Boards may often express confidence in their cyber readiness but recent high-profile incidents show how fragile that assurance can be under pressure. According to Willis’s Cyber in Focus 2025 report, based on 4,650 cyber claims, losses tend to be longer, broader and costlier than many leaders expect.
The report identifies four areas where boards regularly misjudge risk. On revenue losses arising from downtime, while many boards assume ransomware outages last days, the claims data shows a median outage of 24 days, with an average ransomware loss of around £2.2m.
Further, boards often treat vendor exposure as secondary – yet around half of breaches originate via suppliers, and weak audit, liability or notification clauses can escalate costs.
When it comes to overall resilience, most boards claim to have cyber response plans but only 68% report having tested them in the past year.
Finally on regulation, rising accountability under evolving frameworks, including the EU AI Act, new US state rules and forthcoming critical-infrastructure laws in Hong Kong – is upping expectations on governance, incident response and disclosure.
Peter Foster, chairman, global FINEX cyber and cyber risk solutions at Willis, said: “Boards often believe cyber risk is contained, but the data proves otherwise. Untested plans, weak vendor contracts, and unclear wordings are exactly where firms lose money, reputation, and regulatory standing. The cost of untested resilience shows up in lost revenue, shareholder disputes, and fines and it’s rising faster than boards expect. Ransomware simulations, vendor analytics, AI governance, and policy optimisation can help bridge the gap between perception and reality.”
The report also cites a single largest claim reaching around £270m. Its authors argue that while boards often highlight AI’s upside, claims already show use of deepfakes, synthetic IDs and generative malware in fraud. Other findings include that publicly-held companies account for 36% of total losses, despite having fewer incidents overall.
Printed Copy:
Would you also like to receive CIR Magazine in print?
Data Use:
We will also send you our free daily email newsletters and other relevant communications, which you can opt out of at any time. Thank you.
YOU MIGHT ALSO LIKE