As an SME do you really need Cyber Insurance? Most of us when we see the news will hear of the large organisations that get hacked but we don’t often hear about the smaller companies that are attacked. So, does that mean that SME businesses are safe? The resounding answer to that is no. 43% of cyber attacks are targeted at small businesses. As a small business you are not safe and our blog is going to delve into what types of attacks occur, how you can avoid it and what would a cyber insurance policy do for you.
What is the impact of a cyber-attack?
The biggest impact is your businesses survival – 83% of SME’s are not equipped to recover from a cyber attack. Most of the costs associated with data breaches occur after the incident has been contained. This includes delays and other knock-on effects of the breach, fines, and the requirement to strengthen cyber security defences in line with regulatory requirements. These are costs and scenarios that most SME’s haven’t budgeted for.
As alluded to above the impact of a cyber attack broadly fits into three categories, financial, reputational and legal.
Economic cost of cyber attack
Cyber-attacks often result in a substantial financial loss arising from:
- Theft of corporate information
- Theft of financial information (eg bank details or payment card details)
- Theft of money
- Disruption to trading (eg inability to carry out transactions online)
- Loss of business or contract
- Businesses that suffered a cyber breach will also generally incur costs associated with repairing affected systems, networks and devices.
Reputational damage
For any business, trust is an essential element. Once a customer realises that your business has been compromised it can make them nervous and it can have the same effect on suppliers as well. Once the trust has been broken it is hard to repair your reputation which can lead to a loss of customers. The loss of customers will of course then have a knock-on effect on sales and company revenue. Going beyond suppliers and customers cyber-attacks can damage your business’ reputation with partners, investors and other third parties vested in your business.
Legal consequences of a cyber breach
Data protection and privacy laws require you to manage the security of all personal data you hold – whether on your staff or on your customers. If this data is accidentally or deliberately compromised, and you have failed to deploy appropriate security measures, you may face fines and regulatory sanctions.
Types of cyber-attacks.
Cyber-attacks are increasingly common, and according to the Cisco Annual Cybersecurity Report, attackers can launch campaigns without human intervention with the advent of network-based ransomware worms.
Being aware of the types of cyber-attacks is one of the best ways for a company to start their cyber preparations. According to Datto the top most common types of cyber-attacks are:
1) Malware
Malware, short for “malicious software,” refers to any intrusive software developed by cybercriminals (often called “hackers”) to steal data and damage or destroy computers and computer systems. The most common types of malware are:
- Viruses
- Trojan
- Worms
- Ransomware
- Spyware
2) Phishing
Phishing attacks are extremely common and involve sending mass amounts of fraudulent emails to unsuspecting users, disguised as coming from a reliable source. An example of this could be an email claiming to be from Amazon asking you to click on a link to check on your delivery, or in recent times an email asking you to click a link to opt in or out of a covid digital passport.
There are several different types of phishing attacks, including:
- Spear Phishing—targeted attacks directed at specific companies and/or individuals.
- Whaling—attacks targeting senior executives and stakeholders within an organization.
- Pharming—leverages DNS cache poisoning to capture user credentials through a fake login landing page.
Phishing attacks can also take place via phone call (voice phishing) and via text message (SMS phishing).
You can read a more in-depth article on phishing scams here.
3) Man in the middle attacks
Occurs when an attacker intercepts a two-party transaction, inserting themselves in the middle. From there, cyber attackers can steal and manipulate data by interrupting traffic. This type of attack usually exploits security vulnerabilities in a network, such as an unsecured public WiFi, to insert themselves between a visitor’s device and the network.
4) Denial of service attack
A Denial-of-Service (DoS) attack is an attack meant to shut down a machine or network, making it inaccessible to its intended users. DoS attacks accomplish this by flooding the target with traffic or sending it information that triggers a crash. In both instances, the DoS attack deprives legitimate users (i.e. employees, members, or account holders) of the service or resource they expected.
You can read more about a denial of service attack here.
5) SQL injections
This occurs when an attacker inserts malicious code into a server using server query language (SQL) forcing the server to deliver protected information. This type of attack usually involves submitting malicious code into an unprotected website comment or search box. Secure coding practices such as using prepared statements with parameterized queries is an effective way to prevent SQL injections.
6) Zero-day exploit
“Zero-day” is a broad term that describes recently discovered security vulnerabilities that hackers can use to attack systems. The term “zero-day” refers to the fact that the vendor or developer has only just learned of the flaw – which means they have “zero days” to fix it. A zero-day attack takes place when hackers exploit the flaw before developers have a chance to address it.
Zero-day is sometimes written as 0-day. The words vulnerability, exploit, and attack are typically used alongside zero-day, and it’s helpful to understand the difference:
- A zero-day vulnerability is a software vulnerability discovered by attackers before the vendor has become aware of it. Because the vendors are unaware, no patch exists for zero-day vulnerabilities, making attacks likely to succeed.
- A zero-day exploit is the method hackers use to attack systems with a previously unidentified vulnerability.
- A zero-day attack is the use of a zero-day exploit to cause damage to or steal data from a system affected by a vulnerability.
You can read more about zero-day attacks here.
7) Password attack
Password attacks are one of the most common forms of corporate and personal data breach. A password attack is simply when a hacker tries to steal your password. In 2020, 81% of data breaches were due to compromised credentials. Because passwords can only contain so many letters and numbers, passwords are becoming less safe. Hackers know that many passwords are poorly designed, so password attacks will remain a method of attack as long as passwords are being used.
Types of password attacks include:
- Phishing
- Man in the middle attacks
- Brute force attacks
- Dictionary Attack
- Credential stuffing
- Keyloggers
More information on password attacks is available here.
8) Cross-site scripting
Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute malicious scripts in a web browser of the victim by including malicious code in a legitimate web page or web application. The actual attack occurs when the victim visits the web page or web application that executes the malicious code. The web page or web application becomes a vehicle to deliver the malicious script to the user’s browser. Vulnerable vehicles that are commonly used for Cross-site Scripting attacks are forums, message boards, and web pages that allow comments.
9) Rootkits
Rootkits are installed inside legitimate software, where they can gain remote control and administration-level access over a system. The attacker then uses the rootkit to steal passwords, keys, credentials, and retrieve critical data.
10) Internet of things attack
While internet connectivity across almost every imaginable device creates convenience and ease for individuals, it also presents a growing—almost unlimited—number of access points for attackers to exploit and wreak havoc. The interconnectedness of things makes it possible for attackers to breach an entry point and use it as a gate to exploit other devices in the network.
IoT attacks are becoming more popular due to the rapid growth of IoT devices and (in general) low priority given to embedded security in these devices and their operating systems. In one IoT attack case, a Vegas casino was attacked and the hacker gained entry via an internet-connected thermometer inside one of the casino’s fishtanks.
Best practices to help prevent an IoT attack include updating the OS and keeping a strong password for every IoT device on your network, and changing passwords often.
Can Cyber Insurance help?
Before we look into the benefits of how cyber insurance can help it is important to note that the key word here is help. As highlighted throughout this blog there are numerous cyber risks out there and it is up to you as an organisation to keep on top of your cyber security. A cyber insurance policy will work based on the principle that you have put procedures in place to protect your business from cybercrime.
It is therefore important to either make sure that your in-house IT team are up to date on their training or it is worth considering hiring an external cyber security company, some of the benefits to that can be found here.
What is cyber insurance
Cyber insurance is a type of business insurance, designed to protect businesses of any size from the financial consequences of attacks on their work computer systems.
Cyber insurance gives you a safety net and covers your liability, to an extent, for any incidents. It includes both first-party and third-party claims.
There are two types of cyber insurance. Depending on the type of business you have, you can take out one or both:
- First-party insurance – first-party cyber insurance covers your business’s own assets. This policy pays out for direct and indirect costs if you lose money, data, software, intellectual property or customers to cybercrime – either from the direct attack, or from the business downtime and reputational damage it causes. It can also cover the cost of response efforts, such as setting up an emergency call centre to notify your customers of the breach.
- Third-party insurance – also known as cyber liability insurance, this covers the assets of others, e.g. your customers. For example, hackers may steal customer information, damage their data, block their accounts, or tamper with their profiles and websites. Like any liability insurance, third-party policies will cover the costs you’re legally liable to pay, including those related to investigation, legal defence, civil damages and compensation.
If your business doesn’t handle a lot of customer data electronically, third-party insurance might not be necessary.
Does cyber insurance cover ransomware?
The answer is sometimes, Ransomware attacks involve a piece of hostile software (‘malware’) that might encrypt your files, lock your computers or otherwise threaten your IT systems, and then demand money from you in order to release your data or equipment. Such incidents are on the rise, so many cyber insurance policies offer cover for them, others may offer it as an additional extra. GMi Insurance Services is an independent insurance broker with access to a wide range of insurers, this means that we can search the market to find the right cyber insurance policy that matches your needs.
What is not covered by cyber insurance?
Like any insurance, cyber insurance policies have their exclusions. These can differ by provider, but, in general, this insurance does not cover:
- Potential future lost profits – cyber insurance covers money lost during business downtime. However, this doesn’t extend into future lost profits. For example, if your turnover at the end of the year is going to be less than projected because of the data breach, you can’t make a claim for this.
- Loss of value due to intellectual property (IP) theft – there are many hidden and indirect costs related to IP theft that are hard to identify and quantify. Losing your IP, for example, can result in lost opportunities, revoked contracts or the devaluation of a trade name. Similar to the above, your insurance won’t cover the costs of these long-term losses.
- Betterment costs – after a security breach, businesses often upgrade their technology systems. Although your insurance will help you recover your current systems, it won’t help you improve them.
To conclude
The risk of cyber-attacks are on the rise and are going to continue to increase. It is therefore important that you have the right cyber security policies in place, but these won’t always stop determined cyber-criminals attacking your business. In this situation a cyber-insurance policy is designed to protect your business and should be given serious consideration.


