UK businesses faced record cyberattack attempts

Cyber Reports

Q3 Cyber Threat Report

UK businesses faced an average of 203,585 cyberattack attempts each between July and September 2026, a 7.0% increase on the same period last year and the highest quarterly average since monitoring began.

The systems that help your people work and connect with customers need regular attention. Keeping security part of everyday operations helps your business manage risk as people, technology and working arrangements change.

Our latest analysis explains the findings, the services targeted and practical steps to strengthen your business’s security and resilience.

 

Attack volumes moved upwards again

Quarterly activity increased by 6.7% from Q2 2026. Pressure remained high across the summer.

Allowing for the different lengths of the quarters, the average daily rate increased by 5.6% from Q2 to Q3 2026.

What this means for your business: Allow time for routine security work alongside other IT priorities. Clear responsibilities help prevent maintenance being overlooked when people are busy.

 

A sustained challenge, rather than a sudden surge

Q3 2026 had the highest quarterly average since Beaming began recording threats in 2016. However, it was only 0.9% above Q3 2024, when businesses received an average of 201,701 attempts each.

The longer-term comparison is more substantial. The Q3 2026 quarterly average was 29.2% above Q3 2019, when the equivalent figure was 157,528 attempts per business.

What this means for your business: Maintain security through quieter periods as well as busier ones, and review it when your business or technology changes.

Chart of Beaming’s average detected attempts per monitored UK business by quarter from Q1 2019 to Q3 2026. Activity fluctuates over time. Q3 2026 reaches 203,585 attempts, compared with 201,701 in Q3 2024, the previous highest quarter in the supplied series. Detected attempts are not confirmed breaches.

Remote control services still need close attention

Remote Control remained the most heavily targeted of the business applications in Beaming’s analysis. Its daily rate fell from Q2, but remained above the same period last year.

Remote control and remote desktop services support work and technical assistance. Know which tools are in use and whether access still reflects a business need.

What this means for your business: Check that access reflects how your business works today. Employees changing roles, suppliers completing projects and tools being replaced are all useful prompts to review permissions.

Chart showing the business application targeted by cyber threats in Q3 2026. Remote control devices such as CCTV and building control systems are by far the most targeted, with web applications second.

 

Brazil continued to rise within the source-country comparison

China, the USA and Brazil recorded the largest summed monthly source-IP counts in Q3 2026.

Brazil’s increase continued the movement seen in Q2, when its equivalent count was 19,849. Russia moved above India within the group, while India’s count fell by 51.9%.

These counts indicate the locations associated with the IP addresses generating the detected activity, not the identity, nationality or physical location of the attackers.

What this means for your business: Country information provides context, but it should sit alongside checks on the user, their device and the access they need. An IP address’s location alone does not establish whether a connection is safe.

 

Practical priorities for the months ahead

Use October’s Cyber Security Awareness Month to bring colleagues together and check responsibilities.

  • Confirm what needs updating. Identify unsupported equipment and applications, outstanding security fixes and who will address them.
  • Check access arrangements. Review firewall rules, remote-access tools and accounts that are no longer required.
  • Strengthen sign-in protection. Check where multi-factor authentication is available and whether it is enabled for remote access, administrator accounts and important business systems.
  • Make escalation clear. Agree who reviews security alerts, when concerns need action and how your team contacts support.
  • Test recovery. Restore a backup to check it works and walk through how essential operations would continue if a key system became unavailable.

 

‘Good cyber security needs to keep pace with the way your business works. When people join or leave, suppliers need access or new systems are introduced, it is worth checking that permissions and protection still fit. This report is a useful prompt to have that conversation with your team or provider. Keeping systems up to date, reviewing access and testing recovery arrangements helps businesses prepare, while allowing their people to get on with their work.’
Sonia Blizzard, Managing Director, Beaming.

Our guide to Cyber Essentials provides a practical starting point. For organisations supporting remote workers, our latest VPN checks can help structure a conversation with your IT team or provider.

Security support that fits your business

Whether you are reviewing remote access, planning a network change or checking your existing firewall arrangements, Beaming’s engineers can help you work through the requirements.

Speak directly to experienced firewall engineers about your requirements.

 

Beaming has analysed cyberattacks in real-time targeting thousands of UK-based businesses since the beginning of 2016 to better understand their nature and origin. From this, it can calculate the average number of attacks businesses receive and use the analysis results to help organisations improve their cyber security. These figures measure detected attempts, not successful breaches.

Talk to a Beaming security expert about how we can help strengthen your business protection