Home » Latest news » Cyber Security Awareness Month 2026: what UK businesses should prioritise
October is Cyber Security Awareness Month, which means a month of padlock graphics and recycled advice is already heading for your feed. It's easy to be cynical about it, and yet the month keeps earning its place for one reason: it is the only fixed point in the calendar when boards reliably ask the security question, and a prepared IT leader can do a great deal with that moment, from budget approvals to the policy decisions that have waited all year.
This news article is the list we would put in front of a UK business this October: the risks that deserve attention, drawn from what our cybersecurity services team actually sees in mid-sized UK environments week to week, set against the national figures so you can tell where your business sits.
Only for organisations that convert it into decisions. The background numbers barely move year to year. The government's Cyber Security Breaches Survey 2025/26, published in April found that 43% of UK businesses identified a breach or attack in the previous 12 months, around 612,000 businesses, and the figure climbs with size: 46% of small businesses and 65% of medium ones. Phishing was the most disruptive type of attack for 69% of those affected, as it has been every year the survey has run. Awareness alone has never fixed that, because the problem was never that people are unaware of phishing. The problem is that the defences, habits, and rehearsals that stop it are nobody's job in a busy quarter.
The same survey puts numbers on the gap between knowing and doing: only 25% of businesses have a formal incident response plan; only 22% test their own staff with mock phishing; only 15% review the cyber risks of their immediate suppliers. Those three figures, more than any threat statistic, are the reason October is worth a month of anyone's attention.
Before the month is out, put the same questions to your own business.
Incident log. If you cannot say how many attacks or breaches your business recorded last year, that is the finding.
Incident response. Ask who would run the first hour of an incident, and whether that is written down.
Phishing simulation. Find the date of your last simulation and its click rate.
Suppliers. Count the suppliers with admin access or a copy of your data, then count how many you have assessed.
Source: DSIT, Cyber Security Breaches Survey 2025/26 (fieldwork August to December 2025, published 30th April 2026).
Identity, and who your service desk trusts. The most damaging UK attacks of the last two years have not started with clever malware. They started with a phone call: an attacker impersonating an employee to a service desk, or a service desk to an employee, and talking their way to a password reset. The attack that cost Marks & Spencer an estimated £300 million in 2025 began, by the company's own account, with a sophisticated impersonation aimed at its outsourced helpdesk. Verification procedures for resets and MFA changes cost almost nothing and would have stopped most of these incidents cold. If your support is outsourced, ask your provider to show you theirs; a blank look is an answer too.
Phishing that reads like a colleague wrote it. Generative AI has removed the tells everyone was trained to spot. The clumsy greeting and the odd grammar are gone; what arrives now is fluent, contextual, and personalised at scale, often referencing real colleagues and live projects scraped from public sources. Your filters and your reporting culture matter more than ever, and our earlier guide to phishing prevention covers the layered approach in detail.
The machines that fell out of support. Windows 10 reached end of support on 14 October 2025, and a year later plenty of UK estates are still running it, along with the ageing server nobody wants to touch and the appliance whose vendor went quiet. Unsupported means unpatched, and unpatched is where automated attacks go first: the NCSC's Annual Review 2025 traced 29 of the incidents it managed to just three known vulnerabilities. If your asset register cannot tell you how much of this you own, that is finding number one.
Your suppliers' security, not just yours. The most expensive UK cyber incident on record did most of its damage to businesses that were never attacked. The Cyber Monitoring Centre put the cost of the 2025 Jaguar Land Rover shutdown at around £1.9 billion, spread across more than 5,000 organisations, most of them suppliers whose orders simply stopped. Ask your critical suppliers the questions you would want to answer yourself. Our guide on how to vet an IT provider is a reasonable template for the conversation.
Recovery you have actually rehearsed. Backups that have never been restored are a hope, and hope is not a control. Ransomware groups target backup infrastructure deliberately, because paying is the only option left when recovery fails. Testing restores, and rehearsing the wider incident response around them, is the difference between a bad week and a company-ending quarter. This is the ground our business resilience services cover, and October is an ideal month to book the exercise.
Not the IT manager alone, and October is the month to say so out loud. Cyber risk is a board risk: the consequences land on revenue and reputation rather than on servers, and several of the priorities above are procedural decisions only leadership can make. The verification rule for payment requests belongs to finance. The service desk policy belongs to whoever owns the support contract. The decision to fund the Windows 10 replacements belongs to the budget holder who has been deferring it. The survey says 31% of businesses have a board member with explicit responsibility for cyber security; the Cyber Security and Resilience Bill, now in its final Lords stages, is about to make that expectation harder to ignore for the sectors it covers.
The practical move is a standing agenda item rather than an annual scramble. A board that hears a one-page security report quarterly, with the same four or five measures each time, builds the context to make fast decisions when something real happens. A board that hears about security once a year, in October, makes its first decisions during an incident, which is the most expensive classroom there is.
Simulate, do not lecture. Annual training satisfies an auditor; simulated phishing, run regularly and followed by coaching rather than blame, changes behaviour. The goal is a workforce that reports suspicious messages quickly, because reporting speed determines how far a real campaign gets before someone shuts it down. A culture where the person who clicked feels safe saying so within minutes is worth more than any single product you could buy this month.
We can offer our own estate as evidence. Highgate runs Ironscales across 160 mailboxes, combining detection with regular phishing simulation for our own staff. The platform captured 334 incidents in its first year, and our most recent simulation came back with zero clicks across the team.
"Honestly, the toughest email security customer I have is my own team. We see incidents at customer sites every other week, and I knew what I didn't want. Ironscales is the only platform I've been comfortable signing off for our staff. The latest simulation came back without a click, which told me I'd made the right call." – Paolo Rodia, Services Director at Highgate IT Solutions
We sell and support the platform, so read that with the obvious caveat. The reason we cite it anyway is the shape of the result: measurable behaviour change, evidenced by simulation, in a company full of people who should already know better. That shape is available to any organisation willing to measure itself, and the national figure for businesses doing so is 22%.
Plenty, if you pick actions over campaigns. Audit MFA coverage and close the gaps, starting with email and finance systems; since April, a missing MFA on any cloud service is an automatic fail under Cyber Essentials, which tells you how seriously the scheme now takes it. Run one tabletop exercise: two hours, senior people in a room, one written scenario, and the honest question of who does what by hour six. Baseline your phishing risk with a first simulation. Pull the asset register and count the out-of-support machines. None of these needs a budget line that would trouble a CFO, and each produces evidence you can act on in November.
The tabletop exercise deserves special mention because it is the one businesses postpone longest and rate highest afterwards. Two hours of imagined crisis surfaces the gaps, the missing phone numbers, the unclear authority to shut systems down, the insurer nobody thought to call, at a price of nothing but mild embarrassment.
The organisations that get value from October are the ones that leave it with fewer unknowns than they entered: which systems are exposed, which people would be fooled, which recovery steps have never been tried. Awareness is knowing the questions. The month is for getting answers with dates on them, and for putting the security conversation on an agenda it never leaves.
If the list above is longer than your team can face alone, that is normal, and it is fixable in an ordered way rather than all at once. Everything here sits under our Reduce risk services, from gap analysis through to a fully monitored estate; our companion piece publishing later this month on what actually hit UK businesses in 2026 shows the same risks from the incident side. Talk to us and we'll set out where we'd begin with yours.