Care Circle Network | Cyber Insurance Is Not a Recovery Plan: Where Cover Ends and Operational Resilience Begins

Adult social care is no longer simply using digital technology.

It is becoming operationally dependent on it.

Digital social care records hold information about:

  • medication;
  • mobility;
  • communication;
  • nutrition;
  • mental capacity;
  • safeguarding;
  • behaviour;
  • personal preferences;
  • and changing health needs.

Electronic medicines systems guide administration.

Rostering platforms determine who should arrive, where and when.

Payroll, HR and training systems support the workforce around the care.

Telecare, alarms and monitoring technologies can identify events requiring intervention.

Email, broadband and mobile services connect providers with families, commissioners, pharmacies and health professionals.

When these systems work, they can improve visibility, speed and continuity.

When they fail, the consequences are not confined to an IT department.

A cyber incident can become a care-delivery incident within minutes.

That distinction is the starting point for understanding cyber insurance.

Insurance may help fund parts of an insured incident.

It may provide access to specialist technical, legal or communications support.

Depending on the wording, it may respond to particular interruption costs or third-party claims.

But it cannot administer the evening medicines.

It cannot tell an unfamiliar agency worker how someone communicates pain.

It cannot reconstruct tomorrow morning’s home-care rota from memory.

It cannot reassure a person whose alarm has stopped connecting.

And it cannot decide which care-critical system should be restored first.

Cyber insurance may support the recovery. It does not run the service while recovery is taking place.


Digital Progress Has Increased the Importance of Recovery

By the 30 June 2026 deadline, almost 76.5% of CQC-registered adult social care services in England had an up-to-date Data Security and Protection Toolkit.

That represented 22,429 services, including 12,887 care homes and 9,562 home-care services. Almost 14,500 had published the toolkit for at least three consecutive years.

This is substantial progress.

It shows that data protection and cyber security are becoming established parts of care-provider governance.

But the DSPT is a self-assessment and improvement mechanism—not proof that every provider could maintain safe care through a complex ransomware attack, software failure or supplier outage.

The Department of Health and Social Care’s major study of cyber security in adult social care reached a similar conclusion. Participants regarded the DSPT as useful for increasing awareness and basic controls, but did not view completion alone as an accurate measure of cyber resilience. The study found concerns that some organisations approached it as a compliance exercise without equivalent depth of practical understanding.

That is not an argument against the DSPT.

It is an argument for completing the work it begins.

A policy stating that backups exist needs to be followed by evidence that they can be restored.

A continuity plan needs to be tested under realistic conditions.

A supplier-assurance process needs to continue after procurement.

And an insurance schedule needs to be understood in relation to the systems, people and losses the organisation could actually experience.


The Threat Is Broader Than Ransomware

Ransomware receives the greatest attention because its effect is visible and dramatic.

Systems become inaccessible.

Files may be encrypted.

Data may be stolen.

Attackers may demand payment while threatening publication or further disruption.

But the cyber exposure facing care providers is wider.

The government’s 2025/26 Cyber Security Breaches Survey found that 43% of UK businesses identified a breach or attack during the preceding 12 months. Within the health and social care sector, the figure was 33%, although the sector-specific result was based on a relatively small sample and should therefore be interpreted cautiously. Phishing remained the most frequently identified attack type.

The dedicated DHSC adult social care study provides more care-specific context.

Based on fieldwork involving 575 regulated providers, it found that one third reported experiencing a cyber incident or unsuccessful attack during the previous three years. Among affected providers, phishing was the most common event, followed by impersonation. Just under half of the incidents or attacks were reported as originating from a third-party organisation.

This creates several distinct loss scenarios.

A provider may face:

  • encryption and operational interruption;
  • theft of personal data;
  • fraudulent payment instructions;
  • compromised email;
  • unauthorised network access;
  • corrupted systems;
  • accidental disclosure;
  • supplier failure;
  • or manipulation of an employee through impersonation.

These incidents do not necessarily trigger the same technical, legal or insurance response.

A policy described broadly as “cyber cover” should not be assumed to treat every technology-related loss identically.


Cyber Cover Is Not One Standard Product

Cyber insurance is often discussed as though it were one consistent form of protection.

In practice, policies differ.

The NCSC advises organisations to examine what a policy covers, what it excludes, what services are available during an incident and what controls or information must be maintained for the policy to respond as intended. It also notes that some cyber-related protection may appear within other policies, while those policies may alternatively contain cyber exclusions.

Depending on the wording and circumstances, areas that may be addressed can include:

  • technical investigation;
  • system restoration;
  • legal assistance;
  • crisis communications;
  • interruption losses;
  • privacy liabilities;
  • and certain third-party claims.

That does not mean each element is present in every policy.

Nor does it mean every cost following an incident falls within the insured loss.

The appropriate interpretation depends on the individual contract, facts, conditions, exclusions, limits and notification requirements.

This is precisely where editorial coverage must remain careful.

Care Circle Network can explain the risk categories and questions that arise.

It cannot determine whether a particular provider’s policy would respond or whether one form of cover is suitable.

Those are policy-specific matters for an appropriately authorised intermediary, insurer or relevant professional adviser.


Where Insurance May Add Value

The immediate hours following a serious incident are difficult because several workstreams begin simultaneously.

The provider needs to understand what has happened.

It needs to contain further damage.

It needs to maintain care.

It may need to assess whether personal information is at risk.

It must communicate with staff, suppliers and other relevant parties.

It may require specialist technical, legal and communications expertise before its ordinary advisers are available.

The NCSC notes that some cyber insurance arrangements include access to services such as IT forensics, legal assistance, public-relations support and incident-response specialists. It also explains that insurance may help reduce financial disruption and support legal or regulatory work after an event.

This response infrastructure can be significant.

A smaller care provider may not retain specialist forensic, privacy and crisis advisers directly.

An incident-response route linked to the insurance arrangement may give the organisation access to expertise quickly.

But the existence of external support does not remove the need for internal ownership.

The advisers will still need the provider to explain:

  • which systems are critical;
  • where information is stored;
  • who has administrative access;
  • which suppliers are involved;
  • what care is at immediate risk;
  • and which decisions have already been made.

The response cannot be outsourced completely because the consequences remain operationally specific to the provider.


The First Gap: Insurance Does Not Prevent the Attack

The NCSC’s position is direct: cyber insurance does not prevent a breach or attack and does not solve the organisation’s cyber-security weaknesses. Providers remain responsible for implementing appropriate controls around the things they need to protect.

This sounds obvious, but it exposes a common governance problem.

Insurance can create false reassurance when it is treated as the response to weak security rather than one component of a broader risk strategy.

A provider may believe it has transferred the risk while continuing to operate with:

  • shared passwords;
  • former staff accounts;
  • unsupported devices;
  • weak multi-factor authentication;
  • unreliable backups;
  • untested continuity plans;
  • or excessive dependence on one software supplier.

The financial consequences may be partly transferable.

The care responsibility is not.

The person receiving support does not become the insurer’s service user during the outage.

The provider remains responsible for maintaining safe arrangements.


The Second Gap: Insurance Does Not Create a Downtime Care Model

Imagine a residential service discovers at 6:15am that its digital care record and eMAR are inaccessible.

The provider may be insured.

The emergency contact may be called immediately.

Technical specialists may begin investigating.

None of that answers the first operational question:

How will the 7am medicine round be completed safely?

Staff need current information about:

  • medicines;
  • allergies;
  • omitted or refused doses;
  • variable instructions;
  • covert-administration decisions;
  • PRN guidance;
  • and recent changes.

They also need to prevent duplicate administration when the system returns.

The same problem applies to:

  • food and fluid guidance;
  • repositioning;
  • seizure protocols;
  • positive behaviour support;
  • scheduled visits;
  • and health-escalation instructions.

A recovery plan is therefore not simply a technical restoration plan.

It must explain how care continues before restoration.

The NCSC tells boards that effective incident planning should support business continuity and prioritise the organisation’s essential functions and the systems and information required to maintain them.

For a care provider, the essential functions are human.

The continuity model must begin with what people need during the outage, not with the server architecture.


The Third Gap: A Backup Is Not a Recovery Outcome

The DHSC adult social care study found that 81% of participating providers backed up their data and that 96% of those providers were confident their backups were complete and usable.

The same study recorded concern from sector representatives that backups and continuity arrangements might not always be implemented as robustly as providers believed, and that recovery times could be underestimated.

This is a critical distinction.

A backup can exist while remaining:

  • inaccessible;
  • incomplete;
  • outdated;
  • infected;
  • dependent on compromised credentials;
  • or incapable of restoring the complete environment.

The NCSC describes backups as essential to recovery from destructive ransomware but warns that attackers frequently target backups and infrastructure during the early stages of an attack. Backups therefore need specific protection rather than being assumed safe by default.

Care leaders need to understand what “restored” actually means.

Restoring a database does not automatically restore:

  • the application;
  • user identities;
  • access permissions;
  • integrations;
  • mobile devices;
  • supplier connections;
  • or the knowledge needed to validate the recovered information.

The provider should also understand how long recovery may take.

A backup capable of restoring the system in four days may be technically successful.

It may not meet the operational requirement of a service that needs medication information within an hour.


The Fourth Gap: Third-Party Failure Can Become the Provider’s Incident

Care providers increasingly rely on external organisations for:

  • cloud hosting;
  • managed IT;
  • digital care records;
  • eMAR;
  • payroll;
  • rostering;
  • telecare;
  • payment processing;
  • and communications.

The provider may have strong internal controls and still experience serious disruption because a supplier has been compromised.

The DHSC care-sector research found that 44% of incidents reported by affected providers originated from a third-party organisation. It also identified reliance on a relatively small number of technology suppliers as one of the sector’s underlying vulnerabilities.

The same research found that provider monitoring of supplier cyber risk after procurement was limited in some cases.

Supplier support tended to focus on system setup and functionality, while assistance when the care provider itself experienced an incident could be offered on a goodwill basis rather than through a formal commitment.

This has direct insurance and continuity implications.

The provider needs to understand:

  • whether losses caused by supplier failure are treated differently;
  • which supplier systems are critical;
  • how quickly the supplier must notify the provider;
  • what offline information will be supplied;
  • what contractual recovery commitment exists;
  • and who coordinates multiple affected organisations.

A contract stating that the supplier is responsible for security does not ensure that care can continue during the supplier’s outage.

And an insurance arrangement cannot repair a continuity plan that never considered a third-party event.


The Fifth Gap: Cyber Loss and Financial Crime Can Diverge

Not every digitally enabled financial loss is treated as the same type of event.

One of the most important examples is business-email compromise.

An attacker may impersonate:

  • a director;
  • payroll contact;
  • supplier;
  • commissioner;
  • employee;
  • or finance professional

and persuade somebody to change bank details or approve a fraudulent transfer.

This may involve compromised email or sophisticated social engineering.

But the principal loss is money transferred voluntarily under deception rather than data encrypted or systems interrupted.

The NCSC specifically warns that some cyber policies may not cover money lost through business-email-compromise fraud. It advises organisations to understand the distinction and check the actual wording rather than assuming a common cyber label creates universal protection.

This makes financial controls part of cyber resilience.

Useful operational controls can include:

  • independent verification of bank-detail changes;
  • separation of payment duties;
  • call-back procedures using known numbers;
  • and additional approval for unusual transfers.

Whether a particular loss sits within cyber, crime, fidelity or another section is contract-specific.

The wider lesson is not.

Providers need to map the loss scenarios they could experience rather than assume that purchasing one cyber-labelled product addresses all technology-enabled crime.


The Renewal Declaration Is an Operational Statement

Cyber insurance applications and renewals may ask about:

  • multi-factor authentication;
  • backups;
  • endpoint protection;
  • staff training;
  • privileged access;
  • patching;
  • remote access;
  • incident-response planning;
  • and supplier controls.

These questions are not merely administrative.

They describe how the organisation operates.

The NCSC stresses that security information given to insurers should remain accurate and current. It warns that where an organisation states that controls exist when they do not, this may affect whether the insurer is obliged to meet a claim.

This creates a governance responsibility above the person completing the form.

Finance may know the premium.

The IT supplier may know the technical controls.

HR may know the training position.

Operations may know about workarounds.

The registered manager may know that staff continue sharing a device or login because the current setup is impractical.

No single person necessarily holds the whole truth.

A reliable renewal process should therefore draw information from the people who understand:

  • technology;
  • contracts;
  • workforce practice;
  • data protection;
  • finance;
  • and care delivery.

The insurer’s question may be technical.

The answer often depends on operational reality.


The Incident Notification Clock Does Not Wait for Certainty

The early stages of a cyber incident are characterised by incomplete information.

The provider may not know:

  • how the attacker entered;
  • what information was accessed;
  • whether data was copied;
  • which systems are trustworthy;
  • or how long recovery will take.

Yet several notification and communication processes may already be active.

Where a personal data breach meets the reporting threshold, the ICO says it must be reported without undue delay and within 72 hours of the organisation becoming aware of it. The ICO advises organisations to begin a breach log immediately, contain the event and record the facts and decisions as the investigation develops.

Insurance policies can have their own notification requirements, which vary.

The NCSC’s ransomware guidance states that organisations with cyber insurance should report the attack through the insurer or broker’s incident route, which may operate outside normal business hours.

This does not mean every suspicious email requires every external organisation to be notified.

It means the provider needs a pre-agreed decision pathway.

The organisation should know:

  • who assesses the incident;
  • who holds policy details;
  • who contacts the relevant parties;
  • what evidence must be retained;
  • and who can act when senior leaders are unavailable.

A cyber incident beginning at 2am on a Sunday should not wait for somebody to search an inbox for the policy schedule on Monday morning.


Evidence Can Determine Both Recovery and Claim Progress

During a crisis, documenting activity can feel secondary to restoring service.

But a reliable evidence trail supports:

  • technical investigation;
  • regulatory reporting;
  • internal learning;
  • communication;
  • loss calculation;
  • and insurance notification.

The provider may need records of:

  • when the incident was discovered;
  • which systems were affected;
  • who made each decision;
  • what external support was contacted;
  • which additional costs were incurred;
  • how normal operations were disrupted;
  • and when services were restored.

This is particularly important where the provider is trying to distinguish ordinary expenditure from incident-related additional cost.

Examples may include:

  • temporary devices;
  • overtime;
  • agency cover;
  • manual administration;
  • specialist advisers;
  • emergency communications;
  • and alternative systems.

The editorial point is not that every cost will be insured.

That can only be determined from the relevant policy and facts.

It is that poor evidence can make it harder for the provider, insurer, legal advisers and regulators to understand what occurred and what loss followed.


A Care Provider’s Loss Has Several Layers

A cyber incident should not be understood only through the cost of repairing computers.

For adult social care, the impact may develop across five layers.

Care continuity

Can people still receive medicines, visits, meals, repositioning, emergency support and appropriate escalation?

Technical recovery

Can systems, data, accounts, devices and integrations be restored safely?

Privacy and legal response

Has personal information been lost, changed, disclosed or made unavailable, and what notification or communication duties arise?

Financial loss

What income, additional expenditure, fraud, supplier liability or interruption has occurred?

Workforce and reputation

How much additional pressure is falling on employees, and how will confidence be maintained among people, families, commissioners and staff?

These layers overlap.

A delayed technical recovery increases workforce cost.

A weak continuity plan may increase the effect on people.

Poor early communication may deepen reputational harm.

The insurance discussion should therefore begin with the complete incident—not merely the damaged technology.


The Human Cost of Recovery

Cyber incidents create intense pressure on employees.

Care staff may be asked to:

  • revert to temporary records;
  • repeat documentation;
  • work additional hours;
  • contact families;
  • verify information manually;
  • and operate with reduced visibility.

Managers may need to make rapid decisions while balancing:

  • safeguarding;
  • medicines;
  • staffing;
  • regulatory communication;
  • and technical advice they may not fully understand.

The DHSC sector study found that additional staff time was one of the most commonly reported effects among providers experiencing incidents. For providers reporting at least one incident, average costs were much higher than across the full survey sample, and the reported range included a small number of very substantial losses.

These figures were based on provider-reported experience and should not be used as a prediction of future loss.

They do show why the effect cannot be assessed only through an invoice from the IT supplier.

An organisation recovering its system while exhausting its workforce has not achieved complete resilience.

Incident plans should consider:

  • shift cover;
  • decision relief;
  • protected rest;
  • communication;
  • and the long tail of manual reconciliation after systems return.

What Operational Resilience Looks Like Before the Incident

Operational resilience begins with knowing which services matter most.

For a care provider, these might include:

  • access to care instructions;
  • medication administration;
  • visit scheduling;
  • emergency communication;
  • safeguarding;
  • payroll;
  • and telecare response.

The organisation then needs to understand which:

  • systems;
  • suppliers;
  • data;
  • devices;
  • people;
  • and locations

support each service.

This creates a dependency map.

Without it, recovery may focus first on the system that is easiest to restore rather than the one carrying the greatest consequence for people.

A provider should also know the maximum tolerable disruption for each function.

The question is not simply:

How quickly can IT restore the system?

It is:

How long can this care process remain unavailable before people face unacceptable risk?

Those are different measures.


The Board’s Role Begins Before the Policy Renewal

Cyber insurance is sometimes discussed only during annual renewal.

Operational resilience should appear within routine board and provider governance.

Senior leaders should understand:

  • the principal cyber scenarios;
  • care-critical systems;
  • supplier concentration;
  • backup and restoration tests;
  • incident exercises;
  • access weaknesses;
  • workforce training;
  • previous incidents;
  • and the relationship between insurance assumptions and actual controls.

The FCA has made cyber insurance a specific focus for 2026, stating that it is reviewing the market to improve its understanding of risks, opportunities and barriers to purchase. This reflects the broader recognition that cyber insurance is becoming an important but developing part of the risk-transfer market.

That does not change the provider’s regulatory position or create a recommendation to purchase any particular product.

It reinforces the need for clear, evidence-led understanding of what cyber risk looks like in practice.


Test the Response, Not Only the Documentation

A provider may have:

  • a cyber policy;
  • a breach procedure;
  • an insurance schedule;
  • a continuity plan;
  • and a supplier list.

The most useful assurance comes from testing how those documents work together.

A tabletop exercise could begin with a simple scenario:

The care-record and rostering supplier is unavailable. Its status page refers to a security incident. Staff cannot access current care information, and the supplier cannot provide a recovery estimate.

Leaders should work through:

  • the first 15 minutes;
  • first hour;
  • first medicine round;
  • first shift change;
  • first family enquiry;
  • and first reporting decision.

The exercise should expose practical questions.

Who declares the incident?

Who contacts the insurer’s response line?

What happens when the policy documents are stored on the unavailable network?

Which offline record is current?

Who verifies agency-worker instructions?

How are temporary records reconciled later?

What additional expenditure is authorised, and by whom?

The purpose is not to perform perfectly.

It is to discover uncertainty before the real event.


Where Specialist Support Fits

Cyber resilience requires several forms of expertise.

A care provider may need input from:

  • managed IT;
  • cyber-security specialists;
  • data-protection professionals;
  • incident-response organisations;
  • legal advisers;
  • business-continuity specialists;
  • software suppliers;
  • and insurance professionals.

These roles should complement rather than replace one another.

The IT company may secure and restore systems.

The privacy adviser may assess the data impact.

The insurer or authorised intermediary may explain the policy route.

The business-continuity specialist may help maintain essential operations.

The provider retains responsibility for integrating those workstreams around safe care.

This is also where supplier quality becomes visible.

The strongest partners will understand that recovery in adult social care is not complete when the server is running.

It is complete when:

  • care information is reliable;
  • medicines records are reconciled;
  • missed actions are identified;
  • temporary documents are secured;
  • staff understand the restored process;
  • and people experience safe continuity.

Ten Questions Care Leaders Should Be Able to Answer

  1. Which digital system would create the greatest immediate risk to people if it failed?
  2. How would medicines and scheduled care continue during a 24-hour outage?
  3. Which cyber-related losses sit outside our current understanding of the insurance arrangement?
  4. Are the security controls described during renewal operating in practice?
  5. Which third-party suppliers could interrupt several services at once?
  6. When were backups last restored successfully?
  7. Who holds the incident-notification details outside office hours?
  8. How would we record additional expenditure and operational disruption?
  9. Can staff work safely if email, care records and the rota are unavailable together?
  10. What would still need to happen even where the incident were fully insured?

That final question defines the boundary between risk transfer and resilience.


Cyber Insurance Is Part of the Plan—not the Plan Itself

Cyber insurance can play a valuable role.

It may provide financial protection.

It may provide access to expertise that would otherwise be difficult to mobilise quickly.

It may support legal, technical and communications activity during a highly disruptive event.

But the policy cannot know which person requires a thickened drink.

It cannot maintain safe staffing.

It cannot verify that a restored care plan contains the latest information.

It cannot replace local leadership.

And it cannot prevent the provider from experiencing the operational consequences of poor preparation.

That is why insurance and resilience must be discussed together.

The provider needs to understand:

  • the risks it has retained;
  • the losses it may have transferred;
  • the conditions attached to that transfer;
  • and the care responsibilities that cannot be transferred at all.

The strongest position is not an organisation claiming that every loss is covered.

It is an organisation that has reduced the likelihood of an incident, limited its potential impact, prepared to continue essential care and understood where specialist and financial support may begin.

Cyber insurance is not a recovery plan.

It is one possible resource within a recovery model that must already exist.

When the screens go dark, the provider still needs to know what happens next.


Frequently Asked Questions

Can cyber insurance prevent a cyber attack?

No. The NCSC states that cyber insurance does not prevent a breach or solve an organisation’s cyber-security weaknesses. Providers remain responsible for suitable preventive and resilience measures.

What can cyber insurance cover?

The scope varies. Policies may address certain response, restoration, interruption, legal or liability costs, while exclusions, limits and conditions differ. The actual wording and circumstances determine the position.

Is ransomware the main cyber risk facing care providers?

Ransomware can be highly disruptive and costly, but care providers also face phishing, impersonation, unauthorised access, data breaches, supplier outages and technology-enabled fraud. The DHSC sector study identified phishing as the most commonly reported incident among affected providers.

Does the DSPT prove that a provider is cyber resilient?

No. The DSPT is an important self-assessment and improvement mechanism, but sector research found that completion alone was not viewed as proof of deep practical resilience.

Are fraudulent bank transfers always covered by cyber insurance?

No universal assumption should be made. The NCSC notes that some cyber policies may not cover money lost through business-email-compromise fraud. The position depends on the relevant contract and facts.

Why do backups need to be tested?

A backup may be incomplete, inaccessible or vulnerable to the same attack. The NCSC warns that ransomware actors commonly target backups and infrastructure to make recovery harder.

When must a personal data breach be reported to the ICO?

Where the reporting threshold is met, the ICO says the breach must be reported without undue delay and within 72 hours of the organisation becoming aware of it.

What should a care provider test during a cyber exercise?

A useful exercise should test continuity of care records, medicines, rotas, communications, supplier escalation, notification decisions, temporary documentation and the reconciliation process after systems return.


Editorial note

This feature provides general information about insurance, cyber risk and operational resilience. It does not constitute insurance, legal, cyber-security or financial advice, a personal recommendation, or an assessment of any organisation’s insurance needs. Insurance cover, exclusions, conditions and claims outcomes vary. Providers should obtain policy-specific information from an appropriately authorised insurance intermediary, insurer or relevant professional adviser.


Editorial sources

This feature has been developed using information available by 16 July 2026, preserving the integrity of its backdated publication position.

  • Digital Care Hub, Record Numbers of Care Services Have DSPT, published 1 July 2026.
  • Department of Health and Social Care, The State of Cyber Security in Adult Social Care.
  • Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025/26.
  • National Cyber Security Centre, Cyber Insurance Guidance.
  • National Cyber Security Centre, Planning Your Response to Cyber Incidents.
  • National Cyber Security Centre, Ransomware-Resistant Backups.
  • Information Commissioner’s Office, 72 Hours: How to Respond to a Personal Data Breach.
  • Financial Conduct Authority, Regulatory Priorities: Insurance.
CSN Editor
Author: CSN Editor