Cyber

Helping you to manage information and cyber risks

Aviva policyholders can benefit from exclusive access to our in-house Aviva Cyber risk management team.

Our expert consultants are dedicated to help safeguard your business from cyber threats. We provide onsite cyber risk assessments to help identify potential vulnerabilities in your organisation and our external vulnerability scanning capabilities can help to make sure that your digital perimeter is secure against external threats. Leveraging our intelligence source, we can provide you with the latest insights to help to stay ahead of emerging risks.

We also have a library of Loss Prevention Standards, providing guidance on cyber-related issues and a collection of cyber Specialist Partners, aimed at helping to support your business with things such as phishing testing, managed detection and response services.

Do you need specialist Cyber risk management guidance?

Get in touch with our expert cyber risk managers to support you and your business.

Did you know?

38.59%

rise in data security incidents reported to the ICO from 2022-20241

8.58 million

estimated and approximately cyber crime attempts against UK businesses in 20242

Guidance to help manage cyber risks

Download our range of Loss Prevention Standards (LPS)

Our Cyber offering

Whether you're looking to assess your current posture, train your teams or prepare for the unexpected, the Aviva Risk Management Solutions (ARMS) Cyber team is here to help you stay ahead of the threat.

Aviva Risk Training Solutions (ARTS)

External attack surface assessments

Incident response planning support

IT disaster recovery reviews

Cyber risk quantification assessments

Cybersecurity certifications

ISO 27001:2022 support

Self-assessment

Cyber Assessment

Our Cyber Assessment is designed to provide a clear, structured view of your organisation’s current cyber risk posture, structured around the six core functions of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.

1. Govern

Strategy, leadership, accountability and oversight of cyber risk
  • Who is responsible for cyber risk governance?
  • Do you have written cyber policies and procedures?
  • How is cyber risk integrated into wider enterprise risk management?

2. Identify

Understanding assets, data and business context to prioritise risk
  • Are third-party risks assessed and managed?
  • Is there a data protection impact assessment process?
  • Do you conduct yearly cyber risk assessments?

3. Protect

Controls and safeguards in place to defend against threats
  • What technical controls are in place?
  • How is access to sensitive data managed?
  • Are staff trained in cyber awareness and secure behaviours?

4. Detect

Capabilities to identify cyber events and anomalies

  • Do you have tools in place to detect suspicious activity?
  • Is there a process for identifying/escalating incidents?
  • How do you detect unauthorised access or data exfiltration?

5. Respond

Preparedness for incidents

  • Do you have a documented incident response plan?
  • How is communication managed during a cyber incident?
  • Are roles and responsibilities clearly defined in the event of a breach?

6. Recover

Ability to restore operations

  • Is there a business continuity/disaster recovery plan?
  • How quickly can critical systems be restored?
  • Are post-incident reviews conducted and documented?

How we work with you

  • Initial engagement: Introducing the assessment to understand your organisational structure and agree on the scope
  • Documentation review: Reviewing documentation such as policies, network diagrams, incident response plans and governance frameworks
  • Structured discussion: Conducting a guided conversation with stakeholders, exploring how cyber risk is managed across people, processes and technology
  • Scoring and benchmarking: Analysing and scoring responses to benchmark your organisation against Aviva’s standards and your peers

Our Specialist Partners to help manage cyber risks

To access these solutions at preferential rates and terms, contact our Specialist Partners.

Horizonscan

Business Continuity

Horizonscan specialise in making businesses more resilient to crisis events. Their team consists of a range of relevant subject matter professionals, who are experts in coaching and training. They deliver consultancy on Business Continuity and Crisis Management globally. 

Phishing Tackle

Cyber Security Awareness Training

Phishing Tackle provides cyber security awareness training to help to reduce the risk of a cyber incident caused by human error. Services and products include phishing simulation exercises, micro-training modules and a fully managed service to help support your Human Risk Management strategy.

RiskEye

Reputational Risk

RiskEye provides a robust set of services and solutions to help to protect the reputation of your business and its brand in the digital world. They utilise specialist risk analysts and technology to detect, identify and mitigate online reputational risks.

Popular links

Need further help or assistance?

Call our Risk Help Line to speak to our Risk Management Solutions team for help and advice on

0345 366 6666

Opening times: Monday - Friday* 9:00am - 5:00pm

* Excludes Bank Holidays. The cost of calls to 03 prefixed numbers are charged at national call rates (charges may vary dependent on your network provider) and are usually included in inclusive minute plans from landlines and mobiles. For our joint protection telephone calls may be recorded and/or monitored.

Data security incident trends | ICO

Cyber security breaches survey 2025 - GOV.UK

Contains public sector information published by the Health and Safety Executive and licensed under the Open Government Licence.