Crime Is Crime. The Invoice Is Not. New UK Research Puts Cyber Incidents At 28% Of Businesses

Estimated reading time: 14 minutes

A burglar takes your stock. A hacker takes your Tuesday, your payroll run and your customer list. Both are crime. Both cost money. Only one of them gets insured properly.

New research from business lender Capital on Tap surveyed 500 United Kingdom business owners in June 2026. More than one in four, 28%, reported a cybersecurity incident. Physical crime hit 45%. Fraud or a scam hit 21%. Crime of all kinds cost the average business £2,886. Recovery took an average of 18.2 days.

The study is about crime broadly, and cyber runs through it. We asked Capital on Tap to expand on the insurance angle. Chief Financial Officer Rebecca Alford supplied commentary on cover, cost and recovery.

The cover numbers are the ones underwriters should read first. For theft or vandalism, 47% of businesses said they were fully covered and 37% mostly covered. Among small businesses, only 33% were fully covered. Sixteen percent said they had no cover at all. Among businesses with one to five employees, 40% reported no cover.

“So the wider concern is whether businesses have sufficient financial protection when something goes wrong,” Alford said. “The findings suggest that smaller firms in particular may have less capacity to absorb losses.”

UK business crime and cyber insurance graphic showing a British high street shopfront split between a broken shop window with police tape and a ransomware lock screen, illustrating that only one in ten UK businesses hold a specific cyber insurance policy.

One In Three Covered For The Risk They Can See. One In Ten For The Risk They Cannot. That Gap Is The Market.

That 33% figure is the pivot point.

Theft and vandalism are the risks a shop owner understands. They are visible, familiar and easy to price. Two thirds of small firms still do not carry full cover for them.

Cyber cover runs far thinner, and the government measures it directly. The Cyber Security Breaches Survey 2025/2026 was commissioned by the Department for Science, Innovation and Technology and the Home Office. Ipsos surveyed 2,112 businesses between August and December 2025 on a random probability basis.

Almost half of businesses, 47%, reported being insured against cyber risks in some way. That headline is the one most coverage quotes. The detail underneath it matters more.

Only 10% of businesses hold a specific cyber security insurance policy. The rest rely on cyber cover sitting inside a wider commercial policy. Among micro businesses, 8% hold a specific policy. Among small businesses, 15% do. Medium businesses reach 24% and large businesses 32%.

A cyber extension within a general policy is not the same product as a standalone cyber policy. Sub-limits, exclusions and notification conditions can bite exactly when a breach lands.

There is a further gap behind the numbers. One in five businesses, 22%, did not know whether they held any cyber cover at all. The survey asked that question of the person each organization named as most responsible for cyber security.

Putting A Number On The Opportunity

The survey estimates that its 43% breach figure equates to roughly 612,000 United Kingdom businesses. Work backwards and the in-scope business population runs to around 1.4 million. Sole traders, public sector bodies and firms with no online presence sit outside the sample.

Apply the 10% figure to that population. Somewhere near 142,000 businesses hold a specific cyber policy. Roughly 1.28 million do not.

That is the addressable market, published in an official statistics release in April. It is not a niche segment. It is nine in ten of the trading population that insurers already reach for property, liability and motor.

The same brokers speak to these firms every year at renewal. The product exists. The capacity exists. The conversation does not happen.

The Barrier Is Awareness, Not Price

The same survey asked uninsured organizations why they had no policy.

Thirty-nine percent of businesses said they were not aware of cyber insurance. Thirty-four percent said it was not a budgetary priority. Twenty-seven percent said leadership was not interested. Only 19% said it was too expensive.

Read that order carefully. Price ranks fourth. Awareness ranks first.

For carriers and brokers, that changes the problem entirely. A pricing problem is solved with rate, and rate competition is brutal and thin on margin. An awareness problem is solved with distribution, broker education, and plain language. The second is cheaper to fix, and the payoff lasts longer.

The market has spent two years fixing the first while the second went untreated.

Uptake shows it. The share of businesses with some form of cyber cover moved from 43% to 45% to 47% across three consecutive surveys. Two points a year, against a population where four in five hold no specific policy. That is a plateau, not a growth curve.

Cyber Essentials tells a version of the same story. Only 5% of businesses hold the certification. Yet 24% already run technical controls in all five of its areas. Those firms are doing the work and skipping the badge, which means they also skip the underwriting conversation that usually follows it.

See also  Cyber Risk Strategy Shifts as Directors Face Increasing Cyber Threats: Willis Survey 2025

Prevention Is Not Preparedness

The study found 28% of businesses had invested in cybersecurity software or infrastructure. Forty-five percent had invested in staff training. Both figures fall sharply at the small end. Among small businesses, 20% bought security technology and 26% bought training.

Alford drew the line that carriers have been drawing for a decade.

“There appears to be a distinction between investing in prevention and preparing for the consequences of an incident,” she said. “That suggests cyber resilience can’t just be measured by how much a business spends on technology. Prevention and being financially prepared for the practical fallout of an incident appear to be two separate things, and the data points to a gap between the two.”

Government has reached the same conclusion. Digital Minister Liz Lloyd addressed brokers at the British Insurance Brokers’ Association manifesto launch in January. We covered the speech in full.

“Cyber security is not optional,” Lloyd said. “It is foundational to our national security, our economy, and our way of life.”

She called cyber coverage “an important part of the toolbox,” and tied controls directly to claims outcomes. “Certified organisations are 92% less likely to make a claim on their cyber insurance,” Lloyd said, pointing to the Cyber Essentials scheme.

Lloyd also cited the buying experience. Only 8% of small and medium-sized enterprises rated insurer or broker information as very clear. Seventy-six percent of insured firms bought through a broker.

AI AGENT LIABILITY – PODCAST

The Authorization Gap: Cyber Insurance in the Age of Agentic AI – Featuring: Julia Garcia-Trombley, US & Canada, CertX, Jeremy Epstein, CEO, Mayflower Specialty, Rich Gatz, Head of Cyber Claims, Arch Insurance and Tristan Morris, CEO, SplitSecure

cyber insurnace news podcast thumbnail for podcast on agentic AI liability

The Sector Split

Education reported the highest cyber incidence at 46%. Accountancy and finance followed at 42%. Engineering, construction and manufacturing came in at 33%.

Education also reported the highest security spending. Forty-six percent bought cybersecurity software. Fifty-eight percent bought training. Accountancy and finance reported 42% incidence against 21% investment in security technology.

Read that pairing carefully. The sector spending most on detection also reports the most incidents. Firms that deploy monitoring see attacks that unmonitored firms never notice.

Alford was measured about how far the sector data travels.

“I wouldn’t say the data proves that any particular sector is underinsured, because we didn’t ask about cyber insurance by sector,” she said. “But it does suggest that different industries face different levels and types of exposure, so their approach to resilience and insurance needs to reflect that.”

One practical note for anyone rebuilding these figures. Capital on Tap surveyed 500 owners across eight named industries. Sector base sizes were not published. Treat the sector splits as directional.

Eighteen Days Is A Cash Flow Event

The recovery figure comes with a caveat that Capital on Tap raised without being asked. “The important caveat is that the 18.2-day average relates to crime-related incidents, not specifically cyber incidents,” Alford said.

That applies to the cost figure too. The £2,886 average describes crime broadly. It is not a cyber number. The operational point still lands.

“Recovery can mean lost trading, operational disruption, staff time and management attention,” Alford said. “For smaller businesses, even a relatively short interruption can have a significant cash-flow impact because they typically have less financial headroom.”

Her cost split matters more than the headline average. Small businesses reported around £1,981 per incident. Larger businesses reported £3,691. The smaller firm loses less in absolute terms and feels it far more.

“For smaller businesses in particular, that combination, less financial headroom and a costly recovery period, appears to make cyber incidents a bigger relative risk than the headline figures alone suggest,” Alford said.

She closed with the sentence brokers should clip and keep. “Overall, the findings suggest cybersecurity is as much a business resilience issue as an IT one.”

How The 28% Sits Alongside Other UK Research

Different surveys ask different questions of different populations, and the cyber incidence numbers vary widely as a result.

The Cyber Security Breaches Survey 2025/2026 found 43% of businesses had a breach or attack in the previous 12 months. That equates to roughly 612,000 United Kingdom businesses. Broken down by size, the figure runs 42% for micro businesses, 46% for small, 65% for medium and 69% for large. The Cyber Security Longitudinal Survey Wave Five put the medium and large figure higher still, at 82%. The government’s Lock The Door campaign reported that half of small businesses had a breach or attack.

The Capital on Tap study sits below that range at 28%. Framing explains much of the difference. This survey asked business owners about crime against their business, including shoplifting, burglary and vandalism. Owners report what they noticed. A smashed window is noticed. A quiet credential theft often is not.

See also  One Ransomware Group. One Device. Nearly Half Of All Claims. At-Bay's 2026 InsurSec Report

The government survey says the same thing about itself. It notes that it only captures breaches organizations identified and were willing to report, and that hidden attacks mean the findings may understate true prevalence.

For underwriters, the takeaway is familiar. Applicants report detected incidents, and detection varies with tooling.

What A Cyber Loss Actually Costs, And Why Averages Mislead

Two government figures on cost sit side by side, and they look contradictory until you read them properly.

Modeling for the government puts the average cost of a significant cyber attack at almost £195,000 per business. That figure covers incidents costing £500 or more, averaged across all sectors and sizes. The national bill runs to £14.7 billion a year, around 0.5% of gross domestic product.

The Cyber Security Breaches Survey reports something very different. The median perceived cost of the most disruptive breach was £0 for businesses. Most respondents fell between £0 and £200. At the 95th percentile, the figure reached £4,000 for micro and small businesses, and £10,000 for medium and large ones.

Both are accurate. They measure different things.

Most cyber incidents cost a small business almost nothing. A rare one is catastrophic. The £195,000 average is dragged upward by a thin tail of severe events, and the survey itself warns that extreme costs are hard to capture in a sample of its size.

That distribution is the argument for cover, not against it. Low frequency and high severity is precisely the shape of risk insurance exists to absorb. A business does not buy a policy for the median event. It buys one for the event that ends the company.

Which makes self-insurance a difficult position to defend. The Department for Science, Innovation and Technology study of small and medium-sized enterprises found that among the uninsured, 47% described themselves as self-insured. Another 47% had no formal approach at all. We covered that study in detail.

Self-insurance works until it meets the tail. Then it is not a strategy. It is a wager.

Capacity Is Arriving. Demand Is The Constraint.

The supply side has moved quickly.

Brit put its C360 small business cyber product onto Acturis, reaching more than 30,000 brokers. Kovrilo added HSB-underwritten cyber cover to its modular platform. Pen Underwriting raised its small business cyber limit. Willis expanded CyMax across Europe, the Middle East and Africa. Mulberri and Omnyy brought underwriting automation to United Kingdom small business lines.

The market is responding. Policies rose 17% in 2024. Payouts to support recovery reached £197 million.

What the supply side has not solved is reach. Every product above competes for the same 10% of businesses that already know the category exists. None of it touches the 1.28 million firms that do not.

Our podcast with Cowbell co-founder Trent Cooksley covered why small firms keep assuming they are too small to target. The assumption is wrong. The awareness figures show how far it still reaches.

Lloyd made the same point to brokers in January. She said cost, complexity, and low awareness hold back small business adoption, and she put brokers at the center of fixing it.

The American Comparison

United States data tells the same story in a different currency.

The Federal Bureau of Investigation’s Internet Crime Complaint Center logged 1,008,597 complaints in 2025. Reported losses reached $20.877 billion, up 26% from the previous year. Investment fraud accounted for $8.65 billion. Business email compromise accounted for $3.05 billion. Those are reported losses only, and the real figure is higher.

Claims data sharpens the picture. Coalition’s 2026 Cyber Claims Report drew on more than 100,000 policyholders across five countries. Average losses for the smallest businesses fell 15% to $77,000. The largest companies averaged $268,000. Businesses above $100 million in revenue experienced claims nearly five times more often than businesses below $25 million.

Read those findings together. Large firms get hit more often. Small firms get hit harder relative to what they can absorb. A $77,000 loss is a rounding error for a corporate treasury. For a firm with £2,000 of headroom, it is the end.

The pattern repeats on both sides of the Atlantic. Frequency rises with size. Survivability falls with size.

Consumers Pay The Bill Too

Business crime does not stop at the shopfront.

Frontier Economics research commissioned by the United Kingdom government estimated that 437,000 people became fraud victims in 2023 because of organizational data breaches. That is roughly 11% of all fraud victims that year, and around £755 million in annual fraud costs.

A breached company becomes a supply line for consumer fraud. The stolen record leaves the building and comes back as somebody’s drained account.

See also  Patch Management And Cyber Insurance: What The Adobe Reader Zero-Day Reveals

Lloyds made the same point to brokers in January. “A cyber incident isn’t just a statistic,” she said. “It’s people, livelihoods and community services at risk.”

About The Research

Capital on Tap is a business credit card provider. It surveyed 500 United Kingdom business owners in June 2026 and submitted Freedom of Information requests to police forces in England for 2025 crime data. The full study is published on the company’s website.

The Bottom Line

Crime is crime. The response should not depend on whether the thief arrived through a window or a login.

Right now it does. Sixty-four percent of businesses bought closed-circuit television. Twenty-eight percent bought cybersecurity software. Businesses insure the shopfront and self-insure the server.

Two-thirds of small firms lack full cover for the crime they can see. Only 15% hold a specific policy for the crime they cannot. Among micro businesses, it is 8%.

The threat is documented. The losses are documented. The capacity exists. Around 1.28 million United Kingdom businesses hold no specific cyber policy, and two in five uninsured firms have never heard of the product.

That is not a market failure of price. It is a market failure of reach. Whoever solves the reach problem takes the segment, and the bill for leaving it open lands on the smallest businesses first.

FAQ – UK Business Crime

How many UK businesses experienced a cybersecurity incident?

Capital on Tap’s survey of 500 United Kingdom business owners found 28% reported a cybersecurity incident. Government research reports higher figures. The Cyber Security Breaches Survey found 43% of all businesses, and the Cyber Security Longitudinal Survey found 82% of medium and large businesses had at least one incident.

What does business crime cost a UK business on average?

The study reported an average of £2,886 across all surveyed businesses. Small businesses averaged around £1,981 and larger businesses £3,691. These figures cover crime generally rather than cyber incidents specifically.

How long does it take a business to recover from a crime incident?

The survey found an average of 18.2 days. Health and social care organizations reported the longest average at 39 days. Capital on Tap confirmed the figure relates to crime-related incidents rather than cyber incidents alone.

Are small UK businesses insured against crime?

Not consistently. For theft or vandalism, 47% of all businesses said they were fully covered. Among small businesses that fell to 33%, with 16% reporting no cover at all. Among businesses with one to five employees, 40% said they had no cover.

How many UK businesses have cyber insurance?

The Cyber Security Breaches Survey 2025/2026 found 47% of businesses were insured against cyber risks in some way. Only 10% held a specific cybersecurity insurance policy. That falls to 8% among micro businesses and rises to 15% for small, 24% for medium and 32% for large businesses. A further 22% did not know whether they had cover.

Why do UK businesses not buy cyber insurance?

The same survey asked uninsured organizations directly. Thirty-nine percent said they were not aware of cyber insurance. Thirty-four percent said it was not a budgetary priority. Twenty-seven percent said leadership was not interested. Nineteen percent said it was too expensive.

What does a cyber incident cost a UK business?

It depends heavily on which measure you use. The Cyber Security Breaches Survey found a median perceived cost of £0 for the most disruptive breach, reaching £4,000 at the 95th percentile for micro and small businesses. Government modeling puts the average cost of a significant cyber attack at almost £195,000, a figure pulled upward by rare severe events. Coalition’s 2026 claims data put the average loss for businesses under $25 million in revenue at $77,000.

Does Cyber Essentials reduce insurance claims?

Government figures say organizations holding Cyber Essentials certification made 92% fewer insurance claims. The scheme covers five controls: firewalls, secure configuration, software updates, user access control and malware protection.

Leave a Comment

×