Your clients aren't the target - their supplier is

JLR and M&S didn't just lose money themselves. They took hundreds of other businesses down with them

Your clients aren't the target - their supplier is

Cyber

By Matthew Sellers

Ask most businesses to describe their cyber risk and they'll talk about their own systems, their own staff, their own firewalls. Rarely do they lead with the supplier they've never heard of, three tiers down their own supply chain, whose outage could stop their production line dead. That gap between where businesses think their risk lives and where it actually sits was the starting point for a UK cyber broker panel convened by Insurance Business TV.

The two cases the panel kept returning to happened almost back to back in the UK last year. Jaguar Land Rover was forced to shut down its IT systems globally after a cyberattack in late August 2025, halting production at its Solihull and Halewood plants for around five weeks. The UK's Cyber Monitoring Centre later categorised it as a Category 3 systemic event, estimating a UK-wide financial impact of £1.9 billion and disruption reaching over 5,000 UK organisations through JLR's dealer and supplier network. None of those thousands of firms were attacked directly. They simply depended on one that was. Marks & Spencer suffered a separate attack the same year, with reported losses of around £300 million after roughly two months of disrupted online services.

Read next: Jaguar Land Rover did not finish cyber insurance purchase

Colin Fox, cyber insurance consultant at Integrity, part of Hayes Parsons, pointed to both as evidence of a blind spot in how the market thinks about exposure. "I think it's been an exposure that has been sort of forgotten about," he said, arguing that most businesses remain focused on managing their own cyber losses when the reliance on suppliers "does prove that there are some big losses that can be had."

Selorm Kofi Domeh, broking manager at Talbot Jones, described a distinction he raises constantly with clients but which rarely gets made explicit: the difference between being a specific target and an incidental one. "No one works in isolation," he said. A business doesn't need to be the hacker's intended victim to end up bearing the cost, if it happens to sit downstream of whoever was.

Read next: M&S cyberattack: lessons to learn for insurance brokers

That distinction changes what cover a client actually needs. Daniel Winn, a development broker at Jensten London Markets specialising in technology, media and cyber, pointed to business interruption cover tied to third-party technology dependency as the area most businesses underestimate. Most companies now rely on at least one external technology provider closely enough that its outage would stop them working entirely, he noted. Most insurers will offer that cover, but working out how much of it a client actually needs, given their real dependency chain, is where the broker's job gets harder than simply ticking a box.

The market has been building product to match this. Ethan Godlieb, associate partner for cyber and fintech at Consilium Insurance Brokers, said the market now provides insurance "pretty comprehensively" for supply chain risk in both directions, upstream and downstream, meaning the knock-on impact of an attack on a client's supplier can be covered rather than just an attack on the client itself. Insurance Business's 5-Star Cyber research has highlighted breadth of cover like this as one of the things separating leading carriers from the pack, pointing to insurers offering a single broad policy grant instead of forcing clients to stitch together separate covers for different angles of the same underlying exposure.

Sector matters too. Fox pointed specifically to manufacturing and retail as the areas hit hardest by the JLR and M&S incidents respectively. Both cases carry a reputational dimension that outlasts the immediate business interruption, something the panel kept coming back to. Losing a supplier's data is one thing. Losing customer confidence because a well-known brand was seen to fail its supply chain is another, and considerably harder to price.

None of this is entirely new terrain for the London Market. Insurance Business has previously reported on how cloud and technology-vendor concentration is reshaping the cyber underwriting agenda. What JLR and M&S did, judging by this panel, was turn an abstract aggregation worry into two very concrete, very expensive case studies. UK brokers are now using them to have a different kind of conversation with clients - not "are you protected," but "do you actually know who you depend on."

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!