October’s National Cyber Security Awareness Month is a useful reminder to us all to take stock of cyber security arrangements by assessing risks and ensuring your business is prepared for today’s ever evolving cyber threats.
Recent cyber-attacks affecting major retailers, airports and a leading automotive manufacturer have demonstrated that cyber criminals do not discriminate by sector or size. While larger organisations often attract the media’s attention, the reality is that businesses of all sizes face the same threat. In fact, the UK’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses experienced a cyber security breach or attack during the previous 12 months, equivalent to around 612,000 businesses nationwide.
If organisations with substantial resources and dedicated cyber security teams can beaffected by cyber incidents, it’s worth considering whether your business has appropriate preventative measures and response arrangements in place.
Understanding your cyber risk
Cyber risk refers to the potential for your systems, networks or data to be compromised by malicious activity. This could include ransomware attacks, business interruption, data breaches, fraudulent transactions or unauthorised access to sensitive information.
One of the most common threats is phishing. Phishing is a cyber scam that uses fraudulent emails, texts or messages designed to trick you or your employees into clicking malicious links, opening infected attachments, or sharing sensitive information such as passwords and banking details.
The risk is significant. According to the UK Government’s Cyber Security Breaches Survey 2025, 85% of businesses that experienced a cyber breach or attack identified phishing emails or messages as a factor, making it the most common cyber threat facing UK organisations today. This highlights the importance of employee awareness, cyber security training and having appropriate safeguards in place.
What can you do to reduce your risk?
There is no single solution to cyber risk, but there are several practical steps you can take to improve your resilience:
- Use strong passwords and multi-factor authentication.
- Keep software and security systems up to date.
- Back up critical business data regularly.
- Train employees to recognise phishing attempts and other cyber threats.
- Review supplier and third-party security arrangements.
- Develop and test an incident response plan.
- Consider whether cyber insurance forms part of your wider risk management strategy.
Taking proactive steps today can help reduce both the likelihood and impact of a cyber incident.
How can an Insurance Broker help?
Understanding cyber risks and the insurance market can be complex. Working with a broker can help you make informed decisions based on your business’s specific circumstances.
- Risk assessment
Every business faces different cyber exposures. A review of your operations, systems and processes can help identify vulnerabilities and highlight areas where additional protection may be appropriate.
- Reviewing insurance options
Cyber insurance policies can differ significantly in the cover and support they provide. Understanding policy features, limitations and exclusions can help ensure your selected cover aligns with your business needs and objectives.
But what happens if the worst occurs?
As we’ve seen in the media, even with robust preventative measures, cyber incidents can still happen.
Depending on the policy selected, cyber insurance may provide access to specialist support services that may include incident response teams, legal advisers, forensic investigators and claims support. Access to experienced professionals during the early stages of an incident can help your business respond effectively and minimise disruption, subject to policy terms, conditions and exclusions.
Prompt action following a cyber incident can help organisations manage their response and recovery more effectively
Having a clear response plan and access to appropriate support can make a significant difference to your recovery.
Review your cyber resilience today
Cyber security is no longer ‘just an IT issue’. It is a business risk that can impact your operations, finances, reputation and your customers.
Rather than assuming cybercrime only affects large organisations, now is the time to review your cyber resilience and ensure you have effective safeguards in place.
Have a chat with us today about cyber insurance – appropriate insurance arrangements may help reduce the financial impact of a covered cyber incident and support better outcomes for your business and your customers.
Found this article useful? You may also find this forthcoming webinar of interest:

Simon Hall
Client Executive
Adler Fairways

