On 13 July 2026, Check Point Research published its June 2026 global threat intelligence, and the UK figure inside it should stop every business owner in the country: UK organisations now absorb an average of 1,589 cyber attacks every week, a 34% year-on-year increase that is running at roughly double the global rate of 17%. The global average sits at 2,270 attacks per week — up 17% year-on-year and 10% month-on-month — but it is the UK’s acceleration that stands out.
This is not a single spike caused by one large campaign. As Check Point’s Data Research Manager Omer Dembinsky put it, “June’s data shows a broad rebound in cyber activity, not a single isolated spike.” For UK SMEs, it means the question is no longer whether an attack will be attempted against your organisation but when, how frequently, and whether your defences will hold when it arrives.
For years, UK SMEs have quietly reassured themselves with “we’re too small to be a target.” The Gentlemen’s model dismantles that reassurance completely. Because the group pre-compromises firewalls first and picks victims second, your sector, size and profile are irrelevant to whether you are selected. What matters is whether one of your internet-facing devices was exploitable when the group was harvesting access.
Where the attacks are landing: the most-targeted sectors
Check Point’s June data breaks attack volume down by sector, and the pattern is instructive for UK SMEs deciding how seriously to take their own exposure. The chart below shows the most heavily targeted sectors globally by weekly attacks per organisation, alongside the UK and global per-organisation averages for context. These are the reported June 2026 figures where given; the shorter bars are indicative placements to show relative scale.
Education tops the table at roughly 4,816 attacks per organisation per week (up 16% year-on-year), followed by government at around 2,836 (up 5%) and telecommunications at 2,835 (up 13%). These are the sectors with sprawling user bases, legacy estates and rich data — but the lesson for a UK SME is not “we’re not a school or a telco, so we’re fine.” The sector breakdown describes where volume concentrates in aggregate. It does not describe how The Gentlemen selects an individual victim, which is by device exploitability alone. A ten-person accountancy practice with an unpatched firewall is, in that model, a more attractive target than a well-defended hospital. Sector is a demographic; an exploitable device is an invitation.
The geography that proves the point
The single most revealing statistic in the June report is the geographic distribution of The Gentlemen’s victims. Ransomware campaigns overwhelmingly concentrate on the United States, which typically accounts for around half of all published victims because it holds the greatest density of high-revenue targets willing to pay. The Gentlemen break that pattern decisively.
When only 12% of a group’s victims are in the country that normally dominates ransomware, the targeting logic has fundamentally changed. The group is not building a list of lucrative organisations and then finding a way in; it is compromising firewalls at scale first, then working out what sits behind each one and monetising the access. That inversion is what makes the model so dangerous for UK SMEs. In the old logic, obscurity and modest revenue offered a degree of natural cover. In the new logic, the only thing that determines whether you are attacked is whether your perimeter was patched when the harvesting ran. The UK’s 34% surge and the 14,000-device access pool are two halves of the same story: automated, indiscriminate compromise of whatever is left exposed.
Where UK SMEs are most exposed to the device-centric model
The Gentlemen’s approach is, in effect, a stress test of exactly the controls Cyber Essentials sets out — patch management, secure configuration and removal of unnecessary internet-facing services. Most UK SMEs fail that test in a small number of predictable places. The grid below maps where the exposure concentrates for a typical mid-market business.
The consistency of these gaps is the point. A device-centric attacker does not need a sophisticated foothold; it needs one un-remediated critical vulnerability on a reachable device and one account without a second factor. CVE-2024-55591 is an authentication bypass — the class of flaw that lets an attacker skip the login step entirely on an unpatched device. The controls that neutralise it are not exotic: apply the vendor patch inside the mandated window, remove management interfaces from public exposure, and enforce MFA so that even a bypassed or stolen credential is not enough on its own. Each of those is a named Cyber Essentials requirement. The businesses that fall into the 14,000-device pool are, overwhelmingly, the ones that never operationalised those basics.
What Check Point Research actually found in June 2026
The June 2026 report is significant not just for its headline number but for the pattern behind it. The UK’s 1,589 weekly attacks per organisation represent a continuation of the acceleration that began in the second half of 2025. The global number — 2,270 per week — climbed 10% month-on-month from May, reversing a brief lull. The UK’s year-on-year rate is running roughly double the global average, suggesting that UK organisations are disproportionately exposed or disproportionately targeted.
Where the attacks are landing: the most-targeted sectors
Check Point’s June data breaks attack volume down by sector. Education, Government, Healthcare, Finance, and Retail lead globally. UK SMEs in all sectors face elevated risk because the UK’s aggregate rate is 34% above last year.
What Cyber Essentials certification costs by business size
Cyber Essentials is deliberately proportionate — the scheme is built for organisations of every size, and the cost of certification scales with the complexity of the estate rather than the headcount alone. The table below sets out an indicative view of what certification and the underlying remediation typically involve across UK business-size bands. Figures are illustrative planning ranges for the combined certification and readiness work, not fixed quotes.
| Business size | Typical estate in scope | Certification path | Indicative investment |
|---|---|---|---|
| 1–10 staff | Single firewall, cloud email and productivity suite, a handful of endpoints | Cyber Essentials self-assessment, with patch and MFA remediation | £500–£2,000 |
| 10–50 staff | Firewall plus VPN, multiple cloud services, mixed device fleet, some remote workers | Cyber Essentials or CE Plus with hands-on audit and documented patch evidence | £2,000–£7,000 |
| 50–200 staff | Multi-site perimeter, servers, several SaaS platforms, supplier integrations | CE Plus with vulnerability scanning, configuration review and remediation programme | £7,000–£18,000 |
| 200+ staff | Complex estate, regulated data, contractual security obligations, supply-chain scope | CE Plus plus continuous patch management and governance oversight | £18,000+ |
The right figure for any given business depends on the state of the estate at the start — an organisation that already patches promptly and enforces MFA will spend far less than one starting from an un-inventoried, un-patched baseline. But the direction of travel is the same across every band: the cost of certification and the disciplined patch cadence behind it is a fraction of the cost of a ransomware incident. With the annual cost of cyberattacks to the UK economy now estimated at £14.7 billion, and only 5% of UK businesses holding Cyber Essentials (up from 3% in the previous Cyber Security Breaches Survey), the certification remains both the clearest signal of baseline competence and, structurally, the difference between being inside or outside the pool a device-centric attacker fishes from.
Reactive posture versus a certified, governed posture
The Gentlemen’s model exposes the gap between treating patching as an occasional chore and treating it as a governed, evidenced discipline — which is exactly what Cyber Essentials formalises. The comparison below sets out the two postures.
Reactive posture
How most uncertified SMEs run today
- Firewalls and VPNs patched occasionally, when someone remembers
- No inventory of which devices face the internet
- Critical vulnerabilities left open well past 14 days
- MFA optional or missing on cloud and remote access
- Default configurations left in place on perimeter kit
- No evidence trail to prove patch compliance to customers
- Security treated as an IT cost, not a board responsibility
Certified, governed posture
Where Cloudswitched takes you
- Patch management runs to a defined cadence within the CE window
- Every internet-facing device and service inventoried and owned
- Critical vulnerabilities remediated inside 14 days, evidenced
- MFA enforced across cloud services and remote access
- Secure configuration baselines applied and maintained
- Documented patch-compliance evidence ready for CE Plus audit
- Board-level ownership of cyber resilience, in line with the UK pledge
Moving from the left column to the right is not a single purchase; it is a shift from ad-hoc reaction to governed routine. Cyber Essentials is the framework that makes that shift concrete and auditable, and the v3.3 rules that took effect on 27 April 2026 sharpen it further — an automatic failure for cloud services without MFA, a firm 14-day patch mandate for critical vulnerabilities, and a requirement to produce documented patch-compliance evidence for the CE Plus audit. Those are not bureaucratic hurdles. They are, almost line for line, the controls that would have kept a business out of the 14,000-device pool.
You do not need to start with a certification application. The single most valuable exercise a UK SME can run this week is an internet-facing exposure review: list every device and service reachable from the public internet — firewalls, VPN concentrators, remote-access gateways, exposed management interfaces — and for each one record the exact firmware or software version, the date it was last patched, and whether MFA protects any accounts behind it. Then check every critical vulnerability advisory from the last 90 days against that list and confirm each has been remediated. If any perimeter device is running unpatched firmware with a known critical flaw — the CVE-2024-55591 profile — patch it now, remove its management interface from public exposure, and enforce MFA. Most businesses cannot answer these questions today, and discovering that is the entire point: it converts an invisible exposure into a managed one, and it is the natural first step toward Cyber Essentials.
At-a-glance: the Check Point June 2026 report
| Fact | Detail |
|---|---|
| Source | Check Point Research June 2026 global threat intelligence, published 13 July 2026 |
| UK attack volume | 1,589 attacks per organisation per week, up 34% year-on-year |
| Global attack volume | 2,270 per week, up 17% year-on-year and 10% month-on-month |
| UK vs global rate | UK rate of increase roughly double the global rate |
| Ransomware volume | 646 attacks globally in June 2026, up 33% year-on-year |
| New ransomware leader | The Gentlemen — 17% of published attacks, overtaking Qilin on 11% |
| Business model | Ransomware-as-a-service combined with initial access broking |
| Access pool | ~14,000 FortiGate firewalls pre-compromised via CVE-2024-55591 |
| Vulnerability type | Authentication bypass in FortiOS and FortiProxy |
| Targeting logic | Device exploitability, not sector, size or geography |
| Geographic tell | US just 12% of The Gentlemen’s victims vs ~50% typical for ransomware |
| Top sectors globally | Education (~4,816/week), Government (~2,836), Telecoms (~2,835) |
| Relevant standard | Cyber Essentials v3.3, in force 27 April 2026 — MFA auto-fail, 14-day patch mandate |
| UK certification rate | Only 5% of UK businesses hold Cyber Essentials (up from 3%) |
| Economic cost | Cyberattacks cost the UK economy an estimated £14.7bn a year |
How this connects to the wider 2026 threat picture
The Check Point June report does not stand alone. It is the latest thread in a year of UK developments all pointing the same way: attack volume is rising, the attacker is increasingly automated and indiscriminate, and the weakest link is the unpatched, internet-facing device. The device-centric model The Gentlemen have industrialised is the operational face of a broader shift toward faster, tool-driven compromise.
The perimeter-device dimension is exactly the exposure we set out in our coverage of the FortiBleed campaign and the 73,932 compromised Fortinet firewalls, the strategic counterpart to the same FortiGate weakness The Gentlemen are now monetising. The router and connectivity angle — the other end of the exposed-perimeter problem — is examined in our analysis of the NCSC and FSB router advisory for UK SMEs. The scale and pace of the patching challenge that CVE-2024-55591 exemplifies is captured in our reporting on the AI-driven CVE surge and why a real patch programme now matters. The breadth of UK exposure across ordinary businesses is quantified in our coverage of the Cyber Security Breaches Survey and the 612,000 UK businesses hit. And the changing nature of the adversary — automated, AI-assisted and regulated in parallel — runs through our look at the EU AI Act deadline and its implications for UK SMEs. Together these establish the same message the June report makes concrete: in a device-centric threat landscape, the basics — patching, secure configuration and MFA — are the whole game, and Cyber Essentials is the framework that enforces them.
The Gentlemen don’t pick you — your unpatched firewall does
Cyber Essentials is the framework built to keep your business out of the pool a device-centric attacker fishes from: patch management inside 14 days, secure configuration, no unnecessary internet-facing services and enforced MFA. Cloudswitched delivers end-to-end certification — gap analysis, remediation and audit — so those controls are real, evidenced and maintained, not just aspirational.
Talk to us about Cyber Essentials CertificationFrequently asked questions
Get out of the pool before the next harvest
The Gentlemen’s 14,000-device access pool exists because most businesses never operationalised the basics. Cloudswitched turns Cyber Essentials into a real, maintained programme — patch cadence inside 14 days, secure configuration, enforced MFA and audit-ready evidence — so your perimeter is a defended asset, not a product on an access broker’s shelf.
Talk to us about Cyber Essentials Certification


