P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

808,000 UK businesses were not confident at one or more of nine tasks, and that measures confidence, not skill

A government survey estimates that 808,000 UK businesses, 57 per cent of 1,417,730 employers, were not confident at one or more of nine basic cyber tasks. It measures one person's confidence per firm, not whether the controls are on, and the rise since 2025 sits in three tasks.

By Parminder Kumar Sharma · · 14 min read

Editorial illustration for the briefing: 808,000 UK businesses were not confident at one or more of nine tasks, and that measures confidence, not skill

808,000 is 57 per cent of 1,417,730, and the 57 per cent is a confidence score

The government's cyber security skills survey says about 808,000 UK businesses had a basic technical skills gap. Divide that by the base the report itself uses, 1,417,730 businesses with one or more employees, and it is 57 per cent: 57 per cent of 1,417,730 is 808,106, which the report rounds to 808,000 (derived). A year earlier the figure was 49 per cent, about 699,000. The report, Cyber security skills in the UK labour market 2026, was published on GOV.UK on 29 September 2026 and covered by The Register on 30 September. Its telephone fieldwork ran from 8 August to 27 October 2025, so the figure describes autumn 2025, 337 days before publication (derived).

What that does not establish is that 808,000 businesses are unskilled. A business is counted if the person responsible for cyber security said they were not confident at one or more of nine tasks. Nobody was tested, and nobody checked whether a firewall was switched on. The report says as much itself: the fall in confidence "does not necessarily indicate reduced capability". The Register's figures match the report. This briefing checks how far the number carries, using the full report, the earlier waves and two other government sources.

What was asked, of whom, and how nine answers became one

The survey is a telephone survey run by Ipsos with Perspective Economics for the Department for Science, Innovation and Technology, whose cyber team moved to the Department for Digital, Culture, Media and Sport in July 2026. It interviewed 982 UK private sector businesses, 162 charities and 117 public sector organisations, weighted to represent each population. The findings report refers to a technical report, but the GOV.UK page lists only the findings. Where the 2026 report is silent I have used the 2025 technical report, the latest published, and I say so.

What the questionnaire asked, from the 2025 questionnaire:

  • The respondent is the senior person with the most knowledge or responsibility for cyber security at the head office.
  • The question asks how confident they would feel about themselves or anyone else directly involved in cyber security being able to do each task. The interviewer note says to answer for the most confident staff member. If the task is not needed today, they answer for the future. The scale runs from very confident to not at all confident. The 2026 text does not restate where not confident begins; the 2024 tables split not very from not at all, and I read both as the gap.
  • A task handed to an outside provider is not asked about and counts as no gap.
  • The nine tasks are detecting and removing malware; storing or transferring personal data securely; restricting the software that runs on devices; setting up configured firewalls; choosing secure settings; setting up automatic updates; setting up new user accounts and authentications securely; controlling who has admin rights; and creating back-ups. The report says they combine the Cyber Essentials technical areas with other basic aspects, and it leaves out incident response, which it treats separately.
  • The 57 per cent is the share of businesses not confident at one or more of the nine.

What the survey states, and what it does not

The 2026 report's claims set against what it leaves open. Sources: the 2026 findings report, and the 2025 technical report where marked. Derived figures are my arithmetic.

QuestionStated in the reportNot stated or not established
How bigAbout 808,000 businesses, 57% of 1,417,730 employers. Margin of error 4 points: 751,000 to 865,000.A count of businesses anyone examined. It is an estimate from 982 interviews, worth about 590 after weighting (derived).
What is measuredThe confidence of the person responsible, at nine tasks. Outsourced tasks count as no gap.Whether the tasks are done, or done well. No test, no check of whether a control is on.
Whether the rise is real49% to 57%. The report's convention is that changes it describes are significant at 95%.The test for this change is not printed. My calculation from the printed margins gives z of about 2.8.
Why it rosePossibly greater awareness after high-profile breaches, from interviews.Any measure of awareness. The 51 interviews are not representative, and 11 were medium and large business and public sector leads.
Which businessesLarge businesses 24%. Small businesses and charities described as hardest hit.A figure for micro, small or medium businesses. Micro firms are 81% of the base.
Public sector14% to 27%, from 117 organisations.Central government departments. The 2025 technical report says they were excluded from the sample.
WhenFieldwork 8 August to 27 October 2025.How businesses feel now. Publication came 337 days after fieldwork closed.

The base, drawn to scale

The Register's headline says UK businesses. The survey's population is the 1,417,730 businesses with employees, out of 5,690,265 private sector businesses that the Department for Business and Trade counted at the start of 2025. The other 4,272,535 have no employees and are outside the survey. So more than half of UK businesses is, more precisely, more than half of the quarter of businesses that employ someone.

Three bars drawn to scale. Of 5,690,265 UK private sector businesses, 4,272,535 have no employees and are outside the survey; 1,417,730 employ staff. Of those, 57 per cent, about 808,000, were not confident at one or more of nine tasks, with the 2026 interval 53 to 61 per cent just touching the 2025 interval of 45.1 to 52.9. By size, 81.2 per cent are micro, 15.5 small, 2.7 medium and 0.6 large.
Business counts from the Department for Business and Trade business population estimates 2025; survey result and margins of error from the 2026 and 2025 skills reports. Percentages of size bands are derived.

Size decides the number. Micro businesses, one to nine staff, are 1,150,875 of the 1,417,730, or 81.2 per cent; with small firms, 96.7 per cent (derived from the DBT table). Large businesses number 8,335, and the report gives them a gap of 24 per cent. If every large business had a gap, they would still be 1.0 per cent of the 808,106. The report's only size comparison sets large at 24 per cent against 57 per cent for smaller businesses, which is the all-business figure again: with large firms at 0.6 per cent of the base, the two cannot differ by more than rounding (derived). The text prints no separate figure for micro, small or medium businesses, so a reader cannot tell which of them the 57 per cent describes. It is, by construction, mostly a micro business number.

Three tasks rose and six did not

The report prints the nine tasks for both years, and that comparison says more than the total. Detecting and removing malware went from 23 to 38 per cent, restricting software from 19 to 28, and storing or transferring personal data from 25 to 31. The other six were flat or lower: secure settings 15 and 15, back-ups 7 and 7, firewalls 28 to 26, automatic updates 13 to 11, new user accounts 12 to 10 and admin rights 12 to 9. The 2026 text describes only the malware and personal data rises.

A dot plot of the share of UK businesses not confident at each of nine tasks, 2025 against 2026. Malware rose from 23 to 38 per cent, restricting software from 19 to 28 and personal data from 25 to 31. Secure settings stayed at 15 and back-ups at 7. Firewalls fell from 28 to 26, automatic updates from 13 to 11, new user accounts from 12 to 10 and admin rights from 12 to 9.
Drawn from Figure 6.2 of the 2025 and 2026 reports. Differences are of rounded published figures. The sums of the nine shares are derived.

The report suggests the rise may reflect greater awareness after high-profile breaches, on the evidence of interviews. Those interviews are not representative, the report says, and the 57 per cent is dominated by micro firms. If awareness were the whole story I would expect confidence to fall across most of the list; on the published figures it fell in three. That is my inference and rounding could hide small moves, but it points at particular tasks, not a general loss of nerve.

Add the nine shares and you get 154 points in 2025 and 175 in 2026 (derived). Divided by 49 and 57 per cent, the average business with a gap is not confident at about three tasks in both years. On these rounded figures, more businesses have a gap, not more gaps each.

Confidence is not a control

The label skills gap makes a self-rating sound like an audit. Three details show the distance.

  • Malware. The largest gap is detecting and removing malware, a response task. The Cyber Essentials control is malware protection, which the NCSC describes as identifying and immobilising malicious software before it causes harm. The NCSC's small organisations guide says modern devices have antivirus and firewall software built in and switched on by default, and tells readers to check nobody has turned them off. A firm can run the control and still tell an interviewer it is not confident cleaning up an infection.
  • The same season, another survey. The DSIT and Home Office Cyber Security Breaches Survey 2025/2026, also run by Ipsos over August to December 2025 with 2,112 businesses, found 81 per cent with up-to-date malware protection, up from 77 per cent, and 74 per cent with firewalls covering the network and devices. It asks about controls in place, not confidence, on a different sample, and it is also self-reported. Even so, controls rose while confidence fell, and the share of businesses reporting a breach or attack stayed at 43 per cent.
  • The base is all businesses, outsourcers included. The 38 per cent is a share of every business, with outsourcers counted as confident. The report says 35 per cent outsource at least one aspect, and 84 per cent of those outsource malware detection: about 29 per cent of businesses (0.35 times 0.84, derived). On that arithmetic roughly half of the businesses that do the task themselves, 38 of about 71, said they were not confident (derived, approximate). The survey says nothing about how well outsourced providers do it.

Is the rise real? Five reports and one test

Headline basic skills gap in each findings report, 2022 to 2026, with the tasks combined and businesses interviewed. Counts are each report's own extrapolation on its own year's business population. Interview counts: 2025 technical report and 2026 findings.

ReportNot confident at 1 or more tasksTasks combined; businesses interviewed
202251% (about 697,000)8 tasks; 947
202350% (about 739,000)10 tasks; 1,006
202444% (about 637,000)10 tasks, including dealing with a breach; 930
202549% (about 699,000)9 tasks; 1,061
202657% (about 808,000)9 tasks; 982

Two things stop the earlier years being read as one line. The task list changed: the 2024 list included dealing with a breach or attack, which the 2025 and 2026 lists leave out. And in the 2025 wave the business sample moved from the government's business register to a commercial list, according to the 2025 technical report, so its response rate could not be compared with earlier years: 9 per cent of the released sample completed, 11 per cent adjusted. That leaves 2025 to 2026, nine tasks in both, as the cleanest comparison. I could not confirm the 2026 sample source.

The report prints margins of error of 4.0 points for 2026 and 3.9 for 2025 (footnotes 22 and 23): 53.0 to 61.0 per cent against 45.1 to 52.9, 0.1 of a point apart, as the first diagram shows. A difference test on those margins, which is my calculation and treats the samples as independent, gives z of about 2.8 and p of about 0.005. Letting the true difference be a point smaller or larger gives z between 2.5 and 3.2. On the report's own numbers the eight point rise is statistically significant. The 4.0 point margin also implies an effective sample of about 590 interviews (derived), against 982 achieved, because of weighting. What no test can supply is the reason.

Who is speaking

The report is government research commissioned by DSIT's cyber team and endorsed, its acknowledgements say, by the NCSC, the UK Cyber Security Council, techUK and others. It reads its own rise as a sign of the continued and increasing need for support and guidance on basic cyber hygiene, and also as possibly an effect of awareness. It cannot separate the two.

The Register's expert comment comes from executives at two security firms, Bridewell and NCC Group. Bridewell's chief operating officer argues that small firms need affordable managed services, simpler tools or insurer incentives more than tighter regulation. That is a position from a firm in the business of providing security services, and it fits one fact in the survey: 35 per cent of businesses outsource something. But outsourcers are counted as having no gap, so the survey cannot show that outsourcing closes one.

What a UK security lead can do with this, in order

The first four items are NCSC guidance for small organisations and the fifth is my suggestion. I read the NCSC pages on 30 September 2026; the Cyber Essentials price and offers can change.

Take this with you

From the survey's nine tasks to something evidenced

  • Check that antivirus and the firewall are switched on, on every device, including any passed on from a previous user. The NCSC says modern devices have both built in and on by default, but a previous user may have turned them off.
  • Turn on automatic updates for devices and apps, delete software that no longer receives updates, and replace devices the manufacturer no longer supports.
  • Back up what the business needs to run, online or to an external device that is not left connected, and test a restore. The NCSC notes that some viruses also affect connected devices.
  • Write down the NCSC's steps for a suspected infection and name who does them: confirm with an antivirus scan, update the device and programs, scan and act on what it recommends, wipe and reinstall if it cannot clean up, restore from the last known good backup, and report the incident at gov.uk/report-cyber.
  • For each of the nine tasks, record whether it is done in house or by a provider, and what evidence shows it is switched on. This is a suggestion, not NCSC guidance: the survey counts an outsourced task as no gap, so ownership is the first thing to write down.
  • Write an incident response plan. In the survey 49 per cent of business cyber leads were not confident writing one, and the Cyber Security Breaches Survey found 25 per cent of businesses had a formal plan.
  • Consider Cyber Essentials, which asks for five controls: firewalls, secure configuration, security update management, user access control and malware protection. The NCSC lists certification from £320 plus VAT, a free readiness tool, a free 30 minute consultation with an NCSC-assured Cyber Advisor for small and medium sized enterprises, and free cyber liability insurance for certified organisations with turnover under £20 million.
  • When you quote the 57 per cent, quote the base and the measure: 57 per cent of 1,417,730 employers, not confident at one or more of nine tasks, self-reported, autumn 2025.

The Breaches Survey found 24 per cent of businesses reporting controls in all five Cyber Essentials areas and 5 per cent adhering to the scheme, so the gap between doing and certifying is large. NCSC pages used: protecting your devices, backing up your data, infected devices and Cyber Essentials.

The question that exposes the gap

The survey could not test capability, and it cannot tell you which of the 808,000 could show a working control. It cannot tell you about yours either. Which of the nine tasks could your own organisation evidence today, with a setting that is switched on and a named person who owns it, whatever your lead says about their confidence?

A related check on a denominator: our briefing on GitGuardian's twice-the-rate claim asks the same question of a different report.

Key facts

Sources

  1. PrimaryCyber security skills in the UK labour market 2026, HTML report published 29 September 2026, read in full: the 57 per cent and 808,000, the nine tasks, Figures 6.2 and 6.4, footnotes 22 to 24, method, outsourcing, incident response and conclusionsDSIT and DCMS (research by Ipsos and Perspective Economics)accessed 2026-09-30
  2. PrimaryCyber security skills in the UK labour market 2026, PDF version 2 of the same report, used to read the charts and to check that the HTML and PDF agree (the HTML text points to Figure 6.3 where the PDF says Figure 6.2)DSIT and DCMS (research by Ipsos and Perspective Economics)accessed 2026-09-30
  3. PrimaryPublication page for the 2026 report, used for the publication date, the key findings and the note that the cyber team moved from DSIT to DCMS in July 2026; it lists no technical reportGOV.UKaccessed 2026-09-30
  4. PrimaryTechnical report for the 2025 wave, used for the confidence question wording, the most confident staff member rule, the outsourcing filter, the sample frame change, response rates, weighting, exclusions and interview counts by waveDSIT (research by Ipsos and Perspective Economics)accessed 2026-09-30
  5. PrimaryFindings report 2025, used for the 49 per cent and 699,000, Figure 6.2 for the 2025 task values, the 3.9 point margin, the 1,427,165 base and incident response at 32 per cent of all businessesDSIT (research by Ipsos and Perspective Economics)accessed 2026-09-30
  6. PrimaryFindings report 2024, used for the 44 per cent and 637,000, the ten tasks including dealing with a breach and the not very and not at all confident splitDSIT (research by Ipsos)accessed 2026-09-30
  7. PrimaryFindings report 2023, used for the 50 per cent and 739,000 and the ten tasks combinedDSIT (research by Ipsos)accessed 2026-09-30
  8. PrimaryFindings report 2022, used for the 51 per cent and 697,000, the eight tasks combined and the definition of the margin of errorDCMS (research by Ipsos)accessed 2026-09-30
  9. PrimaryCyber Security Breaches Survey 2025/2026, published 30 April 2026, used as a cross-check: up-to-date malware protection 81 per cent, breach prevalence 43 per cent, Cyber Essentials awareness and adherence, incident response plans, external providersDSIT and Home Office (research by Ipsos)accessed 2026-09-30
  10. PrimaryBusiness population estimates 2025, statistical release, used for the 1,417,730 employers, the 5,690,265 total, the 4,272,535 without employees and the size bandsDepartment for Business and Tradeaccessed 2026-09-30
  11. PrimaryCyber Essentials overview, read 30 September 2026, used for the five controls, certification price, free tools, Cyber Advisor consultation and the cyber liability insurance offerNational Cyber Security Centreaccessed 2026-09-30
  12. PrimarySmall organisations guide to cyber security: protecting your devices, published 9 April 2026, reviewed 21 July 2026, used for the built-in antivirus and firewall statement and the update adviceNational Cyber Security Centreaccessed 2026-09-30
  13. PrimarySmall organisations guide to cyber security: backing up your data, used for the backup advice and the warning about connected storage devicesNational Cyber Security Centreaccessed 2026-09-30
  14. PrimaryInfected devices, advice for sole traders and small organisations, used for the steps to confirm and fix an infection and where to report itNational Cyber Security Centreaccessed 2026-09-30
  15. Reported byMore than half of UK businesses lack confidence in basic cyber skills, 30 September 2026, the news pointer; every figure checked against the report, and the two consultancy quotes attributed to itThe Registeraccessed 2026-09-30

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.