Estimated reading time: 5 minutes
Marsh surveyed 350 senior UK retail executives. Among those who went through a major cyber disruption last year, 64% say they are overinvesting in cyber resilience. Marsh says the measure that matters is speed of recovery.
Last year, cyberattacks caused mass disruption at major UK retailers, including Marks & Spencer. The sector responded by spending.
“Cost didn’t seem to be an issue,” said Darren Pidwell, group insurance director at Kingfisher.
A year on, the retailers that went through a major cyber disruption are skeptical of that spending. Sixty-four percent say they are overinvesting in cyber resilience. Marsh defines overinvesting as spending an excessive budget while seeing poor returns. Fourteen percent say they are underinvesting.
The figures come from the Marsh Retail Pulse 2026 report, published 30 September. Marsh surveyed 350 senior executives at UK-based retailers in April and May 2026. Respondents ranged from small firms to multinationals.
UK Retail Cyber Risk And The Spending Gap
Pidwell described an industry that pivoted after last year’s high-profile attacks. Retailers asked what they needed to do to avoid becoming the next headline. He questioned whether they understood their risk profile and control environment before they spent.
Marsh says the problem is often where the money goes. It points to too little investment in identity recovery, asset visibility and third-party controls.
Kelly Butler, head of cyber at Marsh Risk UK, put the test in operational terms. Retailers that still cannot “contain disruption or recover core operations quickly” will find the investment disappointing, she said.
The report pairs the finding with Marsh research on cover. The quiet crisis in cyber insurance found 67% of UK clients buy cyber limits insufficient for a one-in-100-year loss scenario. Marsh says even heavy spenders can carry protection misaligned with their potential loss.
Where UK Retail Cyber Risk Sits
Ninety-five percent of respondents report significant areas of cyber exposure in their business. Twenty-four percent say cyberattacks were a top three disruptor in the past year.
Human error, phishing and social engineering topped the list of exposures, at 53%. Customer data and identity access controls followed at 46%. Third-party IT and service providers came next at 41%.
Marsh says generic security training misses how retail works. Head office staff may face credential theft. Store staff may face attempts to reach point-of-sale systems.
Store-level exposure is harder to watch from the center. Marsh lists connected devices, third-party contractors, and legacy hardware as part of an attack surface outside central oversight. VikingCloud found a similar gap at large multi-location brands. Third-party exposure also runs through supply chains. Andrew Horkan of Cyber Tzar told the CINI podcast about one hauler. It lost £390,000 in the month after the Jaguar Land Rover attack.
Cyber Resilience Investment Measured By Recovery
Marsh wants retailers to judge cyber and resilience spending by speed of recovery, not size of spend. The best-prepared retailers will focus less on how many controls they buy, the report says.
Marsh also says the biggest security budgets did not always produce the fastest recoveries this year. It recommends claims data, cost-benefit analysis and external benchmarking to find where spending would most improve recovery.
For underwriters weighing UK retail cyber risk, recovery speed also shapes the size of a business interruption loss.
Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!
UK Retail Cyber Risk Inside A Wider Squeeze
Cyber sits inside a broader squeeze. Ninety-three percent of retail leaders faced significant disruption in the past year. Seventy-one percent agree disruption is now constant rather than episodic.
Two in five have redirected long-term investment toward short-term costs. Fifty-three percent say cost and efficiency pressures are forcing them to accept higher risk exposure. Forty-seven percent have extended the use of existing core systems and infrastructure. Thirty percent have reduced operational flexibility to protect margins or continuity.
Across UK business, cyber is now the leading risk category. Marsh’s separate UK Business Risk Report 2026 found 46% of business leaders cite it, up from 39% in 2024.
Kelvyn Sampson, Marsh Risk UK’s retail, leisure and hospitality industries leader, summed up the pattern. “The danger now is that constant firefighting has become the strategy,” he said.
FAQ – UK Retail Cyber Risk
What is the Marsh Retail Pulse 2026?
A Marsh survey of 350 senior executives at UK-based retailers, from small firms to multinationals, conducted in April and May 2026.
Do UK retailers think they spend too much on cyber?
Among retailers that went through a major cyber disruption last year, 64 percent say they are overinvesting in cyber resilience, meaning excessive budget with poor returns. 14 percent say they are underinvesting.
Where do retailers see the most cyber exposure?
Human error, phishing and social engineering, cited by 53 percent. Customer data and identity access controls followed at 46 percent, and third-party IT providers at 41 percent.
What does Marsh recommend?
Judging cyber and resilience investment by speed of recovery rather than size of spend, and putting more into identity recovery, asset visibility and third-party controls.
Are UK businesses buying enough cyber insurance?
Separate Marsh research found 67 percent of its UK clients buy cyber limits insufficient for a one-in-100-year loss scenario.
Why does recovery speed matter for cyber insurance?
The length of an outage drives the size of a business interruption loss, which is often the largest part of a retail cyber claim.
Related Cyber Insurance Posts
- 97% Used to Be a Good Grade—But Not for Retailers Facing Data Breaches(Opens in a new browser tab)
- Black Kite: Over 70% of Major Retailers Show Exposed Credentials in 2026(Opens in a new browser tab)
- Retail Cybersecurity Gaps Revealed: 80% of UK Retailers Face Critical Risk, KYND Warns(Opens in a new browser tab)
- Cyber Risk Management Surge: New Report Shows Rising Threats and Bigger 2026 Security Budgets(Opens in a new browser tab)
- Retail Ransomware Demands Double to $2M — Why Ransomware Cyber Insurance Matters Now(Opens in a new browser tab)