In today’s digital world, cyber threats are no longer a distant possibility - they are a constant, evolving reality. Every day, companies face sophisticated attacks that can disrupt operations, damage reputations and trigger costly regulatory penalties. The stakes have never been higher.
Recognising this, the Cyber Security and Resilience Bill has been introduced to raise the bar for all organisations. It’s not just about ticking boxes or buying insurance. The Bill demands that companies embed resilience into their very DNA - from boardroom governance to frontline employee behaviour. It requires clear accountability, robust risk management, timely incident reporting, and a culture that understands and acts on cyber risk.
This is the ongoing issue every organisation must face: cyber risk is complex, fast-moving and deeply human. Technology alone won’t solve it. Without the right culture and communication, even the best cyber insurance can’t protect you from the fallout of a breach.
Complying with the Cyber Security and Resilience Bill is a legal necessity, but it also opens a powerful door for companies to lead strategically. It’s an opportunity to tell a story - a story of commitment, trust and resilience that resonates with customers, partners, regulators and employees alike.
Strategically, companies can position themselves as cyber leaders by openly communicating their compliance journey and resilience plans. This builds confidence and differentiates them in a crowded market. It’s about more than meeting requirements; it’s about shaping a reputation for reliability and foresight.
Tactically, the Bill demands clear, timely communication - incident reporting, employee training, supplier updates and crisis messaging. These are not just checklists but vital tools to embed cyber-secure behaviours and ensure everyone knows their role when it matters most.
This is where Marsh’s cyber solutions come in. We don’t just work with clients to transfer financial risk, we support their resilience and provide expert guidance on managing cyber incidents.. These form part of a wider strategy that includes strategic and tactical communication.
At the heart of cyber resilience are people - their awareness, behaviours and confidence. Marsh’s Impact team specialises in turning complex cybersecurity challenges into clear, engaging stories that employees and stakeholders can understand and act on.
They know that effective communication is more than information - it’s about connection. By creating a consistent visual identity and powerful narratives, they make cybersecurity relevant and memorable. Their targeted change programmes guide employees from awareness to confident action, while interactive learning experiences build real skills and reduce risky behaviours.
This human-centred approach balances the “Heads” (understanding cyber risks) with the “Hearts” (engaging people emotionally). It transforms cybersecurity from a technical obligation into a shared organisational value.
When companies integrate cyber security with strategic communication and culture change, they unlock true resilience, and the numbers prove it:
Strong internal communication programs can reduce cyber incident costs by up to 40%
Creative storytelling and targeted employee engagement reduce phishing susceptibility by 30%
Targeted employee engagement leads to 50% faster incident response, minimizing financial damage
Moreover, firms that embed cyber-secure behaviours through ongoing communication and training experience up to 60% fewer successful cyberattacks, significantly reducing operational disruption and reputational damage. This means fewer regulatory fines and less financial exposure - a clear return on investment.
Marsh’s cyber insurance solutions provide the financial safety net, but it’s the combination with Impact’s communication expertise that builds the behavioural firewall preventing breaches in the first place. This integrated approach delivers measurable risk reduction, faster recovery, and stronger stakeholder trust.
Start by reviewing your cyber insurance cover with Marsh experts to ensure it matches your risk profile and regulatory requirements. Secondly, develop a strategic communication plan that tells your cyber resilience story clearly and confidently.
Marsh’s Impact team can then design and deliver employee communication and culture change programmes that embed cyber-secure behaviours. Implement tactical communication tools – a powerful visual identity and a meaningful narrative, targeted change programmes covering multi-media, training campaigns, partner updates etc., so that everyone knows their role.
Finally, integrate cyber security messaging into your broader resilience strategy, showing how protection and people work hand in hand.
The Cyber Security and Resilience Bill is a wake-up call. It reminds us that cyber risk is everyone’s business, from the boardroom to the break room. Taking out cyber insurance is a smart start, but real resilience comes from embedding cyber-secure behaviours into your organisation’s culture and communications.
This is the story every organisation needs to hear and listen to. Let’s make sure you’re ready to tell it.