3 minute read

PONSONBY PROFESSIONALS

PONSONBY PROFESSIONALS LOGAN GRANGER: PERCY WOOTTON, INSURANCE DESIGN LIMITED

Why your business needs Cyber Insurance.

Many SME owners believe that they don’t have to worry too much about cyber-crime. After all, why would Internet villains bother with small fry when they could go after heavy hitters such as Yahoo, eBay or Uber?

Unfortunately, cyber criminals take an equal-opportunity approach. While they can and do target large organisations, they also realise such organisations have the resources to spend big on cybersecurity. It’s often quicker and easier for them to extort $1,000 from 1,000 small businesses they’ve infected with ransomware than to try to hack into a larger business in the hopes of earning $1million.

It’s the cyber-attacks that devastate multinationals or large government departments, such as Petya and WannaCry that get all the media attention. But, without generating any headlines, tech-savvy crooks target millions of SMEs each year.

“Microsoft claims cybercrime now costs the global economy around US$500 billion (NZ$776 billion) annually and that 20 per cent of SMEs have been targeted by malicious actors.”

What is cyber-crime?

Cyber-crime includes all of the following: • Identity theft • Cyber stalking • Use of malware • Use of viruses • Computer and network hacking • Online scams • Phishing scams • Fraud • Information theft • Extortion

Everybody who uses a computer– or even just a mobile phone or iPad – for work purposes, can be a victim of cyber crime.

What happens if my security is breached?

The two cybercrimes SME owners most need to be worried about are ransomware attacks and data breaches. A ransomware attack involves a business’s files being encrypted and thus rendered unusable. In the digital age, this can quickly result in operations grinding to halt, which in turn soon means revenue stops flowing in.

Business owners often pay a substantial but not excessive ransom (the average demand is around $1,000) to have their files unencrypted. In the case of a data breach, the cybercriminal steals data (think addresses and bank account details) about a business’s customers or, more rarely, staff. This data is then used for identity theft, fraud or extortion. In the past, a SME that failed to safeguard the personal data it was entrusted with typically only had to worry about suffering reputational and legal consequences in the event word of the data breachgot out. In February, the Federal Government introduced the Notifiable Data Breach (NDB) scheme.

As the name suggests, this requires organisations, including businesses, to notify individuals affected by data breaches likely to result in serious harm. Failing to comply with the NDB scheme can attract fines of up to $2.1 million. Of course, complying with it could result in your clients making legal claims against you. At the very least, those clients will not be inclined to place their trust in your business in future.

But I’ve got a firewall! It’s both possible and advisable to minimise the risk of a cyberattack. This is done through some combination of the following:

• Installing reputable anti-virus programs • Having secure data back-ups • Firewall technology • Data encryption • Introducing and enforcing sensible policies around the use of equipment (especially BYOD gear) such as laptops and smartphones

Unfortunately, even if you do have all the right systems and software in place, your business is still at risk. If major banks, governments and even Google can fall victim to cyberattacks, anyone can.

What does cyber insurance cover? Fortunately, while you can never 100 per cent guarantee your cybersecurity won’t be breached, you can insure against the costs that often arise in such a situation. A cyber insurance policy cancover you for expenses related to the following: • Interrupted business • Hiring negotiators and paying a ransom • Recovering or replacing records or data • Liability and loss of third-party data • Defence of legal claims • Copyright infringement • Misuse of intellectual property online • Crisis management and monitoring • Prevention of further attacks

OK, what do I do now? If you’d like to learn more about Cyber Insurance please contact us at Johnston Associates and we will refer you onto one of the Insurance Design teams.

Disclaimer – While all care has been taken, Johnston Associates Chartered Accountants Ltd and its staff accept no liability for the content of this article; always see your professional advisor before taking any action that you are unsure about.

JOHNSTON ASSOCIATES, 14 St Marys Bay Road, T: 09 361 6701, www.jacal.co.nz

14 St Marys Bay Road, St Marys Bay