Just over four in ten businesses (43%) reported having experienced any kind of cyber security breach or attack in the last 12 months - equating to approximately 612,000 UK businesses. Our UK Cyber Claims 2025 report indicates an increase in claim metrics in 2025, which suggests a rise in both claim frequency and severity of cyber incidents. In fact, research shows that the financial cost of cyber incidents continues to climb sharply, with average claim values tripling between 2020 and 2025.
Businesses concerned about cyber risk can make a start by reviewing their cybersecurity policies and procedures to defend against cybercrime and other risks.
A cyber event and the resulting claims can seriously damage your reputation, finances and operations, so a swift, coordinated response is essential. That means rapidly mobilising internal teams, engaging specialist advisers, and managing cyber liability insurance matters promptly to protect both your reputation and your financial position.
This complex and ever-changing security risks landscape remains a significant concern for many UK businesses. However, by deepening our understanding and strengthening our preparedness through effective cyber risk management initiatives, we can build greater resilience against these threats. Discover how you can manage cyber risk with our comprehensive cybersecurity solutions, incident response planning, cyber risk management solutions, and cyber insurance coverage.
Cyber resilience isn’t just about technology; it’s about preparing your entire business to prevent, respond to, and recover from cyber incidents. Here are our five recommended actions to strengthen your cyber resilience:
Cyber insurance is a critical part of a comprehensive cyber resilience strategy. It provides financial protection against losses from incidents such as:
At Marsh Commercial we work with our insurance partners to arrange policies that meet the unique needs of your business. This ensures your policy covers key areas including:
Effective cyber security starts at the top. It’s crucial that your board or leadership team understand and take ownership of cyber risk and integrates it into overall business governance and resilience. This means:
Strong governance also means aligning your policies and procedures with industry best practices and government guidance. This creates a culture of cyber and security awareness throughout your organisation, from executives to frontline staff.
Key areas to focus on include:
No organisation is immune from cyber incidents, so being prepared is key. Develop or refine your incident response plan - a clear, step-by-step plan for how your business will respond to a cyber event. This should include:
Depending on your level of cover, the insurer may be able to mobilise an expert team to provide immediate assistance.
Additionally, establish clear breach notification processes to comply with legal and regulatory requirements. Use the right tools to detect security breaches or anomalies early and respond swiftly. This can help you avoid costly penalties and reputational damage.
A strong cyber resilience plan begins with robust risk management tailored to your business needs. While cyber insurance is important, the best protection comes from clear business processes, policies, and a strong security culture embedded across your organisation. Marsh provides a range of solutions to help your business enhance risk management and lower the risk of cyber threats.
Investing in cyber resilience means prioritising the right controls, training, and technology. Regular staff training raises awareness of cyber risks and teaches employees how to spot and respond to threats like phishing emails.
Make sure your investments align with your cyber insurance coverage to maximise value. For example, some policies may require certain security measures to be in place to qualify for coverage or to reduce premiums.
Your cyber resilience is only as strong as your weakest link, and that often includes your (digital) supply chain and third-party partners. Extend your security requirements and monitoring to cover suppliers, (both physical and digital) contractors, and other external parties who have access to your systems or data.
Aligning third-party risk management practices with your overall cyber risk strategy helps reduce vulnerabilities and ensures that your entire ecosystem is prepared to withstand cyber threats.
Given that cyber risk is constantly evolving, many businesses are now turning to cyber insurance, which helps them recover losses and associated costs, for instance, resulting from large–scale breaches, business interruption, ransomware, and other types of cyberattack.
Get access to exclusive help, advice and support, delivered straight to your inbox.