Somewhere out there is an old account with your name on it. Wrong job, wrong decade, same password you’ve probably reused since. Nobody’s thought about it in years. That’s exactly why it’s more useful to a hacker than the systems your security team checks every week. In 2026: the biggest risk isn’t what businesses are ignoring, it’s what they don’t even know is there.

We compared what the UK searches for online about cyber security with what is actually causing real-world breaches, using data from DSIT, Verizon, IBM and SpyCloud.

The gap and the unknown risks is where the real risk lies.

Key Findings

  • 43% of UK businesses were attacked last year. At that rate, “getting attacked” isn’t a scenario to plan for. It’s an ordinary Tuesday.
  • Stolen usernames and passwords cause 22% of breaches. Not clever malware. A password, reused, on an account nobody remembered to close.
  • Human error features in roughly 60% of attacks. Turns out the weakest link in most security stacks still has a coffee break.
  • It takes 241 days, the better part of eight months, to spot a hacker already inside the system. A test you passed in January says nothing about August.
  • “Cyber Essentials” gets 9,900 searches a month. “Continuous monitoring”, one of the most effective ways to catch an attack early, gets 170. We are, collectively, very interested in the certificate and mildly curious about the thing that actually works.
  • Almost nobody searches for forgotten accounts, yet SpyCloud recovered 5.3 billion stolen logins in a year, plenty tied to work email addresses.
  • Nearly two thirds of organisations have no AI policy, and 1 in 5 have already had a security incident caused by a tool nobody signed off.
  • Businesses using AI to monitor continuously catch attacks 80 days faster and save close to $2 million per breach. Not a marginal improvement. A different result entirely.

The Ranking: What We Search For vs. What’s Actually Getting In

Ranked by search volume, most popular first. Read down the list and watch the plot twist unfold – the protection gets thinner, the risk gets bigger, and the thing that matters most is the one almost nobody thinks to Google.

1. Cyber Essentials: the hi-vis vest that gets mistaken for body armour

Cyber Essentials is the most-searched cyber security term in the UK, and it’s a decent place to start. A government-backed baseline beats no baseline at all. The catch: it only checks five things. It has nothing to say about phishing emails, dishonest insiders, or a password already doing the rounds on a criminal forum, which is to say, nothing about how most businesses actually get breached.

A certificate on the wall isn’t the same as being secure, and 43% of businesses found that out the hard way, tick box fully completed. Some are catching on: searches for the certification are up 50%, which looks a lot like people starting to ask whether passing the test was ever the point.

The verdict:

  • The most-searched term of all, doing the least amount of the heavy lifting
  • A 43% attack rate the certificate alone was never built to move
  • A tick in the box compliance exercise is a floor, not a ceiling, whatever the certificate on the wall implies
  • Rising searches suggest the penny is starting to drop

2. The Pen Test: a very expensive photograph

A pen test is a single, well-documented snapshot: your defences, on one specific Tuesday, held up. It has nothing to say about the other 364 days, and against an average detection time of 241 days, that’s most of the year going unchecked between snapshots.

Cyber security was never meant to be a milestone you hit once a year and file away. It’s a moving target, which is exactly why Acora built the Cyber Incident Baseline & Readiness Assessment differently. Rather than a 250-item list of everything that could theoretically be exploited, our CREST-accredited team, backed by 450+ incident responses and 60+ offensive testing engagements, maps how those weaknesses would actually chain together in a real attack, and ranks them by business risk, not just how they score on a technical scale.

Think of the pen test as the smoke detector, this is the bit that tells you which room to actually worry about. Continuous monitoring is simply what comes next, once you know that.

The verdict:

  • The two most-searched terms here both describe a single day of assurance
  • An eight-month gap that one test a year was never going to cover
  • The approach that’s actually proven to work is the one nobody’s searching for
  • AI-driven monitoring cut detection by 80 days and $1.9 million off the cost of a breach

3. Shadow AI: the tool everyone’s using that nobody’s approved

Shadow AI is what happens when someone pastes a client brief into a free chatbot because it’s quicker than doing the task the long way. No approval, no record, no idea on the business’s part that any of it happened.

Search interest is flat, which is less “nothing to see here” and more “nobody’s looked yet.” Every ungoverned tool is a new, quiet way for sensitive information to leave the building, carried out by someone who was only trying to save ten minutes, and invisible to security systems that were designed before generative AI turned up.

The verdict:

  • 1 in 5 organisations has already had an incident tied to this
  • Almost two thirds have no AI policy at all
  • Adoption is comfortably outpacing governance
  • It sits entirely outside the tools built to catch everything else

4. Forgotten Accounts: the gym membership you meant to cancel

Here, what people search for and what actually causes the damage go their separate ways. “Account hacked” tends to get searched after the fact, once a password’s already been stolen, sold and reused elsewhere. By then, whoever’s searching is managing a breach, not preventing one.

The account already hacked usually isn’t the interesting one. It’s the one nobody remembers signing up for: an old dating profile, a shopping account from 2019, a free trial set up with a work email and never closed. Each one is a spare key still in the lock. Not because anyone was careless, but because nobody thought to add it to the list of things worth watching.

The verdict:

  • The single largest pool of ready-to-use stolen credentials on this list
  • A reused password can turn a personal account into a corporate problem
  • Just 20 searches a month for the widest gap between worry and danger here
  • Practically nobody tracks which personal accounts share a work email

5. Working From Home: the office that quietly grew a kitchen

The least-searched risk on this list touches more than 10 million British workers. Working from home didn’t loosen the rules temporarily. It moved the business perimeter into the kitchen, permanently, and search behaviour suggests most of us still haven’t updated the map. A firewall built for an office is doing very little for a laptop three rooms away from a fridge.

Traditional perimeter security only works if there’s still a perimeter to speak of. Once a laptop’s compromised, or someone’s hopped onto a fake public Wi-Fi network without a second thought, that perimeter has already been left behind. The office wall didn’t collapse dramatically. It just quietly stopped being where the work happens.

The verdict:

  • The biggest mismatch between people affected and attention paid on this list
  • Human error, behind roughly 60% of attacks, has more room to operate than ever
  • Home networks and personal devices remain largely unwatched
  • Search interest is falling as the actual exposure keeps rising

The Shape of the Gap

Line the two lists up and the pattern is obvious. Attention peaks exactly where protection is weakest: the certificate, the annual test. It’s lowest exactly where the real exposure sits: the forgotten login, the unwatched laptop. Worry and risk aren’t just out of sync. They’re pointing in opposite directions. Businesses are searching for what feels familiar and what ticks a box. They’re not searching for what actually works, and that’s the whole gap this report is here to close.

What Has Actually Changed

Cyber crime got easier before businesses got better at defending against it. The tools needed to target a business can now be rented for a subscription fee, and most of the technical skill that used to be a barrier to entry has been designed out of the process.

Stolen passwords trade by the billion. Ungoverned AI tools spread through a workforce faster than any policy can be written to catch up with them. And generative AI can now write a convincing phishing email or forge a document at a speed and scale no human ever could, in seconds, for next to nothing.

The economics changed. What hasn’t changed, for most businesses, is where they’re looking. The easiest way in still runs straight through the things nobody’s searching for: the forgotten account, the home laptop, the unsanctioned AI tool, and the eight-month gap between one annual check and the next.

Why This Matters Now

The attacks doing the most damage today don’t look like attacks. They move through legitimate logins and everyday tools, which is exactly why a quick manual check or a once-a-year review sails straight past them without noticing. This isn’t a story about careless businesses, it’s a visibility problem, and a solvable one.

Most organisations aren’t being reckless, they simply can’t see where risk is quietly building up, and opening that box doesn’t have to unleash chaos. Handled properly, what you get is clarity: a clear, evidence-led picture of where the exposure actually sits, and what’s worth fixing first. Cyber security was never meant to be a milestone you tick off once a year, it’s a moving target, and the businesses doing well here aren’t the ones who avoid getting targeted (nobody does), they’re the ones who’ve made a habit of checking.

What businesses need is a shift from checking occasionally to monitoring continuously, and from treating cyber security as an annual event, to treating it as the ongoing discipline it always should have been.

A certificate is a starting point, not proof of anything. Real security comes from constantly checking, verifying and monitoring what’s actually happening across the business, rather than assuming everything’s fine until next year’s review turns up.

A note from Acora’s Director of Cyber Security, James Fernley

“One thing I’ve observed is that most organisations now recognise AI can find and exploit vulnerabilities far quicker than they can find and fix them, which is exactly why the industry is shifting from one-off checks to continuous response. But knowing you need to respond faster doesn’t tell you what to fix first. That’s where the Cyber Incident Baseline comes in: it helps businesses understand what’s most important and why, rather than handing them another 250-item list. Increasingly, that also means using autonomous testing to keep pace with AI-driven threats and inform prioritised remediation.

Then it comes down to the partner you choose. Any good cyber business can run an assessment and tell you what’s wrong. Very few can then fix it. Because Acora has Cloud, Endpoint, Network, and Data & AI teams sitting alongside our security practice, we’re the ones doing the remediation: migrating you to Entra, doing the patch work, closing the gaps the baseline surfaces, and looking at the fix from every angle, not just the security one. That’s the difference between marking the homework and actually doing it with you.”