
August 29, 2025
Cybercrime continues to dominate the headlines in 2025. High-profile attacks have disrupted operations, exposed sensitive data, and caused significant financial losses for some of the UK’s best-known brands. It might seem like these incidents only affect large corporations, but that’s not the case.
Smaller businesses are now a prime target for cybercriminals. Research from the Association of British Insurers (ABI) reveals a significant cyber protection gap among smaller firms.
In this blog, we’re taking a look at recent cyberattacks, what they mean for smaller operations, and how cyber insurance fits into the bigger picture of protecting your business. We’ll also round up some of the key cyber risks we’ve covered in previous blogs, and share some practical ways to stay one step ahead.
Big names, big losses – but the lessons apply to all of us
2025 has seen a spike in cyber-attacks on well-known retailers, many of them caused by supply chain vulnerabilities, system weaknesses, or human error.
Marks & Spencer suffered a major ransomware attack over Easter, disrupting online orders, in-store payments, and customer services. Some online services remain offline. The incident wiped £300 million off the company’s market value and has been described as the most financially damaging cyber-attack ever faced by a UK retailer.
The Co-operative Group was also hit in April. Member names and contact details were stolen, leading to empty shelves and operational disruption.
Harrods took internal systems offline after an attempted breach in May. Adidas was also affected this year via a third-party customer service provider, with attackers gaining access to customer names and contact information. And H&M experienced a suspected attack in June, when an IT outage took down payment systems across the UK.
These incidents may not have caused long-term damage to every company involved. But they do highlight just how quickly things can go wrong.
Why it matters to smaller businesses
According to research from the Association of British Insurers (ABI), half of all UK businesses suffered a cyber-attack in 2024. And with smaller firms making up the vast majority of UK businesses, it’s clear no one is off limits.
The problem? Many still believe they’re “too small to be targeted” – but this is dangerous thinking. Cybercriminals often see smaller operations as easy targets, especially when there’s no insurance, no plan, and no dedicated IT support in place.
And when things go wrong, it’s not just about lost data or downtime. Your reputation is on the line. If customers can’t access your services, or their data is compromised, it can take years to rebuild trust, if the business survives at all.
That’s why it’s vital to understand what cyber insurance actually covers, and how it can support you if the worst happens.
The Cyber threats that haven’t gone away
Over the past couple of years, we’ve explored many of the key cyber risks facing businesses today, and the spike in 2025 attacks makes these topics worth revisiting.
Social engineering
From phishing emails to fake payment requests, social engineering scams are becoming more sophisticated by the day. These types of attacks don’t target your systems: they target your people. And as we saw with M&S, human error in the supply chain can have major consequences.
👉 Read our blog on social engineering
Data breach response
Whether it’s exposed customer or supplier data to internal records, knowing how to respond to a breach is vital. From legal obligations to PR and reputation management, the first few hours matter and having a plan makes all the difference.
👉 Read about why data breach response planning is essential
Ransomware attacks
These are still one of the most financially damaging threats and one of the most common. In 2025, we’ve seen how disruptive ransomware can be, halting services, locking systems and forcing businesses to choose between massive losses and criminal demands.
👉 Read our ransomware tips and insurance insights
Cyber awareness
The basics still matter. Strong passwords, employee training and regular software updates can stop most attacks before they happen. But awareness needs to stay current. Cyber threats evolve quickly, and so must your defences.
👉 Check out our guide to cyber awareness
Sector-specific risks
Some industries face added challenges, especially when professional liability is involved. In 2022, we highlighted how cyber cover was no longer included in many legal sector professional indemnity policies, prompting firms to seek standalone solutions. A reminder that relying on bundled cover isn’t always enough.
👉 Read our warning for law firms
Are you still overlooking cyber insurance?
It’s easy to assume that standard business or professional indemnity policies will cover the fallout from a cyberattack. Often, they don’t. Or if they do, it’s minimal.
A standalone cyber policy offers far more than compensation. It can give you access to expert breach response, legal guidance, IT forensics, and PR support: all critical in the hours and days after an incident.
The bigger picture: cyber as operational resilience
Cyber insurance is just one part of protecting your business. It works best when combined with strong cyber hygiene, and a clear understanding of the risks you face.
Good habits (like employee training, password management and regular software updates) can prevent the majority of attacks. But if something does go wrong, having the right cover in place can make all the difference to how quickly you recover and how much damage is done.
Time for a cyber health check? How Robert Gerrard can help.
Whether you already have cyber insurance in place and need a review, or are exploring it for the first time, now’s the time to take stock.
At Robert Gerrard, we’re here to support you. Our role goes beyond broking: we’re your risk advisers. That means:
- Helping you assess your cyber risks
- Discussing practical steps to reduce exposure
- Reviewing your current cover and identifying any gaps
- Advising on whether a standalone cyber policy might be worthwhile
Ready to arm yourself with the protection you need for the growing threat of cyberattacks? Get in touch with Team RG today.
Share This Story, Choose Your Platform!
Cybercrime continues to dominate the headlines in 2025. High-profile attacks have disrupted operations, exposed sensitive data, and caused significant financial losses for some of the UK’s best-known brands. It might seem like these incidents only affect large corporations, but that’s not the case.
Smaller businesses are now a prime target for cybercriminals. Research from the Association of British Insurers (ABI) reveals a significant cyber protection gap among smaller firms.
In this blog, we’re taking a look at recent cyberattacks, what they mean for smaller operations, and how cyber insurance fits into the bigger picture of protecting your business. We’ll also round up some of the key cyber risks we’ve covered in previous blogs, and share some practical ways to stay one step ahead.
Big names, big losses – but the lessons apply to all of us
2025 has seen a spike in cyber-attacks on well-known retailers, many of them caused by supply chain vulnerabilities, system weaknesses, or human error.
Marks & Spencer suffered a major ransomware attack over Easter, disrupting online orders, in-store payments, and customer services. Some online services remain offline. The incident wiped £300 million off the company’s market value and has been described as the most financially damaging cyber-attack ever faced by a UK retailer.
The Co-operative Group was also hit in April. Member names and contact details were stolen, leading to empty shelves and operational disruption.
Harrods took internal systems offline after an attempted breach in May. Adidas was also affected this year via a third-party customer service provider, with attackers gaining access to customer names and contact information. And H&M experienced a suspected attack in June, when an IT outage took down payment systems across the UK.
These incidents may not have caused long-term damage to every company involved. But they do highlight just how quickly things can go wrong.
Why it matters to smaller businesses
According to research from the Association of British Insurers (ABI), half of all UK businesses suffered a cyber-attack in 2024. And with smaller firms making up the vast majority of UK businesses, it’s clear no one is off limits.
The problem? Many still believe they’re “too small to be targeted” – but this is dangerous thinking. Cybercriminals often see smaller operations as easy targets, especially when there’s no insurance, no plan, and no dedicated IT support in place.
And when things go wrong, it’s not just about lost data or downtime. Your reputation is on the line. If customers can’t access your services, or their data is compromised, it can take years to rebuild trust, if the business survives at all.
That’s why it’s vital to understand what cyber insurance actually covers, and how it can support you if the worst happens.
The Cyber threats that haven’t gone away
Over the past couple of years, we’ve explored many of the key cyber risks facing businesses today, and the spike in 2025 attacks makes these topics worth revisiting.
Social engineering
From phishing emails to fake payment requests, social engineering scams are becoming more sophisticated by the day. These types of attacks don’t target your systems: they target your people. And as we saw with M&S, human error in the supply chain can have major consequences.
👉 Read our blog on social engineering
Data breach response
Whether it’s exposed customer or supplier data to internal records, knowing how to respond to a breach is vital. From legal obligations to PR and reputation management, the first few hours matter and having a plan makes all the difference.
👉 Read about why data breach response planning is essential
Ransomware attacks
These are still one of the most financially damaging threats and one of the most common. In 2025, we’ve seen how disruptive ransomware can be, halting services, locking systems and forcing businesses to choose between massive losses and criminal demands.
👉 Read our ransomware tips and insurance insights
Cyber awareness
The basics still matter. Strong passwords, employee training and regular software updates can stop most attacks before they happen. But awareness needs to stay current. Cyber threats evolve quickly, and so must your defences.
👉 Check out our guide to cyber awareness
Sector-specific risks
Some industries face added challenges, especially when professional liability is involved. In 2022, we highlighted how cyber cover was no longer included in many legal sector professional indemnity policies, prompting firms to seek standalone solutions. A reminder that relying on bundled cover isn’t always enough.
👉 Read our warning for law firms
Are you still overlooking cyber insurance?
It’s easy to assume that standard business or professional indemnity policies will cover the fallout from a cyberattack. Often, they don’t. Or if they do, it’s minimal.
A standalone cyber policy offers far more than compensation. It can give you access to expert breach response, legal guidance, IT forensics, and PR support: all critical in the hours and days after an incident.
The bigger picture: cyber as operational resilience
Cyber insurance is just one part of protecting your business. It works best when combined with strong cyber hygiene, and a clear understanding of the risks you face.
Good habits (like employee training, password management and regular software updates) can prevent the majority of attacks. But if something does go wrong, having the right cover in place can make all the difference to how quickly you recover and how much damage is done.
Time for a cyber health check? How Robert Gerrard can help.
Whether you already have cyber insurance in place and need a review, or are exploring it for the first time, now’s the time to take stock.
At Robert Gerrard, we’re here to support you. Our role goes beyond broking: we’re your risk advisers. That means:
- Helping you assess your cyber risks
- Discussing practical steps to reduce exposure
- Reviewing your current cover and identifying any gaps
- Advising on whether a standalone cyber policy might be worthwhile
Ready to arm yourself with the protection you need for the growing threat of cyberattacks? Get in touch with Team RG today.

