Retailers overspend on cyber controls but buy too little cover — study
Marsh survey finds 95% of UK retailers report serious cyber exposure, a year after M&S and Co-op were hit
Retailers overspend on cyber controls but buy too little cover — study
CYBER
By Josh Recamara
01 Oct 2026

UK retailers are spending heavily on cyber defences without getting the protection they think they are paying for, according to new research from Marsh.

The broker's Retail Pulse 2026 report found that 95% of retail leaders say their business has significant areas of cyber exposure. Among retailers that went through a major cyber disruption last year, 64% now say they are overinvesting in cyber resilience, while only 14% said they are underinvesting.

Marsh surveyed 350 senior executives at UK-based retailers, ranging from SMEs to multinationals, in April and May 2026.

Controls up, limits short

The findings land just over a year after attacks on Marks & Spencer, the Co-op and Harrods. M&S said its attack would cost around £300 million in lost operating profit. The Co-op later confirmed to Insurance Business that it held no dedicated cyber insurance, having chosen to invest in security controls instead.

That trade-off runs through Marsh's data. The report cites the broker's separate research showing that 67% of its UK clients buy cyber limits too low for a one-in-100-year loss. In other words, heavy spending on tools is not translating into risk transfer that matches the scale of a severe loss.

"Retailers may have bought tools, added controls, and increased budget, but if they still cannot contain disruption or recover core operations quickly, the investment will feel really disappointing," said Kelly Butler, head of cyber at Marsh Risk UK.

Darren Pidwell, group insurance director at Kingfisher, said the sector had pivoted after last year's attacks without always asking whether it understood its own risk profile, its control environment or what assurance the new spending would actually provide.

Retailers identified human error, phishing and social engineering (53%) as their biggest cyber exposure, followed by customer data and identity access controls (46%) and third-party IT providers (41%). Marsh argued that recovery capability, including identity recovery, asset visibility and third-party controls, is where spending is most often lacking.

Accepting more risk

Beyond cyber, the report describes a sector under cost pressure and knowingly taking on more risk. Some 53% of retail leaders say cost and efficiency pressures are forcing them to accept higher risk exposure. That figure barely changes between retailers expecting growth (53%) and those expecting flat or falling revenue (54%).

Two in five have redirected long-term investment towards short-term cost or risk priorities, and 30% have reduced operational flexibility to protect margins.

Stephanie Lavis, senior risk consultant at Marsh Risk UK, said businesses were running with fewer people, less training and simpler controls. She warned that cutting controls without first examining accident and incident rates could leave retailers facing much bigger, more costly problems.

Respondents also pointed to rising employment costs. Half expect the Employment Rights Act to push up operating costs, and 43% expect it to add to their administrative and compliance burden.

A blind spot on the shop floor

The survey found that 85% of executive leaders believe their business is managing employee physical safety effectively, compared with 72% of people and HR leaders. Yet 89% of retail leaders don't see employee wellbeing and safety as a top challenge, even though 30% name retail crime as one of their top three disruptors last year.

The cyber findings give brokers a clear conversation to have at renewal. Retail clients that have spent heavily on controls since 2025 may believe they are better protected than their limits suggest, particularly on business interruption, where the M&S and Co-op losses were concentrated. Recovery costs and outage-driven lost profit are the exposures most likely to outrun a limit set on the strength of new controls.

The willingness to accept more risk matters too. Thinner staffing and lighter controls feed directly into employers' liability, crime and property risk, and insurers will want evidence that cuts haven't weakened risk management. A risk accepted on purpose still needs to be disclosed.

Marsh is a broker with a commercial interest in these findings, and its survey is self-reported. Even so, the gap between what retailers spend and what they transfer is one that brokers on the other side of the table can test with their own clients.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB UK.