This publication is licensed under the terms of the Open Government Licence v3.0 except where otherwise stated. To view this licence, visit nationalarchives.gov.uk/doc/open-government-licence/version/3 or write to the Information Policy Team, The National Archives, Kew, London TW9 4DU, or email: [email protected] .
Where we have identified any third party copyright information you will need to obtain permission from the copyright holders concerned.
This publication is available at
This Technical Annex provides the technical details of the Cyber Security Breaches Survey 2025/2026. It covers the quantitative survey (fieldwork carried out between August and December 2025) and qualitative element (carried out between October and November 2025), and copies of the main survey instruments (in the appendices) to aid with interpretation of the findings.
The annex supplements a main Statistical Release published by the Department for Science, Innovation and Technology (DSIT), covering this year’s results for businesses and charities.
There is another Education Institutions Findings Annex , available on the same GOV.UK page, that covers the findings for schools, colleges and universities.
The Cyber Security Breaches Survey is a research study on UK cyber resilience. It is primarily used to inform government policy on cyber security, making the UK cyberspace a secure place to do business. The study explores the policies, processes and approach to cyber security, for businesses, charities and educational institutions. It also considers the different cyber breaches or attacks and cyber crimes these organisations face, as well as how these organisations are impacted and respond.
For this latest release, the quantitative survey and qualitative interviews were carried out between August and December 2025.
Responsible statisticians :
cybersurveys@dsit.gov.uk
As in years, there were two strands to the Cyber Security Breaches Survey:
Sole traders and public-sector organisations (with the exception of educational institutions) were outside the scope of the survey. In addition, businesses with no IT capacity or online presence were deemed ineligible. These exclusions are consistent with years of the survey.
The survey methodology for this year’s survey is consistent with last year’s survey. Minor changes were made to last year’s questionnaire, as well as some new questions added. These changes are detailed in Chapter 2 in the section ‘Changes made to the questionnaire for the 2025/2026 survey’.
For this year’s survey, DSIT and the Office (HO) decided to update the naming convention used for reference periods for the Cyber Security Breaches Survey from a single year label (e.g. CSBS 2025) to a dual-year format (that is, CSBS 2025/2026 or CSBS 2025 to 2026). This change aims to reduce confusion, as previously the survey’s title aligned with the year of publication but did not typically align with when the fieldwork was conducted, potentially misleading users the timeframe of the findings. The dual-year approach reflects common UK government reporting practices, especially for activities spanning two calendar years or fiscal years.
Table 1.1 maps how CSBS surveys and fieldwork periods relate to the labelling convention in this year’s report.
While there have been other surveys cyber security in organisations in recent years, these have often been less applicable to the typical UK business or charity for several methodological reasons, including:
The 2025/2026 survey shares the same strengths as surveys in the series:
At the same time, while this survey aims to produce the most representative, accurate and reliable data possible with the resources available, it should be acknowledged that there are inevitable limitations of the data, as with any survey project. The following might be considered the main limitations:
Questions on cyber crime, and on fraud that occurs as a result of cyber breaches or attacks (i.e. cyber-facilitated fraud) [footnote 4] in UK organisations were introduced for the first time in the 2022/2023 survey. These questions were re-drafted significantly for the 2023/2024 survey to make questions clearer and responses more accurate. For the 2024/2025 survey, only minor edits were made to the cyber crime questions to aid accuracy. These changes were overseen by both DSIT and the Office. More detail on these changes can be found in Section 2.1 of this annex.
The survey includes estimates for:
The survey approaches these estimates in a similar way to existing official estimates of crime against individuals. This includes police-recorded crime as well as the estimates from the general public Crime Survey for England and Wales (CSEW), both of which follow the Office Counting Rules . The approach aims to be as robust as possible, in the following ways:
Whilst it does remain methodologically challenging to achieve robust estimates of cyber crime via a survey method, we are able to compare this year’s results for cyber crime and cyber crime costs against the baseline in 2023/2024 and against the 2024/2025 results.
We are unable to compare cyber crime results to any wave before 2023/2024 due to significant changes made to the cyber crime section of the questionnaire in 2023/2024.
The 2025/2026 questionnaire included a new question to capture the perceived costs associated with phishing cyber crime. Phishing cyber crime costs have therefore been merged into the overall crime cost variable ( crimecost_num ) and the crime cost variable that excludes any costs from fraud ( notfraudcost_num ) in the dataset. A new variable has been created to allow for comparison with years ( notfraudORphishcost_num ) which includes cyber crime costs excluding costs from fraud of phishing cyber crime.
The questionnaire changes between 2023/2024 and 2024/2025 did include some edits to the questions used to obtain cyber-facilitated fraud estimates. The questions were changed to ask organisations to specifically include instances of fraud that occurred as a result of phishing attacks. On this basis, whilst we are able to compare the latest 2025/2026 results against the last wave in 2024/2025, we are unable to directly compare cyber-facilitated fraud estimates, including prevalence and cost, to 2023/2024.
The cyber crime statistics should ideally be considered alongside other, related evidence on computer misuse, such as the Crime Survey for England and Wales (CSEW) . The CSEW and Cyber Security Breaches Survey are not directly comparable, as the CSEW does not look at crime against organisations and excludes Scotland and Northern Ireland. However, it does provide a benchmark for the scale of cyber crime against individuals in England and Wales, to help contextualise the equivalent results for UK organisations in this survey.
One of the objectives of the survey is to understand how approaches to cyber security and the cost of breaches are evolving over time. Therefore, the methodology is intended to be as comparable as possible to surveys in the series.
The core approach of a random-probability survey, predominantly conducted by telephone remains unchanged in 2025/2026. We therefore are able to continue to make comparisons to years.
This year a single change was made to the weighting approach for businesses. In years of the survey, business data was weighted by size and sector. This year some regions (including the Devolved Nations and the North East) were oversampled to boost interviews in these regions and allow for more robust analysis by region. Consequently, this year region weighting was also applied to businesses (as well as size and sector) to ensure that the region profile of businesses matched the overall UK business population. In years of the survey there was no need to weight businesses by region as the sample was proportionately stratified by business region and consequently interviews were achieved roughly in line with the regional profile of the UK business population. As such, we are still able to make comparisons to years where questions have remained the same or very similar.
The following points cover major changes or additions to the study that have been made in years:
From 2012 to 2015, the government commissioned and published annual Information Security Breaches Surveys. [footnote 6] While these surveys covered similar topics to the Cyber Security Breaches Survey series, they employed a radically different methodology, with a self-selecting online sample weighted more towards large businesses. Moreover, the question wording and order is different for both sets of surveys. This means that comparisons between surveys from both series are not possible.
The survey results for businesses and charities are weighted to be representative of the respective UK population profiles for these organisations. The education institution samples are unweighted, but these groups are included as simple random samples, i.e. without any disproportionate stratification. As such, they are also considered to be representative samples. Therefore, it is theoretically possible to extrapolate survey responses to the wider population (with the exception of the financial cost data, as explained at the end of this section).
We recommend accounting for the margin of error in any extrapolated results. Table 1.2 shows the overall margins of error (MoE) for the sampled groups in the survey, for different survey estimates. Margins of error are calculated using finite population correction (FPC) which is an adjustment that reduces the standard error (and thus the margin of error) when you sample a sizable fraction of a finite population without replacement.
As a worked through example, the overall business sample this year has a margin of error range of ±1.6 to ±2.6 percentage points depending on the prevalence or extremity of a response, based on a 95% confidence interval calculation. That is to say, if we were to conduct this survey 100 times (each time with a different sample of the business population), we would expect the results to be within 1.6 to 2.6 percentage points of the results we achieved here in 95 out of those 100 cases. The table below showing the expected ranges illustrates that survey results closer to a 50/50 response tend to have higher margins of error. This happens because the standard error is largest when the sample proportion is around 50%. If 90% of surveyed businesses said cyber security is a high priority for their senior management, this result would have a margin of error of ±1.6 percentage points, whereas if only 50% said this, the margin of error would be ±2.6 percentage points. The margins of error are calculated using the effective sample sizes (which take into account survey weighting). Figures are only reported on in the main report for effective sample sizes of 30 and above [footnote 7] . Where base sizes are shown on charts or in tables the unweighted base size is quoted to indicate the number of organisations that responded at the relevant question.
For questions only asked to half of respondents in our split-sampled questions, we have also included MoE calculations. Where the business and charities samples are roughly half of the size of the total cases, we have used the lower sample size of the two split-samples. For example, where the business questions are split-sampled, some questions were asked to a randomly selected 1,051 business respondents out of the total 2,112 (Half A) whereas some questions were asked to the remaining 1,061 (Half B). We have calculated the MoE for the 1,051. For charities Half A was made up of 530 charities and Half B was made up of 555 charities. We have calculated MoE for the 530.
When reporting on sub-groups, we note whether or not results from sub-groups differ in a statistically significant way, both against other sub-groups and against the total (minus the sub-group in question). Statistical significance testing is used to determine whether differences in results are likely to be due to a genuine difference between groups, as opposed to chance variation. The threshold used in the main report is the 95% level of confidence, meaning there is less than a 5% chance that results deemed significantly different differ due to chance. This is a standard level of significance used in social sciences. The test used to determine statistical significance is a two-tailed t-test.
The total population sizes for each of these sample groups are as listed below. It should be noted that the population databases referenced here are live and updated regularly and the population figures were accurate as of June and July 2025, ahead of starting fieldwork.
202,539 UK registered charities (combining the lists of registered charity databases, downloaded in June and July 2025 as part of sample preparation for the survey, across England and Wales [footnote 10] that contained 170,931 charities, Scotland [footnote 11] that contained 24,656 charities and Northern Ireland [footnote 12] that contained 6,952 charities)
As the samples for each group are statistically representative, it is theoretically possible to extrapolate survey results to the overall population.
Where extrapolated figures for prevalence and the number of crimes experienced are shown in the main report, they are based on the estimated total population of businesses with employees (1,417,730 according to the Department for Business and Trade Business Population Estimates 2025 Table 1) and the total number of registered UK charities (202,539 when combining the charity registers for England and Wales, Northern Ireland and Scotland). Any extrapolated figures are rounded to three significant figures (or to the nearest thousand, if under 1 million) and unrounded weighted prevalence estimates to one decimal place are used. For number of cyber crimes experienced, the weighted average number of cyber crimes rounded to two decimal places are also used.
We recommend restricting any extrapolation of results to the overall business and charity populations rather than to any subgroups within these populations. The sample sizes for subgroups in our survey are smaller than the overall sample sizes for businesses and charities and consequently have higher margins of error. Similarly, the sample sizes for education institutions are small and have relatively high margins of error (see Section 1.7). For example, the margin of error on a result of 50% for Higher education institutions is ±11.9. This compares to a margin of error on a result of 50% for businesses of ±2.6.
Any extrapolated results should be clearly labelled as estimates and, ideally, should be calibrated against other sources of evidence.
We specifically do not consider the financial cost estimates from this survey to be suitable for this sort of extrapolation (e.g. to produce a total cost of cyber incidents, cyber crime or cyber-facilitated fraud for the UK economy). These estimates tend to have a high level of statistical standard error, and low base sizes, so the margins of error for any extrapolated cost estimate are likely to be very wide, limiting the value of such an estimate.
If you wish to use extrapolated Cyber Security Breaches Survey data as part of your analysis or reporting, then we would encourage you to DSIT via the cyber surveys mailbox: cybersurveys@dsit.gov.uk .
The questionnaire content is largely driven by the Cyber Resilience team at DSIT, alongside the Office (which has co-funded the study since 2022/2023). The questions are designed to provide evidence on UK cyber resilience, and influence future government policy and other interventions in this space.
Ipsos developed the questionnaire and all other survey instruments (e.g. the interview script and briefing materials) with DSIT and the Office. DSIT had final approval of the questionnaire. A full copy is available in Appendix A.
Each year, Ipsos has consulted a range of industry stakeholders, to ensure that the Cyber Security Breaches Survey continues to explore the most important trends and themes that organisations are grappling with when it comes to cyber security. This includes the Association of British Insurers (ABI) and techUK, who were consulted this year and agreed to endorse the survey. Similarly, DSIT and the Office, have consulted a range of stakeholders across government, such as the National Cyber Security Centre (NCSC).
Separately, Ipsos and DSIT engaged with two stakeholders that had relationships with cyber security professionals in the further and higher education sectors Jisc (a membership organisation of individuals in digital roles within the further and higher education sectors) and UCISA (formerly known as the Universities and Colleges Information Systems Association). These organisations subsequently encouraged their members and contacts to take part in the survey, promoting the online survey link created by Ipsos (see Section 2.4).
The main changes to the 2025/2026 questionnaire centred on four main areas, described in more detail below:
The following questions were added as new questions for 2025/2026:
The following additional check questions were also added to validate the data provided during the interview, these included:
Wording updates or addition of new codes to questions included:
Routing changes to the questionnaire included:
The 2024/2025 wave data checking process revealed that several responses to numerical questions in the survey (such as for number of breaches and attacks) were being capped at 999, based on an assumption that it was unlikely to be credibly higher than this and that introducing a cap of this nature would decrease the chance of data input errors (adding erroneous zeros for example). However, a review of the 2024/2025 data indicated that in 12 instances respondents had attempted to give an answer higher than 999 but the interviewer had been forced to input 999 as the response.
A systematic review of all numerical caps in the survey was therefore undertaken and edits to the numerical caps at the following questions were made:
Each year, this survey series has attempted to capture the perceived cost of cyber security breaches or attacks, cyber crime and cyber-facilitated fraud on organisations.
This year, we have stopped reporting the mean costs. Given the distribution of cyber impacts is highly skewed and subject to high sampling error this is not a robust statistical indicator. It can also create a disclosure risk where a dominant of the total cost is from a limited number of organisations.
The median perceived cost is presented, alongside the 25th-75th percentile range where most cases fall, the top 10% of cases (90th percentile) and the top 5% of cases (95th percentile).
There has been a small change in the statistical methodology [footnote 23] used to calculate the median.
The following minimum effective base sizes have been adhered to when reporting percentiles:
Historically, the Cyber Security Breaches Survey used the Government Office Region (GOR) classification to assign businesses to regions. During the 2025/2026 survey the lookup used to assign addresses to regions was found to be outdated and based on Standard Statistical Regions (SSRs) used prior to the introduction of GOR regions. GOR region classification has now been superseded by International Territorial Levels (ITL) as the recognised UK regional classification [footnote 24] . The International Territorial Levels (ITLs) adopt a convention used by the Organisation for Economic Co-operation and Development (OECD) member countries and therefore align with international standards, enabling comparability internationally. Therefore, ITL level 1 (ITL1) region groupings, with the most updated postcode lookups to assign addresses to regions, was used for the 2025/2026 survey, and will be used for future waves of the survey.
The Ipsos research team carried out 8 cognitive testing interviews with businesses, charities and schools between the 7th and 15th of July 2025. These interviews focused on the new questions added for the 2025/2026 wave.
Table 2.2 shows how these cognitive interviews broke down by organisation type and size.
All interviews were conducted via MS Teams or over the telephone and took around 45 minutes to complete. The sample source was organisations that took part in the iteration of the survey and gave permission to be recontacted for subsequent research on cyber security over the 12 months. We offered £50 incentive [footnote 25] to ensure participation from different-sized organisations and as a thank you for taking part.
The cognitive testing highlighted some improvements that could be made to the new questions. These can be summarised as follows:
The pilot survey was used to:
Ipsos interviewers carried out all the pilot fieldwork by phone between the 4th and 6th August 2025. Ipsos applied quotas to ensure the pilot covered different-sized businesses from a range of sectors, charities with different incomes and from different countries. Education institutions were not included in the pilot because it was being conducted in August, which is outside of term time for these organisations. We carried out 22 interviews, as shown in Table 2.3 .
The pilot sample came from the same sample frames used for the main stage survey (see section).
Following the same approach as in years, the pilot was used as a soft launch of the main fieldwork. While quotas were initially applied to achieve the pilot interviews, the remaining pilot sample was subsumed into the main survey and fully worked alongside the other sample batches, following a strict random probability approach. Moreover, there were no substantial post-pilot changes to the questionnaire and the 22 pilot interviews were counted as part of the final data.
The average interview length for the pilot was 23 minutes, one minute above target for the main stage (22 minutes). A few minor amendments were made to the survey questions following the pilot, based on interviewer feedback and the need to reduce the survey length. Minor changes were made at the following three questions:
As in years, a similar GOV.UK page was used to provide reassurance that the survey was legitimate and provide more information before respondents agreed to take part.
Interviewers could refer to the page at the start of the telephone call, while the reassurance emails sent out from the CATI script (to organisations that wanted more information) included a link to the GOV.UK page.
The target population of businesses largely matched those included in all the surveys in this series, i.e. private companies or non-profit organisations [footnote 26] with more than one person on the payroll.
The survey is designed to represent enterprises (i.e. the whole organisation) rather than establishments (i.e. local or regional offices or sites). This reflects that multi-site organisations will typically have connected digital devices and will therefore deal with cyber security centrally.
The sample frame for businesses was the Market Location database which covers businesses in all sectors across the UK at the enterprise level. It is compiled from a mix of public business directories, Companies House data and call centre activity. It is not only a clean database but also high quality; over 10,000 calls are made daily to validate numbers, with each record (telephone, email and senior name) having been validated within a rolling 12-month period.
With the exception of universities, public sector organisations are typically subject to government-set minimum standards on cyber security. Moreover, the focus of the primary sample in the survey was to provide evidence on businesses’ engagement, to inform future policy for this audience. Public sector organisations (Standard Industrial Classification, or SIC, 2007 category O) were therefore considered outside of the scope of the survey and excluded from the sample selection.
In line with the year, businesses listed as having just 1 employee were eligible to take part in the survey (only 0-employee businesses were excluded entirely). However, given that many businesses listed as having 1 employee on business databases were found to have 0 employees, the sampling was only done on businesses listed as having 2 or more employees. This helped to avoid an unreasonably high ineligibility rate during fieldwork.
The target population of charities was all UK registered charities. The sample frames were the charity regulator databases in each UK country:
In England and Wales, and in Scotland, the respective charity regulator databases contain a comprehensive list of registered charities. DSIT was granted access to the non-public OSCR database, including telephone numbers, and a random sample of Scotland-based charities was generated.
The Charity Commission in Northern Ireland does not yet have a comprehensive list of established charities but has been registering charities and building its list over the past few years. Alternative sample frames for Northern Ireland, such as the Experian and Dun & Bradstreet business directories (which also include charities) have been considered in years, and ruled out, because they do not contain essential information on charity income for sampling and cannot guarantee up-to-date charity information.
Therefore, while the Charity Commission in Northern Ireland database was the best sample frame for this survey, it cannot be considered as a truly random sample of Northern Ireland charities at present and is updated on a regular basis. This year, there was a small decline in the number of registered charities on the database compared to 2024/2025 and 2023/2024. This year there was 6,952 registered charities on the Northern Ireland database [footnote 27] at the point of drawing sample, compared to 7,216 in the 2024/2025 survey, 7,157 in the 2023/2024 survey, 6,880 in the 2022/2023 survey and 6,438 in the 2021/2022 survey.
Primary and secondary schools and further education colleges in this survey are all public sector, publicly funded organisations. Higher education institutions in this survey are considered publicly funded organisations but are not government owned and typically operate independently. Private educational institutions are included in the business sample.
The education institutions sample frame came from the following sources:
Given the significant differences in size and management approaches between different types of education institutions, we split the sample frame into four independent groups:
In order to avoid disclosure, we do not include any information the specific school type (beyond fitting responses into the primary or secondary school bracket) in the published data or SPSS file.
In total, 60,011 businesses were selected from the Market Location database for the 2025/2026 survey.
The business sample was disproportionately stratified by size, sector and region. An entirely proportionately stratified sample would not allow sufficient subgroup analysis by size and sector. For example, it would effectively exclude all medium and large businesses from the selected sample, as they make up a very small proportion of all UK businesses according to the Department for Business and Trade Business Population Estimates 2025 Table 1. Therefore, we set disproportionate sample targets for micro (1 to 9 employees), small (10 to 49 employees), medium (50 to 249 employees) and large (250 or more employees) businesses. We also boosted specific sectors and regions, to ensure we achieved robust effective base sizes in these groups, they included:
Post-survey weighting corrected for the disproportionate stratification (see Section 2.6).
Table 2.4 breaks down the selected business sample by size and sector.
The charity sample was proportionately stratified by country and disproportionately stratified by income band, using the respective charity regulator databases to profile the population. This used the same reasoning as for businesses as without this disproportionate stratification, analysis by income band would not be possible as hardly any high-income charities would be in the selected sample. In addition, having fewer high-income charities in the sample would be likely to reduce the variance in responses, as high-income charities tend to take more action on cyber security than low-income ones. This would have raised the margins of error in the survey estimates.
As the entirety of the three charity regulator databases were used for sample selection, there was no restriction in the amount of charity sample that could be used, so no equivalent to Table 2.3 is shown for charities.
Similarly, the entirety of the state education institution databases was available for sample selection, so no equivalent table is shown for education institutions.
Not all the original samples were usable. In total:
We expect the unusable sample does not bias our estimates.
Ipsos undertook significant sample improvement work, using their sampling partners to match the samples to data from organisations’ websites, publicly available pages and other social media, and Companies House data, to add in the names and job titles of relevant individuals within the business, as well as email addresses where available, in order to maximise our ability to get past gatekeepers (e.g. receptionists) and reach the appropriate individual in the organisation.
At the same time as this survey, Ipsos was also carrying out two other surveys with a potentially overlapping sample of businesses and charities: the DSIT Cyber security skills in the UK labour market research and the Cyber Security Longitudinal Survey. We therefore flagged overlapping sample leads across surveys, so telephone interviewers could avoid contacting the same organisations in quick succession for both surveys and minimise the burden on respondents. Similarly, Ipsos flagged and excluded business and charity sample leads that had recently completed the DSIT survey in order to minimise the burden on respondents.
Following cleaning to remove unusable or duplicate numbers, the usable sample amounted to:
Table 2.5 breaks the usable business leads down by size and sector, for the business sample. As this shows, around 9 in 10 business records across the total sample were usable. This compares to around 82% usable records among charities and 81% usable records among education institutions.
For businesses and charities, the usable sample for the main stage survey was randomly allocated into batches. The first batch had 21,537 business records and 6,800 charity records.
The selection counts were modelled according to two criteria:
For primary and secondary schools, we selected simple random sample batches of each group. In the first batch, this amounted to 1,680 primary schools and 2,000 secondary schools.
The colleges and higher education institutions sample was released in full at the start of fieldwork (i.e. we carried out a census of these groups, only excluding records where there was no valid telephone number, or numbers were duplicated).
Subsequent sample batches were selected according to the same criteria, updated with the remaining interview targets and response rates achieved up to that point. For businesses four batches were released throughout fieldwork and for charities and education institutions, two batches were released throughout fieldwork. We aimed to maximise the response rate by fully exhausting the existing sample batches before releasing additional records. This aim was balanced against the need to meet interview targets, particularly for boosted sample groups (without setting specific interview quotas).
We did not use all the available (and usable) records for businesses, charities, primary schools and secondary schools. The remaining records were held in reserve.
Over the course of fieldwork, we used:
Ipsos carried out all main stage fieldwork from 11th August 2025 to 12th December 2025, a fieldwork period of 18 weeks.
In total, we completed interviews with 3,774 organisations:
The average interview length was around 24 minutes across all groups.
In 2022/2023 the survey method was changed to multimode, allowing respondents to take part either by telephone or online.
In practical terms, the multimode methodology worked as follows for businesses, charities, and primary and secondary schools:
For further and higher education institutions, a further option was available. Ipsos created an open link to the online survey to be disseminated by Jisc and UCISA representative bodies for individuals working in IT and cyber roles in colleges and universities to their members. In total, 28 higher education institutions and 1 further education institution took part in the survey via this open link, an increase from 14 higher education institutions and 1 charity in the 2024/2025 wave of the survey. The surveys completed via the open link are included in the online interviews column in Table 2.6 .
In total, 225 interviews were completed using the online survey option, which represents 6% of the 3,774 total interviews. This remains in line with last year’s 2024/2025 survey where 6% of interviews were also conducted online.
Table 2.6 shows how this is split across the different sample groups:
Ipsos made the following efforts to monitor and maintain the quality of the online interviews, and reduce the possibility of mode differences in the responses:
Prior to fieldwork, the Ipsos research team briefed the telephone interviewing team in a video call. They also received:
Telephone interviewers screened all sampled organisations at the beginning of the call to identify the right individual to take part and ensure the business was eligible for the survey. At this point, the following organisations would have been removed as ineligible:
As this was a survey of enterprises rather than establishments, interviewers also confirmed that they had called through to the UK head office or site of the organisation.
At this point, interviewers specifically asked for the senior individual with the most responsibility for cyber security in the organisation. The interviewer briefing materials included written guidance on likely job roles and job titles for these individuals, which would differ based on the type and size of the organisation.
For UK businesses that were part of a multinational group, interviewers requested to speak to the relevant person in the UK who dealt with cyber security at the company level. In any instances where a multinational group had different registered companies in Great Britain and in Northern Ireland, both companies were considered eligible.
Franchisees with the same company name but different trading addresses were also all considered eligible as separate independent respondents.
We adopted random probability interviewing to minimise selection bias. The overall aim with this approach is to have a known outcome for sample record loaded. For this survey, an approach comparable to other robust business surveys was used around this:
We took several steps to maximise participation in the survey and reduce non-response bias:
Ipsos is a member of the interviewer Quality Control Scheme recognised by the Market Research Society. In accordance with this scheme, the field supervisor on this project listened into at least 10% of the interviews and checked the data entry on screen for these interviews.
We monitored fieldwork outcomes and response rates throughout fieldwork, and interviewers were given regular guidance on how to avoid common reasons for refusal. Table 2.7 shows the final outcomes, the response rate and the response rate adjusted for unusable or ineligible records, for businesses and charities. The approach for calculating these figures is covered later in this section.
The fieldwork outcomes for state education institutions are shown in Table 2.8 .
The following points explain the specific calculations and assumptions involved in coming up with these response rates:
The adjusted response rates for all the sampled groups, outside of higher education institutions, are lower than in earlier iterations of this study, that took place before the COVID-19 pandemic. For example, the adjusted response rates for the last survey in this series that took place before the pandemic (CSBS 2020) were 27% for businesses and 45% for charities.
The lower response rates compared to historic years are likely to be due to a combination of unique circumstances, including:
More generally, there has been an increasing awareness of cyber security, potentially making businesses more reticent to take part in surveys on this topic.
Furthermore, the increase in the survey length from c.17 minutes in 2020 and earlier iterations, to just under 23 minutes in 2023 onwards is also expected to have reduced the response rate interviewers must mention the average length to respondents when they introduce the survey, and respondents are naturally less inclined to take part in longer interviews.
It is also likely that the running of three other DSIT surveys in parallel to CSBS 2025/2026 may have impacted the performance of this survey. Ipsos undertook the fieldwork for both the Cyber Security Longitudinal Survey and the Cyber security skills in the UK labour market survey [footnote 29] , which both ran between July and October 2025. Whilst every effort was made to keep the samples between these jobs independent, in some groups with a small population, such as large businesses, this was not possible. Organisations that were sampled for more than one of these surveys may have been contacted for Cyber Security Breaches Survey after being contacted for one of the other surveys and may have been less likely to take part as a result.
However, it is important to remember that response rates are not a direct measure of non-response bias in a survey, but only a measure of the potential for non-response bias to exist. research into response rates, mainly with consumer surveys, has indicated that they are often poorly correlated with non-response bias. [footnote 30]
There were a number of logic checks in the CATI script, which checked the consistency and likely accuracy of answers estimating costs and time spent dealing with breaches. If respondents gave unusually high or low answers at these questions relative to the size of their organisation, the interviewer would read out the response they had just recorded and double-check this is what the respondent meant to say. This meant that, typically, minimal work was needed to manually edit the data post fieldwork.
Nonetheless, individual outliers or errors in the data can heavily affect cyber breach cost and frequency estimates. Therefore, the research team manually checked the final data at these variables for outliers. For each cost and frequency question where numerical data was collected, the data was sorted in descending order in an Excel export of the SPSS file to identify unusually high or low and therefore potentially illegitimate responses. The definition of unusually high or low was purposive rather than based on a specific threshold to ensure that all potential outliers were considered.
A total of 5 potential outliers or errors were flagged for warranting further investigation. The recordings of these interviews were listened back to in order to assess whether the answer recorded in the data was accurate and then cross-referenced against business size and charity turnover (where relevant), as well as cross referenced against other answers provided in the survey. Our findings were flagged to DSIT and the Office, so they could have the final say as to whether we kept these responses in or edited them.
This year, we made edits to the responses of 2 organisations, as detailed below:
The final SPSS data uploaded to the UK Data Archive will reflect the above edits.
During the Cyber Security Breaches Survey 2025/2026, a scripting error at code D (fraud3) for Q88A_FRAUD (How many times, if at all, any of these cyber security breaches or attacks resulted the organisation paying or transferring money to the attackers based on fraudulent information) resulted in 493 respondents not being asked this question and associated downstream questions. The immediate remedy was to deploy a callback script to re- these respondents and administer any missing questions. This process recovered most cases (72%), and their missing answers were merged back into the dataset. However, 140 respondents had either declined to be called back or could not be reached by Ipsos telephone interviewers.
Ipsos considered imputation of responses to the relevant variables, which would involve replacing missing responses with plausible values inferred from observed data. The primary drawback of applying imputation in this instance was the risk of introducing bias into the survey data model given it would require assumptions on missing responses that may not hold true. In addition, the expected benefit was felt to be negligible. Affected questions had very low prevalence (for example 7 in 1,000 respondents overall and less than 1 in the missing sample of 140) meaning imputation would largely preserve observed distribution and headline percentages and narrative would remain unchanged. Based on these factors it was agreed between Ipsos, DSIT and the Office that imputation was not applied.
Following internal review and consultation with DSIT and the Office, it was agreed that the remaining missing cases were kept within final CSBS datasets and denoted with a new flag variable (“fraud3_missingcase”). This allows for straightforward identification of missing cases at the fraud3 variable and associated downstream variables, and differentiation from cases missing for any other reason.
Ipsos will report results for CSBS 2025/2026 based on the valid achieved sample and the final SPSS data uploaded to the UK Data Archive will reflect the above edits.
The verbatim responses to unprompted questions could be coded as “other” by interviewers when they did not appear to fit into the predefined code frame. These “other” responses were coded manually by Ipsos’ coding team, and where possible, were assigned to codes in the existing code frame. It was also possible for new codes to be added where enough respondents (10% or more) had given a similar answer outside of the existing code frame. The Ipsos research team verified the accuracy of the coding, by checking and approving each new code proposed.
The code frame between 2024/2025 and 2025/2026 has remained largely consistent. One new code was added for the 2025/2026 survey:
We did not undertake SIC coding. Instead, the SIC 2007 codes that were already in the Market Location sample were used to assign businesses to a sector for weighting and analysis purposes. The 2022/2023 survey had overwhelmingly found the SIC 2007 codes in the sample to be accurate, so this practice was carried forward to subsequent surveys.
The education institutions samples are unweighted. Since they were sampled through a simple random sample approach, there were no sample skews to be corrected through weighting.
For the business and charities samples, we applied random iterative method (rim) weighting for two reasons. Firstly, to account for non-response bias where possible. Secondly, to account for the disproportionate sampling approaches, which purposely skewed the achieved business sample by size, sector and region, and the charities sample by income band. The weighting makes the data representative of the actual UK business and registered charities populations.
Rim weighting is a standard weighting approach undertaken in business surveys of this nature, because it allows you to weight your sample to represent a wider population using multiple variables. In cases where the weighting variables are strongly correlated with each other, it is potentially less effective than other methods, such as cell weighting. However, this is not the case here.
The population profile data came from the Department for Business and Trade Business Population Estimates 2025 (Tables 1-9) .
Non-interlocking rim weighting by income band and country was undertaken for charities. The population profile data for these came from the respective charity regulator databases.
For both businesses and charities, interlocking weighting was also possible, but was ruled out as it would have potentially resulted in very large weights. This would have reduced the statistical power of the survey results, without making any considerable difference to the weighted percentage scores at each question.
Table 2.9 and Table 2.10 shows the unweighted and weighted profiles of the final data. The percentages are rounded so do not always add to 100%.
A de-identified SPSS dataset from this survey is being published on the UK Data Archive to enable further analysis. The variables are largely consistent with those in the previously archived dataset (from 2024/2025), outside of new questions added for 2025/2026.
Due to the extent of changes at the Q64B_DISRUPTPHISH question, with all of the questionnaire codes changing since 2024/2025, the name for variables relating to this question in the spss file have been changed from ‘disruptphish’ to ‘disruptphishb’.
As noted in Section 2.1, Ipsos engaged Professor Steven Furnell from the University of Nottingham in July 2022 to review how the questionnaire was mapped to the government’s 10 Steps to Cyber Security guidance, and suggest a more accurate and robust mapping. The 10 Steps mapping remains consistent with iterations of the survey since 2022/2023 and is outlined in Table 2.11 .
There are two organisation size variables, including a numeric variable (SIZEA) and a banded variable (SIZEB). The banded variable in the SPSS does not include the highest band from the questionnaire (1,000 or more employees) because there is no analysis carried out on this group. Instead, it is merged into an overall large business (250 or more employees) size band, which is used across the published report.
In the SPSS datasets for 2015/2016 to 2017/2018, an alternative sector variable (sector_comb1) was included. This variable grouped some sectors together in a different way, and was less granular than the updated sector variable (sector_comb2).
The grouping reflected how we used to report on sector differences before the 2018/2019 survey. As this legacy variable has not been used in the report for the last two years, we have stopped including it in the SPSS dataset, in favour of the updated sector variable.
For the questions in the survey estimating the financial costs of an organisation’s most disruptive breach or attack (DAMAGEDIRSX, DAMAGEDIRLX, DAMAGESTAFFX, DAMAGEINDX), respondents were asked to give either an approximate numeric response or, if they did not know, then a banded response. The vast majority of those who gave a response gave numeric responses (after excluding refusals and those saying there was no cost incurred).
We agreed with DSIT from the outset of the survey that for those who gave banded responses, a numeric response would be imputed, in line with all surveys in the series. This ensures that no survey data goes unused and also allows for larger sample sizes for these questions.
To impute numeric responses, syntax was applied to the SPSS dataset which:
Often in these cases, a common alternative approach is to take the mid-point of each banded response and use that as the imputed value (i.e. £300 for everyone saying “£100 to less than £500”). It was decided against doing this for these specific questions, given that the mean responses within a banded range have tended to cluster towards the bottom of the band over the years. This suggested that imputing values based on mid-points would slightly overestimate the true values across respondents.
Since 2023/2024, the SPSS file has included a number of additional derived variables based on the cyber crime questions. Here is a brief description of each derived variable in the cyber crime section:
Please note that, as in waves of the survey, the following variables listed below have ‘yes’ and ‘no’ binary categories. The ‘no’ category includes both those that gave either a ‘no’ or ‘don’t know’ response, but this information (whether they are a ‘no’ or ‘don’t know’) can be found at other variables in the SPSS file:
For the numeric and financial cost estimates for cyber crime, respondents were also able to give a banded response if they could not provide an exact answer. We have opted to impute the numeric or financial value for these questions by taking the mid-point of each banded response (or the specific value mentioned in the top band). This is different from the cyber incident cost estimates, which impute the average value within the band. The sample of cyber crime cost estimates is much lower, so there is not enough data to impute average values within bands. In other words, it is simply not possible to use anything other than the mid-point values.
No numeric cost variables will be included in the published SPSS dataset, both for the cyber incident (DAMAGE) questions and the crime (COSTA) questions. This was agreed to prevent any possibility of individual organisations being identified. Instead, all variables related to spending and cost figures will be banded, including the imputed values (laid out in the section). These banded variables include:
In addition, the following merged or derived variables will be included:
No region groupings are included for any organisation to avoid the risk of identification of these organisations when triangulated against other variables.
We have treated missing values consistently each year.
If running a...
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
