25th June 2021
Do we need Cyber Insurance?
Cyber Insurance is an added layer of protection that some companies may feel isn’t necessary for their organisation.
We have spoken to many businesses and business owners about the benefits of Cyber Insurance, here are some of the most common misconceptions relating to this kind of insurance and the reasons why Cyber Insurance is a very important way to safeguard not only your online security but also your business as a whole:
WE HAVE A GREAT IT TEAM/PAY OUR OUTSOURCED IT CONSULTANT TO SECURE OUR NETWORKS, SO WE DON’T NEED CYBER INSURANCE
A secure network is a fantastic way to protect your business from cyber threats, however, no person or business can ever be 100% secure. Your network is not the only way a criminal may attempt an attack.
Social engineering is a technique that targets the people in your business rather than your systems or network.
Cybercriminals may access your systems just to watch how a business works. They will learn who does what and which positions people hold within your business. They will study the type of language used by you and your staff and only when they are confident they can pull off a believable impersonation will they strike.
Criminals access your company email system and after weeks or even months of research, they will impersonate the Finance Director. From the FD’s email account, they will send a message to a junior member of staff that sounds just like the FD.
We’ve just taken on ABC Limited as a new supplier so that we can get those widgets delivered for Claire’s big project. Can you set them up and transfer £100k to the attached bank account urgently for me? We need the widgets delivered tomorrow so the transfer needs to go through before 11am.
If Dave doesn’t double-check this request in person and simply completes the request, your company will be £100,000 down with no way to recover that money.
This has become even more important over the last 12 months as more and more businesses move to some degree of remote working. Simply checking with a colleague that an email is genuine can save a business huge sums of money, however, if those colleagues are no longer in the same office and are now possibly in different towns, that quick check is harder to make.
A secure network cannot protect you from this kind of social engineering, but a good cyber insurance policy can.
OUR DATA IS ALL HOSTED BY AN EXTERNAL CLOUD PROVIDER, SO IT’S THEIR RESPONSIBILITY, NOT OURS
If your cloud service provider is attacked and their service goes down, this may mean you cannot operate, your business may potentially suffer business interruption and you will incur additional costs as you strive to continue trading. Attempting to recoup these losses from your IT provider can prove extremely difficult.
If a data breach occurs at your cloud service provider that you are responsible for, it is still your responsibility, and you will be liable for any financial losses incurred.
WE’RE ONLY SMALL, CYBERCRIMINALS ONLY TARGET THE BIG BOYS SO WE’RE NOT A TARGET
We’ve all seen recent news stories telling us about huge data breaches at big companies such as British Airways and Talk Talk and it is true that criminals will target businesses of this size as their potential return can be enormous.
It is also true however that criminals will also target small businesses as they are seen as “low hanging fruit” that are much easier to pluck. Smaller companies will have less security than bigger companies and the staff of SMEs are less likely to be trained to spot various types of suspicious behaviour that could lead to a breach.
Attacks on small businesses do not make headlines because they are not deemed newsworthy. However, according to a recent report, 58% of cyberattack victims were classed as small businesses.
EVEN IF THEY STEAL FUNDS FROM OUR ACCOUNT, THE BANK HAS A DUTY OF CARE TO PROTECT ME
Unfortunately, this is not the case if you are found to be negligent in allowing access to a fraudster. Your bank will not protect you if you or an employee of yours is tricked into transferring the funds themselves. No money will be reimbursed unless the bank itself is at fault.-------------------------------------------------------------------------------------------