Cyber-Security Threats Remain High
The UK Government’s Cyber Security Breaches Survey 2025 provides a detailed overview of the current cyber-security threat landscape affecting businesses and charities. The findings indicate that security incidents remain widespread, with 43% of UK businesses reporting at least one cyber-security breach or attack within the previous 12 months, equating to approximately 612,000 organisations. This is down from 50% the previous year. Charities are also affected, with around 30% reporting security incidents over the same period.
Key Points
- Cyber-security incidents remain widespread, with 43% of UK businesses reporting a breach or attack in the past year.
- Phishing remains the most common cyber-security threat and a key driver of wider system compromise.
- Ransomware and impersonation attacks are increasing, contributing to financial and operational risk.
- Cyber-security preparedness remains inconsistent, with limited uptake of advanced protective measures.
- Use of AI in recruitment is increasing, with around 31% of employers adopting such technologies.
- Candidate trust in AI-led recruitment remains low, with concerns centred on transparency and over-automation.
Cyber-Security Risk by Sector
The distribution of security incidents varies by sector. Organisations operating within information and communication industries report the highest levels of digital risk exposure, with 69% experiencing breaches or attacks. Other sectors with elevated cyber risk include professional services, administrative services, finance, insurance, utilities, and production industries, where reported incident rates are approximately 48% or higher. These figures indicate that cyber risk is particularly concentrated in data-driven and commercially sensitive sectors.
Cyber-Security Threat Attack Methods
Phishing remains the most prevalent form of cyber-security attack. It accounts for over half of all security incidents involving fraud and continues to represent the primary entry point for wider system compromise. Approximately 29% of businesses report receiving phishing emails on at least a weekly basis. These incidents frequently lead to secondary impacts, including malware infection, ransomware deployment, unauthorised access to systems, and account compromises.
Impersonation attacks, often originating from phishing activity, are also a significant component of the cyber-security threat landscape. More than one third of organisations experiencing a security breach report some form of impersonation-related activity.
Financial and Operational Impact
The financial consequences of security incidents vary depending on the nature of the attack. The average cost to UK businesses of a cyber-security incident (excluding phishing) is approximately £990. In contrast, fraud-related incidents result in higher average losses of around £5,900 per case, increasing to approximately £10,000 when zero-loss incidents are excluded.
Ransomware represents a growing area of cyber-security concern, with reported prevalence increasing year-on-year. It is estimated to affect approximately 19,000 UK businesses annually. In addition to direct financial loss, incidents increasingly result in operational disruption, including temporary loss of access to systems, data, and networks. Charities also report disruption to third-party services as a consequence of such incidents.
Cyber-Security Preparedness and Controls
Levels of security preparedness vary significantly across organisations. Fewer than half of businesses report implementing core security measures such as multi-factor authentication or formal cyber-security strategies. While basic security controls, such as antivirus software and password policies, are widely adopted, more advanced protective measures remain less common.
Larger organisations have higher levels of security arrangements in place. They are more likely to have formal incident response plans, structured cyber-security training programmes, and comprehensive risk management processes. Smaller organisations show some improvement in risk assessment and continuity planning, but continue to demonstrate lower overall levels of preparedness.
Board-level accountability for cyber-security has declined compared to previous years, with only 27% of organisations assigning direct responsibility at senior leadership level. External security consultancy remains a common source of support, although awareness and utilisation of government guidance has decreased.
Cyber-Security Outlook
The scale of cyber-security threat activity remains substantial, with UK organisations experiencing an estimated 8.58 million incidents over the past year. Repeat incidents are common, indicating persistent targeting and evolving attacker methods. Phishing continues to dominate the cyber-security landscape, while ransomware and other financially motivated threats are increasing in prevalence.
Overall, the data indicates that cyber-security remains a significant and ongoing operational risk. The continued frequency of incidents, combined with evolving attack methods and uneven levels of organisational preparedness, highlights the importance of sustained focus on cyber-security risk management, resilience, and mitigation across all sectors.
AI in Recruitment: Trust and Candidate Experience
New Report
A new report on the recruitment sector from Omni RMS indicates increasing use of artificial intelligence (AI) by both employers and jobseekers, with measurable effects on recruitment processes and candidate experience. The survey, which consisted of 739 jobseekers, found that approximately half are using AI tools, primarily to tailor CVs and prepare for interviews. On the employer side, adoption of AI and machine learning in recruitment has also increased, with around 31% of organisations using such technologies by 2023, according to the CIPD Resourcing and Talent Planning Survey 2024, representing a significant year-on-year rise.
Trust Low Amongst Candidates
Despite the increased use of AI in recruitment, levels of trust in AI-led decision-making remain comparatively low. Approximately 42% of candidates report trusting automated recruitment processes to the same extent as human-led hiring, while 29% indicate that they would consider withdrawing from an application where AI is perceived to be used excessively. Transparency in recruitment processes is identified as a key factor, with candidates seeking clearer information on how AI is applied and the extent of human involvement.
Differences Amongst Age Groups
Differences in response to AI in recruitment are evident across age groups. Younger candidates are more likely to use AI tools in their applications but are also more likely to disengage from recruitment processes perceived to be overly automated. Older candidates demonstrate greater variation in response, with decisions more frequently influenced by the specific role or organisation.
Balance Required
Core employment factors, including salary, benefits, flexible working arrangements, and career development opportunities, continue to be primary drivers of job choice. However, process-related issues remain significant. Approximately half of candidates identify lengthy application processes and poor communication as deterrents, indicating that efficiency gains associated with AI in recruitment must be balanced against overall candidate experience.
Conclusion
Overall, while the use of AI in recruitment is increasing, candidate engagement remains closely linked to transparency, communication, and the continued presence of human decision-making within the recruitment process.
Employers: What This Means
- Review cyber-security arrangements, including multi-factor authentication, risk assessments, and incident response planning.
- Provide regular staff training to mitigate exposure to phishing and other cyber-security threats.
- Ensure business continuity measures are in place to manage operational disruption following cyber-security incidents.
- Use AI in recruitment transparently, maintaining appropriate human oversight and clear communication with candidates.



