Willis Towers Watson plc

10/06/2025 | Press release | Distributed by Public on 10/07/2025 02:08

Boards risk costly cyber exposure as confidence outpaces preparedness, according to Willis report

LONDON, October 6, 2025 According to Willis, a WTW business, (NASDAQ:WTW) corporate boards often express confidence in their cyber readiness. Yet recent high profile cyber events show how fragile that confidence can be when tested. Willis's new Cyber in Focus 2025 report, based on 4,650 cyber claims and board-level data, reveals the same story: losses are longer, broader and costlier than leaders expect.

The report, launched during Cyber Security Awareness Month, focuses on four areas boards consistently misjudge:

  • Revenue (downtime): Boards assume ransomware outages last days; claims data shows a median 24-day outage and an average ransomware loss of US$2.7M. Every week offline means lost revenue.
  • Reputation (vendor risk): Leaders often view vendor risk as secondary, yet ~50% of breaches start with suppliers (MSPs, SaaS, niche vendors). Weak liability, audit, and notification clauses drive cost; regulators increasingly expect proof of vendor oversight.
  • Resilience (tested readiness): Most boards report having a plan, but only 68% tested it in the past year. Regulators and insurers are looking for evidence that controls work in practice, not policy statements alone.
  • Regulation (rising accountability): Emerging frameworks, including the EU AI Act, evolving U.S. state rules, and new critical-infrastructure legislation in Hong Kong are raising expectations on governance, incident response, and disclosure.

Additional findings include:

  • Publicly-held companies account for 36% of total losses despite fewer incidents.
  • The largest single claim reached US$331M; Boards highlight AI's upside, but claims already show deepfakes, synthetic IDs, and generative malware being used to commit fraud.

Peter Foster, Chairman, Global FINEX Cyber and Cyber Risk Solutions, Willis, said: "Boards often believe cyber risk is contained, but the data proves otherwise. Untested plans, weak vendor contracts, and unclear wordings are exactly where firms lose money, reputation, and regulatory standing. The cost of untested resilience shows up in lost revenue, shareholder disputes, and fines and it's rising faster than boards expect. Ransomware simulations, vendor analytics, AI governance, and policy optimization can help bridge the gap between perception and reality."

"

The cost of untested resilience shows up in lost revenue, shareholder disputes, and fines and it's rising faster than boards expect."

Peter Foster | Chairman, Global FINEX Cyber and Cyber Risk Solutions, Willis

About WTW

At WTW (NASDAQ: WTW), we provide data-driven, insight-led solutions in the areas of people, risk and capital. Leveraging the global view and local expertise of our colleagues serving 140 countries and markets, we help organizations sharpen their strategy, enhance organizational resilience, motivate their workforce and maximize performance.

Working shoulder to shoulder with our clients, we uncover opportunities for sustainable success and provide perspective that moves you.

Media contact

Lauren David
External Communication
emailEmail phone+44 7385947619

Related content

Campaign

Cybersecurity Awareness Month: Perception vs reality

Report

Cyber in Focus 2025
Related content tags, list of linksPress Release Cyber Risk Management and Insurance

Related capabilities

Cyber Quantified

Achieve transparency on cyber risk and cyberinsurance value with a scenario-led modeling tool for both CISOs and risk managers to quantify threats and the impact of risk controls.

arrow_forward
Cyber Risk Consulting

Enhance cyber risk resilience and align cybersecurity strategies with priorities driven by finance, operations, information and technology with tailored cyber risk consulting solutions.

arrow_forward
Willis Towers Watson plc published this content on October 06, 2025, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on October 07, 2025 at 08:08 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]