Free Tool

Security Risk Score Calculator

Assess your organisation’s security posture across access control, endpoint security, network defences, data protection, and people & process. Get a risk score with prioritised remediation steps.

Your Security Controls

Access Control

Endpoint Security

Network Security

Data Protection

People & Process

UK Cyber Security Statistics & Common Attack Vectors

Statistic / Attack VectorImpactFrequency
Phishing AttacksMost common attack vector - 83% of breachesConstant
RansomwareAverage ransom demand £570K+ for UK businessesRising
Credential TheftStolen passwords used in 49% of breachesVery High
Business Email CompromiseAverage loss £10,000+ per incidentHigh
Insider ThreatsAccount for 25% of all data breachesModerate
Unpatched Vulnerabilities60% of breaches involve known unpatched CVEsHigh
Supply Chain AttacksThird-party compromise affecting multiple victimsRising
UK Business Breach Rate39% of UK businesses reported a cyber attack in 2024Annual

Sources: UK Government Cyber Security Breaches Survey 2024, IBM Cost of a Data Breach Report. Contact Cloudswitched for professional security assessment and managed protection.

More Free Tools

Try our other free security assessments and IT planning tools.

Frequently asked questions

A proper risk assessment weighs technical controls (firewalls, patching, backups), policies (access control, incident response), staff training, and past incident history together, since weaknesses in any one area increase overall exposure. This calculator scores your organisation across those factors to highlight priority gaps.

Phishing and social engineering remain the most common entry point for UK SMEs, often exploited because staff are not routinely trained to spot suspicious emails. Weak or reused passwords and unpatched software are close behind, and all three are typically addressable at relatively low cost.

Most UK SMEs benefit from a formal review at least annually, plus after any significant change such as new software, remote working policy changes, or a security incident. Threats and controls both evolve quickly, so a static one-off assessment loses accuracy within months.

Many UK cyber insurers now require evidence of baseline controls - MFA, endpoint protection, regular backups, and patch management - before offering cover, and some adjust premiums based on assessed risk level. A documented risk score can also speed up the underwriting process.

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

6
  • Cloud Email

Microsoft 365 Email Archiving and eDiscovery: A UK Business Guide to Legal Hold and Compliance Search in 2026

6 Oct, 2026

M365 email archiving is the thing most UK businesses believe they have and very few have configured. The belief usually comes from a reasonable source...

Read more
3
  • VoIP & Phone Systems

VoIP Security: A UK Business Guide to Preventing Toll Fraud and Call Interception in 2026

3 Oct, 2026

VoIP security is usually discussed as a technical problem, and the technical controls are well understood encryption for signalling and media, session border...

Read more
1
  • Internet & Connectivity

Choosing an Internet Service Provider: A UK Business Guide to Comparing Contracts Beyond the Headline Speed in 2026

1 Oct, 2026

A business ISP comparison conducted on headline speed and monthly price will mislead you on both counts. The speed is frequently an up to figure describing a...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.