Skip to main content

From response to resilience: Rethinking cyber incident preparedness

21 September 2026

Just over four in ten businesses (43%) reported having experienced any kind of cyber security breach or attack in the last 12 months - equating to approximately 612,000 UK businesses. Our UK Cyber Claims 2025 report indicates an increase in claim metrics in 2025, which suggests a rise in both claim frequency and severity of cyber incidents. In fact, research shows that the financial cost of cyber incidents continues to climb sharply, with average claim values tripling between 2020 and 2025.

Businesses concerned about cyber risk can make a start by reviewing their cybersecurity policies and procedures to defend against cybercrime and other risks.

Claims and incident management

A cyber event and the resulting claims can seriously damage your reputation, finances and operations, so a swift, coordinated response is essential. That means rapidly mobilising internal teams, engaging specialist advisers, and managing cyber liability insurance matters promptly to protect both your reputation and your financial position.

Expert tips on incident response and insurance

This complex and ever-changing security risks landscape remains a significant concern for many UK businesses. However, by deepening our understanding and strengthening our preparedness through effective cyber risk management initiatives, we can build greater resilience against these threats. Discover how you can manage cyber risk with our comprehensive cybersecurity solutions, incident response planning, cyber risk management solutions, and cyber insurance coverage.

5 recommended actions to strengthen your cyber resilience

Cyber resilience isn’t just about technology; it’s about preparing your entire business to prevent, respond to, and recover from cyber incidents. Here are our five recommended actions to strengthen your cyber resilience:

1. Integrate cyber insurance into your risk strategy

Cyber insurance is a critical part of a comprehensive cyber resilience strategy. It provides financial protection against losses from incidents such as:

  • system failures;
  • data breaches;
  • business interruption;
  • ransomware extortion;
  • and reputational harm.

At Marsh Commercial we work with our insurance partners to arrange policies that meet the unique needs of your business. This ensures your policy covers key areas including:

  • incident response costs;
  • forensics
  • business interruption;
  • data restoration;
  • extortion payments;
  • and regulatory defence costs.

2. Review and strengthen cyber governance

Effective cyber security starts at the top. It’s crucial that your board or leadership team understand and take ownership of cyber risk and integrates it into overall business governance and resilience. This means:

  • regular reporting on cyber threats, risks, and mitigation efforts at meetings;
  • making cyber security a board-level responsibility to ensure it receives proper attention and resources.

Strong governance also means aligning your policies and procedures with industry best practices and government guidance. This creates a culture of cyber and security awareness throughout your organisation, from executives to frontline staff.

Key areas to focus on include:

  • Understanding your financial & operational exposures should a cyber incident impact your business.
  • Access management controls to carefully manage who can access your network and other digital elements.
  • Protecting hardware and software products from vulnerabilities.
  • Ensuring your security posture is robust and adaptive.
  • Conducting a regular assessment of your security measures to maintain integrity.
  • Research into potential and emerging threats.

3. Align incident response with government guidance

No organisation is immune from cyber incidents, so being prepared is key. Develop or refine your incident response plan - a clear, step-by-step plan for how your business will respond to a cyber event. This should include:

  • roles and responsibilities;
  • communication protocols;
  • procedures for containing and mitigating damage;
  • recovery plans based on recovery priorities.

Depending on your level of cover, the insurer may be able to mobilise an expert team to provide immediate assistance.

Additionally, establish clear breach notification processes to comply with legal and regulatory requirements. Use the right tools to detect security breaches or anomalies early and respond swiftly. This can help you avoid costly penalties and reputational damage.

4. Upgrade resilience investments

A strong cyber resilience plan begins with robust risk management tailored to your business needs. While cyber insurance is important, the best protection comes from clear business processes, policies, and a strong security culture embedded across your organisation. Marsh provides a range of solutions to help your business enhance risk management and lower the risk of cyber threats.

Investing in cyber resilience means prioritising the right controls, training, and technology. Regular staff training raises awareness of cyber risks and teaches employees how to spot and respond to threats like phishing emails.

Make sure your investments align with your cyber insurance coverage to maximise value. For example, some policies may require certain security measures to be in place to qualify for coverage or to reduce premiums.

5. Enhance third-party risk management

Your cyber resilience is only as strong as your weakest link, and that often includes your (digital) supply chain and third-party partners. Extend your security requirements and monitoring to cover suppliers, (both physical and digital) contractors, and other external parties who have access to your systems or data.

Aligning third-party risk management practices with your overall cyber risk strategy helps reduce vulnerabilities and ensures that your entire ecosystem is prepared to withstand cyber threats.

Expert cyber risk advice and insurance

Given that cyber risk is constantly evolving, many businesses are now turning to cyber insurance, which helps them recover losses and associated costs, for instance, resulting from large–scale breaches, business interruption, ransomware, and other types of cyberattack.

 

Real-world insight that we don't share anywhere else

Get access to exclusive help, advice and support, delivered straight to your inbox.

Try it