Every year a new headline repeats the same claim: the cost of a data breach UK businesses face has hit £3.13 million. Every year, most UK businesses read that figure and correctly conclude it has nothing to do with their ten-person firm. They move on without doing anything about their actual risk. That reaction is understandable. It is also a mistake. The £3.13 million average and your own exposure are two different questions, and conflating them leaves most businesses either falsely reassured or falsely terrified.
A more useful question is not “what does the average breach cost.” It is “what would a breach cost a business like mine, and what is it worth spending to stop one.” Getting that answer right matters far more than memorising the cost of a data breach UK headlines quote.

Table of Contents
The £3.13 million figure is not describing your business
IBM’s Cost of a Data Breach Report 2026 is a serious piece of research. Its UK average of £3.13 million is accurate for what it measures: organisations that suffered a confirmed, material data breach requiring investigation and disclosure. That sample skews heavily toward larger organisations with more data, more regulatory exposure and more complex recovery. UK financial services breaches in the same report averaged £5.46 million; services firms averaged £4.23 million.
If you run a small accountancy practice or a regional manufacturer, quoting that figure to your board is not wrong. But it is just not your figure. Using it as your planning number backfires either way: it scares a board into inaction (“we could never justify that spend”), or it produces false confidence once someone points out the number does not match your size.
The £0 median is just as misleading, in the other direction
The government’s Cyber Security Breaches Survey 2025/2026 reports a median cost of £0 for the most disruptive breach across all UK businesses. That figure rises to just £30 among medium and large firms. It is also accurate, and also easy to misread. It reflects a simple fact: most reported incidents are minor, blocked phishing attempts, failed logins, low-level scanning that never turns into a real compromise.
Reading that as “breaches don’t really cost anything” ignores the same survey’s own tail. The worst 5% of incidents still cost £4,000 to £10,000, and that is only the reported, quantifiable slice. It also says nothing about businesses that suffered something severe enough to close down. A firm that shut its doors is not answering a survey the following year.
The number that actually matters is the one in the middle
Vodafone Business’s 2025 SME research is, in practice, the most useful figure for most readers of this article. It found an average of £3,398 per cyber attack for a small UK business, rising to £5,001 once a firm passes 50 employees. It is grounded in the same population most businesses actually belong to, not the largest 1% or the mildest 90%.
Even that number understates the real cost. It does not fully price in what follows an incident: days of management time spent on containment, customers who quietly stop calling, the insurance excess, a supplier who now asks harder questions before renewing your contract. The 2025/2026 government survey found more businesses reporting revenue loss and reputational damage after an incident than the year before. It never attaches a single number to that damage.
The one factor everyone underweights: your suppliers
If there is a single figure from the 2026 data worth remembering, it is this one. A UK breach that originates with a third-party supplier adds an average of £241,620 to the total cost, the largest single cost driver IBM measured. Most businesses spend far more effort securing their own network than setting testing requirements for the suppliers that hold that access. The data suggests that balance is wrong.
What businesses get wrong when they quote these figures to a board
The most common mistake is not picking the wrong number. It is picking one number and treating it as settled fact, rather than explaining which population it describes and why. A board that hears “the average breach costs £3.13 million” without context reacts in one of two ways. It approves an unrealistic security budget out of fear, or it quietly discounts the whole conversation once someone points out the business is nowhere near that scale.
A better approach is to present the range honestly. Start with the government’s evidence that most incidents are minor if caught early. Add the SME-specific figure that most closely matches the business in the room. Finish with the multi-million-pound tail, which shows what happens when detection and basic controls fail at the same time. That framing survives scrutiny in a way a single borrowed statistic never does. It gives the board something to act on, rather than something to be frightened or reassured by.
What this actually means for your spending decisions
Stop anchoring your cyber security budget to the £3.13 million headline. It is not your number, and using it either paralyses smaller businesses or gets dismissed as irrelevant. Instead, work from what the National Cyber Security Centre has said plainly: most cyber attacks exploit basic, preventable gaps. Yet only 13% of UK businesses currently run a penetration test, and just 5% hold Cyber Essentials certification, according to the government’s own figures. That gap, between what attacks exploit and what businesses actually check, is where the real cost sits. It is not in a national average.
Testing your own environment turns an abstract risk into a specific, prioritised list of what would actually fail if someone tried. Aardwolf Security runs exactly that kind of test for UK businesses who want to know their real exposure instead of a headline figure that was never about them. We have set out what that kind of test actually costs in a separate guide. If that sounds like a more useful number to have, get in touch and we will scope what a test would look like for your setup.
Frequently asked questions
Is £3.13 million a realistic cost of a data breach for a UK small business?
No. That figure, from IBM’s Cost of a Data Breach Report 2026, describes organisations that suffered a large, confirmed data breach. It is heavily weighted toward big businesses in sectors like financial services. Vodafone Business’s 2025 SME research, at £3,398 per attack for a small firm, is a far closer match for most UK small businesses.
Why does one UK survey say breaches cost £0?
The government’s Cyber Security Breaches Survey 2025/2026 reports a median cost of £0 because most recorded incidents across its representative sample are minor, such as a blocked phishing email. It is not saying breaches never cost anything. It is saying the typical reported incident is low-severity.
What actually drives the cost of a data breach UK businesses report higher?
Sector and third-party involvement are the two biggest factors in IBM’s 2026 UK data. Financial services breaches averaged £5.46 million. Any breach that began with a third-party supplier added an average of £241,620 to the total, the largest single cost driver measured.
Should a small business worry about the multi-million-pound breach figures?
Not directly, since those figures come from a different population of larger, more complex breaches. What matters more is that only 13% of UK businesses currently run a penetration test. Most attacks exploit basic, fixable weaknesses, according to the National Cyber Security Centre.
Does cyber insurance close the gap between these figures?
Only partly. Just 47% of UK businesses hold cyber insurance, per the 2025/2026 government survey, and policies vary in what they cover. Insurance can offset some direct costs but does not prevent downtime, lost customers or the management time a breach consumes.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.