Skip to Content

Cyberattacks: The Growing Threat to UK Businesses.

Cybercrime is now one of the most serious risks facing UK businesses. An attack can interrupt trading, prevent access to essential systems, expose confidential information and cause substantial financial and reputational damage.

Large organisations may present attractive targets because of the volume of money and data they hold, but smaller businesses are also vulnerable. Criminals frequently target organisations with limited security resources, outdated software or weak access controls.

How Common Are Cyberattacks?

The government's Cyber Security Breaches Survey 2025/26 found that 43% of UK businesses had identified a cyber breach or attack during the previous 12 months.

Approximately 19% of businesses had experienced conduct classed as cybercrime. Larger businesses were more likely to be affected, with almost half of large businesses reporting at least one cybercrime during the year.

Phishing remained the most common form of attack. However, businesses also reported hacking, ransomware, malicious software, denial-of-service attacks, online account takeovers and unauthorised access to files or networks.

What Is a Cyberattack?

A cyberattack is a deliberate attempt to gain unauthorised access to computers, networks, accounts or data, or to disrupt the operation of a digital system.

Cyberattacks may be carried out by:

  • Organised criminal groups
  • Individual hackers
  • Disgruntled employees or contractors
  • Commercial competitors
  • State-sponsored groups
  • Political or ideological organisations

The purpose may be financial gain, espionage, disruption, retaliation, theft of intellectual property or damage to public confidence.

Phishing and Fraudulent Emails

Phishing involves sending fraudulent emails, messages or websites designed to persuade someone to disclose information, open a malicious attachment or make a payment.

An attacker may impersonate a director, supplier, bank, customer or professional adviser. Business email compromise commonly involves a convincing request to change bank details or make an urgent transfer.

Staff should be trained to verify unusual payment requests using a separate and trusted method of communication. An email should not be assumed to be genuine merely because it appears to come from a familiar address.

Ransomware

Ransomware is malicious software that encrypts data or blocks access to systems. Criminals then demand payment in return for restoring access or promising not to publish stolen information.

An attack can prevent a business from processing orders, accessing customer records, paying staff or delivering essential services.

Payment does not guarantee that systems will be restored or that stolen information will be deleted. It may also encourage further attacks and create legal or sanctions risks where the recipient is connected to a prohibited organisation or jurisdiction.

Supply-Chain Attacks

A business may be attacked through a supplier, software provider, IT contractor or managed service provider.

Criminals may compromise one organisation and use its trusted access to reach multiple customers. Businesses should therefore assess the security of organisations that process their data or have access to their systems.

Contracts should deal clearly with security standards, breach reporting, access controls, audit rights, business continuity and responsibility for losses.

The Cost of a Cyberattack

The direct cost of an attack may include:

  • Loss of sales and operational downtime
  • IT investigation and system restoration
  • Replacement equipment and software
  • Legal and regulatory advice
  • Customer notification and support
  • Fraudulent payments or stolen funds
  • Compensation claims
  • Regulatory penalties
  • Increased insurance premiums

The longer-term effect may include lost contracts, reduced customer confidence, damage to the company's reputation and difficulty obtaining finance or insurance.

Directors' Responsibilities

Cybersecurity should be treated as a management and board-level risk rather than solely as an IT issue.

Directors should understand what information and systems are critical to the business, who has access to them and how the organisation would continue operating following an attack.

A failure to consider known and foreseeable cyber risks may expose the business and its directors to regulatory scrutiny, contractual claims or allegations that reasonable care was not taken.

Protecting Personal Data

Businesses that process personal information must comply with the UK GDPR and Data Protection Act 2018.

They must use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or disclosure.

The appropriate safeguards will depend on the nature of the information, the risks to individuals and the size and resources of the organisation.

Reporting a Personal Data Breach

A cyberattack involving personal information may amount to a personal data breach.

Where the breach is likely to create a risk topeople'ss rights and freedoms, it must generally be reported to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it.

An organisation should not delay its initial report simply because every detail is not yet known. Further information can be provided as the investigation progresses.

Where the risk to affected individuals is high, the organisation may also have to inform those individuals directly.

Other Reporting Obligations

Depending on the circumstances, an incident may also need to be reported to:

  • The National Cyber Security Centre
  • Action Fraud or the police
  • A sector regulator
  • Insurers
  • Banks and payment providers
  • Customers or commercial partners
  • Professional regulators

Businesses in regulated or essential-service sectors may have additional reporting obligations under sector-specific legislation.

Cyber Security and Resilience Legislation

The government has introduced the Cyber Security and Resilience Bill to strengthen the protection of essential and digital services.

The proposed reforms are intended to update the Network and Information Systems Regulations 2018, extend protection to additional organisations and improve regulatory oversight and incident reporting.

Businesses should monitor the Bill's progress and consider whether they, their suppliers or their managed service providers may fall within the expanded regulatory regime.

Basic Steps to Reduce the Risk

No organisation can eliminate every risk, but many common attacks can be prevented or limited by basic security measures.

Businesses should consider:

  • Using multi-factor authentication
  • Installing security updates promptly
  • Removing unused accounts and access rights
  • Using strong, unique passwords or passkeys
  • Restricting administrator privileges
  • Backing up important data separately from the main network
  • Encrypting sensitive information
  • Training staff to recognise phishing and payment fraud
  • Testing incident-response and business-continuity plans
  • Reviewing supplier and contractor access

The National Cyber Security Centre recommends Cyber Essentials as a minimum cybersecurity standard for organisations of all sizes.

Backups and Business Continuity

Backups should be made regularly and kept separate from systems that could be compromised during an attack.

A backup is only useful if it can be restored. Businesses should therefore test recovery procedures rather than assuming that stored data will be available when needed.

A business-continuity plan should identify how the organisation will communicate with staff and customers, maintain essential services and make decisions if its email, telephone or payment systems are unavailable.

What Should a Business Do During an Attack?

The immediate priorities are to contain the incident, preserve evidence and prevent further damage.

Depending on the nature of the attack, the business may need to:

  • Disconnect affected devices or systems
  • Contact its IT security provider
  • Activate its incident-response plan
  • Secure unaffected accounts and systems
  • Inform its insurer
  • Record decisions and actions taken
  • Assess whether personal data has been affected
  • Notify the appropriate authorities

Systems should not be wiped or restored before specialist advice is obtained where doing so could destroy evidence or interfere with the investigation.

Cyber Insurance

Cyber insurance may help cover some of the financial consequences of an attack, including specialist investigation, data recovery, legal advice and business interruption.

Policies vary considerably and may contain strict requirements concerning security controls, reporting deadlines and the use of approved incident-response providers.

Businesses should review the policy before an incident occurs and ensure that statements made during the insurance application remain accurate.

Claims Following a Cyberattack

A cyber incident may lead to disputes involving customers, employees, suppliers, software providers or IT contractors.

Potential claims may concern breach of contract, negligence, misuse of confidential information, breach of data-protection law or failure to provide agreed security services.

Whether compensation is recoverable will depend on the contract, the cause of the incident, the security measures used and the losses that can be proved.

Obtaining Legal Advice

Businesses affected by a serious cyberattack should obtain legal and technical advice promptly.

A solicitor can advise about regulatory notifications, contractual obligations, communications with affected individuals, insurance coverage and potential claims.

Advice obtained at an early stage may also help protect legally privileged communications and reduce the risk of inconsistent or inaccurate statements being made during the response.

Important Information

Solicitors.com is not a firm of solicitors. This article is provided for general information only and does not constitute legal, regulatory or cybersecurity advice. Cybersecurity threats, reporting duties and legislation may change, and their application will depend on the circumstances. You should seek advice from a suitably qualified solicitor and cybersecurity professional before taking or refraining from action.

Image Description
related news
recent articles
Double Jeopardy Law

What is Double Jeopardy? and is it still Law in the UK?..

link

Speeding motoring offences

Speeding motoring offences
Over 100,000 motorists are caught speeding each year, many have attended speed awareness courses, many were fined and received point..

Children and the Law Leaving a child at home.

There is no age laid down by the law stating when your child is old enough to be left home alone; however, it is against the law to leave a child home alone if..

The sex offender register

The sex offender register - Guide..

What is a Section 60 notice?

Over 2000 section 60 notices have been issued in London last year..

link

law on legal highs to be reviewed

The law banning legal highs in the UK is to undergo an urgent review...

Unauthorised Encampments: The Powers of Landowners and the Police

Greater power to evict travellers planned.
- The Tory government are set to announce new measures to evict travellers from illegal camp sites, which include s..

Injunctions.

How to apply for one, and what is an injunction? - If you are seeking an injunction we would recommend that you take immediate advice...

Stop and Search Laws to be changed?

Police Chiefs are calling for a change in the 'stop and search' l..

link

Revenge Porn and Intimate Image Abuse

Is Revenge Porn Illegal in England.
Hundreds of people in England have had explicit photos or videos published on the internet without their consent, but what..

Reporting a Crime.

If the crime is ongoing call 999, you should not put yours or anyone else’s safety at risk by taking action yourself...

Motoring Offences | Drink Driving.

Motoring Offences - Drink Driving.
If you have been stopped for drink driving it is important that you obtain legal advice as soon as possible and, to assist y..

Image Description
Is there anything wrong with this page? - any amendments will receive accreditation - email us

Solicitors.com are not a firm of solicitors, and any content on the site should not be used in substitute for obtaining Legal advice from a solicitor regulated in the UK, Solicitors.com recommends that you contact a firm of solicitors to discuss your individual legal requirement. Whilst we strive to bring you accurate up to date content, all content on this site is not legal advice and is not guaranteed to be correct. Use of this site does not create a client relationship.

Information by area of law
Back to top