Context
The ABI and PwC UK have published a new report which highlights how cyber insurance can further strengthen the UK’s resilience to cyber risk. Alongside this, the ABI has also issued new guidance to help organisations better protect themselves against escalating and evolving cyber threats.
Key points to note and next actions
- The risk to organisations and the wider economy from cyber attacks is increasing.
- A survey from the Department for Science, Innovation & Technology found that 43% of UK businesses experienced a cyber breach or attack in the previous 12 months.
- Separate research suggests nearly a third of CEOs now feel their organisations are highly exposed to major cyber-related financial loss in the year ahead.
The new guidance is designed to help organisations of all sizes improve their cyber resilience. Drawing on insurers’ experience and claims data, it identifies practical measures that can help organisations prevent attacks, reduce harm and recover more quickly when incidents occur. These include:
- Regular staff training to help employees recognise and avoid common threats
- Reliable offline backups to ensure critical data can be restored as quickly as possible
- Clear incident response plans to enable faster, more coordinated action during an attack
- Multi-factor authentication to guard against unauthorised access to systems
- Good logging and monitoring to spot suspicious activity early
- Strong encryption to protect sensitive data
- Supplier and third-party checks to reduce the risk of attacks via external systems
The guidance also highlights the role cyber insurance can play in strengthening resilience. Alongside financial protection, insurers increasingly provide services such as threat monitoring, incident response support and system recovery.
The new joint ABI/PwC UK report explores how cyber insurance has developed into a key tool for managing cyber risk. From novel ways to mitigate risk to advancing product design, the report highlights the cyber insurance market’s ability to adapt and innovate to this evolving threat and meet growing demand. It also identifies opportunities to further strengthen its contribution to UK resilience.
Its recommendations include improving understanding of cyber insurance through clearer policy language and stronger distribution, aligning more closely with wider cyber resilience initiatives and regulation, enhancing data sharing to support better risk management, and encouraging organisations to invest in higher levels of cyber preparedness.
