Lockton’s SME cyber message: prevention and insurance are not substitutes
Lockton’s March 2025 guidance on cybersecurity best practices for small and medium-sized enterprises is timely because UK SMEs are increasingly exposed to the same criminal tactics used against larger organisations, but rarely have the same in-house security resources. A fraudulent Microsoft 365 login page, a compromised supplier mailbox or an unpatched remote-access tool can be enough to stop invoicing, payroll, customer service and stock ordering.
The important takeaway for a UK business owner is not simply that cybersecurity matters. Most directors already know that. The practical issue is whether the business can identify its critical systems, prevent routine attacks and respond coherently during the first few hours after an incident. Cyber insurance can fund specialist support and reduce the financial shock, but it is not a replacement for the controls that make an attack less likely and less damaging.
For SMEs exploring cyber insurance, Lockton’s focus on good practice also reflects a market reality: insurers increasingly assess basic cyber hygiene before offering broad cover, competitive terms or lower excesses. Security improvements can therefore protect operations and strengthen the firm’s insurance position at the same time.
Why SMEs are attractive targets
Cybercriminals do not need to target a household-name company to make money. Smaller firms are often attractive because they may rely on one general IT provider, use shared administrator accounts, have limited monitoring and face intense pressure to restore systems quickly. That pressure is valuable to ransomware groups and fraudsters.
A UK SME can also hold data and access that criminals want. Examples include:
- Customer contact details, payment information and identity documents.
- Employee records, bank details and payroll data.
- Commercially sensitive quotations, contracts and intellectual property.
- Credentials for cloud accounting, email, document storage and e-commerce platforms.
- Trusted access to larger clients’ systems or supplier portals.
The loss is not confined to the cost of repairing a laptop or resetting passwords. A successful attack can produce lost trading income, payment-diversion fraud, regulatory obligations, third-party claims, recovery costs and reputational harm. If a manufacturer cannot access production schedules, or a professional services firm loses access to case files before a deadline, the interruption itself may be the largest loss.
The controls that matter most before buying cyber insurance
Make multi-factor authentication non-negotiable
Multi-factor authentication (MFA) is one of the most effective protections against account takeover. It should be enabled for email, remote access, cloud file-sharing, finance applications and administrator accounts—not merely for a small group of senior staff.
However, an SME should avoid treating MFA as a box-ticking exercise. Attackers may use MFA fatigue prompts, phishing pages that capture session tokens, or social engineering to persuade staff to approve a login. Number matching, phishing-resistant authentication methods where available, conditional access rules and prompt reporting of unexpected sign-in requests provide a stronger defence.
For a business using Microsoft 365 or Google Workspace, the first audit should establish whether every user, particularly directors and finance staff, is genuinely enrolled and whether legacy authentication remains enabled.
Patch systems and remove unsupported technology
Unpatched software remains a common route into business networks. The priority is not only staff laptops. SMEs should include firewalls, routers, virtual private network appliances, remote desktop services, servers, point-of-sale devices and line-of-business applications in a patching register.
A sensible approach is to assign an owner, define how quickly critical patches must be applied and record exceptions. Unsupported operating systems or applications require a migration plan, segmentation or compensating controls. Saying that an old machine is “not connected to the internet” is not enough if it can be reached from another compromised device on the network.
Protect payments from business email compromise
Business email compromise is especially damaging because it exploits normal commercial processes rather than necessarily deploying malware. A fraudster may impersonate a director, supplier or conveyancer and request an urgent bank-account change or payment.
The vital control is independent verification. Any change to supplier bank details should be confirmed using a known telephone number from the organisation’s records, not a number supplied in the email. Dual approval for material payments, clear escalation routes and warnings about unusual urgency can prevent a six-figure loss that technology alone may not stop.
Keep tested, separate backups
Backups are essential, but only if they can be restored. Businesses should keep copies separate from the main network and cloud environment, protect backup administration with MFA and test restoration against realistic timeframes.
A daily backup is of little operational value if restoring it takes two weeks and the business cannot survive two days without its systems. Directors should ask their IT provider: which systems are backed up, how often, where copies are held, who can delete them and how long a full recovery would take.
Limit privileged access and prepare staff
Every user should have only the access needed for their role. Administrator rights should be limited, separate admin accounts should be used for privileged tasks, and accounts must be removed quickly when employees or contractors leave.
Training also needs to be specific. A generic annual awareness module is less useful than short, repeated training based on the scams staff actually receive: invoice fraud, shared-document lures, fake parcel notifications, password-reset requests and impersonated executives. Simulated phishing can help, provided it is used to improve reporting rather than embarrass employees.
What cyber insurance can add after an attack
Cyber insurance is most valuable when it is viewed as an incident-response resource, not as a promise that every cyber loss will automatically be paid. Policies differ substantially, so UK SMEs should examine the wording, endorsements, exclusions, excesses and sub-limits with a broker or suitably qualified adviser.
Depending on the policy, cover may help with forensic investigation, legal advice, data-protection support, notification costs, public relations, restoration expenses, cyber extortion, business interruption and liability claims. Some policies also provide a 24-hour incident-response helpline, giving a small business access to specialists it could not retain permanently.
But there are limits. A policy may impose conditions around security controls, exclude known circumstances, restrict cover for particular payment fraud scenarios or calculate business interruption in a way that differs from the owner’s expectations. Social engineering and funds-transfer fraud should be checked carefully; they may be covered differently from ransomware or data restoration.
The key lesson is to align insurance with the real business model. An online retailer should focus on e-commerce outage, payment data and peak-season trading. A solicitor, accountant or recruitment agency should consider confidential data, email compromise and professional client obligations. A manufacturer may need particular attention on operational technology, supplier dependency and the cost of a production halt.
A practical 30-day action plan for UK SME directors
Week one: map the essentials
List the systems without which the business cannot trade for 24 hours: email, accounting, telephony, customer relationship management, e-commerce, payroll and production tools. Record who owns each system, where data is stored and which supplier provides support.
Week two: close obvious access gaps
Enforce MFA, remove dormant accounts, review administrator privileges and disable any unnecessary remote access. Ensure leavers’ accounts and devices are covered by a formal offboarding process.
Week three: test resilience
Review patching status and backup reports. Restore a sample of important files or a non-production system. Run a short payment-fraud exercise with finance staff, including how supplier bank changes are validated.
Week four: build the response and insurance file
Create a one-page incident plan stating who contacts the IT provider, insurer, bank, solicitor and affected customers. Keep policy details and insurer emergency contact numbers offline as well as digitally. When requesting cyber insurance quotations, provide accurate information about controls; inaccurate declarations can create serious problems at claim stage.
The strategic implication for UK SMEs
Lockton’s guidance should encourage owners to move cybersecurity from an IT-only task to a management responsibility. The director who approves a payment process, decides whether backups are tested and signs an insurance proposal is making cyber-risk decisions, whether or not they use that label.
The strongest position is not “we have cyber insurance” or “our IT company handles it”. It is a documented, rehearsed combination of technical controls, staff processes, supplier oversight and insurance that responds to the risks the business actually faces. That approach is more likely to preserve cash flow, customer confidence and insurability when an incident occurs.
FAQ
Does a UK SME need cyber insurance if it already uses antivirus software?
Yes, it may still need it. Antivirus is one layer of defence, but it cannot guarantee protection against invoice fraud, compromised cloud accounts, human error, data breaches or business interruption. Cyber insurance may provide access to response specialists and cover selected financial consequences, subject to the policy terms.
Insurers commonly ask about MFA, backups, patching, endpoint protection, remote access, staff training, incident history, revenue, sensitive data and reliance on key IT suppliers. Requirements vary by insurer and policy, so answers should be verified with the IT provider rather than guessed.
Is cyber extortion always covered by cyber insurance?
No. Cyber extortion cover can be subject to sub-limits, conditions and exclusions. The policy should be checked for the costs it covers, whether insurer consent is needed before expenditure and how sanctions laws may affect a response.
What should an SME do in the first hour of a suspected cyber incident?
Contain the issue without destroying evidence: disconnect affected devices where appropriate, do not wipe systems, preserve suspicious emails, notify the IT provider and contact the insurer’s incident-response line if cover is in place. If payment fraud is suspected, contact the bank immediately using a trusted number. Follow the incident plan and obtain legal or specialist advice before making broad notifications.
Fuente: Lockton — Thu, 13 Mar 2025 07:00:00 GMT