Close Menu
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing & Mental Health
  • Marketing
  • HR & Recruitment
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
X (Twitter) LinkedIn YouTube
Trending
  • New Venture Aims To Help Propel Growth For Start-Ups
  • Building community, one cause at a time
  • How to build a £1 million pension and ISA portfolio
  • 5 Reasons Why Every Office Should Include Flexible Spaces to Work and Their Key Benefits
  • Pension reforms risk higher prices, fewer jobs and slower growth, FSB warns
  • Building Trust in AI Through a Decision-Centric Approach in Manufacturing
  • In Profile: Michael Stausholm, founder and CEO of SproutWorld
  • A beginner’s guide to growth shares (and why they’re so popular right now)
X (Twitter) LinkedIn YouTube
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing
  • Marketing
  • HR & Recruitment
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • Twitter
  • LinkedIn
  • YouTube
  • RSS
You are at:Home»Technology»Cyber Security Compliance: the regulatory requirements for businesses
Cyber security and protection of private information and data

Cyber Security Compliance: the regulatory requirements for businesses

0
Posted By sme-admin on July 12, 2024 Technology

With an increasing reliance on technology, the protection of sensitive data and digital assets has become paramount for businesses of all sizes. The UK Government’s Cyber Security Breaches Survey 2023 estimates there were 2.39 million instances of cybercrime affecting UK businesses in the prior 12 months – and for small businesses, navigating the complex landscape of cyber threats can be daunting and confusing. It’s never been more important for business owners to understand the laws and regulations, and how to mitigate against potential risks.

Rob Rees, Divisional Director at Markel Direct, explains the regulatory requirements for businesses when it comes to cyber security and how to navigate them to keep both your business and customers safe.

What cyber security laws and regulations do UK businesses need to be aware of?

There are currently four main laws and regulations that businesses need to be aware of when it comes to cyber security. These are:

•    The Data Protection Act 2018: The Data Protection Act 2018 (DPA) governs the processing of personal data in the UK, ensuring that organisations handle personal data lawfully and protect individuals’ privacy rights.

•    UK GDPR and EU GDPR: The UK GDPR and EU GDPR are comprehensive data protection regulations that set out rules and principles for the processing of personal data, aiming to safeguard individuals’ rights and freedoms across the United Kingdom and the European Union. Prior to Brexit in 2020, the UK followed the EU GDPR regulations, but a UK version has since been created. Businesses that serve EU customers, however, will still need to comply with both.

•    Network and Information Systems Regulations 2018: The Network and Information Systems (NIS) Regulations require operators of essential services and digital service providers to ensure the security of their network and information systems, reducing the risks of cyber threats and disruptions to critical services.

•    Computer Misuse Act 1990: The Computer Misuse Act 1990 is legislation in the United Kingdom that criminalises unauthorised access to computer systems, unauthorised access with intent to commit further offences, and unauthorised modification of computer material.

5 ways businesses protect themselves against cyber threats

Larger businesses may have the assistance of an information security or legal team to help them navigate these regulations and put appropriate measures in place to mitigate risk. Smaller businesses have the same responsibility but are less likely to have the resources available, leaving it to themselves to handle.

To help, here are five ways to help small businesses protect against cyber threats and prepare themselves should the worst happen.

1. Conduct a risk assessment

Before implementing any cyber security measures, business owners should conduct a thorough risk assessment to identify any potential vulnerabilities and threats to the security of their digital assets and data.

As a specialist insurer of small businesses, we have created a simple cyber risk assessment that considers IT systems, data storage practices, employee behaviours and potential points of entry for cyber-attacks, and provides guidance on how to mitigate these risks.

Markel Direct have created a cyber risk assessment tool that businesses can use to assess how likely they are to face a cyber threat.

2.    Create a cyber security policy

A cyber security policy outlines guidelines that employees within a business must follow to protect the company’s digital infrastructure, information and client data.

While the specifics of the policy will vary for different businesses, depending on various factors, there are some basics which should be included in all cyber security policies. These include:

•    Guidelines for employees: Every comprehensive cyber security policy should incorporate an employee-friendly guide covering secure password practices, email usage protocols, phishing detection, social media guidelines, risk mitigation strategies and specific instructions for remote workers, including network access protocols.

•    Compliance with wider regulations: Adhering to standard GDPR regulations is also essential. Key policy components include obtaining data transfer consent, the process for notifying the Information Commissioner’s Office of a breach within 72 hours, granting users data deletion and access rights, offering comprehensive explanations of user rights, and, where relevant, outlining procedures to protect children’s data.

•    Systems and infrastructure: Provide details on software/programs used to safeguard data, such as how they work, what they do to protect information and tips on how employees should use these programs, if necessary. You should also include how your business trains IT workers to keep digital systems safe from threats and vulnerabilities. Outline fully their role in both preventing a cyber-attack and what should happen if one does occur, ensuring they’re fully aware of their responsibilities.

•    Cyber-attack response: It’s important to also outline the company’s response in the event of a cyber-attack. This should be included in the policy by outlining responsibilities for investigation, timely client communication, incident reporting, reviewing insurance coverage, and ongoing employee training, ensuring compliance and responsible action in the event of a breach.

For more in-depth information use this guide on creating a cyber security policy.

3.    Invest in employee training
Employees are often the weakest link in the cyber security chain. In fact, according to Information Commissioner’s Office (ICO) data, about 90% of attacks occur because of human error. This is why ensuring that all employees are properly educated and trained should be a priority when it comes to keeping the data safe.

Training sessions should educate employees on best practices for cyber security, such as how to identify phishing emails, recognise suspicious behaviour and secure data handling procedures.

4.    Implement cyber security measures
Businesses, of all sizes, should invest in robust cyber security measures to protect their IT infrastructure and data assets from unauthorised access and potential cyber-attacks. This could include deploying firewalls, installing antivirus software, implementing intrusion detection systems and using encryption tools to safeguard sensitive information and prevent data breaches.

5.    Ensure you are protected should the worst happen

Not all business insurance policies cover against cyber-attacks, so it is vital that you check what your current policy actually covers and assess whether additional insurance is needed.

Cyber insurance is a specific form of cover that can help protect your business in the event of a malicious attack on your computer systems and data. This type of policy can help minimise disruption to your business, covering the financial costs involved in handling and recovering from a cyber-attack or hacking threat. Examples of some of the events it can cover include; informing clients of a data breach, the costs of restoring data and equipment and meeting ransom demands.

If you are unsure whether or not cyber-attacks are covered by your current policy, review your documentation and speak to your insurer or broker to make sure you are not caught out should the worst happen.

While navigating the cyber security landscape may seem daunting, implementing these strategies can help safeguard against potential threats, keeping businesses safe.

For more information about being cyber secure, visit the Markel Direct website.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Building Trust in AI Through a Decision-Centric Approach in Manufacturing

Ransomware payment ban: What is it and how can businesses prepare?

How Generative AI is Giving SMEs a Marketing Edge

Comments are closed.

Follow SME Today on Linkedin and share all the topics you find interesting
Verify your identity for Companies House

The Newsletter

Join our mailing list for the best SME stories, handpicked and delivered direct to your inbox every two weeks!

Sign Up
Events Calendar
    • Marketing
    July 7, 2025

    Bold Business Marketing Specialist Speaks In Swindon This Week

    July 4, 2025

    How Generative AI is Giving SMEs a Marketing Edge

    • Finance
    July 10, 2025

    How to build a £1 million pension and ISA portfolio

    July 10, 2025

    Pension reforms risk higher prices, fewer jobs and slower growth, FSB warns

    • Health & Safety
    July 1, 2025

    Temperatures Soaring: Is Your Workplace Becoming Unsafe?

    January 29, 2025

    UK takeaways guilty of shocking hygiene failures:

    • Events
    July 4, 2025

    £20k grant for female-founded SME up for grabs

    July 2, 2025

    As Seen on BBC Panorama – Brad Burton to Headline The South West Expo in Swindon

    • Community
    July 11, 2025

    Building community, one cause at a time

    June 23, 2025

    Celebrating One Year In Fairford Supporting The Community

    • Food & Drink
    June 23, 2025

    England Cricket Captain, Ben Stokes OBE, takes a stake in Spencer Matthews’ alcohol-free spirits brand, CleanCo

    June 16, 2025

    Hospitality industry risks collapse

    • Books
    April 24, 2025

    Values-Driven Professionalism: A Path to Client Loyalty

    December 2, 2024

    Banish the banshee boss: how to lead without fear – addressing the issue of fear-based management and how NOT to be this manager

    About

    SME Today is published by the same team who deliver The Great British Expos’. We have been organising various corporate events for the last 10 years, with a strong track record of producing well managed and attended business events across the UK.

    Join Our Mailing List

    Receive the latest news and updates from SMEToday.
    Read our Latest Newsletter:


    Sign Up
    X (Twitter) YouTube LinkedIn
    Most Recent Posts
    July 11, 2025

    New Venture Aims To Help Propel Growth For Start-Ups

    July 11, 2025

    Building community, one cause at a time

    July 10, 2025

    How to build a £1 million pension and ISA portfolio

    July 10, 2025

    5 Reasons Why Every Office Should Include Flexible Spaces to Work and Their Key Benefits

    July 10, 2025

    Pension reforms risk higher prices, fewer jobs and slower growth, FSB warns

    Categories
    • Books
    • Community & Charity
    • Education and Training
    • Environment
    • Events
    • Features
    • Finance
    • Food and Drink
    • Health & Safety
    • HR & Recruitment
    • In Profile
    • Legal
    • Marketing
    • News
    • Property & Development
    • Sponsored Content
    • Technology
    • Transport & Tourism
    • Wellbeing & Mental Health

    Copyright © 2020 SME Today.

    • ABOUT SME TODAY: THE GO TO RESOURCE FOR UK BUSINESSES
    • Privacy
    • Contact
    Copyright © 2025 SME Today.
    • ABOUT SME TODAY: THE GO TO RESOURCE FOR UK BUSINESSES
    • Privacy
    • Contact

    Type above and press Enter to search. Press Esc to cancel.