By Jon Fielding
Coming clean about a cybersecurity incident is now a priority for businesses that are looking to deal with breaches more effectively. There has been a sharp rise in the number that are reporting themselves to the UK Information Commissioner’s Office (ICO) post-breach in order to limit regulatory penalties and reputational damage. Self-disclosure rose from 53% in 2024 to 69% in 2025, according to a recent annual survey of IT security decision-makers by Apricorn. And there was a corresponding decline in the number being reported by a third party, from 14% to just 8%.
This newfound zeal coincides with a raft of recent legislation, making businesses much more compliance-conscious. We have seen the introduction of the Digital Operational Resilience Act (DORA), the EU AI Act, and the EU Cybersecurity Act, as well as the overhaul of UK GDPR following Brexit. Plus, NIS2 is capturing more organizations in scope and holding senior management responsible for overseeing risk management. The upcoming UK counterpart, the Cyber Security and Resilience Bill (CSRB), is likely to do the same. That means people are now personally invested in the security of the business.
But regulators have also sought to make requirements less rigid. There has been a shift away from the tick box approach for some time now towards more outcome-based frameworks, but it is only in the latest iterations of some standards that we have seen true flexibility. If you look at the Payment Card Industry Data Security Standard (PCI DSS) version 4.01, for instance, it adopts a risk-based approach that allows for customised security controls as opposed to a one-size-fits-all approach.
All of these changes have seen compliance become much more embedded in the day-to-day operations of the business. This, in turn, has led to stronger internal reporting processes and ownership of breach response. However, the disclosure trend is also likely to be influenced by a desire to appease the regulator. Following disclosure, the ICO will usually issue a reprimand or enforcement notice and only affix a penalty if that enforcement is not observed. Therefore, businesses that are cooperative and seek to remediate are much less likely to be fined.
In its 2025 annual report, the ICO notes that it only took formal action in response to 33% of the total cases it received spanning data protection complaints, FOI requests, and personal data breach reports. There were 204 GDPR incidents, of which only 43 resulted in investigations, nine of which warranted reprimands, and only two penalty notices were handed out. Of these, just one related to a company in the private sector – Advanced Computer Software Group Ltd, which was fined £3,076,320.
With respect to cybersecurity, out of 1,746 reports of an incident, 61 incidents were ‘managed’, and there were 15 investigations. Of these, three resulted in reprimands concerning failures to implement appropriate technical and organizational measures. Nine monetary penalties were issued totalling £890,000, and nine under the marketing regulations, the Privacy and Electronic Communications Regulations (PECR). The regulator’s criminal investigations resulted in four prosecutions and three cautions.
Facing the music
It is important to point out, however, that the ICO has not and will not be adopting a more lenient approach towards the commercial sector. Its decision following a breach is driven by risk, i.e. how widespread the breach is and the risk it represents to personal data. Its preferred method of sanctions is a reprimand, as it revised its guidance on reprimand procedures in 2024.
However, an ICO reprimand is no slap on the wrist. There will be remedial recommendations and requirements that must be met within a given timeframe, evidence of compliance must be demonstrated, and the ICO may well publish those details on its website even if no fine is issued, potentially resulting in bad press and reputational damage. Plus, the ICO can revisit the business in the future to continue to ensure it is observing those requirements.
Greater transparency is, of course, to be welcomed, as is the pragmatic guidance of the ICO which equates to more carrot and less stick. But is more self-reporting and remediation having the desired impact? It may be too early to tell, but results from the Apricorn survey indicate otherwise. It found that the number of organizations suffering a data breach remains worryingly high, with only 7% of those questioned claiming they had not suffered a breach.
Of those that were breached, 37% said this was due to phishing attacks, 33% employee error, 26% misconfigured software, and 25% ransomware. This suggests that while ransomware may hog the headlines, it is not the main culprit. Rather, the less glamorous causes, such as human error and susceptibility to scams such as phishing emails, are far more likely to result in data loss.
Interestingly, there was also a rise in the number of insider breaches due to malicious employees from 15% to 20%, perhaps due to worsening economic conditions which make employees more susceptible to offers from adversaries. Insiders are being recruited by threat actors who quite blatantly advertise for willing accomplices. Another rising risk is that of AI-based attacks, which were included in the Apricorn survey options for the first time. These were found to be the cause of a fifth of breaches due to data leakage. There have been numerous examples of AI leakage, from ‘shadow AI’, whereby employees are using Large Language Models (LLMs) without authorisation, to issues with the LLM itself.
Redrawing the boundaries
Given that AI is here to stay and we are now seeing the emergence of agentic AI, which can act autonomously without the need for human prompting, this begs the question: what can businesses do to reduce these risks and protect their data? Governance has a big part to play here, but so too does how we build AI deployments. Many of the APIs these LLMs are connecting to, for instance, do not have basic controls in place, such as access and authentication. So, it is a matter of getting back to basics and looking at the architecture itself.
At the end of the day, each and every one of these attack types, no matter how new, all come back to the data which must be safeguarded and protected. The Apricorn survey further revealed that 58% thought their employees lacked the technology or skills to secure that data, putting the onus firmly back on the business to secure its most precious resource.
It is this swing of the pendulum that we are seeing in regulatory spheres, and the reason why we are seeing self-reporting rise, because the buck stops with those overseeing that risk. Management must step up and address the existing and emerging threats to its data, not only to fulfil compliance obligations, but to protect their employees, customers, and their livelihood.
The author
Jon Fielding is Managing Director, EMEA, Apricorn






