ESET's 2026 SMB Cyber Risk Report counts familiar failures
The central figure is well corroborated. Infosecurity Magazine reported that half (49%) of the UK's SMEs suffered a cybersecurity incident over the past year, and DIGIT reported the same result. Both are reporting ESET's own survey, though, so they confirm what ESET published rather than measuring anything themselves. ESET commissioned the research firm Go4insight to survey cybersecurity decision-makers at 500 UK SMBs in the first quarter of 2026.
ESET's definition of an SMB is worth checking before you apply the numbers to your own clients. The survey covered organisations with 25 to 1,000 endpoints. That leaves out the smallest firms, and it includes some organisations far larger than most people would call a small business. The UK's National Cyber Security Centre (NCSC), for comparison, aims its small-organisation guidance at bodies with up to 250 employees. The ESET figures describe mid-sized, IT-managed organisations, not the corner shop.
TechRadar, which covered the report, adds that 13% of those experiencing an incident had more than one. That repeat-incident figure does not appear in the findings listed in ESET's UK press release. According to Infosecurity Magazine, ESET found that the average respondent took over four weeks to identify and recover from a breach. For a firm with no dedicated security staff, that is a month of disruption.
The list of causes is the most practical finding. Infosecurity Magazine summarised it: incidents were caused by phishing, unpatched vulnerabilities, weak passwords, and a lack of monitoring – all things that best practice hygiene of the sort advocated by Cyber Essentials should address. None of those four is new, and none depends on AI. Each can be addressed with tools and processes most Windows shops already have.
AI-powered malware tops the worry list, but phishing causes the damage
ESET reports that AI-powered malware was respondents' top security concern. TechRadar's headline, "greater AI security threats than ever," is built on that concern. But being worried about a threat is different from being hit by it. The UK release does not measure how many of the 49% of incidents involved AI in any way.
ESET's own staff are more cautious than the headline. Jake Moore, ESET's Global Cybersecurity Advisor, said AI "will help cybercriminals to speed up their attacks," but that core tactics like phishing and exploiting software vulnerabilities "will largely stay the same." He argued that smaller businesses will stay easy targets until they lock down the basics.
The global version of the research says the same thing more bluntly. When ESET released its broader SMB Cyber Readiness Index 2026 in June, Juraj Jánošík, ESET's Vice President of Artificial Intelligence, told SecurityBrief that "the practical impact of AI today is much less about novel autonomous malware and more about enabling higher volumes of more convincing phishing campaigns, faster malware development, and scalable abuse of publicly available AI tools and agentic skills". Silicon Republic summarised the same research as finding that "businesses are losing sleep over a high-tech threat that has barely shown up in real attacks", while everyday scams get through and cost money.
This explains how a report can say both "AI is the top concern" and "phishing is the main cause" without contradicting itself. In the vendor's own framing, AI mostly makes the old attacks cheaper and more convincing. If a phishing email written by AI lands in a user's Outlook inbox, it is still a phishing email. What stops it is the same set of defences as always: filtering, user awareness, and multifactor authentication that makes a stolen password useless on its own.
The UK government's figures point the same way. In the Cyber Security Breaches Survey 2025/2026, qualitative interviews found a perception that phishing had become easier for attackers to commit, which interviewees felt was driving more attacks. That is a perception, not a measured AI effect, but it matches ESET's view of AI as an accelerant for existing techniques.
The UK numbers are a slice of ESET's 4,400-firm Cyber Readiness Index
The UK report does not appear to be a standalone study. ESET's global index, released in June, used the same research partner and the same endpoint range. Silicon Republic reported that ESET partnered with Esomar member Go4insight to collect data from 4,400 organisations with 25 to 1,000 endpoints across 13 countries, and that the countries included Canada, the Czech Republic, Denmark, France, Germany, Italy, Japan, the Netherlands, Slovakia, Spain, Sweden, the UK and the US. ESET's US page says its national results come from 500 US organisations collected in February 2026, as part of a broader survey of 4,400 respondents across 13 countries. The UK's 500 respondents surveyed in Q1 2026 fit the same pattern.
That makes a comparison possible. Across all 13 countries, ESET found that 45% of SMBs faced a cybersecurity incident in the past 12 months and 14% experienced an incident more than once. The UK's 49% is a little above that, and TechRadar's 13% UK repeat rate is close to the global 14%. Globally, SecurityBrief reported that phishing was the most common cause of incidents, cited in 26% of cases, and that while phishing remained the most common route for incidents, respondents identified AI-powered malware as their top concern.
So the UK pattern is not unusual. The mismatch between worrying about AI and being hit by phishing shows up across the whole international sample. The UK is a few points worse on incident rate, and it matches the global picture on where the risk actually comes from.
The global report also offered a view that sits awkwardly with calling SMBs "woefully unprepared." ESET's blog concluded that confidence is growing, not because threats are diminishing, but because businesses are learning to live with them, citing insurance, training and faster response. It added that the fundamentals remain decisive. The balanced reading is that preparation is uneven, not absent.
The Cyber Security Breaches Survey 2025/2026 undercuts the "more than ever" claim
TechRadar's story opens by saying British small businesses are being hit by more cyberattacks than ever before. ESET's UK release gives no year-on-year comparison to support that. The best independent baseline, the UK government's official Cyber Security Breaches Survey 2025/2026, points the other way.
The government survey, published on 30 April 2026 by the Department for Science, Innovation and Technology (DSIT) and the Home Office, found that 43% of UK businesses had identified a breach or attack in the previous 12 months. That was the same as the year before, which itself followed a significant fall from 50% in 2023/2024. By size, 42% of micro businesses and 46% of small businesses reported a breach or attack, rising to 65% of medium and 69% of large businesses.
The attack-type trends also fail to show a surge. Phishing affected 38% of businesses, down from 42% two years earlier. Ransomware fell to 1% of businesses from 3% in each of the previous two years. The government warns that its survey only counts incidents organisations were able to spot and willing to report, so true prevalence is probably higher, especially among smaller firms that are less able to detect attacks. That warning cuts both ways, though: it makes the statistics less precise, but it gives no evidence of a record year.
A direct comparison between the two surveys would be misleading. ESET's 49% covers organisations with 25 to 1,000 endpoints, sampled by a vendor. The government's figures use its own size bands and a much wider population. The accurate statement is that incident rates among UK SMBs are high and have stayed there, not that they are rising to new peaks.
Where the government data does support the "unprepared" argument is in governance. Among small businesses, 41% carried out cyber risk assessments, down from 48% the year before. 52% had a formal cyber-security policy, down from 59%, and 44% had a business continuity plan that covers cyber incidents, down from 53%. Across all businesses, only 47% used two-factor authentication and 30% used user monitoring. The same survey found that 81% had up-to-date malware protection and 74% had secure cloud backups, password policies and network firewalls. Most firms have the basic technical controls in place. The weak spots are the layers above them: planning, policy and identity protection.
The consequences are also rising slightly. Businesses reporting lost revenue or share value after an incident rose from 2% to 5%, and reports of reputational damage rose from 1% to 3%.
The 86% outsourcing gap and four-week recoveries fall on thin IT teams
The most useful ESET figures for sysadmins and MSPs are about who handles security. ESET says 86% of UK SMBs in its sample do not outsource even part of their cybersecurity to a managed detection and response (MDR) service, a managed service provider (MSP) or a managed security service provider (MSSP). Among respondents, 32% said security is part of an IT specialist's broader job, 33% have a dedicated cybersecurity specialist, and 21% have an internal security operations centre (SOC) team. Only 11% outsource partly and 3% outsource fully. ESET presents these as separate answers, so they should not be read as one set of percentages that adds up to 100.
Among the firms that do outsource, 57% use an MSP or MSSP, 21% also use their MSP for MDR, 27% get MDR through a cyber insurer, and 16% get it through a security vendor. Keep in mind that ESET sells MDR and endpoint products. The company's UK country manager, Matt Knell, framed the findings as a chance for SMBs to bring in outside support "before a costly incident occurs." The outsourcing figures are survey data, but the conclusion that firms should buy managed services is the vendor's argument.
The link between these figures is still easy to see. Two of the four leading causes, unpatched vulnerabilities and lack of monitoring, depend on someone having time to do the work. When security is one part of a general IT role, patching and log review are the first jobs to slip. The skills shortage and the difficulty of keeping up with patch management that respondents reported point to the same problem. A four-week average recovery time is what you would expect when nobody is watching the alerts.
Budgets are moving the right way. ESET says 55% of surveyed UK SMBs expect cybersecurity spending to rise over the next 12 months, with employee training and cloud security as top priorities. The government survey suggests training has plenty of room to grow: only 19% of businesses ran staff training or awareness activities, unchanged from the year before.
Certification is rising too, but from a low base. DIGIT reported that the government-backed Cyber Essentials scheme has recorded its highest annual number of certifications, with 61,430 certificates awarded between July 2025 and June 2026, which represent a 20% increase compared with the previous year, although the number of businesses participating in the scheme remains relatively small compared with the UK's wider SME population. The government survey found that Cyber Essentials certification among small businesses rose from 5% to 12%.
What this means for you
If you run IT for a UK small or mid-sized firm, or support such firms as an MSP, don't buy an "AI defence" product until the four basic failures ESET found are closed. Phishing, missed patches, weak passwords and unmonitored systems caused the incidents. AI-assisted attacks mostly make those same weaknesses easier to exploit, so fixing them also covers most of the AI risk.
The NCSC's free resources for organisations with up to 250 employees fit this well. The Cyber Action Toolkit offers short first steps for sole traders and small businesses. The Check Your Cyber Security tool checks whether criminals could target you. Exercise in a Box lets a team rehearse its incident response. The NCSC also publishes a Small Business Guide on response and recovery, a guide to choosing an MSP, and a service that tells you where to report an incident. If ransomware hits, the NCSC advises against paying: payment doesn't guarantee your data back, your systems stay infected, and you become more likely to be targeted again. Cyber Essentials is the government-backed certification built around the same basic controls.
- Put two-factor authentication on email and remote access first. Only 47% of UK businesses use it, and it blunts both password guessing and credential phishing.
- Make patching someone's named job with a schedule. Unpatched vulnerabilities were one of ESET's four leading causes, and respondents listed patch management as a barrier.
- Write down and test an incident response and continuity plan. Fewer small businesses had one this year (44%, down from 53%), and ESET's four-week average recovery time shows what happens without one.
- Treat monitoring as a real gap. If nobody reviews alerts, consider outsourced MDR, since 86% of ESET's sample handle everything in-house.
- Put new security budget into training as well as tools. Only 19% of businesses run staff awareness activities, and phishing is still the most common way attackers get in.
- Use Cyber Essentials as a benchmark even if you don't certify. Its controls match the failures behind most of the incidents in ESET's report.
Read carefully, the ESET report argues against panic about AI. Half of UK SMBs in its sample were breached, mostly through basic weaknesses. The government's data shows incident rates stuck high rather than climbing, and small firms falling behind on planning and policy. With 55% of ESET's sample expecting bigger security budgets over the next year, how that money is spent will decide whether next year's figures improve: firms that spend it on MFA, patching, monitoring and response plans will be better protected against AI-assisted attacks too.