5 Steps to take after a Cyber Attack

February 16, 2026

a screen with the text cyber security

Cyber Attacks Are Increasing... According to the UK Government’s Cyber Security Breaches Survey, around 43% of UK businesses reported experiencing a cyber security breach or attack in the past 12 months. Would you know what to do if it happened to you? Having a clear incident response plan for a cyber attack is essential.

Common Cyber Threats

Knowing what to look out for helps you act quickly. Common threats include:

  • Phishing Emails
    Fake emails trick staff into clicking harmful links or giving away information. These are behind 90% of attacks.
  • Ransomware
    Criminals lock or steal your data and demand payment. Some also leak stolen data.
  • Business Email Compromise (BEC)
    Hackers use fake or hacked emails to trick finance teams into sending money.
  • Supply Chain Attacks
    Attackers get in through suppliers or contractors.
  • Insider Threats
    These can be accidental (e.g. clicking a bad link) or intentional.

How to Prevent Cyber Attacks

You can’t stop every attack, but these steps make you a harder target:

  • Limit admin access to only those who need it.
  • Back up data regularly and keep one copy offline.
  • Train staff to spot suspicious emails and behaviour.
  • Keep software updated to fix security gaps.
  • Use multi-factor authentication (MFA) for extra protection.
  • Use strong passphrases made of random words.

5 Key Steps to Handle a Cyber Attack

Based on the NIST Cybersecurity Framework, here’s what to do:

1. Identify

  • Know your key systems, data, and suppliers.
  • Have a response plan and assign roles.
  • Keep a log of actions taken.
  • Contact your insurer for support.

2. Protect

  • Use strong passphrases and MFA.
  • Update software and patch systems.
  • Keep tested backups, including one offline.
  • Train staff to spot threats.

3. Detect

  • Watch for signs like renamed files or locked accounts.
  • Turn on logging in email, firewall, and VPN tools.
  • Encourage staff to report anything unusual.

4. Respond

  • Declare the incident and appoint a lead.
  • Isolate affected devices (unplug from Wi-Fi, don’t power off).
  • Contact IT support or an approved response provider.
  • Report to NCSC, Action Fraud, and the ICO if personal data is involved.
  • Communicate clearly with staff, customers, and suppliers.

5. Recover

  • Rebuild from clean systems and restore verified backups.
  • Reset passwords and enforce MFA.
  • Monitor for reinfection.
  • Review the incident and update your plan.
  • Consider Cyber Essentials certification.

Need Help Protecting Your Business?

The best time to prepare is before an attack happens. Whether it’s ransomware, phishing, or a supply chain breach, planning ahead makes all the difference.

Ae Insurance Brokers can help you:

  • Build a tailored incident response plan
  • Run penetration testing to find hidden risks
  • Perform regular vulnerability scans
  • Find an insurance solution that is tailored to your needs

We’ve been busier than usual here at AE Insurance Brokers lately. As part of our ongoing commitment to staying current and effective, we recently underwent a brand refresh. While it looked like a cosmetic change - a new logo, a fresh colour palette and font - the process was actually a deep dive into who we are, how we serve our clients, and where the industry is heading.

And while we were looking in the mirror, something struck us: many businesses don’t look in theirs often enough.

When we talk to UK business owners one pattern emerges consistently. Companies grow, pivot, hire, launch new products, or expand into new territories. Yet their insurance policies often remain frozen in time, reflecting the version of the business that existed twelve months ago - or worse, five years ago.

Insurance is often treated as a compliance checkbox: a bill that needs paying, a certificate that needs sending. But if your business has changed, your risk profile has changed too, and when your policy doesn’t match your reality, you’re likely overpaying and potentially leaving dangerous gaps in your protection.

Related Posts

September 8, 2026

Growing Up: Why Your Insurance Needs to Evolve With Your Business

We’ve been busier than usual here at AE Insurance Brokers lately. As […]

August 19, 2026

What the Renters’ Rights Act Means for Your Portfolio

The landscape of the private rented sector (PRS) has shifted dramatically. Following […]

newspaper headline saying cyber attack

June 18, 2026

Commercial Cyber & Cyber Crime Insurance: A Critical Protection for UK Businesses

Cybercrime is no longer just an IT issue – it is one […]

0 Comments