
Published 05 October 2026
Last Updated 05 October 2026
The UK's Most Security-Exposed Industries in 2026
Most security conversations still get split down the middle.
There are the cybersecurity worries about phishing and ransomware, and there's
the facilities team worrying about who can walk through the front door. Our new
research combines both sides to reveal the most exposed 11 UK industries.
We built the UK Industry Security Exposure Index by
combining two official UK data sources: data breach reports from the Information Commissioner's Office (ICO),
and business crime figures from the Home Office's Commercial Victimisation
Survey (CVS). The result is a single score for 11 UK industries that reflects
both digital and physical exposure, not just one or the other.
Below is the complete breakdown, sector by sector, plus
everything else the underlying data revealed about how, why, and how often UK
organisations are actually not secure.
The Most Security-Exposed Industries
Rank | Industry | Exposure Score /100 | Breach Rate /10k businesses | Crime Prevalence |
1 | Retail & Manufacturing | 50.9 | 24.2 | 36.2% |
2 | Utilities | 43.1 | 75.2 | 32.0% |
3 | Transport & Leisure | 40.7 | 15.1 | 32.0% |
4 | Charitable & Voluntary | 32.5 | 46.4 | 28.0% |
5 | Membership & Professional Associations | 31.0 | 9.6 | 28.0% |
6 | Finance, Insurance & Credit | 7.5 | 184.1 | 15.0% |
7 | Legal Services | 5.5 | 20.6 | 17.0% |
8 | Marketing | 4.7 | 1.4 | 17.0% |
9 | Land & Property Services | 2.1 | 53.5 | 15.0% |
10 | Online Technology & Telecoms | 0.7 | 17.3 | 15.0% |
11 | Media | 0.0 | 1.5 | 15.0% |
Breach rate is ICO-reported breaches per 10,000 UK
businesses (2023 to 2025 average, benchmarked against a wider 16-sector
national baseline). Crime prevalence is the share of business premises hit by
crime in the past year (Home Office, 2022/23, the most recent data available).
The UK’s most security-exposed industry
Retail and Manufacturing tops the index with a combined
score of 50.9. It's a genuine double hit: the sector has the highest crime rate of any sector in the Home Office's latest survey (2022/23), with 41% of wholesale and retail premises hit by
crime in the past year, and its data breach numbers are climbing too. In 2025
alone, the sector reported 31 separate data breaches that each exposed the
personal details of 100,000 or more people, more large-scale breaches than
any other industry we measured.
Utilities providers rank second overall (43.1) and actually
have the second-highest raw data breach rate in the whole index, behind only Finance, with over 75 reported
breaches per 10,000 businesses. Combined with a 32% crime prevalence rate, it's
a sector getting hit hard on both fronts, even though it's a relatively small
industry by business count.
UK industry with highest data breach rate
The Finance, Insurance and Credit sector has the highest
data breach rate of any sector in the index, at 184 breaches per 10,000
businesses, nearly two and a half times the rate of Utilities. But because the sector's
physical crime rate is comparatively low (15%), it only ranks 6th overall on
the combined index. It's a reminder that a sector can be a major target for
breaches without necessarily carrying the same combined risk as a sector facing
both problems at once.
Human errors in the Legal sector’s security
More than 1 in 3 breaches reported by law firms in 2025 (36%)
came down to a single cause: sending sensitive information to the wrong
recipient by email. That's the highest rate of any industry in the index, and
it's not a hacking problem. It's a process and access control problem, since
the same discipline that stops the wrong person walking into a building also
stops the wrong recipient ending up with a confidential file.
Phishing is the single most common cause of breaches in only three of the 11 industries in the index: Marketing (31.9% of incidents), Media (28.1%) and Retail and Manufacturing (21.5%). That suggests these sectors are being actively targeted, rather than simply making internal mistakes. Marketing and Media sit near the bottom of the overall exposure index, but Retail and Manufacturing sits at the top, which adds to its double hit.
Public sector security-exposure
One of the more uncomfortable findings didn't make it into
the main index at all. Education, health and government sectors report some of
the highest data breach volumes in the country, but there's no way to score
their physical crime exposure on a comparable basis, because the Home Office's national business crime survey simply doesn't cover them.
When we looked at breach data for these sectors alone,
benchmarked against the same national baseline as the main index:
Sector | Breach Rate
/10,000 organisations |
Local Government | 1,214.8 |
Central Government | 608.1 |
Education &
Childcare | 364.9 |
Health | 208.8 |
Social Care | 36.3 |
Local Government has the highest breach rate of any sector
we measured nationally, about fifty times the rate of Retail and
Manufacturing, the top-ranked commercial industry. Central and Local Government
also stand out for a different reason: 93.8% and 95.4% of their breaches, respectively, are down to human error or non-cyber causes, not hacking, and Central Government has
the worst late-reporting rate of any sector measured, with a third of breaches (33.2%) in 2025 taking more than a week to be reported to the ICO.
It's a genuine gap in how the UK measures organisational
risk, and one worth flagging to anyone who assumes public sector data is better
protected than the private sector.
Which UK industry has the most data breaches?
Health reports the highest volume of data breaches of any
sector tracked by the ICO, though it isn't part of the main combined index
because there's no comparable physical crime data available for it. Among the
11 commercial industries that could be measured on both digital and physical
exposure, Retail and Manufacturing ranks highest overall.
Which UK industry has the highest data breach rate relative to its size?
Finance, Insurance and Credit has the highest breach rate of
any commercial sector, at 184 breaches per 10,000 businesses. Outside the
commercial index, Local Government has the highest rate of any sector measured
nationally.
Are most UK data breaches caused by hacking?
No. 75.6% of UK data breaches in 2025 were caused by human
error or process failure, such as misaddressed emails or lost paperwork, rather
than cyber-attacks like phishing or ransomware.
The biggest causes of data breaches in UK companies
Here's the stat that should reframe how most organisations
think about security spend: 75.6% of all UK data breaches in 2025 were caused
by human error or process failure, not cyber-attacks. Think misaddressed
emails, lost paperwork, and staff accidentally sharing the wrong file, not
phishing or ransomware.
Nearly 1 in 5 breaches (19%) in 2025 took more than a week to be reported to the ICO, well beyond the 72-hour deadline, a compliance problem that sits alongside the security one.
Where access control fits in
Across all sectors, 16.5% of 2025 breaches involved
unauthorised access, lost or stolen devices, or system misconfiguration, the
exact failure modes that physical and digital access control exists to close.
Membership and Professional Associations (27.9%) and Online Technology and
Telecoms (26.3%) had the highest rates of these access-related breaches of any
commercial sector, and Health recorded more unauthorised access incidents than
any other sector measured, 516 in 2025 alone.
This is the thread that runs through the whole index.
Whether it's a retail stockroom, a hospital ward, or a shared office building,
the organisations getting hit hardest tend to be the ones where it isn't always
clear who should and shouldn't have access, physically or digitally.
Ransomware incidents have grown 290% since 2019, rising
from 158 incidents that year to a peak of 1,253 in 2023, before falling back to
617 in 2025. Total data breach reports have grown a more modest 9.8% since
2019, and didn't climb steadily either, dropping to a low of 8,798 in 2022
before recovering to 13,457 in 2025. The honest picture is a real but uneven
rise, not a steady climb that shows no sign of slowing.
What organisations can do to be less security-exposed
A few practical starting points, based on where the data
shows the real risk sitting:
- Audit
who actually has access, not who's supposed to. Unauthorised access
and device loss show up again and again in the data, especially in
Membership organisations, Online Technology and Telecoms, and Health. A
clear, enforced access control system, physical or digital, closes this
gap faster than almost anything else.
- Treat
"who can walk in" and "who can log in" as the same
question. The businesses with the biggest combined exposure, like
Retail and Manufacturing and Utilities, aren't choosing between physical
and digital security; they're weak on both, often for the same underlying
reason: nobody owns the full picture.
- Fix
the boring stuff first. With 3 in 4 breaches nationally coming down to
human error, and over a third of Legal sector breaches being a simple
misaddressed email, better processes, checked recipients, controlled
paperwork disposal, and clear visitor management will do more for most
organisations than another piece of cyber security software.
- Don't
assume the public sector is better protected. Local and Central Government have the highest breach rates of any sector we measured, and Central Government has the worst late-reporting record.
At ID Card Centre, we've spent over 25 years helping
organisations across retail, healthcare, education, government and events get
the fundamentals of access control right, because a badge that only lets the
right person through the right door is still one of the simplest, most
effective security tools available. If this research has raised questions about
where your own organisation sits, get in touch with our team
for advice on access control and ID solutions suited to your sector.
About the Author
Ben O'Brien
Managing Director
Ben O’Brien is the Managing Director of ID Card Centre and a recognised authority in complex access control applications and eco-friendly identification solutions. Since entering the ID card printing industry in 1998, Ben has led countless projects across sectors, combining deep technical knowledge with a commitment to sustainability and innovation. Under his leadership, ID Card Centre continues to set standards for secure, efficient, and environmentally conscious ID systems.


















