General News

Cyber Alerts and Patches: Who Owns the Response?

  • Nicky Whitson
  • 9 October, 2026
Cyber Alerts and Patches: Who Owns the Response?
Picture for Cyber Alerts and Patches: Who Owns the Response?

Why it matters

A security tool can raise the right alert while a business still misses the warning. A new UK data protection case shows why named ownership matters just as much as buying cyber technology.

The Information Commissioner's Office published its findings on 12 August 2026. A hacker had gained access to a public-facing website and content management system between August 2022 and March 2023.

Personal information relating to up to 10,920 people may have been affected. The organisation could not determine conclusively whether the staged information was removed from its systems.

The regulator found gaps in patch management and alert handling. Third-party providers delivered parts of the security service, but responsibility for identifying and monitoring critical updates was unclear.

The affected system had gone without relevant updates for years. Security software also produced warnings during the attack period, yet those alerts were not properly reviewed or escalated.

For an ordinary business, the lesson is straightforward. Outsourcing IT does not remove the need to decide who watches for patches, who approves them and who checks they were installed.

The same applies to monitoring. An alert dashboard is not a response process. Someone needs authority to investigate, isolate a system, preserve evidence and contact the right decision-maker.

Small businesses can be particularly exposed to unclear handovers. A web developer may maintain the website, a managed provider may support devices, and a software vendor may issue updates. Each supplier can assume another party owns the missing task.

The result is a gap between a technical signal and business action. That gap can last through staff changes, contract renewals and supplier changes unless responsibility is written down and tested.

The case also shows the value of network separation. The regulator said segmentation stopped the attacker moving from the compromised web environment into core systems. That reduced the potential scale of harm.

No single control provides certainty. Patching, monitoring, logging, access control, backups and network design work together. Weak records can also make it harder to establish what happened after an incident.

For SMEs, the practical question is simple: can the business name the person who owns each security task? If the answer is only the name of a supplier, the handover may need closer review.

 

Insurance implications

Cyber insurance is not a replacement for security controls. It can support incident response and certain insured costs, subject to the policy wording, limits, excesses and circumstances.

Patching and monitoring can be relevant when arranging cover. Insurers may ask about software updates, unsupported systems, managed service providers, security monitoring and how quickly serious alerts are handled.

Answers should reflect the real process. A business should not describe patching as managed simply because a supplier contract mentions it. The useful evidence is who receives updates, how risk is assessed, when work is completed and how exceptions are recorded.

Notification also matters. Policies can contain requirements for reporting circumstances or incidents, and response services may need to be accessed through an insurer-approved route. The exact process depends on the policy.

If an alert suggests an active compromise, avoid deleting logs or rebuilding systems without advice. Those steps can remove evidence needed by technical responders, regulators, legal advisers or insurers.

Supplier contracts deserve a separate check. The business should know which party owns each control and what happens outside normal hours. Liability limits, incident cooperation and access to logs can become important after a breach.

 

Useful checks include:

  • List every internet-facing system and identify its business owner.
  • Name who monitors vendor updates and security advisories.
  • Set timescales for assessing and applying critical patches.
  • Record who reviews alerts and how serious events are escalated.
  • Test that logs are retained for long enough to support an investigation.
  • Confirm where supplier responsibility starts and ends.
  • Keep the insurer, broker and incident-response contact route accessible offline.
  • Review whether the cyber proposal form still matches the current setup.

 

These checks should be proportionate to the business. A small firm may not need a large security team, but it still needs clear decisions and evidence.

Where a supplier manages the work, ask for reports that show outstanding vulnerabilities, overdue actions and alert outcomes. A monthly green status means little if nobody can explain what was tested.

Cover decisions and claims remain policy-specific. The wider lesson is that clear ownership helps the business reduce risk and explain its controls accurately before an incident.

 

Speak to Ratcliffes

If responsibility for patches, alerts or incident response is unclear, call Ratcliffes on 01242 544544 to review whether your Cyber Liability cover and response arrangements still fit. We can help you prepare the insurance questions to take into your next IT supplier review.

 

Sources


Back to Insights page...

We use cookies for analytics to improve your experience on our website and check our ads performance.