Directors Warned That Cyber and Physical Security Gaps Could Leave Businesses Exposed

ESSEX, UK. September 14th, 2026: UK company directors are being encouraged to take a more proactive approach to identifying weaknesses in their cyber and physical security, as criminals continue to develop new ways of exploiting vulnerabilities across technology, people and premises.

The Government’s Cyber Security Breaches Survey 2025/26 found that 43% of participating UK businesses had experienced a cyber breach or attack during the previous 12 months, equivalent to around 612,000 businesses.

Despite this, only 41% of small businesses had conducted a cyber-security risk assessment. Just 52% had a formal cyber-security policy, while 44% had a business-continuity plan that addressed cyber risk.

Under the Companies Act 2006, company directors have a duty to exercise reasonable care, skill and diligence when managing business risks, including cyber security.

The importance of effective protection has been highlighted by a recent incident in which a small UK power plant was forced to shut down following a cyber-attack. Although the Government confirmed that the UK’s wider energy system was not placed at risk, the Department for Energy Security and Net Zero subsequently contacted power companies to highlight the ongoing threat posed by cyber-attacks.

Steve Cross, Group Technical Director at PIB Insurance Brokers, said: “Over the last few years PIB have found that many organisations simply don’t know what ‘good’ looks like when it comes to fundamental cyber-security and controls.

“At the same time, small and medium-sized enterprises continue to emerge as the hidden victims of cyber-crime, often targeted by opportunistic hackers but ill-prepared to defend against or recover from attacks.”

The threat landscape is continuing to evolve, with cyber criminals using increasingly sophisticated tools and methods to overcome existing defences. Stolen information has also become a valuable commodity within a wider criminal economy, supporting activities ranging from online fraud to ransomware. Criminal organisations can buy and sell personal data and access to compromised networks through underground online marketplaces.

Emerging technologies such as artificial intelligence are also expected to increase the capabilities available to cyber criminals. Generative AI is already being used by criminals, including through AI-powered chatbots capable of producing increasingly convincing phishing messages and social engineering scams.

Peter%20Collins%20%20ls

Mark McSweeney, Director of Security Operations at risk and security specialists R5 Global, said: “We provide intelligence-led physical penetration testing that assesses how security measures perform against real-world threats, not just compliance standards. By replicating attacker tactics, techniques and behaviours, we identify vulnerabilities before they can be exploited and give organisations practical recommendations to reduce risk.”

R5 Global’s services can include intelligence-led physical penetration testing alongside broader response testing. This can examine physical security arrangements, the actions of security personnel and how the wider organisation identifies, escalates, communicates and coordinates during a realistic incident. The objective is to uncover weaknesses throughout the response process before they are exposed during an actual security event.

Cyber insurance, D&O insurance and commercial property policies are designed to address different areas of risk and each can contain specific conditions and requirements. Businesses need to understand their policies and meet the relevant requirements to ensure protection remains available when it is needed.

Leading insurance agency Bespoke Risk Solutions is encouraging company directors to review their existing insurance arrangements and establish exactly what their policies cover.

Peter Collins, Director of Bespoke Risk Solutions, said: “On several occasions, we have carried out audits and found that directors had not read the small print in their policy wordings. In some cases, that left the company’s financial future at risk because there was no effective insurance protection.

“Insurance is important and should form part of every company’s disaster planning. If a major cyber incident, theft or security failure occurs, directors may need to explain what protections were reviewed, what vulnerabilities were identified and what action was taken. Using the excuse of ‘We assumed someone else had it covered’ may be a difficult answer for shareholders to accept.”

More Stories

Related Articles