A figure doing the rounds in 2025 claims nearly half of UK small businesses had a cyber breach in the past year, mostly thanks to dodgy emails, though whoever wrote it down forgot to say whose research it was. This includes practices like yours.
Practices holding client health notes, booking details or payment records on ordinary office kit are exactly the kind of small firm this claim is talking about, named source or not.
| Original Research | A claim that just under half of small UK firms had a cyber security incident in the last twelve months, with fraudulent emails the most common route in. |
|---|---|
| Source | https://www.enterpriseresearch.ac.uk/our-work/publications/ |
| Overview | The figure is loosely attached to the Enterprise Research Centre's small business work, but the specific survey it comes from isn't named or linked anywhere. |
| Year | 2025 |
| Publisher | Academic (claimed), Enterprise Research Centre, though this particular figure could not be traced to a named study |
| Relevance to Wellbeing | Cyber security concerns any practice storing client records, appointments or payment details, which is nearly all of them. |
| Our Verdict | Too early to tell the headline number has nothing visible behind it, so treat it as a prompt to check your own setup rather than a fact worth quoting. |
| Our Summary |
|
| Our Geo View | Specific to UK small businesses, though even for that market the underlying figures haven't been verified. |
A cyber breach figure attributed, rather loosely, to the Enterprise Research Centre's small business research, with no visible way to check where the number actually came from.
Enterprise Research Centre, publications page, 2025 (no specific report title, publish date or survey given for the underlying figure).
Credibility flags: methodology not disclosed, sample size not disclosed, publisher status unconfirmed for this specific claim.
A relevance score out of 100, built from three things: how well it fits the six practice types, how recent it is, and how solid the methodology behind it is.
Marked down heavily on how solid the method is, since there's no attribution to check, though it scores well on how current it is and reasonably on general fit for practices handling client data.
| Practice type | Relevance | Recommended action |
|---|---|---|
| Coaching | Medium | Review how client goals and contact details are stored. |
| Therapy | High | Check session notes aren't sitting somewhere easily phished. |
| Training | Medium | Tidy up where client health forms and payments are kept. |
| Alternative Healing | Medium | Protect intake forms and booking records with basic hygiene. |
| Clinical Practices | High | Cross-check data handling against clinical record rules. |
| Retreats/Centres | High | Brief every staff inbox on fraudulent email tactics. |
Best before: revisit once the Enterprise Research Centre publishes an actual named report, or sooner if a properly sourced version of this figure turns up elsewhere.
Most practices already suspect their laptop and their inbox are doing more heavy lifting than they should, this is just a reminder nobody's checking.
You stayed to the end and here we both are. We have a visual river, a story garden and a listening wind that belong to a practice exactly like yours - and a discovery call where they all make beautiful sense over coffee. Biscuit?