As social engineering surges, it’s time to insure and secure your business, says Espria
Building a cyber-aware culture and threat-protected business is the smartest risk investment to stay on top of the threat landscape.
In a move that highlights the escalating cyber threats, the UK government recently announced the launch of a dedicated Vulnerability Research Institute (VRI) to bolster UK business cyber security defences. Designed to bring together the public and private sectors as well as individuals, the VRI emphasises the importance of collaboration across our cyber defences.
“There is a broader systemic risk that many companies have begun to face: even with great internal defences, human error can compromise even the most robust security.” said Brian Sibley, VCTO, at Espria.
The UK’s new Vulnerability Research Institute adds a layer of promise by advancing knowledge sharing and understanding of industry wide infrastructure weaknesses.
“A 2025 Sophos report found that social engineering attacks such as malicious emails caused 37% of ransomware attacks in the UK last year – the very same modus operandi of Scattered Spider. Adding to the concern, over 40% of ransomware victims lacked the expertise to detect and stop an attack.
“These figures raise an important question; what is the business sector doing to plug the skills gap? Organisations must leverage vulnerability intelligence from institutions like VRI but also train staff to spot and respond appropriately to social engineering attacks to close the gap at both the human and technical level.”
Sibley emphasises the advantages of employee training in relation to recent attacks to raise general awareness across the business.
“For businesses lacking in formal training, they may find that the weakest link in security is not their tools and IT but their own people. Human error is what threat actors rely on as it only takes a momentary lapse in judgment to fall victim. To combat this, it is critical to continuously refresh employee knowledge on what to look out for.
“From the IT team to the reception desk, employees across the business should be provided with targeted training on threat spotting and taught the correct procedures for reporting suspicious behaviour and credentials resets. Additional training should also be considered for those who would be involved in the incident response process.
“However, the work does not stop there; businesses should regularly revisit their incident response plans and stress test them with cyber defense exercises. These can identify any gaps that could create issues during a real life incident.”
Sibley continued, “Preparation is equally important when it comes to creating a streamlined incident response. This level of preparedness and risk mitigation is something cyber insurers view favourably. Unfortunately, even the best cyber protection isn’t bulletproof, but the true value of a managed detection and response service lies in the expertise of its threat hunters and the remediation and recovery tools it delivers”.
“Depending on the nature of your business and the type of data you handle, such as payment information or personal customer details, your organisation may be at greater risk of common cyberattacks. Once robust monitoring and detection strategies are in place, cyber insurance can help protect the business from significant financial losses in the event of an incident.”
Sibley concluded, “Initiatives such as VRI may prove valuable in an increasingly digital world but this must be coupled with an internal proactive approach to cyber security. Although the retail sector is in the spotlight, threat actors are constantly seeking the weakest entry points for any and all businesses. Rather than waiting for your sector to make headlines, businesses should reassess their security controls and training now, and invest in cyber insurance to close the door of opportunity.”
You may be interested in
Phishing just got personal
AI-powered phishing attacks are becoming harder to detect, with increasingly sophisticated emails bypassing traditional security controls. As a result, organisations are placing greater focus on Human Risk Management, recognising employee behaviour as a measurable cybersecurity risk. SecureLearn, powered by KnowBe4 and fully managed by Espria, helps businesses reduce human risk through continuous security awareness training, phishing simulations, targeted coaching, and board-ready reporting that demonstrates improvement over time.
The Hidden Environmental Cost of Office Printing
Most offices know that reducing paper is good for the environment, but few have visibility over what their printing actually costs in resources: energy, paper, and consumables. A managed print service brings sustainable office printing into focus by measuring what is actually happening, rather than estimating it. Every printer left on standby overnight, every unnecessary colour print, and every cartridge thrown away with usable toner left inside adds up. For a business printing several thousand pages a month, the difference between an efficient and inefficient setup can be significant, both in cost and in environmental…
Is Your Office Printer a Way In for Cybercriminals?
Most small businesses think of cyber security as a laptop problem, a server problem, or an email problem. The office printer rarely gets a mention, yet it is connected to your network, holds a hard drive, and processes some of the most sensitive documents in the business, from invoices to HR letters and client contracts. However, it is important to realise that office printer vulnerabilities can be exploited by cybercriminals, potentially leading to cyber attacks. A modern multifunction printer is a computer. It has an operating system, a network connection, often Wi-Fi, and increasingly a…
The Cyber Resilience Act: what it means for your business
By Stephen Cook From 11th September 2026, a new EU regulation starts changing how connected products and software are built, sold and supported – and UK businesses trading into Europe are firmly in scope [1] [2]. Here is what the Cyber Resilience Act actually requires, why it matters beyond the compliance paperwork, and how Espria helps clients meet it. What is the Cyber Resilience Act? The Cyber Resilience Act (CRA) is an EU regulation – Regulation (EU) 2024/2847 – that sets mandatory cybersecurity requirements for “products with digital elements.” In practice, this covers hardware and software that can connect to a device or network: IoT devices,…
The Hidden Costs of Printing: How Managed Print Services Reduce Business Waste
Introduction For many organisations, printing is viewed as a routine operational expense. Printers are purchased, toner is replaced when needed, and documents continue to flow through the business without much scrutiny. However, the true cost of printing extends far beyond paper and ink. Unmanaged print environments often create hidden expenses through inefficient device usage, excessive energy consumption, IT support demands, security risks, and employee downtime. These costs can accumulate significantly over time, impacting productivity and profitability. This is particularly relevant as businesses seek to optimise operations, reduce waste, and improve sustainability while controlling expenditure. Whether…
Can Your Business Actually Recover? The Operational Resilience Question Most SMEs Cannot Answer
Operational resilience is not a technology problem. It is a business problem. And until boards and leadership teams own it, no amount of IT investment will be enough. The Gap Between Confidence and Reality Most organisations believe they are more resilient than they are. The backups are running. The antivirus is licensed. The IT team knows what they are doing. That confidence, in our experience, rarely survives first contact with an actual incident. The question is not whether your systems are protected. The question is whether your business can keep delivering its most important services…





