The UK Government's Cyber Security Breaches Survey 2025/26 shows only 20% of retail and wholesale businesses have board-level responsibility for cyber security.

The UK Government's Cyber Security Breaches Survey 2025/26 landed on 30 April 2026, and the headline number is the one everyone will quote: 43% of businesses reported a cyber security breach or attack in the last 12 months, roughly 612,000 companies nationwide.
That number isn't the story. The story is who is responsible when it happens, and the survey's own data shows that in retail, the answer is often nobody.
Across all sectors, only 31% of businesses have board-level responsibility for cyber security, up from 27% the year before.
Break that figure down by sector and retail or wholesale sits at just 20%, against 54% in finance or insurance and 51% in information and communication. Only transport or storage (17%) and construction (24%) come in lower.
The survey's own analysis notes that the retail or wholesale sector was also less likely to treat cyber security as a genuine priority at all.
That's a striking finding for an industry that sits at the exact point where customer trust, payment data and brand reputation collide: the checkout. Retailers are handling more card data, running more third-party scripts, and facing more targeted attacks than most other sectors, while being among the least likely to have anyone at board level accountable for it.
The survey also asked how many businesses review the cyber risk posed by the vendors and partners they rely on.
Only 15% review the risks posed by their immediate suppliers. Just 6% look any further than that, into the wider supply chain.
For a checkout page, that gap is not abstract. A typical checkout loads analytics tags, chat widgets, review plugins, tag manager containers and marketing pixels, often from a dozen or more third-party domains, updating automatically and outside the retailer's direct control. Every one of those is a supplier. Every one of those is part of the attack surface. Magecart-style skimming attacks exist precisely because criminals know that most retailers cannot answer a simple question: exactly which scripts are running on our checkout page right now, and did we approve all of them?
Recent, well-publicised breaches at major UK retailers have shown how quickly a single compromised supplier or third-party access point can cascade into a full-blown incident. The pattern is consistent: the retailer assumed someone else, a payment provider, a platform, an agency, had it covered. Nobody owned the checkout itself.
This is exactly why PCI DSS v4.0.1 shifted the standard away from a once-a-year checkbox exercise and toward continuous evidence of control. Passing an annual PCI scan tells you your checkout was safe on the day you tested it. It says nothing about what's running on that page today, after the last marketing tag update or the latest third-party script change.
Ownership means being able to answer, at any point, not just on audit day, what is loading on your checkout and whether it's still what you approved. That's a board-level question as much as a technical one, because the consequences of getting it wrong land on revenue, regulatory standing and customer trust, not just on an IT ticket queue.
Based on what the data shows retailers are missing, ownership means:
Checkout Audit exists for exactly this gap. It gives retailers ongoing, auditable visibility into every script running on their checkout, continuous monitoring rather than a once-a-year snapshot, and clear evidence they can put in front of a board, a QSA or a customer to prove control, not just claim it.
The government's own data confirms what we've said before: checkout security only works when someone actually owns it. Right now, in retail, that ownership gap is wider than almost anywhere else.
Read the full survey: Cyber Security Breaches Survey 2025/2026, GOV.UK
Run your first audit today and see exactly what's running on your checkout.
Simple proof, steady monitoring, fewer surprises.
