Half of UK Small Firms Reportedly Hit by Cyber Attacks, Though Nobody's Named the Source

A figure doing the rounds in 2025 claims nearly half of UK small businesses had a cyber breach in the past year, mostly thanks to dodgy emails, though whoever wrote it down forgot to say whose research it was. This includes practices like yours.

Practices holding client health notes, booking details or payment records on ordinary office kit are exactly the kind of small firm this claim is talking about, named source or not.

Original ResearchA claim that just under half of small UK firms had a cyber security incident in the last twelve months, with fraudulent emails the most common route in.
Sourcehttps://www.enterpriseresearch.ac.uk/our-work/publications/
OverviewThe figure is loosely attached to the Enterprise Research Centre's small business work, but the specific survey it comes from isn't named or linked anywhere.
Year2025
PublisherAcademic (claimed), Enterprise Research Centre, though this particular figure could not be traced to a named study
Relevance to WellbeingCyber security concerns any practice storing client records, appointments or payment details, which is nearly all of them.
Our VerdictToo early to tell the headline number has nothing visible behind it, so treat it as a prompt to check your own setup rather than a fact worth quoting.
Our Summary
  • Phishing emails as the top attack method lines up with what's reported elsewhere, and they're cheap to guard against.
  • There's no named survey, sample size or publisher behind the figure, so it can't actually be checked.
  • The link provided leads to a general publications page, not the report the claim supposedly comes from.
  • Even unverified, it points the same direction as sturdier data: small firms are common targets.
Our Geo ViewSpecific to UK small businesses, though even for that market the underlying figures haven't been verified.
Abstract of wellbeing niches and revenue flow
Recognise how this might impact your practice

Why this might matter to you

  • Coaching: this matters because your inbox probably holds client goals and personal details a fraudster would love to see.
  • Therapy: this matters because session notes are exactly the sort of thing you don't want landing anywhere but your own files.
  • Training: this matters because client health forms and payment details tend to sit in the same place as everything else.
  • Alternative Healing: this matters because bookings and intake forms are often the only records you keep, and worth protecting.
  • Clinical: this matters because clinical data has extra rules attached, breach or no breach.
  • Retreat/Centre: this matters because a centre with several staff has more inboxes for a fraudulent email to land in.

Where this came from

A cyber breach figure attributed, rather loosely, to the Enterprise Research Centre's small business research, with no visible way to check where the number actually came from.

Enterprise Research Centre, publications page, 2025 (no specific report title, publish date or survey given for the underlying figure).

Credibility flags: methodology not disclosed, sample size not disclosed, publisher status unconfirmed for this specific claim.

How we scored this

A relevance score out of 100, built from three things: how well it fits the six practice types, how recent it is, and how solid the methodology behind it is.

40%
Practice fit, 25How new, 100How solid, 0

Marked down heavily on how solid the method is, since there's no attribution to check, though it scores well on how current it is and reasonably on general fit for practices handling client data.

Faces of satisfied clients
It's worth considering changes to your marketing practices

What this means for your marketing

  • Put a line about how you protect client data somewhere visible on your booking page.
  • Brief your team on spotting a fake email before one turns up asking for a "quick payment".
  • Back client records up somewhere other than the one laptop at reception.
  • Mention your privacy approach in your welcome pack, not buried in the terms nobody reads.

Who this is most useful for

Practice typeRelevanceRecommended action
CoachingMediumReview how client goals and contact details are stored.
TherapyHighCheck session notes aren't sitting somewhere easily phished.
TrainingMediumTidy up where client health forms and payments are kept.
Alternative HealingMediumProtect intake forms and booking records with basic hygiene.
Clinical PracticesHighCross-check data handling against clinical record rules.
Retreats/CentresHighBrief every staff inbox on fraudulent email tactics.

Best before

Best before: revisit once the Enterprise Research Centre publishes an actual named report, or sooner if a properly sourced version of this figure turns up elsewhere.

What next?

Most practices already suspect their laptop and their inbox are doing more heavy lifting than they should, this is just a reminder nobody's checking.

Talk to us about Whole-practice Marketing

Therapy Space

Consider This The Footnote That Changes Things.

You stayed to the end and here we both are. We have a visual river, a story garden and a listening wind that belong to a practice exactly like yours - and a discovery call where they all make beautiful sense over coffee. Biscuit?

Find your Sunlight  ▶