Cybersecurity threats: prevention, not cure
The global average cost of a data breach is now reported to be USD 6 million (according to IBM’s Cost of a Data Breach Report 2026). The data also shows the highest volume of incidents are now led by AI deepfake impersonations and AI-enabled malware, with a 56% increase in AI-driven attacks.
As businesses across the world scramble to increase AI adoption, the National Cyber Security Centre warns that while Al will ultimately help improve cyber defence, it currently also accelerates the speed, scale, and sophistication of the threat.
Cybersecurity insurance provides organisations with some comfort against this evolving threat. However, it is not a substitute for preventing the problem. In addition to reputational damage, cybersecurity incidents are expensive, often triggering regulatory obligations (under an increasing range of EU and UK legislation), as well as potential litigation. The UK’s evolving data breach case law exposes organisations to regulatory fines, as well as the risk of substantial class action litigation. There may also be contractual liability towards any counterparty affected by the incident.
This article considers the wider risks posed by cybersecurity and what businesses can do to minimise the rise of internal threats enabled by AI technology.
Cyber risk – the rise of the machine
The expanding use of cloud platforms, outsourced technology services and AI-enabled tools has increased the ways in which people and systems can reach valuable information. While the methods have evolved, the vulnerabilities remain constant: excessive permissions, shared credentials, poor offboarding, and poorly drafted or imbalanced contractual protections. AI can increase the speed and credibility of an attack, but the attack usually succeeds through an existing gap in people, process or technology.
Insurance remains an important part of resilience but cover is normally subject to conditions, exclusions, and notification requirements. It may also do little to repair lost trust and reputation, or to restore inaccessible systems and resolve disputes.
AI-powered fraud
Generative AI has lowered the cost of producing credible fraudulent material. Poor spelling and awkward phrasing are no longer reliable warning signs. Attackers can create polished messages, imitate a supplier’s tone, produce plausible invoices and build lookalike websites with limited technical skill.
The practical lesson is not that every unusual message is generated by AI. It is that verification must move away from visual flags towards checking through trusted channels. A change of bank details, an urgent transfer, a password reset or a request for sensitive data should trigger an independent check, even when the message appears to come from a senior colleague or established supplier.
Businesses seeking to minimise their exposure must ensure they have adequate policies and procedures in place, that employees are aware of these policies, that training can be evidenced, and that the effectiveness of these accountability measures is regularly reviewed. From a litigation perspective, organisations may be able to successfully defend claims if they can show that adequately robust procedures were in place and were implemented effectively.
What is the litigation risk?
Cybersecurity incidents typically lead to two main types of litigation risk: a) service disruption and consequential loss claims from corporate contractual counterparties; and b) data protection or damages claims from individuals suffering harm directly from a data breach.
Corporate supply chain claims
Corporate claimants will normally claim against the supplier or service provider that has ‘caused’ the incident. This is not always easy to identify, particularly where the cause is an employee or contractor acting outside the scope of their role.
Cybersecurity incidents arising from authorised access to systems can be particularly problematic. A frequent scenario is where an IT supplier controls essential passwords and server access during a handover, then delays or refuses to release them. Alternatively, consultants or contractors whose engagement has ended retain customer information, threatening disclosure unless demands are met.
Neither situation depends on advanced hacking or AI-enabled fraud. Instead, both arise from the practical leverage wielded by those who retain possession of key information in breach of contract, and can be exacerbated by weaknesses in contract, access and exit management planning and provisions. For example, some complex outsourcing agreements envisage exit plans that the parties never get around to finalising, creating ambiguity and vulnerability.
How can supply chain risk be mitigated?
One key step for businesses is to audit contractual arrangements to ensure that they accurately reflect the parties’ agreed allocation of risk. However, this is a complex and sometimes unattractive step, particularly at the outset of a commercial relationship. Some organisations may instead prefer to negotiate liquidated damages clauses – providing at least a fixed exposure in the event of a cyber incident.
Agreements vary broadly in relation to the indemnities given for breaches of data protection obligations. Depending on the contractual terms, claimants can be faced with broad exclusion and limitation of liability clauses. Sometimes suppliers find themselves having to agree to unlimited liability to their customer in the event of data protection or confidentiality breaches, but with no recourse to a supplier further down the chain whose cloud solution has caused the breach due to such exclusions and limitations. A contractual risk ‘flow-down’ analysis and consequent improvements to terms and conditions can provide important protections.
Claims may also possibly be brought in tort, although a claim for pure economic loss arising from a cyber incident has yet to be successfully established. The UK Jurisdiction Taskforce confirms there are a range of circumstances in which businesses or individuals could be liable for AI harms under English private law, even if they do not set out deliberately to cause harm.
Specific situations where confidential information is likely to be exchanged may also warrant additional consideration. The Court of Appeal’s decision in Logix Aero Ireland Ltd v Siam Aero Repair Company Ltd [2026] EWCA Civ 510 illustrates the difficulty of using a standard confidentiality clause to recover losses caused by cybersecurity incidents.
In this case, fraudsters inserted themselves into correspondence concerning Logix’s purchase of two aircraft engines and substituted their own Vietnamese bank details. Logix paid US$824,900 to the fraudsters and later alleged that Siam Aero had breached a confidentiality clause by unwittingly communicating with them. The court assumed for the purpose of the strike-out application that a breach was arguable, but held that it was not the effective cause of the loss. It merely formed part of the opportunity for the fraud; the intervening deception and mistaken payment caused the loss. The clause protected confidential commercial information, but did not impose a specific duty to guard against payment diversion fraud.
Parties exposed to email interception fraud should consider express protections and procedural safeguards rather than relying on general confidentiality wording. These may include independent verification of new or amended bank details, agreed channels for payment instructions, prompt alerts and notification of suspected compromise, evidence-preservation and cooperation duties, and a clear allocation of responsibility where agreed verification procedures are not followed. The drafting should identify the particular fraud against which protection is required and connect that obligation to workable operational controls.
Individual data breach claims
Individuals affected by a data breach can claim from data controllers or data processors under Article 82 UK GDPR for any material or non-material damage as a result of a breach of data protection laws.
Increasingly, individuals whose personal data is impacted by a cyber incident may also pursue contractual claims or claims for breach of confidence, as well as those under GDPR.
How to mitigate individual data breach claim risk?
Mitigating the risk of damages for individual claims (which are not substantial individually but can be significant for a class action based on a mass data breach), requires establishing and evidencing that appropriate technical and organisational measures were in place, that the accountability principle has been satisfied (in terms of governance, risk assessments, policies and procedures and required training), and that the relevant organisations acted with reasonable care and skill. Contractual provisions around fitness for purpose, good industry practice, and reasonable care and skill as well as mandatory data processing contract provisions which place specific obligations on data processors are similarly in the spotlight when it comes to supply chain contractual claims.
The future for cybersecurity
Resilient organisations are those that combine appropriate technical safeguards with careful and disciplined governance and organisational measures and contracts that work under pressure. Alongside existing data protection laws, the EU Cyber Resilience Act requires in-scope manufacturers to comply with new reporting obligations for actively exploited vulnerabilities and severe incidents from 11 September 2026. The legislation highlights the crucial importance of acting swiftly upon notification. Reporting timelines, for instance, are measured in hours rather than days.
In the UK, the Cyber Security and Resilience Bill is currently being debated. Recent proposed amendments include an AI ‘kill switch’ that would allow the government to deactivate powerful AI systems or switch off data centres in the event of an extreme threat to national security. Draft legislation aimed at preventing the development of ‘artificial superintelligence systems’ within the UK and beyond has been introduced into the UK parliament, albeit as a private members’ bill.
Ultimately, as we increasingly grapple with the concept that ‘frontier’ AI is evolving faster than we can understand it, and still less coherently regulate it, we all need to ensure that we seek to understand and address the risks we face. The key question is not simply whether a cybersecurity incident can be prevented. It is whether it can be detected early, contained quickly and managed in such a way to allow a business to continue operating while investigations take place.


