Articles - How to manage cyber risk as a strategic imperative



If a ransomware event shuts down a critical system, your board will focus on operations, revenue and recovery long before it discusses the technical vulnerability that led to the incident. Which operations and supplier relationships can continue? Which customers will feel the impact and what will this do to revenues? What will it take to recover, should you pay the ransom and how much will the business interruption cost otherwise?

By Adrian Ruiz, Head of FINEX GB Cyber & TMT at WTW

These kinds of questions were at the heart of the agenda at a recent Willis cyber risk event, which brought together cyber risk and insurance specialists, legal professionals and cybersecurity experts to explore cyber risk management as a strategic imperative.

In this, the first of a series of articles based on insight from the event, we look at what recent incidents, the influence of AI and claims experience tell your business about better resilience and stronger recovery.

Why does cyber risk now demand board-level business leadership?
Cyber incidents can quickly create operational disruption and financial loss, putting the issue alongside more traditional board-level concerns like liquidity and regulatory scrutiny.

Should your systems go down, your organisation will want to know it can keep your customers informed, restore critical activity, manage suppliers, protect cash flow and make fast decisions with incomplete information. That means finance, legal, operations, risk management and executive leadership all need to understand what a cyber event would mean for the business to better prioritize investments in cyber resilience and how it will recover should an incident hit.

Our recent Cyber in Focus report showed ransomware incidents are disrupting organisations for an average of 25 days, with business interruption often driving a significant share of losses. The 2025 Jaguar Land Rover cyber attack, for example, lasted weeks, reaching UK factories, overseas operations, suppliers, business partners and local communities.

Without the right preparation supported at the highest levels, your teams may struggle to sustain manual workarounds and may uncover dependencies and insurance gaps they haven’t fully mapped.

How is AI changing your organisation’s cyber risk profile?
AI may not be creating a separate cyber risk category today, but it is making familiar attack routes faster, more convincing and harder for your teams to contain.

Willis cyber specialists have seen attackers use AI to enhance impersonation, social engineering, credential misuse and deepfakes, making attacks easier to launch and harder to spot. One reported agentic AI-powered attack showed malicious actors using AI to identify vulnerabilities and exploit them with very little human input.

How should your cyber risk strategy address AI-enabled threats?
Your cyber strategy should strengthen the fundamentals instead of rebuilding strategy around each new threat label. Strong authentication, identity security, approval controls, employee awareness and clear escalation routes can help your teams reduce risks around the people and processes attackers are targeting every day.

Every organisation needs disciplined cyber risk governance, tested response plans and clear recovery priorities. It also needs robust vendor management and supplier backups with a detailed understanding of which providers support critical activities, what your teams would do if those providers became unavailable and how long your business could keep operating without them.

How can cyber insurance improve resilience?
Willis’ Cyber in Focus report showed cyber insurance is responding to claims, with more than 95% of the average data breach loss and 90% of the average first-party loss covered.

Cyber insurance also has a role in helping your organisation quantify cyber risk and connecting your specific exposures to the operational disruptions and financial losses your board needs to plan for above all others.

Your organisation can get the most value from cover by using cyber risk quantification to set the appropriate limits and structure your policy around your specific operating exposures. Calling on insurers and brokers to align wordings, decide on approved vendors and refine incident response processes before an event hits will also help the business maximise insurance value alongside its resilience and recovery capabilities.

Discover more practical perspectives on maximising value from cyber insurance. Access Willis’ Cyber in Focus 2026 report.

Back to Index


Similar News to this Story

How to manage cyber risk as a strategic imperative
If a ransomware event shuts down a critical system, your board will focus on operations, revenue and recovery long before it discusses the technical
Soft markets, AI and next steps for London Market pricing
The twin impacts of softening markets and AI mean that London Market pricing teams will need to evolve their approach rapidly over the coming years.
Flood risk in changing climate: What risk managers must know
Flood risks are not restricted to those places labelled as flood zones. Neil Gunn and Hayley Fowler look at why flooding can occur well beyond mapped

Site Search

Exact   Any  

Latest Actuarial Jobs

Actuarial Login

Email
Password
 Jobseeker    Client
Reminder Logon

APA Sponsors

Actuarial Jobs & News Feeds

Jobs RSS News RSS

WikiActuary

Be the first to contribute to our definitive actuarial reference forum. Built by actuaries for actuaries.