Data & Economics
What does a data breach actually cost a UK public body?
Government's own survey puts a number on it: how much a breach costs, and how long a public sector body typically takes to even notice one has happened.
The short answer
The government's Cyber Security Breaches Survey puts the average cost of the most disruptive breach at around £1,600 per business, rising to a mean of roughly £10,000 for organisations that were able to quantify their losses in full, and £3,240 for charities. For the public sector specifically, the same body of research found organisations took an average of 202 days to identify a breach and a further 74 days to contain it, both slower than the global average. The direct cost is only part of the bill; the detection gap is where the real exposure sits.
Data breach costs get quoted constantly, usually from a vendor's own annual report, with a methodology nobody outside the vendor can check. The UK government publishes its own figures, and they are worth using instead, because they come from an actual survey of businesses, charities and public bodies rather than a sales document.
The headline numbers
The Cyber Security Breaches Survey 2025/2026, commissioned by the Department for Science, Innovation and Technology (DSIT) and the Home Office, puts the average cost of the most disruptive breach at around £1,600 per business and £3,240 per charity. Among organisations able to fully quantify their losses, the mean cost was closer to £10,000, a reminder that the headline average is pulled down by a large number of minor incidents sitting alongside a smaller number of expensive ones.
The number that matters more: detection time
The cost figure is a snapshot. The more revealing number is how long an incident sits undetected, because every additional day is additional exposure. For the public sector specifically, the same research found organisations took an average of 202 days to identify that a breach had occurred, and a further 74 days to contain it once found. Both figures run behind the global averages cited in the same reporting, 181 days to identify and 60 to contain, which means the UK public sector is, on the government's own numbers, slower than the international norm at the two stages that matter most.
The average cost is a snapshot. Two hundred and two days of undetected access is the real exposure.
Why detection time is an economics question, not just a security one
Every day a breach goes undetected is a day of continuing exposure, additional data at risk, and a longer, more expensive remediation once it is finally found. A council or public body budgeting for cyber risk on the direct cost figure alone is pricing only part of the problem. The detection gap is where cost compounds: longer exposure windows mean larger incidents, more extensive notification obligations, and a harder job proving to a regulator or an auditor exactly what happened and when.
What this means for procurement decisions
These figures are a useful benchmark for any public body evaluating how it holds sensitive data, and for weighing the cost of a shared, third-party-managed estate against infrastructure it can see into directly. This is one part of the wider economics this journal covers: not whether AI and digital sovereignty sound appealing in principle, but what the numbers, this survey's own numbers, actually say about the cost of getting detection and control right, or wrong.
For context on where that spend currently goes, see our companion piece on UK public sector dependency on hyperscale cloud.
Frequently asked
- Where do these figures come from?
- The Cyber Security Breaches Survey, commissioned by the Department for Science, Innovation and Technology (DSIT) and the Home Office, published on GOV.UK. It is the UK government's own annual research into breach costs and incident response across businesses, charities and the public sector, and is the most cited source for these figures precisely because it is official rather than vendor-produced.
- Why does the public sector take longer to spot a breach?
- The survey does not give a single cause, but the pattern fits what practitioners describe: larger, more fragmented estates, legacy systems, and reliance on third-party and shared infrastructure make it harder to see an incident clearly and quickly. The comparison point is stark either way: 202 days to identify against a global average of 181, and 74 days to contain against a global average of 60.
- Does keeping data on infrastructure you control reduce this?
- It changes the shape of the problem rather than eliminating it. An organisation running its own infrastructure still has to invest in detection and response, but it is not waiting on a third party to notice or disclose an incident on its behalf, and it has direct visibility into its own systems rather than partial visibility into a shared, multi-tenant environment. Whether that translates into a shorter detection time depends on what is actually built, not on ownership alone.