UK government report: 46% of UK businesses had a cybersecurity breach in the last year, 67% lack a cybersecurity risk policy, only 24% report breaches to police
The 2017 UK Govt produced Cyber Security Breaches Survey is out and it says nothing new. Across 66 pages it repeats what businesses and the industry already know.
Context & Ripple Effects
This 2017 survey is the baseline for a series the UK government has repeated almost annually since: when the same methodology ran again in 2025, it found 43% of businesses still facing a breach or attack in the past year — meaning the headline breach rate has barely moved across nearly a decade of surveys. What has changed is the cost side: Howden's broker analysis put cumulative revenue losses at ~£44B over five years, and the NCSC's caseload of nationally significant incidents hit a record 204 in the year to August 2025.
The 2017 numbers that stand out are the governance gaps rather than the breach rate itself — 67% of businesses with no cybersecurity risk policy and only 24% reporting incidents to police. Those two figures frame everything downstream: an uninsured-by-policy population absorbing multi-billion-pound losses, and official statistics built on a quarter of the true incident base.
First-order effects
- Two-thirds of UK businesses learn they have no formal risk policy only when a breach lands, leaving them to improvise response while the minority who do report give police visibility into just a quarter of incidents.
- Insurers gain their clearest underwriting signal yet: with breach rates near half the business population, cyber policies priced off self-reported data carry systematic blind spots.
Second-order effects
- Enterprise demand for transfer of risk follows the exposure — cyber insurance uptake rose from 34% in 2017 to 47% by 2019 per the ZDNet survey, pushing insurers toward requiring documented policies before writing coverage.
- Under-reporting compounds: Bitdefender later found 42% of IT professionals were told to cover up breaches that should have been reported, so both police statistics and insurer loss models understate the real incident pool.
Third-order effects
- If the pattern holds — flat breach rates alongside rising severity and cost — UK cyber policy shifts from awareness campaigns toward mandates, because voluntary adoption of risk policies has stalled at roughly one-third of businesses for years.
- A structural reporting gap this size means regulators increasingly cannot measure the threat from victim disclosures alone, tilting measurement toward state signals like the NCSC's nationally significant incident counts.
The trend: UK business cyber exposure has stayed stubbornly around 43–46% of firms breached for nearly a decade, while costs, state-level incident counts, and insurance uptake climb around a static base of unprepared companies.