A look at major UK businesses hit by cyberattacks in 2025; a government survey estimates 43% of businesses and 30% of charities were hit in the past 12 months
The true cost of cyber attacks on UK business is greater than it seems — Are this year's major attacks the …
Context & Ripple Effects
The survey’s 43% business figure aligns with an earlier government assessment of widespread UK breaches, while the inclusion of charities widens the story from corporate losses to organisations with fewer resources for resilience. Earlier coverage also put the business impact in revenue terms through Howden’s estimate of cyberattack-related losses.
This matters as an indicator of persistent exposure rather than a one-off incident cycle: the rate remains close to the level reported in a 2017 government survey, despite greater board-level attention to cyber risk.
First-order effects
- UK businesses and charities face a clearer benchmark for how common cyber incidents are, increasing the urgency of phishing prevention, incident response and continuity planning.
- The reported attacks make operational disruption and financial loss a current management issue for affected organisations, not solely an IT-security concern.
Second-order effects
- Security providers, insurers and incident-response firms are likely to see stronger demand as organisations translate broad breach prevalence into spending on prevention and recovery.
- Large companies’ resilience requirements can increasingly flow through to suppliers and charities that handle their data or depend on their systems, extending cyber-risk scrutiny beyond directly attacked firms.
Third-order effects
- If high attack prevalence persists, cyber resilience is likely to become a more explicit condition of commercial relationships and public-private coordination, rather than a discretionary compliance function.
- The pattern points toward an economy-wide resilience problem: later reporting that the NCSC handled a record number of nationally significant incidents reinforces the possibility that systemic disruption, not only individual breaches, will shape policy and investment priorities.
The trend: UK cyber risk is shifting from a recurring enterprise-security expense toward an economy-wide resilience challenge spanning companies, charities and critical business relationships.