UK national survey data records 50% of businesses and 32% of charities experiencing some form of cyber security breach or attack in 2025, with phishing the most commonly reported form — 84% of businesses and 83% of charities.
This Is The Instrument The Corpus Keeps Asking For
A government-run survey of a representative sample, repeated annually, covering organisations of every size including those far below any notification threshold.
It does not depend on an organisation choosing to disclose, on a leak site listing, on a vendor’s sensor population, or on a class action being worth bringing. It is the closest thing in this database to a measurement of incidence rather than of visibility — the gap named at 25-0613b and 25-1225.
And The Phishing Figure Is The Most Useful Number In The File
Eighty-four per cent, across organisations of all sizes. This corpus spends most of its pages on consent-grant abuse, connected applications, edge appliance zero-days and supply-chain campaigns.
For most organisations, most of the time, the answer is a phishing email. The sophisticated techniques this database records are what happens to organisations large enough to be worth the effort.
That is a genuine corrective to the corpus’s own emphasis, and it is consistent with the size-bias argument at 25-0613b.
Charities Reporting Less Is Probably Not Good News
32% against 50% could mean charities are attacked less. It could also mean they detect less — the same reading this desk applied to national comparisons at 25-1117 and 25-1206.
An organisation without monitoring reports fewer breaches, and 25-0614b records the sector describing its own resilience as insufficient. Graded high on the survey’s reliability; the interpretation of the gap is not established.
Built on published UK national survey data, listed below. The survey measures self-reported experience of breaches or attacks, which depends on detection. Corrections: corrections@forensicpost.com.
- Cyber security breaches survey findingsNI Cyber Security Centre
- The crucial role of cybersecurity for nonprofit organizations in 2025BDO