Cyber risk: why prevention has to come before the payout
Sep 18, 2026
Cyber cover, prevention, staff awareness and preparedness each do a very important but different job. The overlap between them keeps a business standing.
This is why cyber risk is no longer just an IT issue. According to the government’s Cyber Security Breaches Survey 2025/2026, 31% of UK businesses now assign responsibility for cyber security at board level, reflecting a growing recognition that cyber risk is a business risk.
Cyber insurance is designed to help businesses recover when an incident occurs. It can support system restoration, regulatory compliance, legal costs and the recovery process following an attack. However, it does not prevent cyber incidents from happening.
That’s where prevention and awareness come in. Good cyber hygiene, including software updates, access controls and secure backups, reduces the likelihood of an attack succeeding. Equally important are employees who can recognise phishing attempts and suspicious requests before damage is done. Most cyber claims now originate from email compromise.
But no system, employee or software is bulletproof, which is why the conversation has moved away from “if” and “when” to “how”. “How will the criminals access my system, and how prepared am I?”. The same government survey suggests that only 25% of businesses have an incident response plan, which means most are ‘making it up as they go along’. They’re not prepared for a cyber event as they still think it won’t happen to them.
Together, awareness, prevention, preparedness and insurance create a more resilient business. Awareness helps people make better decisions, prevention reduces the risk of attack, preparedness means you’re ready for an incident, and insurance helps organisations recover when incidents occur.
Jerome Thong, Head of Technology, Media, Cyber & Sciences at Jensten Insurance Brokers (part of the Jensten Group), says: “Cyber has moved up the agenda. The conversations we’re having now are with boards, not just IT teams, and the question has shifted from ‘are we covered?’ to ‘how quickly could we carry on trading?’ Insurance is the risk transfer piece; it absorbs the financial shock and funds the recovery, but it works best when it sits alongside good prevention and a workforce that knows what to look for. The clients who come through an incident in the best shape are the ones treating all three as one strategy.”
If your business has changed in the last year, whether through new systems, different access permissions or changes to how data is managed, it may be worth reviewing both your cyber risk management strategy and your insurance arrangements.
Speak to your Account Executive about reviewing your cyber risk management strategy, or get in touch.
Source: Cyber Security Breaches Survey 2025/2026, Department for Science, Innovation and Technology (DSIT) and the Home Office, gov.uk.



