What Investors Actually Check Before Writing the Cheque
Here’s an uncomfortable number for anyone raising right now: 43% of UK businesses reported a cyber breach or attack in the last 12 months, roughly 612,000 organisations. And only 31% have actually assigned board-level responsibility for cyber security, meaning most companies still haven’t.
If you’re a founder heading into investor meetings, that second number matters more than the first. Few investors actually ask whether you’ve been breached, since most companies haven’t been this year. What they’re really testing is whether anyone in your company would own the response if it happened, and for most companies, the honest answer is still no.
The Question You Can’t Wing
You already know the moment. You’re mid-pitch, the deck’s landed well, and then someone asks: “Talk me through how secure your platform is,” or “What’s your technical governance look like?”
If you’re a non-technical founder, that question can feel like you’ve suddenly been dropped into a conversation everyone else understands except you. If you’re the “accidental CTO,” the developer who got promoted into leading tech because someone had to, you might have a rough answer, but not one you’d want written into a data room.
Neither reaction is a reflection of how good your product is. It’s simply that nobody has helped you build a structured answer, because few founders have been through enough of these conversations to know what a strong answer actually sounds like.
Why This Question Isn’t Going Away
This reflects a real shift in what due diligence looks like at seed and Series A.
Government data backs this up directly. The UK’s official Cyber Security Breaches Survey 2025/2026, published by the Department for Science, Innovation and Technology (DSIT) and the Home Office based on Ipsos fieldwork, found that 43% of UK businesses (around 612,000 organisations) experienced a cyber breach or attack in the past year. Board-level ownership of cyber security is improving but still low: just 31% of businesses have assigned it, up from 27% the year before. And further down the chain, it gets worse: only 15% of businesses assess the cyber risk posed by their immediate suppliers, and just 6% look at their wider supply chain at all.
Separately, the National Cyber Security Centre’s own Annual Review 2025, published in October 2025, recorded 204 “nationally significant” cyber incidents in the twelve months to August 2025: more than double the 89 recorded the year before, a 130% jump. The NCSC’s own conclusion was blunt: the threat is outpacing organisations’ ability to defend against it.
Put those together and you start to see the logic behind the questions investors ask. For many early-stage startups, the immediate concern isn’t whether they’ll be targeted today. It’s what happens as they grow, once they’ve got customer data, a bigger team, and a supply chain of their own. That’s what investors are really trying to understand. They’re looking for evidence that someone is already thinking about these challenges, rather than discovering they’ve become nobody’s responsibility.
Three Questions to Have Real Answers For
You can answer these well without a security team, as long as someone has actually thought them through and written the answers down. Before your next investor conversation, make sure you can speak to:
1. Who owns this, specifically?
An actual name, not a description like “we take security seriously.” Even at pre-seed, naming one person, usually you or your lead developer, as explicitly responsible for technical and data risk is a real signal. Only 31% of UK businesses have assigned this at board level, so doing it at all puts you ahead of most companies your size.
2. What happens if something goes wrong?
Describe, in three or four sentences, what you’d actually do if you got a breach alert tomorrow: who finds out, who decides what to tell customers, who decides what to tell investors. That’s the bar, not a 40-page incident response plan.
3. What do you actually know about your vendors and suppliers?
This is the one almost nobody has an answer for. Only 15% of businesses even assess their immediate suppliers’ risk.If you can name your main vendors (hosting, payments, any AI tooling) and say one sentence about what you’d do if one of them had a breach, you’re already ahead of most of the market.
None of these answers need to be overly technical. A straightforward conversation, in plain English, covers all three, as long as you’ve taken the time to think them through and written them down somewhere you can find them again. Ideally somewhere that would stand up in a data room, rather than buried in a Notes app.
Where Raise Ready Fits
The purpose of Raise Ready isn’t to turn founders into security specialists overnight.
It’s to help you understand whether you’re prepared for the questions investors are likely to ask before you’re sitting across the table from them.
The free Raise Ready assessment gives you a practical starting point, helping you understand where your business is already well prepared and where there may be gaps to address before due diligence begins.
It isn’t about having every answer. It’s about knowing where you stand today, so you can approach investor conversations with greater confidence tomorrow.
Ready to See Where You Stand?
If this has made you think differently about investor readiness, start with the free Raise Ready assessment and understand how prepared your business is before those conversations begin.
Take the free Raise Ready assessment.
Sources
- 43% of UK businesses experienced a cyber breach or attack in the last 12 months (~612,000 organisations); 31% have board-level responsibility for cyber security (up from 27% the previous year); 15% assess immediate supplier risk; 6% assess wider supply chain risk. Cyber Security Breaches Survey 2025/2026, UK Department for Science, Innovation and Technology (DSIT) and Home Office, fieldwork by Ipsos, published 30 April 2026. GOV.UK
- NCSC recorded 204 “nationally significant” cyber incidents in the twelve months to August 2025, up from 89 the previous year (a 130% increase). National Cyber Security Centre, Annual Review 2025, published 14 October 2025. NCSC (figures corroborated via independent trade press: Infosecurity Magazine)
Note on confidence: all statistics trace to primary government or official-body sources (DSIT/Home Office/Ipsos survey; NCSC’s own Annual Review 2025). CYP pricing re-checked against the live site on the day of drafting.
