The Department for Science, Innovation and Technology and the Home Office published the Cyber Security Breaches Survey 2025/2026 on 30 April 2026. It is the eleventh edition of the official statistics release that benchmarks the state of cyber resilience across UK organisations, drawn from random-probability interviews with 2,112 businesses and 1,085 charities between August and December 2025.

The headline figure is that 43 per cent of UK businesses, and 28 per cent of UK charities, reported experiencing a cyber breach or attack in the prior twelve months. Extrapolated nationally, that is roughly 612,000 businesses and a further 57,000 charities. The numbers are sobering on their own. What gets lost in the cyber framing, however, is how often the entry point for these incidents is a physical or human one: a door held open, a badge cloned in a coffee shop, a contractor waved through reception, a USB device dropped in a car park. This is the part of the convergence story that boards routinely under-fund.

What the survey actually found

Phishing remains the dominant attack vector, reported by 38 per cent of all businesses and 25 per cent of charities. Among organisations that suffered any kind of breach, phishing was implicated in roughly 85 per cent of business incidents. Ransomware dropped to one per cent of survey participants, down from three per cent in each of the preceding two years, but the average financial impact has worsened. Reported loss of revenue or share value rose from two per cent to five per cent of breached businesses, and reported reputational damage rose from one per cent to three per cent.

On governance, board-level responsibility for cyber security increased from 27 per cent to 31 per cent across all businesses, reversing five years of decline. In large businesses the figure is 68 per cent. Formal cyber strategies are in place at 57 per cent of medium businesses and seven in ten large businesses. Supply chain oversight, however, remains weak: only 15 per cent of businesses review the cyber risk posed by immediate suppliers, and just six per cent extend that review to the wider supply chain.

AI adoption is now a flagged concern in the survey for the first time at this scale. Of the organisations using, adopting, or considering AI tools, only around a quarter say they have security practices in place to manage the associated risks.

The physical-security thread the headlines miss

Read the survey closely and the picture is not of a purely digital attack surface. Phishing campaigns, the most common cause of breach, rely on a target organisation being legible from the outside: org charts on LinkedIn, names on lanyards visible through reception glass, badge designs photographed by visitors, contractor uniforms reused on second-hand sites. Each of these is a physical-security control point.

Three patterns we see repeatedly on commercial sites in London map directly onto the survey’s findings:

  • Tailgating at controlled-access lobbies. An unbadged visitor, often well-dressed and carrying a coffee, follows an employee through a card-reader door. Once inside, the attacker can plug a rogue device into a meeting-room ethernet port, photograph a whiteboard, or simply walk to a server-room door and probe it. A trained reception officer who actively challenges visitors, rather than waving them through, removes this category of risk almost entirely.
  • Server-room and comms-room access discipline. Physical access to networking equipment is a near-total bypass of cyber controls. Many sites we audit have comms rooms whose doors are propped open during contractor visits, or whose access lists have not been reviewed in years. The Survey’s emphasis on supply-chain risk applies here in the most literal sense: a cleaner, an HVAC engineer, or a fibre installer who is not vetted and supervised is a privileged-access risk.
  • Badge and uniform cloning. Lanyards photographed at events, uniforms bought second-hand, and high-vis vests purchased online turn a stranger into a plausible insider within minutes. Officers who know their staff list by sight, and who insist on radio-confirmation for unfamiliar visitors, are an inexpensive but effective control.

What this means for boards and security leads

The Survey’s data on board engagement is encouraging, but a 31 per cent figure also means more than two-thirds of UK businesses still do not assign cyber security at board level. For those that do, the practical question is whether the board’s mandate covers physical access controls as part of the cyber estate, or whether the two are still being treated as separate budgets reporting to different functions.

For organisations reviewing their posture in light of the 2025/2026 figures, our team would suggest four concrete steps:

  • Audit physical access to any room containing networking, server, or critical-systems equipment. Verify that access lists are current and that contractor access is logged and supervised.
  • Brief reception and front-desk officers on social-engineering tactics specifically. Tailgating, pretexting, and uniform impersonation should be drilled, not just covered in induction.
  • Review the supply-chain controls applied to physical-security contractors: cleaners, maintenance, deliveries, and engineers. The 15 per cent figure in the Survey is a national average; the better number is what your own organisation actually does.
  • For sites adopting AI tools, ensure the physical environment around AI infrastructure (on-premise servers, model-training hardware, edge devices) is treated as critical asset infrastructure from day one rather than retrofitted later.

The convergence between cyber and physical security is no longer a forward-looking talking point. The DSIT figures show it is the current operating environment for every UK business of meaningful size. Investing in cyber tooling while leaving the front door, the comms-room door, and the reception desk under-resourced is a false economy, and it shows up in the breach numbers.

Need a security review?

Our SIA-approved team works with corporate clients across London on integrated physical-security programmes that complement existing cyber-security investment. We can audit access controls, brief reception and guarding teams on social-engineering threats, and provide vetted manned guarding for sensitive sites.

To discuss a security review of your premises, call us on 020 3700 0967, email info@secureonsitesecurity.co.uk, or visit our contact page.

Related services: corporate security, manned guarding.

Loading...
Share This