ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
Which industry has seen the biggest growth in cybersecurity incidents? / Which industry has seen the biggest decrease in cybersecurity incidents?
2
Which cybersecurity incident had the biggest increase in reports last year?
3
SectorNumber of cases reported in 2023Number of cases reported in 20242023-2024 percentage changeIncidentNumber of cases reported in 2023Number of cases reported in 20242023-2024 percentage changeTime Taken to ReportNumber of cases reported in 2023Number of cases reported in 20242024 percentage total2023-2024 percentage change
4
1Marketing40116190%1Phishing2053336664%1
24 hours to 72 hours
3629455851%26%
5
2Membership association11721584%2Malware395362-8%272 hours to 1 week1771174420%-2%
6
3Social care15326674%3Ransomware34603011-13%3Less than 24 hours1507132015%-12%
7
4Justice61067%4Brute Force311212-34%4More than 1 week1474126914%-14%
8
5Health39664362%5Unauthorised access323177-45%8891
9
6Central Government589157%6Denial of Service61-83%
10
7Retail and manufacture1523213440%
11
8Legal53769129%
12
9Utilities678019%
13
10Land or property services34640116%
14
11Transport and leisure3713772%
15
12
Online technology and telecoms
3453450%
16
13Charitable and voluntary684646-6%
17
14Education and childcare15801436-9%
18
15Religious3026-13%
19
16General business250209-16%
20
17Local government505381-25%
21
18Finance, insurance and credit1310790-40%
22
19Regulators158-47%
23
20Media4715-68%
24
25
26
YOY total change6%
27
28
29
Methodology:
30
1. Reboot Online analysed data from the Information Commissioner’s Office (ICO) to identify:
a. How many times six major cyber security incidents were reported to the ICO in the first three quarters of 2023 and 2024*.
b. How many times each sector reported cyber security incidents to the IOC in the first three quarters of 2023 and 2024.
c. The time taken to report cyber security incidents to the IOC in the first three quarters of 2023 and 2024.
2. Reboot Online established phishing, unauthorised access, ransomware, malware, hardware/software misconfiguration and brute force as the six major cyber security incident types - as included in the IOC report.
3. Reboot Online then calculated how many cases in each section of the analysis were reported to the ICO in the different quarters.
4. Once the figures for each incident type were established, the year-on-year percentage change was calculated using the figures from 2023 and 2024.
5. The figures were then ranked from highest to lowest based on those with the highest percentage increase of cases reported to the ICO.
6. The 2023 case figures for each of the six major cyber security incident types were compared against the 2024 case figures to see if there was a year-on-year increase or decrease (represented as percentages) in case numbers for each of them.
*This timeframe was analysed because the data for Q4 2024 is not yet available, so to keep a fair analysis the Q1, Q2 and Q3 were reported on for 2023 and 2024.
*Political sector was removed as the results were inconsistent
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100