Business & Technology
The new UK cyber survey is out, but here’s what the numbers aren’t telling you
The latest Cyber Security Breaches Survey makes for uncomfortable reading for UK businesses. According to the Government’s 2025/2026 report, 43% experienced a breach or attack in the last 12 months – that’s around 612,000 organisations. The findings also estimate approximately 5.19 million cybercrimes over the same period, while the proportion of breaches or attacks resulting in lost revenue or share value has more than doubled, rising from 2% to 5%.
On a surface level, the story is familiar – cyber attacks remain widespread, phishing continues to dominate and businesses are once again being urged to improve resilience. Experts have already described the findings as depressingly familiar, and it’s not difficult to see why. The numbers move slightly from year to year, but the underlying pattern remains largely unchanged, which is the real concern here.
After years of major incidents, boardroom briefings, regulatory warnings and national awareness campaigns, the UK is still stuck in a cycle where risk is recognised, but not consistently governed. Businesses know threat exists, but many still lack the ability to demonstrate, in a structured and reliable way, how that threat is being managed before something goes wrong.
Breach numbers only tell us what has already happened
A breach shows the visible outcome of decisions, controls, gaps and assumptions that existed long before the incident itself. By the time a breach appears in a survey, the more important questions have already been missed: Were the right controls in place and were they being reviewed? Was there clear ownership? The answers to these determine whether an organisation is genuinely resilient or simply fortunate.
The survey tells us a great deal about the scale of cybercrime and reveals too many companies are still measuring risk at the point of failure rather than at the point of control.
The governance gap is hiding in plain sight
Only 31% of businesses have board-level responsibility for cyber security, just 15% review the risks posed by their immediate suppliers and only 6% look at the wider supply chain. The survey also points to small businesses going backwards in some areas of basic preparedness.
Cyber security is still too often treated as a technical function, owned somewhere inside IT and discussed seriously only when an incident takes place. Yet most of the weaknesses exposed by modern incidents are structural, with no clear accountability, no consistent control framework, no live view of risk and no board-level visibility until they are already under pressure.
Small businesses face risk differently from large enterprises
Smaller businesses are often told to adopt better cyber hygiene. Whilst this advice is valid, it can also oversimplify the challenge. SMEs typically operate with less internal capacity, fewer dedicated roles, more informal processes and greater dependence on external suppliers, creating a very different kind risk profile from larger enterprises.
For many, cyber risk is managed through individual knowledge rather than institutional structure. One person knows where the policies are stored, one external provider understands the systems and one senior leader owns the customer assurance process, but that kind of system becomes fragile quickly.
The business needs clear visibility over the data it holds, the systems affected, the suppliers involved, the controls in place, what evidence exists and who is authorised to make decisions. If that information has not been organised in advance, incident response becomes slower and more expensive. This is where governance needs to become more practical.
Smaller organisations don’t need the same level of bureaucracy as global enterprises, but they do need a clear way to map risks, assign ownership, manage controls, maintain evidence and show progress over time. Without that, cyber resilience remains dependent on goodwill, memory and last-minute effort.
Supply chain risk is becoming the unanswered question
Modern companies rely on software providers, outsourced IT partners, consultants, payment systems, logistics platforms, cloud environments and data processors, which means cyber risk rarely sits neatly within the four walls of their organisation. A weakness in one supplier can quickly become a weakness in the business itself.
But as the survey shows, only a small minority of organisations are reviewing immediate supplier risk and even fewer are looking at the wider supply chain. Customers are already asking more detailed questions about security controls, investors are looking more closely at operational resilience, regulators are moving towards stronger expectations around supply chain accountability and insurers are becoming more interested in evidence. In that environment, “we trust the supplier” is not enough.
The Cyber Security and Resilience Bill will raise the evidence bar
The UK is moving away from a model where cyber security is largely treated as voluntary good practice and towards one where resilience must be demonstrated. The Bill is part of that shift.
Demonstrating that the right controls, oversight and processes were in place before a breach happened relies on evidence, ownership and current information. It requires cyber risk to be connected to compliance, operations, procurement and leadership.
This is where many organisations will feel the gap most sharply. They may be doing some of the right things, but if those activities are fragmented, undocumented or disconnected from recognised frameworks, they will struggle to prove it.
The real lesson is not more awareness, but more proof
The UK doesn’t have a cyber awareness problem in the traditional sense. Most business leaders understand that attacks can disrupt operations, damage trust and create financial loss.
But, businesses need to better understand which frameworks apply, which controls are in place, who owns them, when they were last reviewed and where the evidence sits. That means treating compliance as a live management discipline rather than a project that begins shortly before an audit or customer request. Frameworks such as ISO 27001, SOC 2 and Cyber Essentials are becoming more important because they give organisations a common structure for turning cyber intent into demonstrable control. They also help in moving away from reactive reassurance and towards evidence-led governance.
Why the numbers keep looking the same
The real value in the Cyber Security Breaches Survey is in showing why progress remains slow. Too many businesses are using an approach that creates the appearance of activity without the discipline of governance and, until that changes, the annual numbers will continue to look familiar.
To move ahead, businesses need to build the evidence first, connect controls to risk, bring suppliers into scope and give leadership a clear view of resilience before pressure hits. Compliance isn’t a report, it’s a posture – that’s what the latest survey is really telling us.
Business & Technology
Rosa’s Thai is giving away 4000 free Pad Thais to students
Celebrating both GCSE and A-Level Results Days, the chain will offer the popular dish to students who buy one of its bubble teas.
The free offer is available at all 42 Rosa’s Thai restaurants across England and Wales.
To avail of the free noodles, students need to register on Rosa’s Thai website for a unique code, which they should present at the restaurant together with a copy of their results.
Rosa’s Thai has a new range of bubble tea flavours, including Ube-Taro, Matcha-Coconut, Mango Sticky Rice, and Milo Chocolate Milk, as well as favourites like Home-brewed Thai Tea with Tapioca, and Lychee Mango with mango boba.
Students can sign up for their free Pad Thai at rosasthai.com/result-day-free-pad-thai and find their nearest restaurant at rosasthai.com/locations.
Business & Technology
Historic coin company enters administration after 20 years
The London Mint Office, which distributes commemorative coins and medals, appointed administrators on July 31 after 20 years in business.
The company’s website now displays a message confirming the appointment of Michael Magnay and Jonny Marston of Alvarez & Marsal Europe LLP as joint administrators.
A spokesman for Alvarez and Marsal said: “On July 31 2026, Michael Magnay and Jonny Marston of Alvarez & Marsal Europe LLP were appointed as Joint Administrators of The London Mint Office Limited in administration (the “Company”).
“Regrettably, the Company’s liquidity challenges have led to a number of immediate redundancies. We are supporting the affected employees through the redundancy process.
What Happens When a Company Goes Into Administration?
“The affairs, business and property of the Company are being managed by the Joint Administrators who act as agents of the Company and without personal liability.”
The announcement confirms that it is no longer possible to purchase coins or medals through the company’s website.
The London Mint Office operates a distribution centre in Tonypandy, Rhondda Cynon Taf, where it employs a significant number of people.
Administration is a formal insolvency process triggered when a business cannot meet its financial obligations.
An insolvency practitioner is appointed to manage the company’s affairs and may attempt to restructure the business or sell off assets to repay creditors.
What happens when a company goes into Liquidation?
Founded in 2006, The London Mint Office describes itself as “one of the UK’s most trusted suppliers of historic, commemorative, and collector coins.”
It is part of Samlerhuset AS, a Norwegian company based near Oslo and one of Europe’s largest distributors of commemorative coins and medals.
Samlerhuset’s website states that it offers “provide a wide range of coins from ancient to modern, originating from virtually every country in the world.”
The London Mint Office has advised anyone with an interest in the company’s assets to contact the administrators at INS_THLMOL@alvarezandmarsal.com.
Business & Technology
Warning of new rules for Aldi and Lidl after watchdog review
The Competition and Markets Authority (CMA) has provisionally decided that both discounters should be added to the Groceries Market Investigation (Controlled Land) Order 2010, which currently applies to Asda, Co-op, Marks and Spencer, Morrisons, Sainsbury’s, Tesco, and Waitrose.
This order is designed to prevent large grocery retailers from using land agreements to block competitors from opening nearby stores, often through restrictive covenants or exclusivity terms.
Juliette Enser, executive director of competition enforcement and markets at the CMA, said: “We want everyone to have the best choice of supermarket and range of prices when buying their groceries.
“To ensure this happens, we put rules in place to prevent big supermarket chains blocking rival stores from opening nearby – and now we propose applying those rules to Aldi and Lidl too.
“This is about allowing shoppers to choose where they spend their money and levelling the playing field for all major supermarkets.
“Today’s proposals are provisional and we welcome views before deciding the best way forward.”
The CMA’s review found that Aldi, Lidl GB, and Lidl NI now meet the criteria of ‘Large Grocery Retailers’ (LGRs) due to their store footprint, nationwide presence, procurement model, and the breadth of their grocery range.
Aldi and Lidl were originally excluded from the 2010 order as ‘limited assortment discounters’, offering a smaller selection of products compared to traditional supermarkets.
However, the CMA’s provisional findings indicate that this is no longer the case.
All three now operate large grocery stores, each with more than 1,000 square metres of shop floor space, and offer a full range of products, though with less category choice than some competitors.
They also purchase goods directly from suppliers through integrated wholesaling.
With the UK grocery market estimated to be worth £215 billion, Aldi and Lidl are now ranked among the top five retailers by market share.
The CMA is seeking feedback from stakeholders before reaching a final decision.
Aldi and Lidl could join the other supermarket chains later this year.
The CMA is inviting views until 5pm on Monday, September 7, 2026, and will issue its final decision in the autumn after reviewing responses.
If the discounters are included under the order, they will be prevented from using land agreements to limit competition from other supermarket chains.
The CMA aims to ensure competition across the grocery sector to give shoppers more choice and competitive pricing by removing obstacles to new store openings.
-
Business & Technology3 weeks agoHSBC UK & Visa test AI shopping with live payments
-
Business & Technology3 weeks agoValarian lands USD $50 million backing for sovereign AI
-
Oxford Events4 weeks agoHenley Festival 2026 highlights: Five nights of unforgettable performances and festival moments
-
Oxford united FC3 weeks agoOxford United three players who be kept after transfer ban
-
Business & Technology4 weeks agoZYMIX uses Henley event to pitch social app to Gen Z
-
Business & Technology2 weeks agoSlice golf bar swings to new heights after successful launch
-
Business & Technology3 weeks agoUK AI firms raise record GBP £4.56bn in Q2 funding
-
Oxford News3 weeks agoMan jailed for ‘sickening’ sexual assault of three girls in Cotswolds
