Skip to main content
Comment & Opinion

Cyber risk and debt facilities considerations for lenders and borrowers

“Cybersecurity is not just an IT issue; it’s a real risk for all businesses with material implications for your financing arrangements.”

Lauren Hall, Senior Associate, Banking & Finance
Lauren-Hall

The UK Government’s 2025/26 Cyber Security Breaches Survey, issued on 30 April 2026, showed that cyber risk is now a mainstream business issue, with 43% of UK businesses experiencing a cyber breach or attack in the last year. Exposure increases significantly with scale, affecting around 65% of medium‑sized businesses and nearly 70% of large organisations (69%), compared to just over 40% of micro and small businesses. This reinforces the importance of robust cyber risk management as organisations grow and operate in increasingly complex digital environments.

For lenders and borrowers, cyber considerations in relation to financing arrangements should receive the same attention as other critical risks. The questions for every finance transaction are simple: could a cyber event impair debt service, disrupt operations, and erode asset value or goodwill?

While you can put plans in place to reduce harm, including business continuity and disaster recovery plans, it’s important to consider these risks and how they can arise and impact debt funding arrangements.

Before funding

Proactive assessment is now critical. Lenders are increasingly treating cybersecurity as a core lending consideration, with cyber‑related deliverables often required as conditions precedent. These typically include a documented incident response plan, appropriate assurances from key third‑party suppliers, and evidence of fit‑for‑purpose cyber protection measures and insurance that would cover losses resulting from a cyber breach.

We have launched an interactive Cybersecurity Tool, designed to help and support businesses assess and strengthen their cyber resilience over three key stages: protect and prepare, test and train, and react and rebuild.

Directors’ duties

Cyber risk is not just an IT concern; directors must assess and manage these exposures as part of their statutory duties. Directors should keep a continuous, proactive oversight of cyber resilience, ensuring governance frameworks, risk registers and investment decisions properly show the organisation’s evolving threat landscape.

Boards should regularly challenge management on incident readiness, supply chain and third‑party vulnerabilities, data governance and recovery capability, and make sure that testing, training and resourcing are calibrated to the organisation’s operational profile and financial risk exposure.  Read our previous article to find out more about directors’ duties.

If an incident hits

A cyberattack can decrease revenue, increase costs, and strain financial covenant headroom. Lenders will very closely monitor cross-defaults, solvency triggers, and supply chain contagion and portfolio company borrowers may need short-term liquidity and covenant flexibility.

Insurance is not a complete solution. Scope often excludes lost profits, and proceeds often need to be applied in prepayment, so the details of coverage should be assessed by lenders before agreeing to the placement of insurance. Robust notification mechanics to lenders and regulators, periodic risk reporting, and cyber-specific undertakings provide a more reliable toolkit than relying solely on material adverse effect clauses.

Why this matters now

Recent cyber-attacks show that the financial consequences can be severe. Marks & Spencer has indicated an approximate £300 million reduction in operating profit following its 2025 cyberattack, with disruption to trading lasting several weeks. Similarly, Jaguar Land Rover’s 2025 cyber incident resulted in long factory shutdowns and material losses while operations were restored. It goes without saying that both events were disastrous for these very large and high-profile businesses.

These examples highlight why cyber resilience should be assessed with debt capacity and why lenders are increasingly focused on the resilience of portfolio companies as part of their broader credit and risk assessment.

Practical actions for documentation and monitoring

As lenders sharpen their focus on cyber resilience, borrowers should expect stricter requirements when raising debt and prepare to streamline the process and protect valuations.

Conditions precedent: expect lenders to request clear evidence of cyber readiness before closing. This may include a robust incident response plan, board-approved cyber policy, key supplier assurances, and confirmation of cyber insurance with lender-acceptable endorsements.

Information undertakings: finance Documentation will likely include obligations for quick breach notification, periodic threat and risk reporting, and post-incident remediation updates.

Covenants and events of default: traditional material adverse change language is increasingly seen as inadequate for addressing cyber risks, so lenders are introducing bespoke covenants requiring companies to maintain defined cyber controls and to remediate incidents within realistic, evidence‑based cure periods.

Security: lenders are ever more aware of how cyber incidents can undermine the value and integrity of digital assets, IP, and operational systems. As a result, you may be required to evidence robust back‑ups, regular disaster‑recovery testing, and safeguards that preserve control and asset value in a security‑enforcement scenario.

Insurance proceeds: lenders may seek rights to apply cyber insurance proceeds to prepay facilities; you should consider restrictions to retain proceeds needed for recovery, potential carve-outs for third-party losses, and reinvestment periods. This remains a developing area in which lenders have yet to establish consistent market norms, but these are the trends we are increasingly seeing as lenders respond to the evolving risk landscape.

How we can help

By combining the expertise of our Finance and Cybersecurity & Data Protection teams with our interactive cybersecurity tool, we can help you assess your resilience, close critical gaps, and respond confidently when incidents occur. Get in touch to find out how we can support your organisation in strengthening its cyber resilience.

Lauren
Hall

Senior Associate

Banking & Finance

CONTACT DETAILS
Lauren's contact details

Email me

CLOSE DETAILS

Nick
Stubbs

Partner

CONTACT DETAILS
Nick 's contact details

Email me

CLOSE DETAILS