A UK law firm's 2025 compliance guide claims the National Cyber Security Centre handled 204 significant incidents in the year to September, which works out to one every two days, though the guide doesn't say where it got the figure. This includes practices like yours, if you keep client records on anything with a login screen.
Practices holding client health or session data are being told cyber risk is rising fast, though the evidence for exactly how fast comes with no visible working.
| Original Research | A claim that the NCSC dealt with 204 major cyber incidents in the twelve months to September 2025, roughly one every two days |
|---|---|
| Source | https://connaughtlaw.com/uk-data-protection-gdpr-compliance-guide/ |
| Overview | The page is a general UK GDPR compliance guide published by a law firm, with the incident figure dropped in as background colour rather than a cited research finding. |
| Year | 2025 |
| Publisher | Brand, Connaught Law |
| Relevance to Wellbeing | Strong as a general nudge that cyber risk is real and growing, but it's a step removed from anything specific to wellbeing practices. |
| Our Verdict | Too early to tell The figure has no named source, no linked NCSC report, and no methodology, so treat it as a claim worth checking rather than a fact worth quoting. |
| Our Summary |
|
| Our Geo View | UK-specific: the NCSC only covers UK incidents, and the GDPR compliance framework referenced is the UK version. |
A UK law firm's GDPR compliance guide states, without naming a source, that the NCSC handled 204 major incidents in the year to September 2025.
Connaught Law, published 2025. The figure appears within a general compliance guide rather than a dedicated research report, and no NCSC publication is linked.
Credibility flags: methodology not disclosed, sample size not applicable, publisher type is a law firm's own marketing content, not an independent or peer-reviewed source.
A relevance score out of 100, built from three things: how well it fits the six practice types, how recent it is, and how solid the methodology behind it is.
Marked down heavily on how solid the method is, since the figure is unattributed, though it scores well on recency and reasonably on general fit given it touches every practice holding client data.
| Practice type | Relevance | Recommended action |
|---|---|---|
| Coaching | Medium | Review where session notes are stored and who can access them. |
| Therapy | High | Double-check your client management system's security claims against reality. |
| Training | Low | Confirm booking and payment systems are reputable and up to date. |
| Alternative Healing | Medium | Tighten up intake forms that collect health information. |
| Clinical | High | Treat this as a prompt to formally document your data security measures. |
| Retreat/Centre | High | Audit guest data handling across booking, health forms and payments together. |
Best before: revisit when the NCSC publishes its own annual review, and verify this figure against that before quoting it anywhere; until then, treat it as unconfirmed. Keep an eye on updates via Connaught Law.
Most practices know they should "do something" about data security, and most have quietly filed that thought under things to worry about later.
We love that about you. Thorough people tend to love what we've built - a story garden, a visual river, a listening wind, and a discovery call that goes properly both ways. The kettle's on. How do you take your coffee?