UK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox Finds
Nearly four in 10 UK small firms were hit by a successful cyberattack in the past year, according to the latest Hiscox Cyber Readiness Report.

Nearly four in 10 UK small firms were hit by a successful cyberattack in the past year, according to the latest Hiscox Cyber Readiness Report. The UK cyberattack rate reached 38%, significantly above the 29% global average recorded among nearly 7,000 smaller businesses surveyed worldwide. The 10th annual report surveyed cybersecurity decision-makers at smaller firms, including 1,000 respondents in the UK. UK cyberattack Rate Outpaces Global Average The findings place UK small businesses at greater exposure to successful cyberattacks than their international counterparts.
However, the two figures are not directly comparable because last year's research surveyed a broader group of 5,750 businesses across seven markets, while this year's report focuses specifically on almost 7,000 smaller firms. The latest Hiscox findings therefore show a combination of high cyberattack exposure, substantial investment in cyber resilience, and relatively limited cyber insurance uptake among UK businesses.
What changed
The global attack rate also fell from the 59% figure reported in Hiscox's previous annual report.
New technology was adopted by 51% of firms, while 55% invested in specialist staff and 62% updated employee training.
Globally, 32% of firms said executive pay is now linked to cybersecurity performance.
Why this matters
However, the two figures are not directly comparable because last year's research surveyed a broader group of 5,750 businesses across seven markets, while this year's report focuses specifically on almost 7,000 smaller firms.
The latest Hiscox findings therefore show a combination of high cyberattack exposure, substantial investment in cyber resilience, and relatively limited cyber insurance uptake among UK businesses.
What to watch next
Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.
What remains unknown
The available reporting does not establish which organizations or systems have been directly affected.
The available reporting does not establish whether the issue is being actively exploited in the wild.