SME Business Cyber Security: 2026 Breach Data
Small business cyber security slipped back this year. What the government's Cyber Security Breaches Survey shows, and what SMEs should fix first.
4 min read
Adam Nichols : Updated on October 5, 2026
In the first hour after a cyber attack, call your IT partner and disconnect affected devices from the network without switching them off. Then start a written log of everything that happens, because every decision after this one depends on it.
Most small businesses will be making it up as they go. According to the government's Cyber Security Breaches Survey 2025/2026, only 25% of UK businesses have a formal incident response plan, and 45% have none of the basic measures in place, such as named roles or guidance on who to notify. One charity summed up its approach to the researchers in five words: it would "probably play it by ear".
This guide is the plan for the first 60 minutes, written for the Office Manager or director who ends up holding it.
The first thing to do is call your IT partner or incident response contact, before you touch anything else.
Every instinct says to start fixing things. Resist it. Deleting files or restoring from backup can wipe out evidence of how the attacker got in, and let them back in afterwards. Your IT partner needs to see the systems as they are.
If a business, charity or organisation is suffering a live attack in progress, Report Fraud (which replaced Action Fraud) asks you to call 0300 123 2040 immediately. In Scotland, call Police Scotland on 101.
No, in most cases you should disconnect an affected computer from the network but leave it switched on.
Unplug the network cable and turn off Wi-Fi. That stops the attack spreading to other machines and cuts the attacker's connection. Powering down, by contrast, can destroy information held in memory that investigators need. The NCSC's guidance on the first hours of an attack describes this as a trade-off, which is exactly why the call to your IT partner comes first. If ransomware is actively encrypting files and you can't reach anyone, shutting down to stop it is the lesser evil.
In the first hour, tell your IT partner and your directors, then check what your cyber insurer needs from you.
Two other deadlines start ticking. If personal data may have been affected, UK GDPR requires you to report it to the ICO within 72 hours of becoming aware, where the breach poses a risk to people. And fraud or cyber crime should be reported to Report Fraud.
The NCSC and UK law enforcement advise against paying a ransom, because payment doesn't guarantee you'll get your data back and marks you out as a business that pays.
Don't reply to the attackers or open negotiations in the first hour either. That decision belongs to your directors, your insurer and your incident responders together. It helps to have made it in advance. 49% of UK businesses have a policy not to pay ransomware demands, and 24% don't know what their policy is.
You keep running by switching to the backup ways of working set out in your business continuity plan, and by communicating through channels the attacker can't see.
Assume your email is compromised until you're told otherwise. Move incident conversations to phone calls or a separate messaging group on personal phones. Then work out what the business needs to keep going today. Can staff take orders by phone? Can invoices wait a day? Who needs to be told their delivery may be late?
This is where a business continuity plan earns its keep. If you don't have one, our disaster recovery and business continuity service will help you build one before you need it.
Write down what happened, when, who noticed and every action taken since, with times against each entry.
Use paper or a device that isn't connected to your network. Screenshots of ransom notes or strange messages help too, taken on a phone if necessary. The NCSC recommends keeping one central record of what's been found and decided. Your insurer will ask for it, and so might the ICO.
SMEs prepare by writing a short incident response plan and practising it with the team at least once a year. Keep a printed copy, because your network may be down when you need it.
A good cyber incident response for SMEs doesn't need a 50-page document. One page covering who to call, who decides, who talks to clients and where the backups are will do more than a manual nobody reads. Then test it. The NCSC's free Exercise in a Box walks your team through realistic scenarios, including ransomware and phishing.
Testing pays off. One large business in the survey ran its test as a Dungeons & Dragons-style tabletop game and came away with questions nobody had thought to ask. Another admitted its untested plan "keeps me awake at night".
For Noble IT clients, the first call in that first hour is to us. Our 24/7 cyber security monitoring often spots an attack before anyone in the office does, and we already know your systems. You carry on with your day, or as close to it as possible.
Don't know who you'd call right now? Not sure your backups would survive an attack? A 360 Review will give you a clear answer. No obligations.
Statistics and quotes: Cyber Security Breaches Survey 2025/2026, Department for Science, Innovation and Technology and the Home Office, published 30 April 2026.
Share this article:
Small business cyber security slipped back this year. What the government's Cyber Security Breaches Survey shows, and what SMEs should fix first.
Is your business prepared for the growing cyber threat landscape? Learn about the latest cyberattacks like phishing, ransomware, and social...
Uncover today's 5 top cyber threats. Boost your defense with our 'Navigating the Cybersecurity Landscape' guide.