Skip to content
Cyber risk is changing: Is your business ready?

Cyber risk is changing: Is your business ready?

Greaterbirminghamchambers • October 7, 2026

If your systems go down, customer data is exposed, money is stolen or your team cannot work, the impact can be immediate.

Phishing, ransomware, data breaches and fraud remain common threats. AI is now adding to that picture by making convincing phishing messages, fake voices, deepfakes and other forms of social engineering easier to create and scale.

At the same time, businesses are using AI more widely for customer service, recruitment, marketing, analysis and everyday administration. That can bring real benefits, but it can also create new risks.

Your staff may enter sensitive information into third party tools, rely on inaccurate outputs, or use systems without fully understanding how data is handled.

A simple way to think cyber resilience is through three areas, Infrastructure, Education and Insurance.

1 Infrastructure is the technology and processes you put in place to protect your business. That includes multi-factor authentication, secure backups, software updates, access controls and clear processes for managing incidents.

2 Education is your people. Your staff need to recognise suspicious activity, understand how to handle information safely and know what they should and should not put into AI tools. Technology can only take you so far if the people using it do not understand the risks.

3 Insurance is the final part of the picture. It does not replace good cyber security, but it can help your business respond when prevention is not enough. Depending on the policy, cyber insurance can provide support with forensic investigation, legal costs, customer notification, system recovery and business interruption.

AI is also changing the legal landscape. The EU AI Act became generally applicable on 2 August 2026. Although it is EU legislation, UK businesses should not automatically assume it does not apply to them. The Act has extra territorial reach and can apply where a business places AI systems on the EU market, operates within the EU, or where the output of an AI system is used in the EU.

The rules take a risk-based approach. Some requirements already apply, while the main obligations for AI systems classified as high risk under Annex III apply from 2 December 2027. Requirements for high-risk systems linked to certain regulated products apply from 2 August 2028.

Whether or not the Act applies to your business, good AI governance still makes sense.

A useful check is TRUST, Transparency, Responsibility, Understanding, Security and Testing.

Do you know what AI your business is using and are your customers aware? Who is responsible for it? What information is being entered and how does it use that data? Do your people understand the risks? Are appropriate security measures in place? Are outputs and systems being tested and checked?

You cannot remove every cyber risk. You can make your business harder to attack, better prepared when something happens and quicker to recover. Strong infrastructure, informed people, sensible AI governance and appropriate insurance all have a part to play.

These themes will be explored further in our upcoming webinar, Navigating Tomorrow's Cyber Risks Today , taking place at midday on 13 October, where our industry-led panel will emerging cyber risks, the growing influence of AI, and practical steps businesses can take to strengthen their resilience.

Every business is different, and understanding whether you have the right measures in place is an important step towards building resilience. Does your business have all the right pieces in place?

If you'd like to Cyber Liability a nd Cyber Crime Insurance, speak to the team at Adler Fairways . We're here to help you navigate the options and make informed decisions your cyber risk management strategy.

Extracted Entities