National Audit Office reviewed central government's cyber resilience in January 2025 and found it wanting. Government runs hundreds of ageing systems whose vulnerability it cannot fully assess, struggles to fill cyber roles, and will miss its own 2025 hardening target. The watchdog called the threat severe and advancing quickly.",
      "stats": [
        {
          "label": "Legacy IT systems across government",
          "value": "At least 228",
          "period": "March 2024",
          "sourceOrg": "National Audit Office",
          "sourceUrl": "https://www.nao.org.uk/reports/government-cyber-resilience/",
          "note": "Of these, 63 are rated high risk and 120 have no fully funded plan to fix them. The NAO notes government does not know how vulnerable many of these systems are."
        },
        {
          "label": "Government cyber roles vacant or filled by temporary staff",
          "value": "1 in 3",
          "period": "2023 to 2024",
          "sourceOrg": "National Audit Office",
          "sourceUrl": "https://www.nao.org.uk/reports/government-cyber-resilience/",
          "note": "Around 70 per cent of specialist security architects in post were temporary staff. Several departments had more than half of their cyber team roles vacant."
        },
        {
          "label": "Government organisations meeting the minimum cyber standard",
          "value": "25%",
          "period": "2022 self-assessment",
          "sourceOrg": "National Audit Office",
          "sourceUrl": "https://www.nao.org.uk/reports/government-cyber-resilience/",
          "note": "Officials reported the cyber resilience risk to government as extremely high. The NAO concluded the 2025 target to be significantly hardened to attack will not be met."
        },
        {
          "label": "Data breaches reported by central government to the ICO",
          "value": "Up to 114",
          "period": "July 2023 to June 2024",
          "sourceOrg": "National Audit Office, citing ICO",
          "sourceUrl": "https://www.nao.org.uk/reports/government-cyber-resilience/",
          "note": "A 75 per cent rise on the year before, affecting the data of more than 100,000 people."
        },
        {
          "label": "MoD payroll records put at risk in the 2024 contractor attack",
          "value": "About 270,000",
          "period": "May 2024",
          "sourceOrg": "National Audit Office",
          "sourceUrl": "https://www.nao.org.uk/reports/government-cyber-resilience/",
          "note": "Names and bank details, with some addresses and National Insurance numbers, held by an external payroll contractor."
        },
        {
          "label": "NHS appointments and procedures postponed after the Synnovis attack",
          "value": "11,862",
          "period": "from June 2024",
          "sourceOrg": "National Audit Office",
          "sourceUrl": "https://www.nao.org.uk/reports/government-cyber-resilience/",
          "note": "The ransomware attack on pathology provider Synnovis postponed 10,152 acute outpatient appointments and 1,710 elective procedures across south east London."
        },
        {
          "label": "Directly attributable cost of the British Library attack",
          "value": "£600,000",
          "period": "by March 2024",
          "sourceOrg": "National Audit Office, citing the British Library",
          "sourceUrl": "https://www.nao.org.uk/reports/government-cyber-resilience/",
          "note": "The October 2023 Rhysida ransomware attack leaked about 600GB of data; the Library refused to pay the ransom and faced a long rebuild."
        }
      ]
    },
    {
      "key": "skills",
      "eyebrow": "Capacity",
      "title": "The cyber skills gap",
      "summary": "Nearly half of UK businesses lack the basic cyber skills to manage their own defences, and the advanced skills shortage, though smaller, still affects a third. Recruitment is not closing the gap: core cyber job postings fell sharply in 2024.",
      "chart": {
        "caption": "Businesses with a cyber skills gap",
        "unit": "per cent",
        "color": "accent",
        "source": "DSIT Cyber security skills in the UK labour market 2025.",
        "bars": [
          { "label": "Basic skills gap", "value": 49 },
          { "label": "Advanced skills gap", "value": 30 }
        ]
      },
      "stats": [
        {
          "label": "Businesses with a basic cyber skills gap",
          "value": "49%",
          "period": "2025",
          "sourceOrg": "DSIT Cyber security skills in the UK labour market 2025",
          "sourceUrl": "https://www.gov.uk/government/publications/cyber-security-skills-in-the-uk-labour-market-2025/cyber-security-skills-in-the-uk-labour-market-2025",
          "note": "The people responsible cannot carry out basic tasks such as setting up firewalls or detecting and removing malware."
        },
        {
          "label": "Businesses with an advanced cyber skills gap",
          "value": "30%",
          "period": "2025",
          "sourceOrg": "DSIT Cyber security skills in the UK labour market 2025",
          "sourceUrl": "https://www.gov.uk/government/publications/cyber-security-skills-in-the-uk-labour-market-2025/cyber-security-skills-in-the-uk-labour-market-2025",
          "note": "29 per cent of charities also reported an advanced skills gap."
        },
        {
          "label": "Core cyber job postings in 2024",
          "value": "32,370",
          "period": "2024",
          "sourceOrg": "DSIT Cyber security skills in the UK labour market 2025",
          "sourceUrl": "https://www.gov.uk/government/publications/cyber-security-skills-in-the-uk-labour-market-2025/cyber-security-skills-in-the-uk-labour-market-2025",
          "note": "Down 33 per cent on the year, even as the estimated workforce gap held at about 3,800 people."
        }
      ]
    }
  ],
  "sources": [
    {
      "org": "DSIT and Home Office",
      "title": "Cyber Security Breaches Survey 2025/2026",
      "url": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026",
      "period": "Published April 2026"
    },
    {
      "org": "DSIT and Home Office",
      "title": "Cyber Security Breaches Survey 2025, including education institutions findings",
      "url": "https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025-education-institutions-findings",
      "period": "Published April 2025"
    },
    {
      "org": "Office for National Statistics",
      "title": "Crime in England and Wales, year ending March 2025",
      "url": "https://www.ons.gov.uk/peoplepopulationandcommunity/crimeandjustice/bulletins/crimeinenglandandwales/yearendingmarch2025",
      "period": "Fraud and computer misuse figures"
    },
    {
      "org": "Home Office",
      "title": "The economic and social costs of fraud",
      "url": "https://www.gov.uk/government/publications/economic-and-social-cost-of-fraud-2023-to-2024",
      "period": "Year ending March 2024 estimate"
    },
    {
      "org": "UK Finance (industry body)",
      "title": "Annual Fraud Report 2026",
      "url": "https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2026-press-release",
      "period": "2025 data"
    },
    {
      "org": "KPMG, Alma Economics and Frontier Economics, commissioned by DSIT",
      "title": "Independent research on the economic impact of cyber attacks on the UK",
      "url": "https://www.gov.uk/government/publications/independent-research-on-the-economic-impact-of-cyber-attacks-on-the-uk",
      "period": "Published November 2025"
    },
    {
      "org": "National Cyber Security Centre",
      "title": "NCSC Annual Review 2025",
      "url": "https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025",
      "period": "Published October 2025"
    },
    {
      "org": "National Audit Office",
      "title": "Government cyber resilience",
      "url": "https://www.nao.org.uk/reports/government-cyber-resilience/",
      "period": "Published January 2025"
    },
    {
      "org": "DSIT",
      "title": "Cyber security skills in the UK labour market 2025",
      "url": "https://www.gov.uk/government/publications/cyber-security-skills-in-the-uk-labour-market-2025/cyber-security-skills-in-the-uk-labour-market-2025",
      "period": "Published September 2025"
    }
  ],
  "caveats": [
    "The Cyber Security Breaches Survey is a survey of organisations based on self reporting. It counts breaches or attacks that organisations identified, not every incident that occurred, and its producers warn its cost figures cannot be scaled into an economy wide total.",
    "The economy wide cost of 14.7 billion pounds comes from independent research commissioned by the government. Its authors describe it as indicative only, as it relies in part on overseas data and on modelling assumptions.",
    "The ONS Crime Survey covers England and Wales only and produces survey estimates with margins of error. Large year on year movements should be read with caution, especially the fall in computer misuse, which follows a sharp rise the year before.",
    "Survey measured computer misuse fell while offences reported to Action Fraud rose. The two measure different things, crime experienced versus crime reported, and both are shown here rather than choosing one.",
    "Payment fraud loss figures come from UK Finance, a banking trade body, not an official statistician, and cover losses reported by its members.",
    "The NCSC, NAO and survey figures count different things over different periods and for different populations, so they are not directly additive or comparable."
  ]
}
