A significant cyber incident every two days, apparently - though nobody named the sums

A UK law firm's 2025 compliance guide claims the National Cyber Security Centre handled 204 significant incidents in the year to September, which works out to one every two days, though the guide doesn't say where it got the figure. This includes practices like yours, if you keep client records on anything with a login screen.

Practices holding client health or session data are being told cyber risk is rising fast, though the evidence for exactly how fast comes with no visible working.

Original ResearchA claim that the NCSC dealt with 204 major cyber incidents in the twelve months to September 2025, roughly one every two days
Sourcehttps://connaughtlaw.com/uk-data-protection-gdpr-compliance-guide/
OverviewThe page is a general UK GDPR compliance guide published by a law firm, with the incident figure dropped in as background colour rather than a cited research finding.
Year2025
PublisherBrand, Connaught Law
Relevance to WellbeingStrong as a general nudge that cyber risk is real and growing, but it's a step removed from anything specific to wellbeing practices.
Our VerdictToo early to tell The figure has no named source, no linked NCSC report, and no methodology, so treat it as a claim worth checking rather than a fact worth quoting.
Our Summary
  • The underlying idea, that cyber incidents are common and rising, lines up with most other reporting on the subject.
  • The specific number comes with no citation, no sample, and no link to an actual NCSC report.
  • A law firm's compliance guide has an obvious interest in making the threat sound urgent.
  • Even without the exact figure, the general direction is a reasonable prompt to check your own basics.
Our Geo ViewUK-specific: the NCSC only covers UK incidents, and the GDPR compliance framework referenced is the UK version.
Abstract of wellbeing niches and revenue flow
Recognise how this might impact your practice

Why this might matter to you

  • Coaching: this matters because client notes and session recordings sitting in an inbox are exactly the sort of thing that gets scooped up in a breach.
  • Therapy: this matters because therapy notes are about as sensitive as data gets, and a leak is a very different kind of headline to a bad review.
  • Training: this matters because booking systems and payment details are still data, even if nobody thinks of a gym as a target.
  • Alternative Healing: this matters because client intake forms often ask about health history, which is precisely the category attackers and regulators both care about.
  • Clinical: this matters because clinical records carry extra legal weight, and "we didn't know the risk was rising" won't hold up well.
  • Retreat/Centre: this matters because a centre holding bookings, health forms and payment info for dozens of guests at once is a bigger prize than any individual practitioner.

Where this came from

A UK law firm's GDPR compliance guide states, without naming a source, that the NCSC handled 204 major incidents in the year to September 2025.

Connaught Law, published 2025. The figure appears within a general compliance guide rather than a dedicated research report, and no NCSC publication is linked.

Credibility flags: methodology not disclosed, sample size not applicable, publisher type is a law firm's own marketing content, not an independent or peer-reviewed source.

How we scored this

A relevance score out of 100, built from three things: how well it fits the six practice types, how recent it is, and how solid the methodology behind it is.

40%
Practice fit, 25How new, 100How solid, 0

Marked down heavily on how solid the method is, since the figure is unattributed, though it scores well on recency and reasonably on general fit given it touches every practice holding client data.

Faces of satisfied clients
It's worth considering changes to your marketing practices

What this means for your marketing

  • Don't quote the "one incident every two days" figure anywhere with your name on it, since you can't back it up if asked.
  • Put a plain-English line on your website about how you store and protect client data, before a prospective client asks.
  • Brief your team on where client files actually live, and who else can see them.
  • Say something reassuring but honest about data security in your welcome pack, rather than waiting for it to come up.
  • Check your booking and payment software actually does what its privacy policy claims, then move on.

Who this is most useful for

Practice typeRelevanceRecommended action
CoachingMediumReview where session notes are stored and who can access them.
TherapyHighDouble-check your client management system's security claims against reality.
TrainingLowConfirm booking and payment systems are reputable and up to date.
Alternative HealingMediumTighten up intake forms that collect health information.
ClinicalHighTreat this as a prompt to formally document your data security measures.
Retreat/CentreHighAudit guest data handling across booking, health forms and payments together.

Best before

Best before: revisit when the NCSC publishes its own annual review, and verify this figure against that before quoting it anywhere; until then, treat it as unconfirmed. Keep an eye on updates via Connaught Law.

What next?

Most practices know they should "do something" about data security, and most have quietly filed that thought under things to worry about later.

Talk to us about Whole-practice Marketing

Therapy Space

You Read The Whole Thing.

We love that about you. Thorough people tend to love what we've built - a story garden, a visual river, a listening wind, and a discovery call that goes properly both ways. The kettle's on. How do you take your coffee?

Find your Sunlight  ▶