Partnership. Expertise. Commitment.
Our industry experts provide insurance coverage, services and solutions tailored to meet your specific needs.
The incidence of cyber attacks targeting businesses and organisations of all sizes has surged in the past couple of years as criminals took advantage of business disruptions and refined new tools as well as proven techniques such as social engineering. Our panel of cyber experts provided their insights and defensive risk management advice at a recent Gallagher Cyber Insight Series Webinar.
Our webinar panel comprised Michael Herron, Gallagher National Head of Financial Lines; Robyn Adcock, Gallagher Cyber/Technology Practice Leader; John Moran, Partner at Clyde & Co and Michael Bruemmer, Vice President, Data Breach Resolution & Consumer Protection at Experian.
While the size of the Optus and Medibank cyber breaches made the global top 10 list, our experts believe these high-profile breaches represent the tip of the iceberg of actual incidents, which may be even more detrimental to smaller businesses with less resources.
By volume 60 to 70% of cyber attack remediation work in Australia is for small to medium-sized businesses, which hits their balance sheets hard if they don't have cyber insurance cover. Even not-for-profits are not exempt, representing 10% of all incidents.
Cyber criminals may target low-hanging fruit: businesses without secure systems, or those with valuable data which they may be able to extort for substantial ransoms or sell. In 2022 41% of the 5,000 breaches Experian serviced were targeted for data that would sell at a high cost on the dark web.
Who are the key targets of cyber attacks on businesses?
Key vulnerabilities targeted
Ransomware and business email compromise topped the list in Australia in Q4 2022. Criminals are going after business credentials by using refined phishing techniques via social engineering emails to compromise senior executives.
Cyber attacks have increased 600% since the start of the COVID-19 epidemic. Complete cyber security may not be an achievable goal but cyber resilience will enable businesses to respond to and recover from breaches more quickly and in better shape.
This calls for a holistic approach to organisational culture, beyond technical security controls, and includes regulatory compliance planning, preparation and testing how the business will respond to an attack, as well as data back-up for recovery.
Experian's records show that companies that follow these recommended principles are 15% less likely to be targeted and breaches are 25% less expensive than businesses that are unprepared.
The cyber insurance market remains highly dynamic and responsive to developments, but in some good news for businesses premium rate increases are stabilising after prior spikes as insurance clients lift their security practices and there is new capacity in the Australian and London markets.
Businesses need to be conscious of coverage changes as insurers are rebalancing their risk transfer and risk retention positions, and that policy conditions will always be under analysis.
Access to cyber insurance cover remains based on best practice cyber security risk management.
The key to getting positive cyber insurance results is to:
Watch a replay of our recent 'Navigating the Cyber Landscape: Top Cyber Risk Predictions for 2023' webinar to learn more about emerging cyber threats, the implications for your business and risk mitigation strategies.
Other webinar topics covered include:
In the event of a cyber attack, a robust cyber insurance policy provides access to experts not only in negotiation but also forensic investigation, remediation measures, as well as cover for the legal and reputational costs involved.
In addition to cyber insurance protection Gallagher offers expertise, advice and resources for building business resilience to withstand cyber security incidents.
Gallagher provides insurance, risk management and benefits consulting services for clients in response to both known and unknown risk exposures. When providing analysis and recommendations regarding potential insurance coverage, potential claims and/or operational strategy in response to national emergencies (including health crises), we do so from an insurance and/or risk management perspective, and offer broad information about risk mitigation, loss control strategy and potential claim exposures. We have prepared this commentary and other news alerts for general information purposes only and the material is not intended to be, nor should it be interpreted as, legal or client-specific risk management advice. General insurance descriptions contained herein do not include complete insurance policy definitions, terms and/or conditions, and should not be relied on for coverage interpretation. The information may not include current governmental or insurance developments, is provided without knowledge of the individual recipient's industry or specific business or coverage circumstances, and in no way reflects or promises to provide insurance coverage outcomes that only insurance carriers' control.
Insurance brokerage and related services to be provided by Arthur J. Gallagher & Co (Aus) Limited (ABN 34 005 543 920). Australian Financial Services License (AFSL) No. 238312