There is much chatter right now about cyber attacks and the impact of UK businesses could be significant;
Cyber insurance alone will not protect UK businesses from the full financial and operational consequences of a cyberattack, according to research commissioned by Cohesity, the leader in AI-powered data security.
The study, conducted by OnePoll among 100 UK CEOs of large enterprises, found that only 22% believe their cyber-insurance policy would cover both the additional costs and lost revenue resulting from a cyberattack.
Research identifies gaps in cyber insurance cover
-
One-third (33%) believe their policy would only cover additional costs
-
One third (33%) expect it to make up lost revenue only
-
One in ten (10%) do not expect it to cover both additional costs and lost revenue fully
This matters because the research found that CEOs estimate that a cyberattack could cut their organisation’s revenue by 15.17% on average. But this figure is only an estimate for many, as one in five (21%) say their organisation has never undertaken business-impact modelling to understand the potential cost of an attack.
Without this analysis, organisations may not know the scale of their potential insurance shortfall, which services and systems are most critical to revenue and operations, or what must be securely recovered first following an attack.
The challenge is compounded by the range of consequences businesses expect to face. CEOs identified their top five risks following a cyberattack as:
-
Data breach: 49%
-
Brand and reputational damage: 38%
-
High recovery costs: 36%
-
Revenue loss: 34%
-
Production downtime: 30%
These findings show that the fallout from a cyberattack cannot be measured solely in terms of ransom payments or threat remediation. An attack can affect data integrity, revenue, production, customer confidence, employee productivity and corporate reputation, consequences that insurance may only cover partially, if at all.
“Cyber insurance should not be treated as a get-out-of-jail-free card when it comes to cyber breaches. As the threat landscape becomes increasingly complex, organisations cannot treat an insurance policy as a substitute for resilience,” said Fraser Hutchison, VP UKI at Cohesity. “Organisations need to understand exactly what their policies will and will not cover, model the potential impact of different attack scenarios and prepare for losses that may fall outside their policies.”
From insurance coverage to recovery capability – the four main challenges
The research highlights the main challenges organisations must address to turn cyber recovery from a process into a proven business capability:
-
Understand the full financial exposure
Organisations must model the direct and indirect consequences of different attack scenarios, including revenue loss, downtime, remediation, customer attrition, reputational damage and lost productivity. -
Understand what insurance will, and will not, cover
Business leaders need clarity on policy limits, exclusions and conditions, as well as the losses the organisation may need to absorb itself. -
Define what must be restored first
Rather than attempting to recover every system simultaneously, businesses should identify the minimum applications, data and services needed to maintain essential operations, the Minimal Viable Company (MVC) -
Prove critical services can be recovered in a trusted state
Recovery plans must be tested regularly. Organisations need confidence that backup data is protected, that recovery points are clean and that restored systems will not reintroduce the threat.
“Cyber insurance can mitigate some of the financial risk, but the only way to truly bounce back from a cyberattack is by embedding genuine resilience into operations,” added Hutchison. “Organisations must be able to identify the systems and data needed to keep the business operating, assigning clear responsibility for recovery decisions and regularly testing whether critical services can be restored securely.”
Research methodology
The research was carried out by OnePoll between 20th May and 10th June 2026 among CEOs at UK-based companies with 500+ employees.

Be the first to comment