Getting your Trinity Audio player ready...

Many businesses still believe cybercriminals only target large organisations, but that's not the reality. Attackers look for any weak spot, whether it's your systems or a third-party partner. Having a plan and cyber insurance to provide the right expert support can make all the difference when something doesn't go as expected.

Digital adoption is accelerating faster than many organisations' ability to safeguard themselves, making cyber risk an increasingly urgent concern for small businesses across Australia and represents an 8% increase in data breach notifications reported to the Office of the Australian Information Commissioner (OAIC).1

From client and financial data to operational systems, even the smallest enterprises now rely on interconnected technologies — often without the security resources of larger counterparts. It is this growing reliance, coupled with evolving threat tactics, that has made small businesses attractive targets for cybercriminals seeking easier entry points.

The growing frequency and cost of cyber incidents highlight an important point: cyber resilience is no longer just an IT issue — it is a business-wide risk. And one of the biggest disruptors at the centre of this evolving risk landscape and rapidly expanding threat is ransomware.

In 2025, the average self-reported cost of cybercrime for small businesses rose to approximately AUD $56,600 per report.2

What is ransomware?

Ransomware is a type of cyberattack where hackers lock users out of computer systems and files. Before locking systems, attackers often copy sensitive information and threaten to publish or sell it unless a ransom is paid.

This creates multiple complexities for businesses. Alongside operational disruption, organisations may face financial losses, reputational damage and potential regulatory obligations arising from a data breach.

Who is most at risk?

While cybercriminals target organisations of all sizes and across industries, some businesses may face greater exposure than others.

  • Professional services firms, including accounting, legal and consulting businesses, often hold large volumes of sensitive client and commercial information. This data can be highly valuable to attackers and may increase the impact of a breach.
  • Businesses that rely heavily on managed service providers, cloud platforms and other third-party technology partners can also face additional risks if those partners experience a cyber incident or security failure.
  • Organisations that provide remote access to systems and applications may face increased exposure if access controls, authentication measures and user permissions aren't regularly reviewed and monitored.

Case study: When a third-party breach becomes your problem

When a sophisticated ransomware attack struck a small business in 2026, operations were brought to a standstill and sensitive data was placed at risk. However, the business had cyber insurance in place. Within hours of contacting the insurer's emergency response hotline, specialist cyber incident response teams were mobilised to investigate the breach, contain the threat and help the organisation navigate the crisis.

Investigators traced the attack to infrastructure managed by the organisation's managed service provider (MSP). During the forensic investigation, they discovered encrypted systems and ransom notes linked to one of the world's most active ransomware-as-a-service (RaaS) groups, indicating that the attackers had compromised systems used to support the business's IT environment.

Business impact

The attack resulted in both the encryption and exfiltration of critical business information. Servers had to be taken offline and isolated to contain the attack, disrupting day-to-day operations and limiting access to key systems.

The organisation also faced significant financial pressure as it considered a ransom demand of approximately USD 100,000 (AUD 142,633).

As a business handling sensitive client information, the incident raised concerns about client trust, as well as posing the potential for reputational damage and scrutiny of regulatory obligations associated with the theft of data.

Resolution

Early action helped the business regain control of the situation. Specialist incident response teams were engaged to contain the attack, investigate the source of the compromise and assess the extent of data exposure. Forensic experts analysed affected systems while legal advisers provided guidance on notification requirements and regulatory obligations.

The business prioritised critical operations, implemented recovery measures and maintained communication with key stakeholders throughout the response. This coordinated effort helped minimise further disruption and supported a structured recovery.

How Gallagher supported

We proactively negotiated a cyber insurance policy for the client. This policy was designed to address the unique risks and exposures faced by the business, ensuring comprehensive coverage in the event of a cyber incident.

When the incident occurred, we worked closely with the client to provide critical support, through the incident, including helping coordinate access to specialist cyber response services and providing guidance during a critical period.

By bringing together the right expertise at the right time, we helped the client focus on business recovery while managing the operational, financial and reputational impacts of the incident.

Five key lessons for small businesses

What should small businesses consider?

  • Do we have cyber insurance that reflects our current risks?
  • Do we understand our exposure to third-party providers and suppliers?
  • Would our team know what to do if a cyber incident occurred tomorrow?
  • Do we know whom to call in a crisis?

The role of cyber insurance and insurance advisers

Cyber insurance can play an important role in helping businesses manage the financial and operational consequences of a cyber incident. Depending on the policy, cover may extend to incident response costs, forensic investigations, legal and regulatory support, business interruption losses, cyber extortion expenses and other recovery costs.

Beyond financial protection, cyber insurance can also provide access to specialist support when an incident occurs. Working with an experienced insurance adviser can help organisations identify potential vulnerabilities, understand coverage limitations and address gaps in protection before a cyber event takes place.

Speak with a Gallagher expert

As cyber threats continue to evolve, understanding your risk and the insurance options available is increasingly important.

Whether you're reviewing your existing cover or exploring cyber insurance for the first time, our cyber specialists can help you understand policy coverage, identify appropriate risk transfer solutions and support your broader cyber risk management strategy.

CONNECT WITH US


Disclaimer

Gallagher provides insurance, risk management and benefits consulting services for clients in response to both known and unknown risk exposures. When providing analysis and recommendations regarding potential insurance coverage, potential claims and/or operational strategy in response to national emergencies (including health crises), we do so from an insurance and/or risk management perspective, and offer broad information about risk mitigation, loss control strategy and potential claim exposures. We have prepared this commentary and other news alerts for general information purposes only and the material is not intended to be, nor should it be interpreted as, legal or client-specific risk management advice. General insurance descriptions contained herein do not include complete insurance policy definitions, terms and/or conditions, and should not be relied on for coverage interpretation. The information may not include current governmental or insurance developments, is provided without knowledge of the individual recipient's industry or specific business or coverage circumstances, and in no way reflects or promises to provide insurance coverage outcomes that only insurance carriers' control.

Gallagher publications may contain links to non-Gallagher websites that are created and controlled by other organisations. We claim no responsibility for the content of any linked website, or any link contained therein. The inclusion of any link does not imply endorsement by Gallagher, as we have no responsibility for information referenced in material owned and controlled by other parties. Gallagher strongly encourages you to review any separate terms of use and privacy policies governing use of these third party websites and resources.

Insurance brokerage and related services to be provided by Arthur J. Gallagher & Co (Aus) Limited (ABN 34 005 543 920). Australian Financial Services License (AFSL) No. 238312