The Department for Science, Innovation and Technology published the Cyber Security Breaches Survey 2025/2026 on 30 April 2026. The headline figure attracted significant coverage: 43% of UK businesses - approximately 612,000 organisations - reported experiencing a cyber security breach or attack in the previous twelve months. For the organisations now in scope of the Cyber Security and Resilience Bill (CSRB) awaiting Lords scrutiny on 14 July 2026, however, the more consequential numbers lie beneath that headline. They reveal an industry-wide readiness gap that will define whether compliance is a straightforward transition or an organisational crisis.
What the Survey Found
The 2025/2026 survey, conducted between August and December 2025, is the most comprehensive official picture of UK business cyber posture currently available. Key headline findings:
- 43% of UK businesses and 28% of charities reported a breach or attack in the past year
- An estimated 5.19 million cybercrimes were committed against UK businesses during the period
- Revenue or share-value impact from breaches more than doubled year on year, rising from 2% to 5% of affected businesses
- Reputational damage from breaches rose from 1% to 3% of affected businesses
- Phishing remained the dominant attack type, affecting 38% of businesses and rated the most disruptive vector by 69% of affected firms
These numbers confirm a central argument that has run throughout the Cyber Security and Resilience Bill's passage through Parliament: the threat is persistent, it is growing in financial impact, and it is predominantly directed at human entry points rather than exotic technical vulnerabilities. Phishing does not require a nation-state adversary or a novel exploit chain. It requires only an unguarded inbox - and the data shows it is succeeding at scale.
The Number That Matters Most for Cyber Security and Resilience Bill Compliance
Of all the survey's findings, the external reporting rate is the most operationally significant for organisations in scope of the Bill.
Only 40% of businesses reported their most disruptive breach externally.
That figure means that when UK businesses experience a significant cyber incident today, the majority - six in ten - tell no one outside the organisation. Under the incident reporting regime in HL Bill 32, that approach becomes a legal liability for regulated entities. The Bill requires notification to the relevant competent authority within 24 hours of becoming aware of a significant incident, with a full technical report due within 72 hours.
The gap between current behaviour and the incoming legal duty is not a minor process adjustment. It represents a categorical change in incident management for the majority of businesses that will fall into scope. That change requires preparation well in advance of the duty taking effect - not a sprint in the final weeks before commencement.
The Incident Response Gap
The survey reveals a second gap that compounds the reporting problem substantially: only 25% of UK businesses have a formal incident response plan.
The 24/72-hour reporting obligation is not simply about sending a notification. To make a meaningful initial notification within 24 hours, an organisation must know: what has happened, to which systems, with what operational impact, and whether the incident meets the definition of a "significant" reportable event under the Bill. None of that is possible without a structured incident response capability - documented procedures, defined roles, tested workflows, and a pre-established channel for regulatory notification.
For the roughly 75% of businesses currently without a formal incident response plan, the CSRB compliance journey begins not when the legislation comes into force but now. Building that capability takes months: drafting procedures, training staff, running tabletop exercises, and refining the plan against realistic scenarios. Organisations that begin now have a material advantage over those that wait for commencement regulations to land.
There is a further dimension. The survey found that in 69% of the most severely disruptive incidents, the attack vector was phishing. If organisations are currently failing to respond effectively to the most common and best-understood attack type, the more complex incidents the CSRB is designed to capture - supply chain compromises, cascading failures across multiple customers, attacks on operators of essential services - represent a substantially larger operational challenge.
Near-Miss Reporting: A New Frontier
One aspect of the Cyber Security and Resilience Bill that has attracted less public commentary than the 24/72-hour duty is the near-miss reporting provision. Under the Bill, certain regulated entities will be required to report incidents that were capable of causing significant service disruption, even where no actual disruption occurred.
This obligation goes beyond both the current UK NIS Regulations and the EU's NIS2 Directive. It is a genuinely new requirement, and the survey data makes clear how large the underlying capability gap is. Most UK businesses currently have no formal mechanism for identifying, classifying, and internally documenting near-miss security events - let alone a workflow for reporting them to a regulator within statutory timeframes.
Implementing a near-miss reporting capability from scratch requires investment in monitoring tooling, alert classification frameworks, and trained security operations resource. For managed service providers and data centre operators - both newly regulated under the Bill - near-miss reporting will also mean capturing and communicating information about incidents affecting their customers' environments. That adds contractual and notification-workflow complexity that needs to be designed, agreed, and tested before the duty takes effect.
The AI Risk Gap
The 2025/2026 survey introduced a new section on artificial intelligence adoption. Approximately a third of UK businesses are currently using AI, actively adopting it, or considering doing so. Of that group, only 24% have cyber security practices or processes in place to manage AI-related risks.
This matters for CSRB compliance in two respects. First, the Cyber Assessment Framework, which will underpin how regulators assess compliance under the Bill, takes a risk-based approach that encompasses emerging-technology risks. Organisations deploying AI in or close to regulated operations that cannot demonstrate they have assessed and mitigated those risks are likely to face difficult conversations with their competent authority.
Second, the forthcoming DSIT implementation consultation - expected during 2026 - is likely to address how AI-related risks within supply chains should be managed by organisations in scope. The survey data suggests that the majority of AI-adopting businesses have not yet developed the necessary security governance, making future compliance more demanding precisely for those organisations investing most heavily in AI.
Who Should Act Now
The survey covers all UK businesses. The CSRB's obligations fall on a defined subset: operators of essential services, managed service providers, data centres above the capacity thresholds, and organisations designated as critical suppliers. The survey notes that larger organisations are more likely to have formal incident response plans and are more likely to report incidents externally - but even among large businesses, gaps remain material. And the organisations most likely to be in scope of the CSRB are precisely those where a failure of incident management carries the greatest systemic impact.
Practical Priorities Before Royal Assent
The House of Lords will hear the Second Reading of HL Bill 32 on 14 July 2026. Committee Stage will follow. Royal Assent is expected in late 2026, with phased implementation continuing into 2028. That timetable leaves a preparation window, but not an open-ended one.
Four priorities, informed directly by the survey's findings:
-
Build and test a 24/72-hour notification workflow now. If current practice is ad hoc or informal, design, document, and exercise a defined reporting process before the duty takes effect. The clock on a live incident does not pause while procedures are being written.
-
Define your significant incident threshold in advance. What constitutes a "significant" incident in your specific regulated environment? Agreeing and documenting that definition before an actual incident removes a critical source of delay when the 24-hour window is already running.
-
Build a near-miss logging and escalation process. Even for organisations not immediately in scope of the near-miss obligation, the underlying monitoring and classification capability will make full compliance substantially easier - and demonstrates the proactive posture regulators will look for.
-
Engage with the DSIT implementation consultation when it launches. This consultation will shape the secondary legislation that defines how incident reporting obligations operate in practice, including thresholds, exemptions, and notification formats. Participating is the most direct way to ensure the final framework is operationally workable.
The full text of HL Bill 32 and a summary of what the Bill changes are available on this site. The official UK Parliament Bill page records the Bill's current status.
This article draws on the DSIT Cyber Security Breaches Survey 2025/2026, published 30 April 2026 by the Department for Science, Innovation and Technology and the Home Office. The position reflects the status as of 3 July 2026.