Cyberattacks are happening to businesses of all sizes, and in every industry. Between 2021 and 2022, one in four businesses reported a cyberattack, and one in five said they’d suffered significantly because of it. The cost of living crisis and the Ukraine conflict have both contributed to a rise in cybercrime, so it is crucial to take steps to make sure your company is doing everything it can to avoid becoming a victim.

Some businesses are of the opinion that just because they’re small, they’re not on the radar of hackers and cyber criminals. But this is simply not the case.

According to the Cyber Breaches Survey 2022 , 39% of UK businesses identified a cyberattack in the past 12 months. The most common were phishing attempts, but one in five experienced something more sophisticated, such as a denial of service, malware or ransomware attack.

From system downtime and loss of productivity to reputational damage, the cost to businesses of a cyber breach is more than just financial. According to the National Cybersecurity Alliance, almost two thirds of small to medium sized organisations go out of business within six months of an attack.

The problem is that a lot of the costs of a cyberattack can transpire a while after the event, sometimes up to 12 months. From the costs to notify customers to getting back up and running, and from reputational damage to staggering regulatory fines, there is a lot to be concerned about.

Even more worrying is that according to an IBM study, 95% of cyber breaches stem from human error. And three quarters of attacks begin with an email. With this in mind, when planning your cybersecurity strategy, it’s vital that staff training is a priority.

How to protect your business from cyber threats

With cybercrime becoming more advanced all the time, it is essential to be aware of how these types of attacks can impact operations and productivity, and to put adequate protective measures in place. Early detection of a data breach is critical to preserving reputation and preventing what can amount to tens of thousands of pounds worth of damage, or in some cases more.

Cybersecurity best practices include:

  • Employee Training: Cybersecurity training for all staff is essential, and it should be ongoing with regular refreshers to stay on top of emerging threats. Training should include sharing knowledge of potential security vulnerabilities, how to recognise and avoid scams, good password management, and how to protect sensitive customer and company data.
  • Cyber protection software: The use of firewalls, anti-virus software, anti-spyware programs and endpoint detection and response (EDR) programs will help ensure sensitive data cannot be easily breached by hackers. These cybersecurity programs rely on regular updates to keep them free from vulnerabilities, and should all be selected in conjunction with advice from an IT specialist with specific cyber risk knowledge to ensure you have the right protection for your needs. Continuous cyber threat monitoring is also helpful when it comes to identifying threats before they’ve had a chance to cause damage, and this is often available as part of a regular IT support contract.
  • Keep software updated: Software vulnerabilities occur fairly regularly, so it’s vital to install updates whenever prompted, as many will include security patches designed to close the gaps that hackers use to target systems. Never ignore updates and, where possible, set them to install automatically when systems aren’t in use.
  • Protect data: Because a great deal of data breaches occur due to employee error, it is good practice to set access permissions, allowing access only to the information staff need to carry out their roles. Consider introducing processes that require employees to purge or archive files that are no longer needed. Regularly back up data on all computers, and put a recovery system in place to allow information retrieval should it become necessary due to a cyberattack.
  • Password management: Put a password policy in place and provide training for staff on good password management. Passwords should never be shared between employees or written down where others can see them. It’s also crucial that the same password isn’t used for different systems. Using a password management program is highly recommended, as it allows strong passwords to be set and recalled securely.
  • Data Encryption: All data accessed via personal devices, computers, or servers should be protected by proper encryption to protect data in the case of unauthorised access attempts. When the data is encrypted at rest, it is protected from being viewed unless the user has the proper credentials and code. This is particularly important for regulated data.
  • Use a VPN: A Virtual Private Network (VPN) allows employees to securely access company networks through an encrypted connection, ensuring privacy and security are kept intact. A VPN is vital for remote workers logging in from their own devices.
  • Multi-factor authentication: Multi-factor authentication (MFA), also known as 2-layer authentication (2LA) requires additional verification information, for example, a security code sent to a phone, in order to log into networks, systems and devices. Use it wherever possible for email, VPN access, firewall, content management systems and other software access for added security.
  • Cyber Essentials certification: The Cyber Essentials  scheme is a UK government-backed certification that helps businesses of all sizes guard against the most common cyber threats. Cyber Essentials certification helps protect against 80% of the most common types of cyberattacks, as well as reducing the risks of business disruption that go hand in hand with cyberattack downtime. What’s more, 61% of certified organisations say they are more likely to choose suppliers with Cyber Essentials or Cyber Essentials Plus certification.
  • Cyber insurance: Cyber insurance is a specialist type of cover designed to protect businesses from the potential extreme costs that can arise from cyberattacks, and the financial and reputational damage that goes hand in hand with data breaches. It is important to be aware that traditional Professional Indemnity and Commercial Combined policies are highly unlikely to provide cover for cyber risks, so a separate, specialist policy is a necessity.

What’s covered by cyber insurance?

Here at Robert Gerrard, we offer cyber insurance cover through a selection of leading providers. Following an individual appraisal of your needs and risk level, we will pair you with the cover that best suits your requirements.

By way of an example, our cyber insurance cover may include:

Cyber incident response – 24/7 access to a cyber incident response team, plus a network of partners, including IT forensics and security, legal and PR specialists to cover every base following a cyber incident.

Comprehensive cybercrime cover – financial loss cover for a wide range of cyber events, including social engineering scams, invoice fraud, ransomware, targeted extortion, cryptojacking and more.

System damage and business interruption – covering the costs involved in restoring or recreating data, rectifying computer systems and restoring your organisation to full service following a cyber event.

Privacy liability and breach notification – covering third party claims arising out of the loss of confidential data, including the costs involved in notifying affected individuals.

Risk management services – access to a wide range of services aimed at preventing cyber issues before they become a crisis.

Cybersecurity measures and cyber insurance are both vitally important, and it’s important not to assume that just because you have one, you don’t need the other.

In fact, all of the protective measures listed above are things that cyber insurance providers look for when setting policy premiums. The more steps you are taking to protect against cyber threats, the better price you’ll get for your policy, because you’ll be considered a lower risk.

Cybercrime – every business is at risk – are you doing enough to protect your livelihood?

Every business of every size and in every industry is potentially at risk from cybercrime, and cyber threats are evolving every day. Taking measures to protect your organisation, and backing this up with a purpose-designed cyber insurance policy, is the only way to achieve the best possible reassurance.

For bespoke advice on protecting your business against the latest forms of cybercrime with tailored insurance cover, we welcome you to get in touch  with our dedicated cyber protection team.

About the Author: Ellie Jackson

Share This Story, Choose Your Platform!

Cyberattacks are happening to businesses of all sizes, and in every industry. Between 2021 and 2022, one in four businesses reported a cyberattack, and one in five said they’d suffered significantly because of it. The cost of living crisis and the Ukraine conflict have both contributed to a rise in cybercrime, so it is crucial to take steps to make sure your company is doing everything it can to avoid becoming a victim.

Some businesses are of the opinion that just because they’re small, they’re not on the radar of hackers and cyber criminals. But this is simply not the case.

According to the Cyber Breaches Survey 2022 , 39% of UK businesses identified a cyberattack in the past 12 months. The most common were phishing attempts, but one in five experienced something more sophisticated, such as a denial of service, malware or ransomware attack.

From system downtime and loss of productivity to reputational damage, the cost to businesses of a cyber breach is more than just financial. According to the National Cybersecurity Alliance, almost two thirds of small to medium sized organisations go out of business within six months of an attack.

The problem is that a lot of the costs of a cyberattack can transpire a while after the event, sometimes up to 12 months. From the costs to notify customers to getting back up and running, and from reputational damage to staggering regulatory fines, there is a lot to be concerned about.

Even more worrying is that according to an IBM study, 95% of cyber breaches stem from human error. And three quarters of attacks begin with an email. With this in mind, when planning your cybersecurity strategy, it’s vital that staff training is a priority.

How to protect your business from cyber threats

With cybercrime becoming more advanced all the time, it is essential to be aware of how these types of attacks can impact operations and productivity, and to put adequate protective measures in place. Early detection of a data breach is critical to preserving reputation and preventing what can amount to tens of thousands of pounds worth of damage, or in some cases more.

Cybersecurity best practices include:

  • Employee Training: Cybersecurity training for all staff is essential, and it should be ongoing with regular refreshers to stay on top of emerging threats. Training should include sharing knowledge of potential security vulnerabilities, how to recognise and avoid scams, good password management, and how to protect sensitive customer and company data.
  • Cyber protection software: The use of firewalls, anti-virus software, anti-spyware programs and endpoint detection and response (EDR) programs will help ensure sensitive data cannot be easily breached by hackers. These cybersecurity programs rely on regular updates to keep them free from vulnerabilities, and should all be selected in conjunction with advice from an IT specialist with specific cyber risk knowledge to ensure you have the right protection for your needs. Continuous cyber threat monitoring is also helpful when it comes to identifying threats before they’ve had a chance to cause damage, and this is often available as part of a regular IT support contract.
  • Keep software updated: Software vulnerabilities occur fairly regularly, so it’s vital to install updates whenever prompted, as many will include security patches designed to close the gaps that hackers use to target systems. Never ignore updates and, where possible, set them to install automatically when systems aren’t in use.
  • Protect data: Because a great deal of data breaches occur due to employee error, it is good practice to set access permissions, allowing access only to the information staff need to carry out their roles. Consider introducing processes that require employees to purge or archive files that are no longer needed. Regularly back up data on all computers, and put a recovery system in place to allow information retrieval should it become necessary due to a cyberattack.
  • Password management: Put a password policy in place and provide training for staff on good password management. Passwords should never be shared between employees or written down where others can see them. It’s also crucial that the same password isn’t used for different systems. Using a password management program is highly recommended, as it allows strong passwords to be set and recalled securely.
  • Data Encryption: All data accessed via personal devices, computers, or servers should be protected by proper encryption to protect data in the case of unauthorised access attempts. When the data is encrypted at rest, it is protected from being viewed unless the user has the proper credentials and code. This is particularly important for regulated data.
  • Use a VPN: A Virtual Private Network (VPN) allows employees to securely access company networks through an encrypted connection, ensuring privacy and security are kept intact. A VPN is vital for remote workers logging in from their own devices.
  • Multi-factor authentication: Multi-factor authentication (MFA), also known as 2-layer authentication (2LA) requires additional verification information, for example, a security code sent to a phone, in order to log into networks, systems and devices. Use it wherever possible for email, VPN access, firewall, content management systems and other software access for added security.
  • Cyber Essentials certification: The Cyber Essentials  scheme is a UK government-backed certification that helps businesses of all sizes guard against the most common cyber threats. Cyber Essentials certification helps protect against 80% of the most common types of cyberattacks, as well as reducing the risks of business disruption that go hand in hand with cyberattack downtime. What’s more, 61% of certified organisations say they are more likely to choose suppliers with Cyber Essentials or Cyber Essentials Plus certification.
  • Cyber insurance: Cyber insurance is a specialist type of cover designed to protect businesses from the potential extreme costs that can arise from cyberattacks, and the financial and reputational damage that goes hand in hand with data breaches. It is important to be aware that traditional Professional Indemnity and Commercial Combined policies are highly unlikely to provide cover for cyber risks, so a separate, specialist policy is a necessity.

What’s covered by cyber insurance?

Here at Robert Gerrard, we offer cyber insurance cover through a selection of leading providers. Following an individual appraisal of your needs and risk level, we will pair you with the cover that best suits your requirements.

By way of an example, our cyber insurance cover may include:

Cyber incident response – 24/7 access to a cyber incident response team, plus a network of partners, including IT forensics and security, legal and PR specialists to cover every base following a cyber incident.

Comprehensive cybercrime cover – financial loss cover for a wide range of cyber events, including social engineering scams, invoice fraud, ransomware, targeted extortion, cryptojacking and more.

System damage and business interruption – covering the costs involved in restoring or recreating data, rectifying computer systems and restoring your organisation to full service following a cyber event.

Privacy liability and breach notification – covering third party claims arising out of the loss of confidential data, including the costs involved in notifying affected individuals.

Risk management services – access to a wide range of services aimed at preventing cyber issues before they become a crisis.

Cybersecurity measures and cyber insurance are both vitally important, and it’s important not to assume that just because you have one, you don’t need the other.

In fact, all of the protective measures listed above are things that cyber insurance providers look for when setting policy premiums. The more steps you are taking to protect against cyber threats, the better price you’ll get for your policy, because you’ll be considered a lower risk.

Cybercrime – every business is at risk – are you doing enough to protect your livelihood?

Every business of every size and in every industry is potentially at risk from cybercrime, and cyber threats are evolving every day. Taking measures to protect your organisation, and backing this up with a purpose-designed cyber insurance policy, is the only way to achieve the best possible reassurance.

For bespoke advice on protecting your business against the latest forms of cybercrime with tailored insurance cover, we welcome you to get in touch  with our dedicated cyber protection team.

About the Author: Ellie Jackson

Share This Story, Choose Your Platform!