Many businesses still believe cybercriminals only target large organisations, but that's not the reality. Attackers look for any weak spot, whether it's your systems or a third-party partner. Having a plan and cyber insurance to provide the right expert support can make all the difference when something doesn't go as expected.
Digital adoption is accelerating faster than many organisations' ability to safeguard themselves, making cyber risk an increasingly urgent concern for small businesses across Australia and represents an 8% increase in data breach notifications reported to the Office of the Australian Information Commissioner (OAIC).1
From client and financial data to operational systems, even the smallest enterprises now rely on interconnected technologies — often without the security resources of larger counterparts. It is this growing reliance, coupled with evolving threat tactics, that has made small businesses attractive targets for cybercriminals seeking easier entry points.
The growing frequency and cost of cyber incidents highlight an important point: cyber resilience is no longer just an IT issue — it is a business-wide risk. And one of the biggest disruptors at the centre of this evolving risk landscape and rapidly expanding threat is ransomware.
What is ransomware?
Ransomware is a type of cyberattack where hackers lock users out of computer systems and files. Before locking systems, attackers often copy sensitive information and threaten to publish or sell it unless a ransom is paid.
This creates multiple complexities for businesses. Alongside operational disruption, organisations may face financial losses, reputational damage and potential regulatory obligations arising from a data breach.
Who is most at risk?
While cybercriminals target organisations of all sizes and across industries, some businesses may face greater exposure than others.
- Professional services firms, including accounting, legal and consulting businesses, often hold large volumes of sensitive client and commercial information. This data can be highly valuable to attackers and may increase the impact of a breach.
- Businesses that rely heavily on managed service providers, cloud platforms and other third-party technology partners can also face additional risks if those partners experience a cyber incident or security failure.
- Organisations that provide remote access to systems and applications may face increased exposure if access controls, authentication measures and user permissions aren't regularly reviewed and monitored.
Case study: When a third-party breach becomes your problem
When a sophisticated ransomware attack struck a small business in 2026, operations were brought to a standstill and sensitive data was placed at risk. However, the business had cyber insurance in place. Within hours of contacting the insurer's emergency response hotline, specialist cyber incident response teams were mobilised to investigate the breach, contain the threat and help the organisation navigate the crisis.
Investigators traced the attack to infrastructure managed by the organisation's managed service provider (MSP). During the forensic investigation, they discovered encrypted systems and ransom notes linked to one of the world's most active ransomware-as-a-service (RaaS) groups, indicating that the attackers had compromised systems used to support the business's IT environment.
Business impact
The attack resulted in both the encryption and exfiltration of critical business information. Servers had to be taken offline and isolated to contain the attack, disrupting day-to-day operations and limiting access to key systems.
The organisation also faced significant financial pressure as it considered a ransom demand of approximately USD 100,000 (AUD 142,633).
As a business handling sensitive client information, the incident raised concerns about client trust, as well as posing the potential for reputational damage and scrutiny of regulatory obligations associated with the theft of data.
Resolution
Early action helped the business regain control of the situation. Specialist incident response teams were engaged to contain the attack, investigate the source of the compromise and assess the extent of data exposure. Forensic experts analysed affected systems while legal advisers provided guidance on notification requirements and regulatory obligations.
The business prioritised critical operations, implemented recovery measures and maintained communication with key stakeholders throughout the response. This coordinated effort helped minimise further disruption and supported a structured recovery.
How Gallagher supported
We proactively negotiated a cyber insurance policy for the client. This policy was designed to address the unique risks and exposures faced by the business, ensuring comprehensive coverage in the event of a cyber incident.
When the incident occurred, we worked closely with the client to provide critical support, through the incident, including helping coordinate access to specialist cyber response services and providing guidance during a critical period.
By bringing together the right expertise at the right time, we helped the client focus on business recovery while managing the operational, financial and reputational impacts of the incident.