A data breach happens when information a business holds is accessed, lost or exposed without permission. That could be customer records, staff files or trade secrets. It can be the work of an outside attacker. It can also start with something as ordinary as an employee emailing a spreadsheet to the wrong address. Either way, the result is the same. Information that should have stayed private no longer has.

UK regulators use a slightly more precise definition. But the practical version above covers most of what business owners need to know before the detail below.
Table of Contents
What actually counts as a data breach?
The Information Commissioner’s Office (ICO) defines a personal data breach as a security incident that affects the confidentiality, integrity or availability of personal data. In plain terms: data seen by the wrong person, data changed without permission, or data lost so nobody can use it. This happens by accident just as often as on purpose. It is not only a hacker stealing a database. It also covers:
- A laptop or phone containing customer data that is lost or stolen
- An email sent to the wrong recipient, or an attachment nobody meant to share
- A misconfigured cloud storage bucket that leaves files open to the internet
- Ransomware that encrypts or copies files before anyone can respond
- A member of staff accessing or altering records they had no reason to touch
So a data breach does not need a determined attacker behind it. Plenty happen because a system was set up carelessly, or because a process had no check built in.
How common are data breaches in the UK?
More common than most owners assume. The government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses had a breach or attack in the past year. So that is roughly 612,000 organisations. The rate then climbs with size. It was 42% for micro businesses and 46% for small ones. It reached 65% for medium businesses and 69% for large ones. Bigger firms are not necessarily worse at security. They simply run more systems, employ more staff, and give an attacker more ways in.
Phishing was by far the most common cause. The survey found 38% of businesses had a phishing attempt. Among those with any breach, 69% said phishing was the most disruptive type they faced. Just over half of affected businesses experienced phishing and nothing else. That is a useful reminder: defending well against one familiar threat stops most incidents on its own.
What causes a data breach?
IBM’s 2025 Cost of a Data Breach report, covering British organisations, found three root causes ahead of the rest:
- Third-party and supply chain compromise, at 18% of breaches. Attackers go through a supplier, contractor or software vendor rather than the target directly.
- Phishing, at 16%. An employee is tricked into handing over credentials or running something they shouldn’t.
- Compromised credentials, at 11%. A password that was reused, guessed or bought from a criminal marketplace.
Together, those three causes account for close to half of all reported incidents. None of them need a sophisticated attacker. What they need is a gap: a supplier nobody vetted, a login page without multi-factor authentication, or a member of staff who has never seen what a convincing phishing email looks like.
How much does a data breach cost?
The same IBM report put the average UK data breach cost at £3.29 million in 2025. That figure covers detection, containment, lost business and regulatory fines. It also covers the long tail of notifying and supporting affected customers. Organisations using security automation and AI extensively cut that average to £3.11 million. But those without it averaged £3.78 million, so the gap comes to more than £600,000. Financial services firms fared worst of any sector, at £5.74 million on average.
Speed matters almost as much as prevention. Businesses with extensive security automation found breaches in a mean of 148 days and contained them in 42. Without it, those figures were 168 and 64 days. Every extra week an attacker sits undetected tends to widen the eventual bill, because there is simply more time to move around a network, find more valuable data, and cause more disruption before anyone notices.
Do you have to report a data breach?
Under UK GDPR, organisations must notify the ICO within 72 hours of becoming aware of a personal data breach. That duty applies whenever the breach is likely to put people’s rights and freedoms at risk. A minor internal mix-up with no real risk to anyone might not need reporting. A breach that exposes financial details, health information or enough personal data to enable fraud almost certainly does. When the risk is high, affected individuals need to be told directly too, not just the regulator.
The ICO publishes a self-assessment tool to help organisations decide whether a specific incident crosses that threshold. Getting the call wrong has consequences either way. Under-reporting risks enforcement action. Over-reporting every trivial slip wastes time and can alarm customers for nothing.
What should you do if you suspect a breach?
The National Cyber Security Centre (NCSC) recommends a calm, structured response rather than a scramble:
- Confirm what happened through your own systems and logs, not through a message someone else sent claiming there has been an incident.
- Contain it. Isolate affected systems, revoke compromised credentials and change any passwords that may have been exposed.
- Work out what data was involved and who it belongs to, so you can assess the risk accurately rather than guess.
- Decide on notification, using the ICO’s guidance, and prepare a clear, honest message for anyone affected.
- Watch for follow-up attacks. Criminals often use breached details to send convincing phishing messages afterwards, so warn staff and customers what to look out for.
If an attack is still live, the NCSC’s 24/7 line (0300 123 2040) triages genuine incidents as a priority. Having that number ready, and a written plan for who does what, saves precious time when everyone in the room is under pressure.
How can a business reduce the risk of a data breach?
Phishing, weak credentials and third-party access cause most breaches. So the highest-value defences are unglamorous. Turn on multi-factor authentication everywhere it is available. Build a proper process for vetting and monitoring suppliers. Run phishing awareness training that goes beyond a once-a-year slide deck.
Testing those defences before an attacker does is the other half of the picture. A penetration test simulates a real intrusion attempt against your systems. It finds the gap that would have let a breach happen while it is still just a line in a report, not a headline. If your last review was more than a year ago, or you have never had one, it’s worth getting a professional assessment of where you actually stand, not where your policies say you should be. If you want to talk through what a review would cover for your setup, get in touch and describe what you are trying to protect.
Frequently asked questions
Is a data breach the same as a cyber attack?
Not always. Most headline data breaches involve an attacker. But a breach can also happen without one, through a lost device, a misdirected email or a misconfigured system. A cyber attack is one way a breach can happen, not the only one.
What is the difference between a data breach and a data leak?
The terms are often used interchangeably. But “leak” tends to describe data exposed by accident, such as through a misconfigured server. “Breach” is the broader term, covering both accidental exposure and deliberate theft.
How quickly must a data breach be reported in the UK?
Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach that poses a risk to individuals’ rights and freedoms. Where the risk is high, the affected individuals must also be told without undue delay.
Can a small business be fined for a data breach?
Yes. UK GDPR applies regardless of company size. The ICO can take enforcement action, including fines, against small organisations that fail to protect personal data or fail to report a breach appropriately. In practice, most enforcement targets organisations that ignored clear warning signs or basic obligations.
What is the first thing to do after discovering a data breach?
Confirm what has actually happened through your own systems. Then contain it: isolate affected accounts or systems and change exposed passwords, before deciding on notification. Acting on an unverified report can waste time, or tip off whoever caused the breach.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.