A new industry report has landed on top of the UK’s own official breach statistics, and the numbers don’t agree with each other, which is exactly the point. ESET’s 2026 SMB Cyber Risk Report, published September 17, 2026, found that 49% of UK small and medium-sized businesses experienced a cyber incident in the past 12 months, according to ESET’s UK newsroom release. That’s a different survey, a different sample and a different number than the government’s Cyber Security Breaches Survey, which put the figure at 43% of all UK businesses when it published in April 2026.
Two surveys, two methodologies, one uncomfortable conclusion: roughly half of the UK’s smaller businesses got hit by something last year, and most of them got hit by the same handful of preventable mistakes. Here’s what the ESET data actually shows, how it stacks up against the government’s numbers, and what security specialists say business owners should fix first.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What ESET’s 2026 SMB Cyber Risk Report Found
ESET commissioned research firm Go4insight to survey 500 UK small and medium-sized businesses running between 25 and 1,000 endpoints, with fieldwork completed in the first quarter of 2026. The topline result: 49% of respondents said they had experienced a cyber incident in the previous year, and among those affected, 13% reported more than one separate incident, according to coverage from TechRadar Pro.
The report also measured recovery time. UK SMBs that suffered an incident took just over four weeks on average to identify and recover from it, per ESET’s release and Infosecurity Magazine’s coverage of the findings. For a business with 25 to 1,000 employees, a month of degraded operations, incident response costs and customer disruption is not a rounding error. It’s the kind of hit that shows up in next quarter’s revenue.
The 49% Number, Explained
It helps to be precise about what “49%” actually measures, because breach statistics get flattened into headlines that don’t always compare like with like. ESET’s figure covers a specific segment: UK SMBs with 25 to 1,000 endpoints, surveyed by Go4insight on ESET’s behalf. It is not a random sample of every UK business, and it is not the same population the government surveys every year.
That distinction matters because a smaller, more targeted sample of mid-sized SMBs will naturally produce a different breach rate than a broad national survey that also counts sole traders and micro-businesses with no real digital footprint to attack. Both numbers can be accurate. They’re just answering slightly different questions.
How This Compares to the Government’s Own Breach Survey
The UK government has run some version of the Cyber Security Breaches Survey since 2016, and it became an official statistic in 2017, published jointly by the Department for Science, Innovation and Technology (DSIT) and the Home Office, according to gov.uk. The most recent completed edition, the Cyber Security Breaches Survey 2025/2026, published on April 30, 2026, found that 43% of all UK businesses had identified a breach or attack in the preceding 12 months, with a clear split by company size: 42% of microbusinesses, 46% of small businesses, 65% of medium-sized businesses and 69% of large businesses.
Phishing led the government’s list too, cited by 38% of all businesses surveyed and named the most disruptive attack type by 69% of businesses that had actually experienced a breach. This site’s earlier coverage of the 43% figure broke down those size-based numbers in more detail. Read side by side with ESET’s SMB-focused data, the message is consistent even where the exact percentages diverge: the bigger and more digitally exposed a business gets, the more likely it is to report an incident, and phishing keeps winning as the most common entry point regardless of which survey you trust.
Worth noting: DSIT has already announced the next round, the Cyber Security Breaches Survey 2026/2027, with fieldwork running from August to December 2026 and results not due until around April 2027. Anyone citing fresh government figures for the 2026/2027 cycle right now is citing something that doesn’t exist yet.
Where Breaches Start: Phishing, Patching and Passwords
ESET’s broader SMB Cyber Readiness Index 2026 report breaks down what actually causes these incidents, and the answer is almost aggressively unglamorous. Phishing accounted for 27% of incidents, ahead of unpatched vulnerabilities at 23%, with weak passwords and insufficient security monitoring tied at 20% each, according to the report’s global edition data. None of these are exotic zero-days. They’re basic hygiene gaps that security teams have been flagging for a decade.
An ESET spokesperson, quoted by Infosecurity Magazine, put the fix in plain terms: “SMEs should start with the fundamentals: secure configurations, strong access controls, software updates and protection against malware. Good cyber hygiene should be treated as part of running a business, rather than something to address after an incident.” That’s not a controversial statement, and that’s exactly the problem. Nearly half of surveyed SMBs still aren’t doing it consistently.
| Incident Cause | Share of Reported Incidents |
|---|---|
| Phishing | 27% |
| Unpatched vulnerabilities | 23% |
| Weak passwords | 20% |
| Insufficient security monitoring | 20% |
| Other / unspecified causes | ~10% |
The Four-Week Recovery Problem
A month to identify and recover from an incident is the detail that should worry SMB owners more than the 49% headline. Large enterprises can absorb weeks of incident response with dedicated security operations teams running in parallel with the rest of the business. A 25-to-1,000-endpoint company usually can’t. The same IT staff, or the same outsourced provider, who normally handle helpdesk tickets are now also doing forensics, containment and recovery, while the business keeps operating on reduced capacity.
That recovery window is also why detection speed matters as much as prevention. Tools built specifically to shorten the gap between compromise and discovery, such as the kind of monitoring covered in this site’s dark web monitoring setup guide, exist precisely because insufficient monitoring is one of the four leading causes ESET identified. Catching a credential leak in hours instead of weeks can be the difference between a contained incident and a four-week recovery slog.
Why AI-Powered Malware Worries SMBs More Than It Currently Should
Here’s a gap between perception and reality that ESET’s data makes explicit. AI-powered malware topped the list of security concerns among surveyed SMBs, according to both ESET’s release and TechRadar Pro’s coverage, despite not appearing among the actual leading causes of the incidents businesses reported this year. Phishing, unpatched software, weak passwords and thin monitoring did the damage. AI-generated threats were the thing people worried about most.
That’s not to say the concern is misplaced long-term. Phishing emails written or refined with generative AI are harder to spot than the clumsy, typo-riddled scams of a few years ago, which is part of why the category still leads the incident list. But for a business trying to prioritize a limited security budget in late 2026, the data says patch management and password hygiene deserve the next dollar before an AI-malware detection product does.
Budgets Are Rising, But Slowly
There is a silver lining in the numbers: 55% of UK SMBs told ESET’s researchers they expect to increase their cybersecurity budgets over the next 12 months, per TechRadar Pro’s reporting. A slim majority planning to spend more is progress, even if it leaves a substantial share of the market either flat or cutting spend heading into a year when breach rates are already sitting near 50%.
Also notable: 81% of surveyed UK SMBs said they view cyber warfare and geopolitical conflict as a real threat capable of affecting their business, according to ESET’s UK release. That figure sits well above the businesses actually reporting nation-state-linked incidents, which suggests SMB security anxiety is currently outpacing SMB security spending, not the other way around.
Cyber Essentials and the Basics That Still Get Skipped
The UK’s Cyber Essentials scheme, the government-backed baseline certification covering exactly the fundamentals ESET’s report flags as weak spots, had what Infosecurity Magazine described as a record year. That’s a genuinely useful data point sitting right next to the 49% breach figure: more businesses are pursuing baseline certification at the same time nearly half are still getting breached through gaps that certification is designed to close.
Read together, the two facts suggest certification uptake is a lagging indicator, not a leading one. Businesses tend to pursue Cyber Essentials after a scare, a client contract requirement, or an insurance renewal, rather than proactively, which is part of why the breach numbers and the certification numbers are climbing in parallel instead of the certification curve pulling the breach curve down.
What Security Guidance Actually Recommends
ESET’s own digital security guidance is specific about where to start, and none of it requires enterprise budgets. Two lines from that guidance are worth quoting directly: “Enforce multi-factor authentication (MFA) on every high risk entry point,” and “Patch internet facing systems and known exploited software,” both from ESET’s UK ransomware prevention guide. A third point from the same guidance reframes staff training: “Employee awareness must reflect how attackers gain access today, through impersonation and credential theft, rather than obvious malware.”
That last point tracks with September’s broader patch news. Microsoft’s September 2026 Patch Tuesday fixed 966 vulnerabilities in a single release, several rated wormable, a reminder of just how large the patching backlog can get for an SMB IT team without dedicated vulnerability management. For businesses that don’t already run one, a free vulnerability scanner such as the one covered in this site’s Nessus Essentials setup guide gives a starting inventory of exactly which systems are exposed before deciding what to patch first.
On the phishing side specifically, since it remains the single largest incident cause at 27%, running periodic internal phishing simulations is one of the few controls that directly targets the top cause rather than a downstream symptom. This site’s GoPhish phishing simulation setup guide walks through standing up that kind of test internally. Pairing simulation with the kind of always-on endpoint protection detailed in the Microsoft Defender for Endpoint setup guide addresses both the human and technical sides of the same 27% number.
Market Impact: Vendors, Insurers and the SMB Security Budget
A near-50% breach rate among SMBs, published by a major antivirus and endpoint security vendor, doubles as a sales pitch, and ESET is not shy about that overlap; the report’s release is built to steer budget toward exactly the categories ESET sells into. That doesn’t make the underlying data wrong, but it’s a reasonable lens for reading any vendor-commissioned breach survey. The 55% of SMBs planning to raise security spend represents real addressable budget for endpoint security, monitoring and awareness-training vendors heading into 2027 planning cycles.
Cyber insurers read reports like this one too. A breach population sitting near 49%, with a four-week average recovery time, is exactly the kind of loss-ratio data that pushes insurers toward stricter minimum-control requirements, like mandatory MFA or patch cadence, before underwriting SMB cyber policies. Expect that pressure to keep tightening faster than most SMBs’ actual security posture improves.
Historical Context: A Decade of Breach Surveys, Same Weak Points
The government’s breach survey has run in some form since 2016 and become an official statistic since 2017. Across nearly a decade of annual editions, the same pattern shows up year after year: phishing leads every incident-type ranking, larger businesses report higher breach rates than smaller ones because they carry more attack surface and more to steal, and the gap between awareness of the risk and actually implementing basic controls never fully closes. ESET’s 2026 report doesn’t contradict that decade of government data. It largely confirms it from a different angle, with a sharper focus on the SMB segment specifically.
Competitive Comparison: Two Surveys, One Consistent Signal
| Detail | ESET SMB Cyber Risk Report | Cyber Security Breaches Survey 2025/2026 |
|---|---|---|
| Publisher | ESET (research by Go4insight) | DSIT & Home Office |
| Sample | 500 UK SMBs, 25-1,000 endpoints | Broad UK business sample, all sizes |
| Breach rate reported | 49% (SMB segment) | 43% overall (42% micro, 46% small, 65% medium, 69% large) |
| Top attack type | Phishing, 27% of incidents | Phishing, 38% of businesses |
| Published | September 17, 2026 | April 30, 2026 |
Neither survey is more correct than the other since they measure overlapping but distinct populations using different methodologies. The value in comparing them is that both independently point to phishing as the dominant attack type and to under-resourced basic controls as the dominant root cause, a stronger signal than either report would provide alone.
Predictions: What to Watch Through 2027
- Expect the government’s Cyber Security Breaches Survey 2026/2027, due around April 2027, to show the size-based breach gap between micro and large businesses persist rather than close, consistent with the decade-long pattern in prior editions.
- AI-assisted phishing content is likely to push the phishing share of incidents higher in next year’s vendor reports, even as raw email volumes plateau, simply because the messages are getting harder to spot.
- Cyber Essentials application volumes should keep climbing through 2027 as more insurers and enterprise clients make baseline certification a procurement requirement rather than a nice-to-have.
- Cyber insurers are likely to tighten minimum-control requirements, particularly around MFA and patch cadence, for SMB policies renewing in 2027, using loss data from reports like ESET’s as justification.
- The gap between SMBs worried about AI-powered malware, currently the top named concern, and SMBs actually breached by it, not yet a leading cause, should narrow over the next one to two survey cycles as attackers operationalize the technology more broadly.
Practical Steps for UK SMBs to Cut Their Risk Now
Based on what both surveys identify as the leading causes, four steps address the bulk of the exposure without requiring an enterprise security budget. First, enforce multi-factor authentication everywhere it’s supported, prioritizing email, remote access and admin accounts. Second, put a real patch cadence in place for internet-facing systems, starting with a free scan to find what’s exposed. Third, run periodic phishing simulations rather than one annual training video, since phishing alone accounts for more incidents than the other three leading causes combined. Fourth, add basic monitoring, even a lightweight or free tier, so a compromise is caught in hours rather than the four-week average ESET’s report measured.
None of these four steps require the kind of budget increase 55% of surveyed SMBs are already planning. They require treating security as operational hygiene, which is precisely the phrase ESET’s own spokesperson used to describe the fix.
FAQ
Is the 49% figure the same as the “43% of UK businesses” figure reported earlier in 2026?
No. The 49% figure comes from ESET’s 2026 SMB Cyber Risk Report, based on a Go4insight survey of 500 UK SMBs with 25 to 1,000 endpoints, published September 17, 2026. The 43% figure comes from the UK government’s Cyber Security Breaches Survey 2025/2026, a broader survey of all UK business sizes published April 30, 2026. They measure overlapping but different populations.
What is the single most common cause of cyber incidents at UK SMBs?
Phishing, in both surveys. ESET’s data puts phishing at 27% of incidents; the government’s Cyber Security Breaches Survey found phishing affected 38% of all businesses and was named the most disruptive attack type by 69% of businesses that had experienced a breach.
How long does it typically take a UK SMB to recover from a breach?
Just over four weeks on average, according to ESET’s 2026 SMB Cyber Risk Report and Infosecurity Magazine’s coverage of it.
Are UK SMBs increasing their cybersecurity budgets in response?
ESET’s research found 55% of surveyed UK SMBs expect to increase cybersecurity spending over the next 12 months, per TechRadar Pro’s reporting on the report.
Is AI-powered malware currently the biggest threat to UK SMBs?
It’s the biggest named concern, but not yet a leading cause. ESET’s report found AI-powered malware topped the list of what SMBs worry about most, while the actual leading causes of reported incidents were phishing, unpatched vulnerabilities, weak passwords and insufficient monitoring.
When will the next official government breach survey be published?
The Cyber Security Breaches Survey 2026/2027 has fieldwork running from August to December 2026, with results provisionally expected around April 2027, according to gov.uk’s statistics announcements page.
What is Cyber Essentials, and does it actually reduce breach risk?
Cyber Essentials is the UK government-backed baseline cybersecurity certification covering the same fundamentals, secure configuration, access control, patching and malware protection, that ESET’s report identifies as the biggest gaps. Infosecurity Magazine reported the scheme had a record year for applications in 2026, though certification uptake and breach rates are currently climbing in parallel rather than certification driving breach rates down.
What’s the fastest, lowest-cost fix an SMB can make today?
Enforcing multi-factor authentication on high-risk entry points and patching internet-facing systems, both explicitly recommended in ESET’s own digital security guidance, address the two largest reported incident causes without requiring new security spend.


