The UK's Most Security-Exposed Industries in 2026

Most security conversations still get split down the middle. There are the cybersecurity worries about phishing and ransomware, and there's the facilities team worrying about who can walk through the front door. Our new research combines both sides to reveal the most exposed 11 UK industries.

We built the UK Industry Security Exposure Index by combining two official UK data sources: data breach reports from the Information Commissioner's Office (ICO), and business crime figures from the Home Office's Commercial Victimisation Survey (CVS). The result is a single score for 11 UK industries that reflects both digital and physical exposure, not just one or the other.

Below is the complete breakdown, sector by sector, plus everything else the underlying data revealed about how, why, and how often UK organisations are actually not secure.

The Most Security-Exposed Industries

Rank

Industry

Exposure Score /100

Breach Rate /10k businesses

Crime Prevalence

1

Retail & Manufacturing

50.9

24.2

36.2%

2

Utilities

43.1

75.2

32.0%

3

Transport & Leisure

40.7

15.1

32.0%

4

Charitable & Voluntary

32.5

46.4

28.0%

5

Membership & Professional Associations

31.0

9.6

28.0%

6

Finance, Insurance & Credit

7.5

184.1

15.0%

7

Legal Services

5.5

20.6

17.0%

8

Marketing

4.7

1.4

17.0%

9

Land & Property Services

2.1

53.5

15.0%

10

Online Technology & Telecoms

0.7

17.3

15.0%

11

Media

0.0

1.5

15.0%

 

Breach rate is ICO-reported breaches per 10,000 UK businesses (2023 to 2025 average, benchmarked against a wider 16-sector national baseline). Crime prevalence is the share of business premises hit by crime in the past year (Home Office, 2022/23, the most recent data available).

The UK’s most security-exposed industry

Retail and Manufacturing tops the index with a combined score of 50.9. It's a genuine double hit: the sector has the highest crime rate of any sector in the Home Office's latest survey (2022/23), with 41% of wholesale and retail premises hit by crime in the past year, and its data breach numbers are climbing too. In 2025 alone, the sector reported 31 separate data breaches that each exposed the personal details of 100,000 or more people, more large-scale breaches than any other industry we measured.

Utilities providers rank second overall (43.1) and actually have the second-highest raw data breach rate in the whole index, behind only Finance, with over 75 reported breaches per 10,000 businesses. Combined with a 32% crime prevalence rate, it's a sector getting hit hard on both fronts, even though it's a relatively small industry by business count.

UK industry with highest data breach rate

The Finance, Insurance and Credit sector has the highest data breach rate of any sector in the index, at 184 breaches per 10,000 businesses, nearly two and a half times the rate of Utilities. But because the sector's physical crime rate is comparatively low (15%), it only ranks 6th overall on the combined index. It's a reminder that a sector can be a major target for breaches without necessarily carrying the same combined risk as a sector facing both problems at once.

Human errors in the Legal sector’s security

More than 1 in 3 breaches reported by law firms in 2025 (36%) came down to a single cause: sending sensitive information to the wrong recipient by email. That's the highest rate of any industry in the index, and it's not a hacking problem. It's a process and access control problem, since the same discipline that stops the wrong person walking into a building also stops the wrong recipient ending up with a confidential file.

Phishing is the single most common cause of breaches in only three of the 11 industries in the index: Marketing (31.9% of incidents), Media (28.1%) and Retail and Manufacturing (21.5%). That suggests these sectors are being actively targeted, rather than simply making internal mistakes. Marketing and Media sit near the bottom of the overall exposure index, but Retail and Manufacturing sits at the top, which adds to its double hit.

Public sector security-exposure

One of the more uncomfortable findings didn't make it into the main index at all. Education, health and government sectors report some of the highest data breach volumes in the country, but there's no way to score their physical crime exposure on a comparable basis, because the Home Office's national business crime survey simply doesn't cover them.

When we looked at breach data for these sectors alone, benchmarked against the same national baseline as the main index:

Sector

Breach Rate /10,000 organisations

Local Government

1,214.8

Central Government

608.1

Education & Childcare

364.9

Health

208.8

Social Care

36.3

 

Local Government has the highest breach rate of any sector we measured nationally, about fifty times the rate of Retail and Manufacturing, the top-ranked commercial industry. Central and Local Government also stand out for a different reason: 93.8% and 95.4% of their breaches, respectively, are down to human error or non-cyber causes, not hacking, and Central Government has the worst late-reporting rate of any sector measured, with a third of breaches (33.2%) in 2025 taking more than a week to be reported to the ICO.

It's a genuine gap in how the UK measures organisational risk, and one worth flagging to anyone who assumes public sector data is better protected than the private sector.

Which UK industry has the most data breaches?

Health reports the highest volume of data breaches of any sector tracked by the ICO, though it isn't part of the main combined index because there's no comparable physical crime data available for it. Among the 11 commercial industries that could be measured on both digital and physical exposure, Retail and Manufacturing ranks highest overall.

Which UK industry has the highest data breach rate relative to its size?

Finance, Insurance and Credit has the highest breach rate of any commercial sector, at 184 breaches per 10,000 businesses. Outside the commercial index, Local Government has the highest rate of any sector measured nationally.

Are most UK data breaches caused by hacking?

No. 75.6% of UK data breaches in 2025 were caused by human error or process failure, such as misaddressed emails or lost paperwork, rather than cyber-attacks like phishing or ransomware.

The biggest causes of data breaches in UK companies

Here's the stat that should reframe how most organisations think about security spend: 75.6% of all UK data breaches in 2025 were caused by human error or process failure, not cyber-attacks. Think misaddressed emails, lost paperwork, and staff accidentally sharing the wrong file, not phishing or ransomware.

Nearly 1 in 5 breaches (19%) in 2025 took more than a week to be reported to the ICO, well beyond the 72-hour deadline, a compliance problem that sits alongside the security one.

Where access control fits in

Across all sectors, 16.5% of 2025 breaches involved unauthorised access, lost or stolen devices, or system misconfiguration, the exact failure modes that physical and digital access control exists to close. Membership and Professional Associations (27.9%) and Online Technology and Telecoms (26.3%) had the highest rates of these access-related breaches of any commercial sector, and Health recorded more unauthorised access incidents than any other sector measured, 516 in 2025 alone.

This is the thread that runs through the whole index. Whether it's a retail stockroom, a hospital ward, or a shared office building, the organisations getting hit hardest tend to be the ones where it isn't always clear who should and shouldn't have access, physically or digitally.

Ransomware incidents have grown 290% since 2019, rising from 158 incidents that year to a peak of 1,253 in 2023, before falling back to 617 in 2025. Total data breach reports have grown a more modest 9.8% since 2019, and didn't climb steadily either, dropping to a low of 8,798 in 2022 before recovering to 13,457 in 2025. The honest picture is a real but uneven rise, not a steady climb that shows no sign of slowing.

What organisations can do to be less security-exposed

A few practical starting points, based on where the data shows the real risk sitting:

  • Audit who actually has access, not who's supposed to. Unauthorised access and device loss show up again and again in the data, especially in Membership organisations, Online Technology and Telecoms, and Health. A clear, enforced access control system, physical or digital, closes this gap faster than almost anything else.
  • Treat "who can walk in" and "who can log in" as the same question. The businesses with the biggest combined exposure, like Retail and Manufacturing and Utilities, aren't choosing between physical and digital security; they're weak on both, often for the same underlying reason: nobody owns the full picture.
  • Fix the boring stuff first. With 3 in 4 breaches nationally coming down to human error, and over a third of Legal sector breaches being a simple misaddressed email, better processes, checked recipients, controlled paperwork disposal, and clear visitor management will do more for most organisations than another piece of cyber security software.
  • Don't assume the public sector is better protected. Local and Central Government have the highest breach rates of any sector we measured, and Central Government has the worst late-reporting record.

At ID Card Centre, we've spent over 25 years helping organisations across retail, healthcare, education, government and events get the fundamentals of access control right, because a badge that only lets the right person through the right door is still one of the simplest, most effective security tools available. If this research has raised questions about where your own organisation sits, get in touch with our team for advice on access control and ID solutions suited to your sector.