Department for Science, Innovation & Technology
All Statistics
Total annual revenue in the UK cyber security sector reaches £14.7 billion, a nominal increase of about 11% since the previous year.
Total gross value added (GVA) for the UK cyber security sector reaches approximately £9.1 billion, an increase of 17% since the previous year.
There are 2,603 firms currently active in the UK providing cyber security products and services, an increase of 438 firms (20%) from 2,165 firms.
Approximately 69,600 full-time equivalent employees work in cyber security roles across the identified UK cyber security firms, an increase of about 2,300 jobs (3%) in the last 12 months.
GVA per employee in the UK cyber security sector increases from £116,200 to £131,200, a 13% rise.
In 2025, dedicated cyber security firms raised £184 million across 47 deals.
Just over four in ten businesses (43%) and around three in ten charities (28%) reported having experienced any kind of cyber security breach or attack in the last 12 months.
The proportion of charities experiencing a takeover has decreased from 3% in 2024/2025 to 1% this year (although was in line with 2% in 2023/2024).
The proportion of businesses and charities experiencing any negative outcome following a breach or attack has remained consistent with 2024/2025 (19% for business and 11% for charities in 2025 compared to 16% for both businesses and charities in 2024/2025).
The median perceived cost of the most disruptive breach or attack was £0 for businesses and £0 for charities, increasing to £30 for medium and large businesses.
The larger the business, the more likely they were to experience cyber crime (17% of micro businesses, 24% of small businesses, 41% f medium businesses and 48% of large businesses).
Ransomware attacks among businesses have declined compared with the previous two years (1% this year down from 3% in both 2024/2025 and 2023/2024)
There has been an increase in businesses reporting that the breach or attack led to loss of revenue or share value (2% in 2024/2025 to 5% in 2025/2026) and an increase in those reporting it resulted in reputational damage (1% in 2024/2025 to 3% in 2025/2026).
Adoption of more advanced controls like two-factor authentication (47% businesses and 38% charities), a virtual private network for staff connecting remotely (36% businesses and 17% charities) and user monitoring (30% businesses and 31% charities) remain lower than other measures.
A formal cyber security strategy was in place for almost six in ten medium businesses (57%), rising to seven in ten large businesses.
Around one in seven businesses (14%) and one in five charities (22%) said they held personal data that was not protected by techniques such as anonymisation or encryption, suggesting that the majority do protect personal data (77% of businesses and 69% of charities).
The most commonly cited individual source of information remained external cyber security or IT consultants/providers (27% of businesses and 13% of charities).
Seeking external information or guidance on cyber security was reported by 44% of businesses and 31% of charities.
The majority of businesses and charities have implemented basic technical controls, such as updated malware protection (81% businesses and 63% charities), backing up data securely via a cloud service (74% businesses and 57% charities), password policies (74% businesses and 56% charities), network firewalls (74% businesses and 45% charities) and restricted admin rights (73% businesses and 65% charities).
Impersonation breaches or attacks were significantly down among charities compared with the previous two years (7% this year down from 11% in 2024/2025 and 12% in 2023/2024).
Around a third of businesses (30%) conducted a risk assessment covering cyber security, in line with last year (29%).
Cyber security was considered a high priority for senior management in around seven in ten businesses (72%) and six in ten charities (60%).
Around eight in ten businesses (81%) and charities (84%) said they informed directors or trustees following an incident, and 62% of businesses and 73% of charities said they kept an internal record of the incident.
Medium (65%) and large (69%) businesses were more likely to have experienced a cyber breach or attack in the last 12 months compared to micro (42%) and small (46%) businesses.
Phishing attacks remained the most prevalent type of breach or attack by far (experienced by 38% of businesses and 25% of charities)
Among those who experienced a breach or attack, the proportion experiencing phishing attacks only (and no other type of breach or attack) has increased among both businesses (from 45% last year to 51% this year) and charities (from 46% last year to 57% this year).