With today’s level of digitisation, cyber attackers are finding more ways to target businesses, creating greater impact.

The UK Government’s Cyber Security Breaches Survey 2025/2026 highlights several findings that businesses need to consider. In this blog we discuss 3 of these findings: the continual threat of phishing attacks, rapid adoption of AI technologies without safeguards, and growing risks within supply chains.

Phishing Threats

Phishing remains the most prevalent and disruptive type of cyber attack, experienced by 38% of businesses. Phishing scams trick people into revealing sensitive information (like passwords) or transferring money. They can do this using links containing malware in the form of fake emails and messages, and even phone calls, usually pretending to be someone else. This enables them to gain access to your systems, where they can move through to create further disruption.

At work this might be in the form of an email from your manager, or a link through Teams from IT support, enabled using newly created accounts and email addresses, or by hacking into existing accounts. They might use social engineering to persuade you to perform certain actions using trust, fear, or curiosity.

Artificial Intelligence and evolving technologies are elevating the quality of these attacks, making phishing attempts harder to spot.

So how do you identify them?

The National Cyber Security Centre (NCSC) has outlined signs you should watch out for:

  • Authority: Using the identity of an official or authoritative person or organisation to evoke trust, such as a senior manager or IT administrator.

  • Urgency: Creating time limitations, usually with fear of negative outcomes if you don’t act quickly, such as account deactivation or security alerts.

  • Emotion: Using language that evokes fear, curiosity, or any emotion to make you act, such as a colleague in need of help.

  • Scarcity: Suggesting something is in short supply, or that you might miss out, such as a deal on products or limited staff discounts.

  • Current Events: Using company or industry events to appear more relevant, such as updating the remote working policy.

Lack of AI Governance

As Artificial Intelligence advances, we are seeing a rapid adoption of AI within businesses, often with little or insufficient safeguards. Almost a third of businesses (31%) are either using AI, in the process of adopting it, or actively considering it, with only 24% of those having practices or processes in place to address the risks.

Furthermore, 31% reported having no current plans to implement any security measures to manage these risks.

This poses significant concern as AI technology comes with its own unique set of risks, such as large-scale data storage, lack of transparency and difficulty in adhering to regulations. If there are no policies outlining its correct usage, then any of these risks could evolve into greater threats, with potential to cause significant financial damage or business disruption.

AI technology creates new types of risk wherever it is used within business. That’s why it’s important to understand where exactly it is being used, who by, and what potential risks this could have in each stage of its lifecycle. By implementing governing structures alongside the adoption of AI in your business, you can ensure that appropriate actions are taken to use AI safely.

Supply Chain Risks

Fewer businesses are taking steps to formally review their immediate suppliers and wider supply chain. Only one in ten businesses reviewed their immediate suppliers (15%), and only 6% looked at their wider supply chain for risks.

Most businesses will focus on internal security, without considering the implications that working with suppliers has. If you work with suppliers or third parties, they may have access to your systems, your offices, or shared platforms, even if only for a short time.

Threat actors will target third-party suppliers, where it may be easier to gain access to your systems or data. Compromises within supply chains and third parties have almost quadrupled in the last 5 years*, and news reports of cyber attacks are increasingly citing third party breaches as the cause.

Auditing your supply chain helps you identify and manage supply chain risks.

Our Supply Chain Audits assess the impact of supplier risks on your business, and help you implement practical measures to strengthen your supplier compliance and assurance long-term.

*IBM Threat Intelligence Index 2026

Awareness will not reduce the risks you could face without making changes. Whether you implement basic controls through Cyber Essentials, or adopt more advanced controls and certifications to demonstrate your security, making any improvement to your cyber security strategy is a step towards better cyber resilience for your business.

If your business could benefit from any of the topics discussed, please visit our Services page to view the services we offer.

If you have any more questions, or wish to get started, please get in touch with our team for further information.