Aviva policyholders can benefit from exclusive access to our in-house Aviva Cyber risk management team.
Our expert consultants are dedicated to help safeguard your business from cyber threats. We provide onsite cyber risk assessments to help identify potential vulnerabilities in your organisation and our external vulnerability scanning capabilities can help to make sure that your digital perimeter is secure against external threats. Leveraging our intelligence source, we can provide you with the latest insights to help to stay ahead of emerging risks.
We also have a library of Loss Prevention Standards, providing guidance on cyber-related issues and a collection of cyber Specialist Partners, aimed at helping to support your business with things such as phishing testing, managed detection and response services.
Do you need specialist Cyber risk management guidance?
Get in touch with our expert cyber risk managers to support you and your business.
Did you know?
38.59%
rise in data security incidents reported to the ICO from 2022-20241
8.58 million
estimated and approximately cyber crime attempts against UK businesses in 20242
Guidance to help manage cyber risks
Download our range of Loss Prevention Standards (LPS)
Our Cyber offering
Whether you're looking to assess your current posture, train your teams or prepare for the unexpected, the Aviva Risk Management Solutions (ARMS) Cyber team is here to help you stay ahead of the threat.
Aviva Risk Training Solutions (ARTS)
External attack surface assessments
Incident response planning support
IT disaster recovery reviews
Cyber risk quantification assessments
Cybersecurity certifications
ISO 27001:2022 support
Self-assessment
Cyber Assessment
Our Cyber Assessment is designed to provide a clear, structured view of your organisation’s current cyber risk posture, structured around the six core functions of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
1. Govern
- Who is responsible for cyber risk governance?
- Do you have written cyber policies and procedures?
- How is cyber risk integrated into wider enterprise risk management?
2. Identify
- Are third-party risks assessed and managed?
- Is there a data protection impact assessment process?
- Do you conduct yearly cyber risk assessments?
3. Protect
- What technical controls are in place?
- How is access to sensitive data managed?
- Are staff trained in cyber awareness and secure behaviours?
4. Detect
Capabilities to identify cyber events and anomalies
- Do you have tools in place to detect suspicious activity?
- Is there a process for identifying/escalating incidents?
- How do you detect unauthorised access or data exfiltration?
5. Respond
Preparedness for incidents
- Do you have a documented incident response plan?
- How is communication managed during a cyber incident?
- Are roles and responsibilities clearly defined in the event of a breach?
6. Recover
Ability to restore operations
- Is there a business continuity/disaster recovery plan?
- How quickly can critical systems be restored?
- Are post-incident reviews conducted and documented?
How we work with you
- Initial engagement: Introducing the assessment to understand your organisational structure and agree on the scope
- Documentation review: Reviewing documentation such as policies, network diagrams, incident response plans and governance frameworks
- Structured discussion: Conducting a guided conversation with stakeholders, exploring how cyber risk is managed across people, processes and technology
- Scoring and benchmarking: Analysing and scoring responses to benchmark your organisation against Aviva’s standards and your peers
Our Specialist Partners to help manage cyber risks
To access these solutions at preferential rates and terms, contact our Specialist Partners.
Horizonscan
Business Continuity
Horizonscan specialise in making businesses more resilient to crisis events. Their team consists of a range of relevant subject matter professionals, who are experts in coaching and training. They deliver consultancy on Business Continuity and Crisis Management globally.
Phishing Tackle
Cyber Security Awareness Training
Phishing Tackle provides cyber security awareness training to help to reduce the risk of a cyber incident caused by human error. Services and products include phishing simulation exercises, micro-training modules and a fully managed service to help support your Human Risk Management strategy.
RiskEye
Reputational Risk
RiskEye provides a robust set of services and solutions to help to protect the reputation of your business and its brand in the digital world. They utilise specialist risk analysts and technology to detect, identify and mitigate online reputational risks.
Popular links
Guidance by Risk Type
Quickly navigate all our guidance here to help manage the relevant risks across your business.
Our Specialist Partner Network
Find out more about the depth of solutions provided by our Specialist Partners.
Latest News and Insights
Access all Aviva Risk Management news and insights.
Need further help or assistance?
Call our Risk Help Line to speak to our Risk Management Solutions team for help and advice on
0345 366 6666
Opening times: Monday - Friday* 9:00am - 5:00pm
Email us at: riskadvice@aviva.com
* Excludes Bank Holidays. The cost of calls to 03 prefixed numbers are charged at national call rates (charges may vary dependent on your network provider) and are usually included in inclusive minute plans from landlines and mobiles. For our joint protection telephone calls may be recorded and/or monitored.
1 Data security incident trends | ICO
2 Cyber security breaches survey 2025 - GOV.UK
Contains public sector information published by the Health and Safety Executive and licensed under the Open Government Licence.