Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 13 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

How poor cybersecurity policies disrupt business continuity

Cyber threat expert Stephen Leach, Detective Inspector and Head of Business Development at NEBRC, reveals why cybersecurity and business continuity planning is essential for all businesses, no matter their size.

by The Gurus
August 17, 2023
in Insight
How poor cybersecurity policies disrupt business continuity
Share on FacebookShare on Twitter

As the world moves increasingly online, risk management professionals and business owners must continue to invest in the prevention of cyber threats. It’s surprising, to see just how many businesses have plans in place for all sorts of things such as fire, flood and COVID-related issues, yet don’t have any action plans in place should a cyber attack occur. 

What happens in the minutes, hours and days after an attack is crucial. This is where business continuity planning can be vital lifeline, with a sound plan saving time and money whilst a threat is addressed. 

Why is a strong cybersecurity policy so important?

A detailed cybersecurity policy is an essential part of any business continuity plan. It ensures that businesses are adequately addressing any weaknesses, are prepared for potential threats, and are ready to mitigate an attack should the worst happen.

Organisations need to be able to detect and respond quickly and effectively to a cyber incident to reduce the financial, operational and reputational harm it can cause. It is crucial that a team has effective cyber security and robust incident response plans in place to follow.

A poor cybersecurity policy can disrupt business continuity making a cyber-attack more likely as defensive measures aren’t in place. It can also make attacks worse as policies necessary for recovery aren’t established and ultimately impact revenue and productivity, all of which affect the bottom line.

1.     How poor cyber policies can cost businesses money

A data breach can result in a variety of costs, such as fines, lawsuits, and extra staff wages. This includes direct costs paid to IT consultants or the attackers, long term costs such as hiring new staff or improving security, and indirect costs where staff couldn’t complete their work or devices needing replacements.

Under GDPR regulations, an individual is also entitled to claim compensation from an organisation if they’ve experienced material (e.g. loss of money) or non-material (e.g. suffered distress) damage as a result of the organisation breaking data protection law. This may result in further financial losses and reputational damage.

2.     How poor cyber policies can cause a loss of reputation

Knowing that a company has been a victim of a data breach can stop customers from trusting the brand and influence them to choose a competitor or avoid the affected company’s services. Consumers don’t want to risk their own personal data, so providing it to a company with a poor cybersecurity policy isn’t worth it. This can result in a loss of revenue for the organisation. 

This can also create a snowball effect. Knowing that consumers don’t trust the business can influence other businesses’ decisions on whether to work with them. Because of this reputational damage, many businesses won’t want to be linked to that brand and may choose a competitor as a result.

3.     How poor cyber policies reduce productivity

Productivity loss as a result of a data breach can be one of the most common business continuity disruptions faced. There are many forms this could take, such as a hairdresser losing access to their diary booking system, a construction company losing access to their subcontractor database, or a small manufacturer losing their production line and communication with customers.

In the short term, a cyber attack will take unplanned time to deal with. This can be from mitigating the attack or downtime through loss of access to networks and data. Overall, 24% of businesses say that a data breach prevented staff carrying out their day-to-day work, this could result in missed deadlines and overtime.

Long term, compromised financial or personal data takes time to correct, as well as time to conduct cybersecurity training and complete audits to update your policies.

What can businesses put in place to reduce losses?

Businesses can however, take measures to reduce such losses. A cyber business continuity exercise is an important part of the process for creating a plan to identify major risks which could cause significant disruption. 

The policies created from such exercises will then form your defence against attacks and potential losses. The policy should identify threats, list actions taken to prevent these threats and persons responsible for actioning, maintaining security and responding to breaches. 

The aim is to then take steps to prevent these disruptions where possible to allow essential processes to continue. The requirements of a cybersecurity policy are ever-changing due to new techniques and tools being used by cyber criminals and should be reviewed regularly. Especially following an incident to determine whether the current policy is still appropriate.

Mitigations listed within the policy might include things like antivirus software and firewalls, managing updates and patches needed to ensure things like browsers and plugins aren’t at risk. It can also include operating systems, and other internet-facing applications. 

Additionally, policies should cover what data an organisation has, how it is processed and protected showing compliance with GDPR regulations. This is especially important since the majority of booking systems and account details are now stored online.

Businesses who need help reviewing their business continuity plan or advice on running exercises such as gap analysis, impact assessments and determining risk can get in touch with non-profit organisations such as the North East Business Resilience Centre. In partnership with the Police and the NCSC, the organisation uses elements modelled off of the International Business Continuity Management Systems standard ‘ISO/IEC 22301:2019’ to help strengthen and sense check any plans.

Poor cybersecurity practices can leave businesses exposed to financial and reputational losses. To find out more about the NEBRC and how they can help your businesses with continuity planning visit the website or sign up to their free core membership.

About the author:

Stephen Leach, Detective Inspector and Head of Business Development at NEBRC.

Steve is a Detective Inspector with 28 years policing experience, the majority spent within CID, both at a Force and Regional level. Steve is currently seconded to the NEBRC and has always had an interest in the digital and cyber world. 

Prior to joining the police he graduated university with an Electronic Systems Engineering degree. Within the police he has worked in internet investigations and managed communication data investigators, radio frequency technicians and Digital Forensic Examiners. More recently he was part of the team that was responsible for creating the force-wide Cyber Crime Unit. He has previous experience of force and region-wide Projects from design through implementation to delivery. 

 

ShareTweet
Previous Post

BT joins line-up for Wales Tech Week

Next Post

International Cyber Expo Launches ‘Grab the Mic: Women in Cyber’ Event

Recent News

Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026
artificial-intelligence

The More Confident Organizations Are in Their AI Security, the More Likely They’ve Been Breached, New Research Finds

June 11, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol