Cyber insurance: why boards need to own the risk

Cyber cover helps businesses prepare, respond and recover when technical defences fail.


There's a common assumption among SME leaders that their IT team keeps them safe from cyber-attacks.

After all, IT handles the technical defences like firewalls, email scanning and basic cyber prevention.

But prevention is not the same as protection.

While strong cyber security can reduce the likelihood and impact of an attack, no system is impenetrable. If an incident does occur, the consequences can quickly extend beyond IT systems to impact revenue, operations, customers, employees and reputation.

Cyber insurance can help a business manage all those consequences, and that distinction matters because it explains why cyber isn’t just a technical risk, but a business risk that belongs in the boardroom.


In all probability

Consider how boards think about other risks. An MD wouldn’t wait for a warehouse to burn down before buying fire insurance. Fire and flood cover is considered standard practice, yet in 2026 a business is almost 100 times more likely to experience a successful cyber-attack than a fire.

Government data shows 612,000 UK businesses experienced a cyber security breach or attack in the last 12 months*, compared with just 6,665 workplaces that had a fire**.

So, why have so many boards not yet bought cyber insurance?

Our research finds that, while 53% of SMEs now agree that cybercrime and data breaches are among the most important challenges facing their business over the next few years, 44% still don’t have cyber insurance cover.

This gives brokers a clear way to open the conversation:

  • What parts of the business depend most heavily on technology?
  • What would happen if those systems were unavailable?
  • Who would lead the response?
  • What support could the business access immediately?
  • How quickly could operations recover?

These are business questions, not technical ones, so the answers should involve leadership teams as well as IT.

And directors have a legal duty to protect their company. If, having been made aware of the risk, a director fails to buy cyber insurance, they could face personal liability through a directors and officers claim. Their own personal assets could be at stake.

That accountability question works. Boards respond to it.


Closing the risk gap

In response, all boards should be commissioning a thorough cyber resilience assessment of their operations. This is simpler than it sounds. Scanning tools can identify exposure on websites and IP addresses and a straightforward report shows vulnerabilities without the IT jargon. Businesses can even run a ransomware stress test to score their susceptibility and estimate potential costs if a breach occurs.

But this isn’t just a ‘one and done’ job. A key part of the value cyber insurance provides is the ongoing services, including continuous monitoring, legal support and breach-response expertise, that help businesses prepare for incidents they can't prevent and recover when incidents do occur.

Businesses aren’t just buying a policy document. Rather, they are investing in the kind of specialist cyber, legal and crisis-management capability that would be prohibitively expensive to have in house.

That's the value brokers are really selling; proactive resilience and expert support when things go wrong.

And it’s time to stop talking about cyber insurance as a grudge purchase and reframe it as a hygiene conversation.

Brokers who position cyber alongside traditional commercial insurance aren't adding complexity, they're closing a gap in the board's risk management and helping directors fulfil their duty of care before, during and after an incident.

The question is no longer simply whether a business could experience a cyber incident. It is whether its leaders understand the risk and are prepared to respond.


Markel UK's No. 1 commercial lines insurer

Insurance Times broker survey names Markel as the UK’s No.1 commercial lines insurer for service 2025/2026.