ComplianceBack to Blog

UK Cyber Breaches Survey 2026: The Cyber Security and Resilience Bill Compliance Gap

DSIT's Cyber Security Breaches Survey 2025/2026 put 43% of UK businesses on the wrong end of a breach. The more revealing numbers sit beneath that headline: only 40% told anyone outside the organisation, and only 25% hold a formal incident response plan. Here is what that gap means once the Cyber Security and Resilience Bill (CSRB) makes 24/72-hour reporting a legal duty.

Precursor Security
3 July 2026
6 min read
1,180 words

Precursor Security

Precursor Security is a UK-based penetration testing and offensive security testing company with 24/7 security operations centres. We are CREST certified in both penetration testing and security operations, providing comprehensive cyber security services to help organisations achieve regulatory compliance and enhance their security posture.

Share:

The Department for Science, Innovation and Technology published the Cyber Security Breaches Survey 2025/2026 on 30 April 2026. The headline figure attracted significant coverage: 43% of UK businesses - approximately 612,000 organisations - reported experiencing a cyber security breach or attack in the previous twelve months. For the organisations now in scope of the Cyber Security and Resilience Bill (CSRB) awaiting Lords scrutiny on 14 July 2026, however, the more consequential numbers lie beneath that headline. They reveal an industry-wide readiness gap that will define whether compliance is a straightforward transition or an organisational crisis.

What the Survey Found

The 2025/2026 survey, conducted between August and December 2025, is the most comprehensive official picture of UK business cyber posture currently available. Key headline findings:

  • 43% of UK businesses and 28% of charities reported a breach or attack in the past year
  • An estimated 5.19 million cybercrimes were committed against UK businesses during the period
  • Revenue or share-value impact from breaches more than doubled year on year, rising from 2% to 5% of affected businesses
  • Reputational damage from breaches rose from 1% to 3% of affected businesses
  • Phishing remained the dominant attack type, affecting 38% of businesses and rated the most disruptive vector by 69% of affected firms

These numbers confirm a central argument that has run throughout the Cyber Security and Resilience Bill's passage through Parliament: the threat is persistent, it is growing in financial impact, and it is predominantly directed at human entry points rather than exotic technical vulnerabilities. Phishing does not require a nation-state adversary or a novel exploit chain. It requires only an unguarded inbox - and the data shows it is succeeding at scale.

The Number That Matters Most for Cyber Security and Resilience Bill Compliance

Of all the survey's findings, the external reporting rate is the most operationally significant for organisations in scope of the Bill.

Only 40% of businesses reported their most disruptive breach externally.

That figure means that when UK businesses experience a significant cyber incident today, the majority - six in ten - tell no one outside the organisation. Under the incident reporting regime in HL Bill 32, that approach becomes a legal liability for regulated entities. The Bill requires notification to the relevant competent authority within 24 hours of becoming aware of a significant incident, with a full technical report due within 72 hours.

The gap between current behaviour and the incoming legal duty is not a minor process adjustment. It represents a categorical change in incident management for the majority of businesses that will fall into scope. That change requires preparation well in advance of the duty taking effect - not a sprint in the final weeks before commencement.

The Incident Response Gap

The survey reveals a second gap that compounds the reporting problem substantially: only 25% of UK businesses have a formal incident response plan.

The 24/72-hour reporting obligation is not simply about sending a notification. To make a meaningful initial notification within 24 hours, an organisation must know: what has happened, to which systems, with what operational impact, and whether the incident meets the definition of a "significant" reportable event under the Bill. None of that is possible without a structured incident response capability - documented procedures, defined roles, tested workflows, and a pre-established channel for regulatory notification.

For the roughly 75% of businesses currently without a formal incident response plan, the CSRB compliance journey begins not when the legislation comes into force but now. Building that capability takes months: drafting procedures, training staff, running tabletop exercises, and refining the plan against realistic scenarios. Organisations that begin now have a material advantage over those that wait for commencement regulations to land.

There is a further dimension. The survey found that in 69% of the most severely disruptive incidents, the attack vector was phishing. If organisations are currently failing to respond effectively to the most common and best-understood attack type, the more complex incidents the CSRB is designed to capture - supply chain compromises, cascading failures across multiple customers, attacks on operators of essential services - represent a substantially larger operational challenge.

Near-Miss Reporting: A New Frontier

One aspect of the Cyber Security and Resilience Bill that has attracted less public commentary than the 24/72-hour duty is the near-miss reporting provision. Under the Bill, certain regulated entities will be required to report incidents that were capable of causing significant service disruption, even where no actual disruption occurred.

This obligation goes beyond both the current UK NIS Regulations and the EU's NIS2 Directive. It is a genuinely new requirement, and the survey data makes clear how large the underlying capability gap is. Most UK businesses currently have no formal mechanism for identifying, classifying, and internally documenting near-miss security events - let alone a workflow for reporting them to a regulator within statutory timeframes.

Implementing a near-miss reporting capability from scratch requires investment in monitoring tooling, alert classification frameworks, and trained security operations resource. For managed service providers and data centre operators - both newly regulated under the Bill - near-miss reporting will also mean capturing and communicating information about incidents affecting their customers' environments. That adds contractual and notification-workflow complexity that needs to be designed, agreed, and tested before the duty takes effect.

The AI Risk Gap

The 2025/2026 survey introduced a new section on artificial intelligence adoption. Approximately a third of UK businesses are currently using AI, actively adopting it, or considering doing so. Of that group, only 24% have cyber security practices or processes in place to manage AI-related risks.

This matters for CSRB compliance in two respects. First, the Cyber Assessment Framework, which will underpin how regulators assess compliance under the Bill, takes a risk-based approach that encompasses emerging-technology risks. Organisations deploying AI in or close to regulated operations that cannot demonstrate they have assessed and mitigated those risks are likely to face difficult conversations with their competent authority.

Second, the forthcoming DSIT implementation consultation - expected during 2026 - is likely to address how AI-related risks within supply chains should be managed by organisations in scope. The survey data suggests that the majority of AI-adopting businesses have not yet developed the necessary security governance, making future compliance more demanding precisely for those organisations investing most heavily in AI.

Who Should Act Now

The survey covers all UK businesses. The CSRB's obligations fall on a defined subset: operators of essential services, managed service providers, data centres above the capacity thresholds, and organisations designated as critical suppliers. The survey notes that larger organisations are more likely to have formal incident response plans and are more likely to report incidents externally - but even among large businesses, gaps remain material. And the organisations most likely to be in scope of the CSRB are precisely those where a failure of incident management carries the greatest systemic impact.

Practical Priorities Before Royal Assent

The House of Lords will hear the Second Reading of HL Bill 32 on 14 July 2026. Committee Stage will follow. Royal Assent is expected in late 2026, with phased implementation continuing into 2028. That timetable leaves a preparation window, but not an open-ended one.

Four priorities, informed directly by the survey's findings:

  1. Build and test a 24/72-hour notification workflow now. If current practice is ad hoc or informal, design, document, and exercise a defined reporting process before the duty takes effect. The clock on a live incident does not pause while procedures are being written.

  2. Define your significant incident threshold in advance. What constitutes a "significant" incident in your specific regulated environment? Agreeing and documenting that definition before an actual incident removes a critical source of delay when the 24-hour window is already running.

  3. Build a near-miss logging and escalation process. Even for organisations not immediately in scope of the near-miss obligation, the underlying monitoring and classification capability will make full compliance substantially easier - and demonstrates the proactive posture regulators will look for.

  4. Engage with the DSIT implementation consultation when it launches. This consultation will shape the secondary legislation that defines how incident reporting obligations operate in practice, including thresholds, exemptions, and notification formats. Participating is the most direct way to ensure the final framework is operationally workable.

The full text of HL Bill 32 and a summary of what the Bill changes are available on this site. The official UK Parliament Bill page records the Bill's current status.

This article draws on the DSIT Cyber Security Breaches Survey 2025/2026, published 30 April 2026 by the Department for Science, Innovation and Technology and the Home Office. The position reflects the status as of 3 July 2026.

Tags:
CSRBcyber securityUK legislationcomplianceincident reportingDSITbreaches surveynear-miss reportingcyber resilienceNISHL Bill 32managed service providersdata centresAI risk
Last updated: 3 August 2026
Share:

You Might Also Like

Explore more insights and guidance on the Cyber Security and Resilience Bill.

Precursor Security
22 Jul 2026

Lords Complete Cyber Security and Resilience Bill Second Reading: Key Themes and Committee Stage on 1 September

The Lords gave the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, cross-party support at Second Reading on 14 July 2026 without calling a division - but they put five pointed themes on the record, from the public sector exemption to the Bill's total silence on AI. Committee Stage begins on 1 September, and those themes are the working agenda. Here is what each one means for in-scope organisations.

CSRBcyber security+19 more
Read Article
Precursor Security
28 Jul 2026

The Cyber Security and Resilience Bill Skills Gap: Can UK Firms Resource the New Duties?

A new think-tank report warns the Cyber Security and Resilience Bill (CSRB) risks becoming a "paper tiger" unless the UK's cyber skills shortage is addressed. With 49% of businesses and 58% of government bodies reporting a basic skills gap, the people needed to run 24/72-hour reporting and ongoing risk management may not be there. Here is what in-scope organisations should do about it before the duties commence.

CSRBcyber security+14 more
Read Article
Precursor Security
21 Jun 2026

Cyber Security and Resilience Bill Clears the Commons: Where It Stands in 2026

The Cyber Security and Resilience Bill (CSRB) has cleared every House of Commons stage and passed to the Lords as HL Bill 32. The core architecture survived intact - expanded scope, 24/72-hour reporting, £17m penalties - with one headline change: Ofcom is now the sole regulator for data centres. Here is the confirmed timeline and what to do before Royal Assent, expected late 2026.

CSRBcyber security+12 more
Read Article