United Kingdom

Aon urges businesses to strengthen cyber defences as UK Government warns of AI threats

LONDON, 16 July 2026Aon plc (NYSE: AON), a leading global professional services firm, today urged the need for stronger cyber risk management as artificial intelligence (AI) rapidly reshapes the threat landscape.

The advice follows the UK government's April 2026 open letter which warned that advances in AI are rapidly transforming the cyber threat landscape. The letter to UK business leaders highlighted that with "AI cyber capabilities…accelerating even faster than had been previously envisaged", it is clear that AI is now capable of "finding weaknesses in software, writing the code to exploit them and doing so at a speed and scale that would have been impossible even a year ago".

AI can amplify existing cyber risks by automating reconnaissance, generating highly tailored phishing and social engineering campaigns, as well as enabling larger-scale attacks. Capabilities once limited to well-resourced threat actors are becoming increasingly accessible and allowing the less sophisticated to launch complex campaigns.

Rob Kemp, CEO of Commercial Risk in the UK for Aon said:
"Aon's recent Global Risk Management Survey found that cyber-attacks and data breaches remain the top enterprise risk in 2026, with this trend expected to continue well into 2028. However, many businesses describe themselves as "somewhat prepared" at best, citing fragmented governance and limited testing of AI-driven incident scenarios. At the same time, some organisations are still viewing AI as a future issue and delaying the implementation of critical cyber risk management strategies."

While AI has not changed the fundamentals of cyber risk management, it has significantly increased the scale and likelihood of attacks. Aon is encouraging businesses to focus on core controls and to stress-test them actively against AI-enabled scenarios. To build resilience and reduce exposure, organisations should implement an action plan to stress-test cyber defences and address governance, control, and insurance gaps.

Key actions should include:

  • Get the basics right: Maintain robust hygiene across core IT assets, including timely patching, vulnerability remediation, and the decommissioning of end-of-life systems. Provide regular, role-appropriate cyber awareness training for employees at all levels, covering phishing, social engineering, and the handling of sensitive data.
  • Reassess cyber resilience and insurance: Update cyber loss scenarios and stress tests, including impacts on operations, reputation, and regulatory exposure. Review whether existing cyber and related insurance policies appropriately respond to AI-related incidents and benchmark preparedness against sector peers using available data and comparators.
  • Update cyber threat modelling for AI: Map realistic AI-enabled attacks against existing controls to identify gaps across detection, prevention, and response. Prioritise measures such as multi-factor authentication, privileged access controls, and enhanced email and domain protection.
  • Strengthen governance and board reporting: Develop a clear AI risk dashboard covering AI applications in use, key AI-enabled threats, existing controls, and priority remediation actions, with defined ownership and timelines.
  • Test incident and crisis response plans: Conduct tabletop exercises to validate business continuity and incident response plans under AI-enabled scenarios, including rapid reporting, escalation, and coordination with incident response, legal, and insurance partners.

More information about Aon's advice on cyber defences is here.

 

 

Media Contacts:

Colin Mayes
Aon
+44 (0)7801 748138
[email protected]