Phishing is still the number one threat to UK businesses — and it is beatable

The government's 2026 breaches survey found 43% of UK businesses were attacked in the past year, with phishing behind most of the damage. Here is what actually works against it, in order of effort.

Every year the Department for Science, Innovation and Technology publishes the Cyber Security Breaches Survey, and every year the headline is roughly the same: the attacks that hurt small and medium businesses are not clever. They are emails.

The 2025/26 edition, published on 30 April 2026, found that 43% of UK businesses identified a cyber attack or breach in the previous twelve months — around 612,000 companies. Among small businesses (10–49 staff) the figure was 46%; among medium businesses (50–249 staff) it was 65%. Phishing was by far the most common attack, reported by 38% of all businesses, and it accounted for 69% of the most disruptive breaches. Ransomware, the thing that makes the news, was reported by just 1%.

So if you run a business of 2 to 500 people, the threat you are most likely to face is a person being persuaded to click, type a password, approve a login, or pay an invoice. That is good news, because it is a problem you can do something about without a large budget.

What phishing looks like in 2026

The badly spelled email from a foreign prince is long gone. What lands in inboxes now is:

  • A login page that looks exactly like Microsoft 365 or Google Workspace. Often reached from a "shared document" or "voicemail" link. The page is a proxy: whatever you type, including the multi-factor code, goes straight to the attacker.
  • Invoice redirection. The attacker has quietly been reading a real mailbox — yours or a supplier's — for weeks. When a genuine invoice is due, a follow-up email arrives with "updated bank details". Nothing about it looks wrong because everything except the sort code is real.
  • MFA fatigue. The attacker has the password and repeatedly triggers the approval prompt on someone's phone at 11 pm until they tap "Approve" to make it stop.
  • The chief executive on the phone. Text messages or WhatsApp from "the boss" asking for gift cards, a quick transfer, or a change of payroll details. Increasingly, a convincing voice call.
  • QR codes in emails and on posters that take the phone — which usually sits outside the company's security tools — to the fake login page.

The common thread: the attack does not break technology, it borrows trust.

What works, in order of effort

1. Multi-factor authentication on everything — and the right kind

If you do one thing, do this. A password alone is no longer a lock. But not all second factors are equal:

  • Text-message codes are better than nothing but can be intercepted or phished.
  • App-based codes and push approvals are good, especially with "number matching" turned on, which defeats the MFA-fatigue trick.
  • Passkeys and security keys (FIDO2) are the gold standard: they are tied to the real website, so a fake login page simply cannot use them. Microsoft 365 and Google Workspace both support them now, and the 2026 Cyber Essentials guidance points firmly in this direction.

Since April 2026, Cyber Essentials requires MFA on all cloud services where it is available. If you want the certificate, this is no longer optional.

2. Make the fake pages harder to reach

Most modern email services can be tuned far beyond their defaults. Turning on the built-in protections — link scanning, attachment sandboxing, impersonation detection for your own senior names and your key suppliers — costs nothing extra in most Microsoft 365 Business Premium and Google Workspace tiers. It is the single most under-used setting we see.

Add SPF, DKIM and DMARC records to your domain. These stop criminals sending email that appears to come from your address, protecting your customers and suppliers and, in the process, your reputation. It is a DNS change, not a project.

3. A payment rule that cannot be phished

Technology does not stop invoice fraud; a process does. Adopt one rule and write it down: any change to bank details is confirmed by phone, using a number you already had, before a penny moves. Not the number on the email. Not a reply to the email. Every finance team we have seen lose money to invoice redirection had no such rule; every one that has the rule has caught an attempt.

4. Training that is short, regular and blame-free

An annual hour of slides does not change behaviour. What does is a few minutes every month or two — a real example that arrived that week, what gave it away, what to do. Simulated phishing emails can help if they are used to teach rather than to catch people out. Someone who is embarrassed for clicking will not report the next one; someone who is thanked for reporting will.

Make reporting effortless: a "Report" button in the email client, or simply forward to a known address. Speed matters. The attacker's window closes the moment IT knows.

5. Limit the blast radius

Assume, one day, someone will click. Then ask what the attacker gets:

  • Does that person have administrator rights they do not need? Remove them.
  • Is there a shared mailbox with a password everyone knows? Replace it with proper delegated access.
  • Are old accounts for people who left still active? Disable them.
  • Is there a backup that a compromised account cannot delete? There must be — see our 3-2-1 backup post for the principle; the business version is the same idea with more zeros.

6. Know what you would do

A one-page plan — who to call, how to reset every affected password, how to tell customers, whether you have cyber insurance and what its conditions are — turns a bad afternoon into a manageable one. Only 25% of businesses in the survey had a formal incident response plan (21% of micro businesses), which means most are working it out live, on the day.

What this costs

Less than people expect. Steps 1, 2, 3 and 5 are mostly configuration of things already paid for, plus an engineer's time. Step 4 is a habit. Step 6 is a document. The survey found that most incidents cost businesses little or nothing in direct terms — which sounds reassuring until you are the exception with a redirected invoice, a locked mailbox and a weekend nobody got back. Set against that, it is a very small number.

If you would like us to look at your Microsoft 365 or Google Workspace tenancy and tell you which of these are already on, which are off, and how long the gap would take to close, that is a fixed-price piece of work and we will put the findings in writing. Start with our cyber security overview or just get in touch.

Want this handled for your business?

A short conversation with an engineer — not a salesperson — is the fastest way to find out what you actually need.

Vision House, 3 Dee Road, Richmond TW9 2JN Registered UK company no. 09064078 No cookies, no trackers on this site