Why SMEs Need Cyber Insurance

Almost three-quarters of small and medium-sized businesses have suffered a security breach, and a report from the Federation of Small Business (FSB) says cybercrime targeting small and medium-sized businesses costs the UK an estimated £5.26bn a year. 

The report also notes that it costs small businesses disproportionately more than big businesses, when adjusted for organisational size.

Mike Cherry, National Chairman of the FSB, explains: “Small firms take their cyber security responsibility very seriously, but often they are the least able to bear the cost of doing so. Smaller businesses have limited resources, time, and expertise to deal with ever-evolving and increasing digital attacks.”

Why are smaller businesses a target?

Cyber criminals love smaller businesses because they have more digital assets than consumers, and less security than larger organisations. In fact, the FSB report found that only a quarter of small and medium-sized businesses have a strict password policy, and just 4% have a cyber attack strategy.

Phishing for small business

The most common cybercrimes affecting small and medium-sized businesses are phishing emails, spear phishing emails, and malware attacks. 

Other threats include ransomware (where data is seized and encrypted for ransom), hack attacks (where hackers access the company network), and Denial of Service (DOS) attacks which push a huge amount of data to a company’s website to make it crash.

Phishing emails send you to a website that looks legitimate, and ask you to update your account details. The fraudsters can then easily steal your personal information to commit identity theft.

Spear phishing attacks are even more sophisticated, and harder to spot. They target individuals within the organisation, often mimicking their colleagues, by using email headers and addresses to extort money. 

Statistics from cyber security firm Symantec show more than half of spear phishing attacks last December were against SMEs.

Malware attacks are just as damaging. You might click a link or unknowingly download malicious software designed to infiltrate your computer and steal sensitive information, extort money, or send unwanted advertising (adware).

Spear phishing hooks fishing retailer

Let’s look at a somewhat ironic, real-world example of a cyber-crime event which recently impacted one of our customers. The business, a fishing tackle retailer, was caught out by a spear phishing attack just months after taking out a cyber insurance policy with NIG.

At the time, the company was shopping around for new office space. The account manager received an email from the managing director, asking him to pay £15,000 to a new account, presumably to secure a space. No eyebrows were raised, and the payment was made, however, the email hadn’t come from the managing director. It was sent by a cyber-criminal using a spoof address.

The company quickly alerted the relevant people within NIG. As part of their policy we sent forensic experts to check the fraud came from outside the business, not from an employee, and had the client’s bank put a stop on the account. Their fast action meant only £3,276 was stolen; in part because fraudsters often drip-feed withdrawals in order to avoid detection. The claim was quickly settled, and the retailer could get back to focusing on fishing, and not phishing.

Why take out cyber insurance?

Without cyber insurance, the fishing tackle retailer would have had a different, and far more devastating, experience. After all, the average cost of a cyber breach to small and medium sized businesses is usually between £75,000 and £310,800.

It’s not just stolen funds that business owners have to worry about. There’s also the cost of loss of data and damage to IT systems and networks as well as replacing any stolen or infected devices. There’s the cost of notifying your customers, and in some cases paying compensation, as well as re-building brand confidence through public relations advice and campaigns. 

There’s also investigation and legal costs, money spent responding to regulatory bodies and penalties from banks for losing customer credit card data. On top of all this there is the issue of damaged reputation and lost profit while your system is down. It’s a lot to lose and can often destroy SMEs who don’t have adequate cover in place.

That’s the true value of cyber insurance. It covers you against serious damage, loss of data, and the costs associated with a cyber-attack whilst helping you get back up and running sooner. 

A policy is imperative if your business holds sensitive customer information like names and addresses or bank information, or if you process payments, or do much of your business online. It should also be recognised that your standard business insurance policy probably won’t cover you for cyber-attacks.

It’s clear cyber insurance can minimise the damage caused by a cyber-attack, however, the best policy is to have robust prevention mechanisms in place. This means keeping your IT software and systems up-to-date, training your staff on safe online practices, and implementing formal policies to reduce your risk. 

Putting in place measures such as these, combined with comprehensive cyber coverage, will help keep your business safe from cybercrime.

NIG:

Cybersecurity Breaches Cost UK Businesses £30 billion Last Year:

No Easy Fix For SME Cybersecurity:
 
Cyber Insurance: 7 Questions To Ask:
 
Directors Report January 2017. Cyber Security Checklist For Management (£):

 

« Cybersecurity Breaches Cost UK Businesses Close To £30bn Last Year
Singapore Defense Ministry Under Remote Attack »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

High-Tech Bridge

High-Tech Bridge

High-Tech Bridge SA is a Swiss MSSP provider offering security auditing, source code review and computer forensics.

OSIRIS Lab - NYU Tandon

OSIRIS Lab - NYU Tandon

The Offensive Security, Incident Response & Internet Security Lab (OSIRIS) is a security research environment where students analyze and understand how attackers take advantage of real systems.

Salient CRGT

Salient CRGT

Salient CRGT is a leading provider of health, data analytics, cloud, agile software development, mobility, cyber security, and infrastructure solutions.

CyberArrow

CyberArrow

CyberArrow (formerly EBDAA) is a consultancy company providing high quality consultancy services in Risk & Compliance and Awareness & Education.

CERT-PH

CERT-PH

CERT-PH is the National Computer Emergency Response Team and the highest body for cybersecurity related activities in the Philippines.

Vector Informatik

Vector Informatik

Vector Informatik is a specialist in automotove electronics and provides services, embedded software and tools for securing embedded systems against cyber-attacks.

Rhino Security Labs

Rhino Security Labs

Rhino Security Labs is a top penetration testing and security assessment firm, with a focus on cloud pentesting, network pentesting, web application pentesting, and phishing.

Aurora Systems Consulting

Aurora Systems Consulting

Aurora is a Cybersecurity solutions provider with a portfolio consisting of security consulting, products and services that proactively prevent, secure and manage advanced threats and malware.

Seccuri

Seccuri

Seccuri is a unique global cybersecurity talent tech platform. Use our specialized AI algorithm to grow and improve the cybersecurity workforce.

Techstep

Techstep

Techstep is a complete mobile technology enabler, making positive changes to the world of work; freeing people to work more effectively, securely and sustainably.

Responsive Technology Partners

Responsive Technology Partners

Responsive Technology Partners provides superior IT support services including cybersecurity and compliance, telephony, cloud services, cabling, access control, and camera systems.

InfoSec4TC

InfoSec4TC

InfoSec4tc is an online Information Security Courses, Training, and Consultancy provider.

Corona IT Solutions

Corona IT Solutions

At Corona IT Solutions, our team of specialists in networking, wireless and VoIP are dedicated to providing proactive monitoring and management of your IT systems.

Airlock Digital

Airlock Digital

Airlock Digital was created after many years of experience in implementing whitelisting/ allowlisting solutions in Federal Government and various enterprises in Australia.

Hartman Executive Advisors

Hartman Executive Advisors

Hartman Executive Advisors is an unbiased IT and cyber advisory firm uniquely designed to help mid-market executives maximize their IT investments.

CloudBees

CloudBees

CloudBees is building the world’s first end-to-end automated software delivery system, enabling companies to balance governance and developer freedom.