Cyber threats and the benefits of insurance cover

Cyber threats and the benefits of insurance cover

In 2022, companies were warned to review their cyber security and protocols in order to protect themselves after alleged cyber-attacks from Russia. The claims about the cyber-attacks we saw were reported to be true by UK government.

Whilst cyber threats have been prevalent for years now, with the raised profile of such risks, we take the opportunity to explain and discuss:

  • Some of the ways in which businesses can be targeted
  • Cyber security terminology
  • Real-life scenarios

We hope that this article will highlight the increased concern around cyber threats and losses to businesses and why cyber insurance is a worthwhile investment.

Why are businesses targeted?

 Businesses are targeted for a whole host of reasons but arguably there are 3 main reasons.

The first, to obtain financial details of the business itself in order to steal money – most cyber crime is, after all, carried out for financial gain.

Secondly, to obtain the financial details (e.g. credit card details) of your customers – it’s likely that a business could hold a huge number of individual customers’ card details and as such, could prove very fruitful for the cyber criminal.

Lastly, it could be for the personal/sensitive information of a business’s customers and/or employees – data which can be sold on to other cyber criminals for their own criminal gains, such as:

  • Identity theft
  • Phishing attacks/extortion
  • Targeted company attacks

Whilst there are numerous other reasons for cyber attacks, such as obtaining login details of staff or customers, email addresses of customers in order to coordinate a phishing attack or to infiltrate your I.T. system and demand ransom – they all generally revolve around obtaining some kind of data in order to gain financially.

Cyber security terminology

There’s a lot of terminology used when it comes to cyber crime and security. Here, we explain what some of the more common terms used, mean.

Malware

Malware is malicious software that is installed into a system, often by using a vulnerable user to breach a network by having them click on a “planted” dangerous link or email attachment, which triggers the install. Malware can, amongst other things:

  • Deny access to the critical components of the network
  • Obtain information by retrieving data from the hard drive
  • Disrupt the system or even render it inoperable

The most common types of malware are:

  • Viruses — these infect applications by attaching themselves to the initialisation sequence; the virus replicates itself, infecting other code in the computer system.
  • Trojans — a program hiding inside a useful program with malicious purposes. Unlike viruses, a trojan doesn’t replicate itself and it is commonly used to establish a ‘backdoor’ to be exploited by attackers.
  • Worms — unlike viruses, they don’t attack the host (a piece of hardware/device that has the ability to permit access to a network) as they are self-contained programs that propagate across networks and computers. Worms are often installed through email attachments, sending a copy of themselves to every contact in the infected device’s email list. They are commonly used to overload an email server and achieve a denial-of-service attack.
  • Ransomware — a type of malware that denies access to the victim’s data, threatening to publish or delete it unless a ransom is paid. Advanced ransomware uses crypto viral extortion, encrypting the victim’s data so that it is impossible to decrypt without the decryption key.
  • Spyware — a type of program installed to collect information about users, their systems or browsing habits, sending the data to a remote user. The attacker can then use the information for blackmailing purposes or download and install other malicious programs from the web.

Phishing

Phishing attacks are extremely common and involve sending mass amounts of fraudulent emails to unsuspecting users, disguised as though they come from a reliable source. The fraudulent emails often have the appearance of being legitimate but link the recipient to a malicious file or script designed to grant attackers access to your device to control it, gather recon, install malicious scripts/files, or extract data such as user information, financial information, and more.

Man-in-the-Middle (MitM) Attacks

Occurs when an attacker intercepts a two-party transaction, inserting themselves in the middle (e.g. between you and your customer or you and a supplier). From there, cyber attackers can steal and manipulate data by interrupting traffic. One example of a MITM attack is active eavesdropping, in which the attacker makes independent connections with the victims and relays messages between them to make them believe they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker.

Denial-of-Service (DoS) Attack

DoS attacks work by flooding systems, servers and/or networks with traffic to overload resources and bandwidth. The result is rendering the system unable to process and fulfil legitimate requests. In addition to denial-of-service (DoS) attacks, there are also distributed denial-of-service (DDoS) attacks.

DoS attacks saturate a system’s resources with the goal of impeding response to service requests. On the other hand, a DDoS attack is launched from several infected host machines with the goal of achieving service denial and taking a system offline, thus paving the way for another attack to enter the network/environment.

Password Attack

Passwords are the most widespread method of authenticating access to a secure information system, making them an attractive target for cyber attackers. By accessing a person’s password – an employee’s for example, an attacker can gain entry to confidential or critical data and systems, including the ability to manipulate and control said data/systems.

Password attackers use a myriad of methods to identify an individual password, including using social engineering, gaining access to a password database, testing the network connection to obtain unencrypted passwords, or simply guessing.

The last method mentioned is executed in a systematic manner known as a “brute-force attack”. A brute-force attack employs a program to try all the possible variants and combinations of information to guess the password.

Social Engineering

In the context of information security, social engineering is the psychological manipulation of people to get them to perform actions or divulge confidential information. You may have seen the typical posts on social media sites that appear to be innocent conversation starters such as ‘What was the name of your first pet?’ but in reality, if answered, can be used to help answer security questions for your account or even lead them to part or all of your password.

Real-life scenarios

It is important to note that anyone can fall victim to a cyber incident. Here, we share 3 different examples of attacks from CFC Underwriting, and how their cyber insurance cover assisted.

Click on each to read the full story.

A machinery manufacturer nearly falls victim to malicious software

This incident began with cyber criminals looking to exploit the Microsoft Exchange Server vulnerabilities first discovered in January 2021 and publicly identified by Microsoft in March 2021, collectively known as “ProxyLogon” – this consisted of four vulnerabilities that allowed cyber criminals to gain access to Microsoft Exchange Servers.

In March, Microsoft released updates to patch the vulnerabilities, but many organisations had been compromised prior to this or were unable to patch before the cybercriminals found them; precisely what happened in this instance.

With the help of the insurer’s proactive risk management services, the threat was detected and resolved before a ransomware attack was due to hit.

An appliance retailer suffers a significant sales shortfall after its website is taken down by hackers

The incident began when an unidentified hacker sent an email to one of the firm’s business email addresses, stating that the company’s website would be taken down within 24 hours unless a payment of $4,000 in Bitcoin was made. However, this email was caught in the company’s spam filters, meaning that it was not initially read by anyone at the company and so no reply was sent to the hacker.

The hacker stayed true to his word and the website became inaccessible to genuine internet users looking to browse products. In an attempt to overcome the issue, the company’s IT team decided to block any internet traffic that came from outside the country in which they were based. This provided a very brief period of respite for the insured. The hacker did not stop there though and used multiple other methods to continue to bring the website down, with the company’s I.T. team continuously looking for ways to rectify the issue.

After numerous attempts with little success, the insured contracted the insurer’s incident response team. The company’s website was soon back up and running, though the time offline resulted in a shortfall of $175,206 in sales due to the disturbance, with the business interruption element of the cyber policy coming in to play.

When an auto parts dealer gets hit by a ransomware attack, it comes close to wrecking their business

The incident began when a hacker gained access to the company’s computer systems through the remote desktop protocol (RDP). RDP allows remote users to connect to the desktop of another computer through a network connection and is typically used by organisations to allow employees to access their networks while working remotely.

Having identified a vulnerability in that the RDP access was open to the internet, the hacker initiated a brute-force attack to obtain credentials to the organisation’s local administrator account. Once the hacker was logged in, they downloaded password scraping software that allowed them to obtain the policyholder’s domain administrator account credentials, allowing for greater access across the network. The hacker then went on to launch their encryption software across multiple servers, leaving a ransom note for the business and requesting that a payment of 40 bitcoin be made in return for the decryption key.

Upon discovering the ransom note and realising that its computer systems and data were no longer accessible, the business notified the insurer’s response team. Alongside the company’s I.T. team, the response team went about restoring the system, but this was a time-consuming process, and it would take nearly two weeks for the system to be restored fully.

In the immediate aftermath of the ransomware attack, the auto dealer’s revenue dropped below 5% of its usual level and even though the organisation’s computer systems were fully operational again within two weeks, it took several more to re-engage suppliers and gain traction with customers. In total, over the course of an 8-week period, the business saw its revenue drop a shortfall of £1,048,049.

More than just insurance – how we can help

We appreciate that quite often, people can see insurance as a contract that promises to pay when a valid claim comes in but cyber policies offer much more than just that. Cyber insurance policies can also provide a service which helps policyholders by assisting with technical experts and advising you on what to do when something goes wrong, something that can be extremely costly in the midst of a cyberattack.

We hope we have provided some context around cyber-related risk and how a robust insurance policy can help. With access to a number of cyber liability products which can be tailored to your needs, McClarrons can help find the right cyber policy and cover for your business, giving you peace of mind around your protection.

For more information, or if you would like a complimentary insurance review, please do not hesitate to contact our Commercial Team on 01653 609151 or by emailing commercial@mcclarroninsurance.com.

Sources:

https://www.datto.com/blog/cybersecurity-101-intro-to-the-top-10-common-types-of-cybersecurity-attacks

https://www.cfcunderwriting.com/en-gb/resources/case-studies/

https://www.gov.uk/government/news/russia-behind-cyber-attack-with-europe-wide-impact-an-hour-before-ukraine-invasion

https://en.wikipedia.org/wiki/Main_Page

Blog updated Oct 2023.

Share this article

Post Info

Continue Reading

Related Articles

From adverse weather and supply chain disruptions to site incidents and contractor issues, construction delays can have significant financial consequences. In this blog, we explore how construction insurance can help your business when projects don’t go to plan.
Cafés and coffee shops face a wide range of everyday risks. Café insurance is designed to help hospitality businesses protect their premises, finances and reputation.
Mistakes, misunderstandings, and allegations of negligence can happen in any professional service business. Professional indemnity insurance can protect businesses against claims of errors, omissions, or advice resulting in a client suffering financial loss.
Changes in stock value, product type or seasonal inventory levels can significantly affect your retail insurance cover. Failing to keep your insurer informed could lead to underinsurance, reduced claim payouts or even declined claims.
What is tradesman insurance? What does it cover? Do you need it? In our video, McClarrons’ commercial insurance specialists have compiled and answered some frequently asked questions to help you understand tradesman insurance.
Running a business today means navigating an increasingly complex legal landscape. Insurance can provide invaluable support; here, we look at how Legal Expenses Insurance (LEI) can help protect your business when legal issues arise.