New research combining official crime statistics with data breach records reveals which UK industries face the greatest combined threat from both digital and physical security failure.
A UK identity and access control specialist has published new research ranking UK industries by combined digital and physical security exposure, a new UK index to bring the two together in a single measure.
The UK Industry Security Exposure Index from ID Card Centre combines data breach reports from the Information Commissioner’s Office (ICO) with crime figures from the Home Office’s Commercial Victimisation Survey, scoring 11 UK industries on a 0 to 100 scale.
Retail and manufacturing tops the index with a score of 50.9, driven by the highest rate of business crime of any sector measured. More than a third of wholesale and retail premises (41%) reported being a victim of crime in the Home Office latest 2022/23 survey, the highest of any sector in the survey, while the combined retail and manufacturing sector was also an average of over 24 a year between 2023 and 2025.
Utilities rank second (43.1), with almost a third of premises (32%) hit by crime and a data breach rate of over 75 breaches per 10,000 businesses. Transport and Leisure (40.7), Charitable and Voluntary organisations (32.5) and Membership and Professional Associations (31.0) complete the top five.
Media ranks lowest of the 11 industries measured (0.002), with Online Technology and Telecoms (0.7) and Land and Property Services (2.1) also scoring among the least exposed.
The research also uncovered a striking gap in the picture for education, health and government. Despite reporting some of the highest breach volumes in the country, none of these sectors are covered by the Home Office’s national business crime survey, meaning there is currently no way to measure their physical security exposure on a comparable basis. Separate analysis of the same ICO data found that Local Government has the highest data breach rate of any sector measured nationally, at over 1,200 breaches per 10,000 organisations.
The research also found that more than three quarters (77%) of all UK data breaches in 2025 were caused by human error or process failure rather than hacking and that nearly one in five breaches (19%) took more than a week to be reported to the ICO, well beyond the 72-hour deadline.
“Security conversations tend to split into two camps: cybersecurity or physical security. Our research shows that’s an increasingly outdated way to think about risk. Retail and manufacturing businesses are being hit hard on both fronts at once, and industries like local government are seeing breach rates that dwarf even the most exposed commercial sectors. Organisations need to be thinking about physical and digital security as one problem, not two separate departments,” said Ben O’Brien, Managing Director at ID Card Centre.

