One in five UK businesses have chosen to keep a serious cyber incident from the authorities rather than face the consequences, according to Databarracks' Data Health Check 2026, an annual survey of 500 IT decision-makers.
Under the UK GDPR and the Data Protection Act 2018, an organisation that suffers a personal data breach likely to put people at risk must notify the Information Commissioner's Office without undue delay, and within 72 hours of becoming aware of it, not from when the breach actually occurred. The definition is broader than most people assume. Any security failure that leads to personal data being accidentally or unlawfully destroyed, lost, altered, disclosed or accessed all qualifies, not only a hacker walking off with a database.
Firms regulated by the FCA face a second, tightening layer of obligation. The regulator published its final rules on operational incident and third-party reporting, Policy Statement PS26/2, on March 18, 2026, creating a single reporting regime with the Prudential Regulation Authority and the Bank of England that takes effect on March 18, 2027.
Brokers are FCA-regulated in their own right, so this isn't only a question of what applies to financial services clients; firms will want to check how the new regime affects their own reporting obligations too.
Charlie Maclean-Bristol, deputy resilience director at Databarracks, said the scale of non-reporting also robs the National Cyber Security Centre and law enforcement of intelligence they need to spot wider patterns.
"It's concerning to see how many cyber incidents are kept behind closed doors," he said. "Staying quiet about a cyber attack is rarely a wise idea. Besides any legal implications, by not informing the police, NCSC or other relevant authorities, you may also be obscuring a wider attack on a sector or region. Authorities cannot identify the pattern if incidents are not reported to them."
He said the reputational cost of concealment can outlast the attack itself: "Covering up an incident can also do lasting damage to trust. If information is withheld from people affected by an attack, especially when they could have acted to protect themselves, the cover-up may ultimately cause more damage than the original incident."
The wider survey points to a gap between how prepared businesses believe they are and how prepared they've actually verified themselves to be. Some 76% of organisations believe they're more resilient than they were a year ago, yet only 43% of those describing themselves as "very confident" in handling a ransomware attack had actually tested recovery from a cyber incident in the past 12 months.
Nearly one in five (18%) have no cyber insurance at all, a finding that sits alongside Everywhen's own recent survey, which found 65% of professional firms now name cyber-attacks as their single biggest business risk for 2026, more than three times higher than any other concern, even as many remain underinsured against it.
Databarracks' data also flagged AI as accelerating the pressure directly: AI-driven attacks have more than doubled in frequency over the past year, now affecting a quarter of organisations, even though 79% of respondents still believe AI is a greater benefit than threat to their own security. Supply chains add a further layer of exposure the survey found harder to manage than incident response itself: one in four organisations suffered a cyber incident that began with a supplier or third party, and nearly half continued working with suppliers even after identifying known resilience or security gaps in that relationship.
There's real good news buried in the numbers. Of organisations hit by ransomware in the past year, 59% recovered from backups without paying, against 18% who paid the ransom. That pattern tracks closely with Coalition's own 2026 Cyber Claims Report, which found a record 86% of businesses in its own book refused to pay despite initial ransom demands surging 47% year on year to over $1 million on average, a shift Coalition attributed to stronger backups and tested incident response rather than luck.
The catch is that dual extortion, attackers both encrypting systems and stealing data before threatening to leak it, now accounts for 70% of ransomware claims industry-wide, and those incidents cost more than twice as much as encryption-only attacks, since stolen data creates a legal, regulatory and reputational problem that a clean backup restore can't fix on its own.
For brokers, a client who kept an incident quiet is often also a client who never drew on the breach-response support already built into their policy, and who may not have met the notification conditions the policy itself requires. Renewal is a natural moment to ask a client directly who they would call in the first hour of an attack, and whether that plan has actually been tested rather than simply written down.
Maclean-Bristol said preparation should start with knowing exactly who to contact before anything goes wrong.
"Prioritise crisis communications efforts on those who need to be informed, then concentrate on mitigating the impact, managing the response and protecting your reputation," he said. "One thing organisations can do when developing and testing cyber playbooks is identify the right law enforcement and regulatory contacts. Establishing those relationships in advance can improve the speed and effectiveness of reporting and support when an incident occurs."