The 43% Cyber Attack Statistic: Are We Being Sold Fear?
Every spring, the UK government drops a cyber statistic that makes headlines, fills vendor slide decks, and gives nervous business owners another reason to stare bleakly into their coffee. The claim? Around 43% of UK businesses suffered a cyber breach or attack last year.
Sounds terrifying, doesn’t it?
Except there is a problem. A bloody big one.
The methodology counts phishing emails as breaches even when nobody clicked, nobody engaged, and nothing happened. In other words, your business could block thousands of dodgy emails, suffer no damage, lose no money, and still get swept into the headline figure.
Buried deeper in the same government report is a far more useful number.
In this episode, the team pulls apart ten years of survey data and asks an uncomfortable question: who benefits when cyber risk gets inflated? Government comms teams get a stronger headline. Vendors get better scare copy. Compliance theatre gets another curtain call. Meanwhile, small businesses are left wondering whether they are genuinely at risk or just being sold another steaming plate of fear.
We also admit something important. We fell for the 43% number ourselves two weeks ago. So this episode is not just a takedown. It is a correction.
What should a 20 person business actually do with this information? Ignore cyber risk? Absolutely not. Panic buy another shiny security product because someone waved a big scary percentage at you? Also no.
The answer sits somewhere far more useful: understand the real risk, ask better questions, spend money where it matters, and stop letting fear based marketing write your security strategy.
Links
Department for Science, Innovation and TechnologyCyber Security Breaches Survey 2026Office for Statistics RegulationOffice for National StatisticsHome OfficeComputer Misuse Act 1990FBI IC3 Annual ReportsNCSC Cyber Essentials Overview