Cyber resilience is now a leadership issue, not an IT task
Crowell & Moring LLP’s October 2025 commentary on enhancing UK cyber security resilience and leadership engagement points to an important shift for small and medium-sized enterprises: cyber security is increasingly being judged as a business-governance responsibility. For UK SMEs, this matters well beyond compliance language or boardroom theory. It affects whether an attack is contained in hours or becomes a prolonged operational crisis, how credible the business appears to customers and suppliers, and whether cyber insurance remains available on workable terms.
Many SME owners still delegate cyber security entirely to an IT provider, a managed service provider (MSP), or the most technically confident employee. External expertise is valuable, but delegation does not remove management responsibility. A phishing compromise that leads to fraudulent payments, a ransomware incident that stops production, or a supplier-account takeover can create decisions that only leadership can make: whether to shut systems down, notify affected people, communicate with customers, approve emergency expenditure, and preserve evidence for insurers and regulators.
The practical message is clear: resilience is not simply the presence of security software. It is the organisation’s demonstrated ability to prevent, respond to, and recover from a cyber incident under pressure.
Why leadership engagement changes cyber insurance outcomes
Cyber insurance is designed to fund and coordinate a response to specified cyber events. It may cover incident-response specialists, forensic investigation, legal advice, notification costs, business interruption, data restoration, cyber extortion and certain third-party liabilities, subject to the policy’s terms, conditions and exclusions. It is not a substitute for basic security controls or a plan for running the business during disruption.
Insurers assess cyber risk using increasingly detailed questions. For a UK SME, the answers commonly concern multi-factor authentication (MFA), endpoint protection, backups, patching, access controls, email security, staff awareness, and incident-response arrangements. These are not merely technical questionnaire items. They indicate whether management understands the organisation’s dependencies and has invested in controls proportionate to its exposure.
A leadership team that receives meaningful cyber-risk information can make better decisions about insurance limits, excesses and policy wording. For example, a firm that depends on a cloud-based accounting platform may face a serious trading interruption even if its own servers are untouched. A manufacturer may be particularly exposed to operational downtime. A professional-services business may be more concerned about confidential client files, email compromise and regulatory notification. Buying a standard policy without considering these scenarios can leave costly gaps.
Insurance underwriters want evidence, not assurances
Statements such as “our IT company handles that” are weak evidence of resilience. A more credible position is documented proof that the business has controls and reviews them. This could include:
- MFA enabled for email, cloud administration, remote access and finance systems;
- a tested backup process, with at least one backup protected from routine network compromise;
- a register of critical systems, suppliers and data flows;
- a patch-management process with clear responsibility and escalation;
- controls over payments and changes to supplier bank details;
- an incident-response plan with named decision-makers and insurer contact details; and
- records of cyber-risk reviews at director, owner or senior-management level.
These measures can improve insurability, but their first value is operational: they reduce the chance that a single stolen password or unpatched device causes a business-wide loss.
The overlooked SME risk: decision paralysis during an incident
Technical containment is only one part of an attack response. During a suspected breach, leaders may need to decide whether systems should be isolated, whether operations can continue manually, whether customers should be warned, and who is authorised to speak externally. Delayed decisions can increase business interruption, create inconsistent communications and complicate insurance claims.
This is where leadership engagement has a measurable effect. A senior team does not need to become cyber-security specialists. It does need to establish decision rights before an incident occurs. The owner, managing director, finance lead, operations lead and IT or MSP contact should all know their roles.
Build an incident-response plan that works at 2am
A concise, usable plan is more valuable than a long policy document that nobody can find. It should include:
- A 24-hour contact list for the insurer or broker, MSP, cyber incident-response provider, legal adviser and key senior staff.
- Authority limits, identifying who can approve emergency spending, system shutdowns and external communications.
- First-hour actions, such as preserving logs, disconnecting affected devices where appropriate, changing compromised credentials and stopping suspicious payments.
- Business-continuity procedures, including manual workarounds, priority services and customer communication templates.
- Data-protection escalation, so the business can obtain legal advice on whether the UK GDPR requires notification to the Information Commissioner’s Office or affected individuals.
Importantly, policyholders should notify their insurer or broker as soon as the policy requires. Do not appoint forensic firms, pay a ransom, negotiate with attackers or promise compensation to customers without checking the policy terms and obtaining insurer approval where required. These steps can affect coverage.
Resilience should be tested, not assumed
A cyber strategy that has never been tested is an assumption. For most SMEs, a tabletop exercise is an affordable starting point. Set aside 60 to 90 minutes and work through a realistic scenario: the finance manager’s Microsoft 365 account has been compromised, invoices have been redirected, and employees cannot access shared files. Ask what happens in the first hour, first day and first week.
The exercise should reveal practical weaknesses. Are emergency phone numbers current? Can staff work if email is unavailable? Is there a second person who can approve payroll? Does the business know which customer contracts impose notification deadlines? Are backups actually restorable? Is the cyber policy available outside the affected network?
Leadership should review the findings and assign owners and deadlines. This converts cyber resilience from an abstract concern into a manageable operational improvement programme.
A practical 90-day action plan for UK SMEs
Days 1–30: establish visibility
Create a simple inventory of the systems that keep the business operating: email, finance, payroll, customer relationship management, file storage, e-commerce, production systems and key SaaS suppliers. Identify the data held in each system, the administrator, and the likely impact if it is unavailable for one day or one week.
At the same time, ask the MSP or internal IT team for clear confirmation of MFA coverage, backup arrangements, patching performance and privileged-account controls. Put the results in writing.
Days 31–60: close high-impact gaps
Prioritise controls that prevent common, expensive events. Enforce phishing-resistant MFA where feasible, particularly for administrators and finance users. Remove unused accounts. Separate administrative accounts from standard daily-use accounts. Introduce a call-back verification process for any request to change supplier bank details. Ensure backups are monitored and restoration-tested.
Days 61–90: align insurance and response planning
Review the cyber insurance policy with a broker who understands the business. Check the business-interruption waiting period, sub-limits, exclusions, territorial scope, dependent-business interruption cover and the claims-notification process. Consider whether the selected limit reflects the likely cost of downtime, expert response, legal advice, customer notification and lost revenue—not simply the value of the company’s IT equipment.
Then run a tabletop exercise and make the resulting response plan accessible offline. Repeat this at least annually and after major changes, such as adopting a new cloud platform, acquiring another business or changing the MSP.
What this means for directors and owners
The underlying lesson from the focus on resilience and leadership engagement is that cyber security should be discussed in the same disciplined way as cash flow, health and safety, supplier concentration and business continuity. Owners and directors do not need to inspect firewall logs. They should ask focused questions: What would stop us trading? Which controls are not fully implemented? When was recovery last tested? What is our maximum tolerable downtime? What does our insurance actually require us to do?
For UK SMEs, that level of oversight can reduce losses, strengthen an insurance application and make a stressful incident more controllable. The aim is not perfect security. It is a business that can make informed decisions, limit damage and recover with confidence.
FAQ
Does cyber insurance cover every cyber attack?
No. Cover depends on the policy wording, limits, exclusions, endorsements and compliance with policy conditions. Common areas to check include ransomware, social engineering or funds-transfer fraud, business interruption, cloud-service outages, regulatory defence costs and claims-notification requirements. Read the policy carefully and seek broker advice before an incident occurs.
Is multi-factor authentication necessary for cyber insurance?
MFA is widely expected by insurers, especially for email, remote access, cloud applications, administrator accounts and payment-related systems. Requirements vary by insurer and policy, but incomplete MFA can lead to higher premiums, restricted terms or difficulties if a policy condition has not been met. Confirm exactly which accounts and systems must use it.
What should a small business do first after discovering a cyber incident?
Contain the issue safely, preserve evidence, contact the insurer or broker according to the policy, and engage approved response providers where required. Do not rush to delete files, reset every system or negotiate with an attacker without professional guidance. Obtain legal advice where personal data may be involved, as UK GDPR notification duties may apply.
How often should SME leaders review cyber risk?
A formal review should take place at least annually, with additional reviews after major technology, supplier or business changes. Short quarterly updates are sensible for many SMEs. The review should cover key risks, control gaps, incidents or near misses, backup testing, supplier exposure and cyber-insurance adequacy.
Fuente: Crowell & Moring LLP — Wed, 29 Oct 2025 07:00:00 GMT