Cloud-based systems are secure – If they’re properly protected

Mike Dickinson, Managing Director of Russell Scanlan

Following several high-profile cyber-attacks on our high street businesses this Spring, a chartered insurance broker is offering advice to British cloud-based businesses who might be vulnerable to a breach. According to news reports[1], the recent cyber-attack on household name M&S could cost up to £300m in lost profit this year.

Russell Scanlan, part of Acrisure UK Broking, is an expert insurance broker based in Nottingham, works with organisations of all sizes across multiple sectors to provide specialist, tailored insurance policies.

Mike Dickinson, Managing Director for the broker, and Regional Director Acrisure Midlands, claims that one of the biggest challenges to businesses in recent years has been mitigating risks associated with cloud migration.

He said: “More than five years on from the Pandemic, cloud migration (or the process of moving all company data to a cloud-based environment) has become the norm, and it certainly has many benefits.

“Companies can scale up and down at pace and no longer must store data on costly easy-to-steal or damage on-site hardware. Perhaps one of the biggest advantages for employees is that they have more flexibility to work from home, with cloud-based systems being remote work ready.

“Like with anything however, there is one challenge to cloud migration that can significantly elevate risk to a business: the question of cybersecurity. Are cloud-based systems really that secure? Do they make a business vulnerable to disruption? And how can businesses protect themselves from a cyber-attack?”

For Russell Scanlan’s clients, the pandemic brought about a major shift in the way they operate, with over 78%[2] of business leaders saying they have migrated to cloud-based working in most or all areas of their business. For context, in 2020, this number stood at approximately 53%, according to AAG[3].

The biggest risk for cloud migration is security. Businesses assume that storing data in the cloud makes it vulnerable to cyber criminals, and recent high-profile attacks in the British supply chain certainly back this up.

Mike continues: “This Spring, M&S, the Co-op and Harrods were targeting using sophisticated social engineering methods, which aimed to impersonate employees to deceive and gain unauthorised control to internal systems.

“While cloud-based systems are generally more secure than previous manual storage systems, you could argue that the increase in the number of entry points a malicious actor could exploit to get access to data has outpaced the implementation of security measures by businesses.

“Here is how you can keep you cloud data safe, and reduce the risk to your business operations:

“Compliance. Take the necessary steps to ensure you’re compliant with UK regulations for data protection. Only collect data that is necessary to your business, audit your data and security measures regularly and always obtain consent.

“Planning and implementing. Work with your IT team to adequately plan your migration strategy. At the beginning of the covid lockdown, businesses may not have had the time to plan ahead, and many are starting to see certain vulnerabilities in their security as a result. Once implemented, constant review of your security will ensure you don’t fall victim.

“Training. This is one of the most important points. Cloud migration is complex and to remain secure, every user must know how to protect it. We’ve learned from the cyberattacks on M&S that human error accounts for the highest proportion of data breaches – so watch out for those phishing emails, flag anything that looks odd, and make sure data protection training is provided on a regular basis.

“Finally, robust, tailored insurance. A problem facing businesses nowadays when trying to source adequate insurance cover is that the language around cyber insurance policy isn’t standardised, and cover may vary greatly between different insurers.”

To cut through the noise and obtain accurate insurance quotes based on ‘predictable’ risks, chartered insurance brokers might provide you with more financial reassurance.

They can be more proactive in their outlook to cyber-security, signposting to training and awareness resources and by paying close attention to detailed integrated cyber response services provided by insurers, as well as expected first and third party covers.

Mike concludes: “It seems like a lot of information. And until recently, businesses were still reticent to purchase cyber insurance because they thought their defences were enough.

“It seems that with the financial ramifications for M&S being shared in the news, the tide might be turning for cyber insurance. We’d urge any business to contact us if they have any concerns about their cyber infrastructure.”

To learn more about our cyber services or claims team, head to the Russell Scanlan website today https://www.russellscanlan.com or contact us on 0115 798 0786.

[1] M&S expects cyber-attack to last into July and cost £300m in lost profits, The Guardian: https://www.theguardian.com/business/2025/may/21/cyber-attack-cost-marks-and-spencer-lost-sales-company-results-reveal.

[2] 2024 Cloud and AI Business Survey, PwC: https://www.pwc.com/us/en/tech-effect/cloud/cloud-ai-business-survey.html.

[3] The Latest Cloud Computing Statistics: https://aag-it.com/the-latest-cloud-computing-statistics/.

You May Also Like

Must Read

Skip to content