Most modern organisations utilise their computer systems to perform key business functions in one way or another making cyber crime a real issue and cyber insurance an important consideration.
What happened?
This particular cyber incident began when a hacker gained access to the company’s computer systems through the Remote Desktop Protocol (RDP). RDP allows remote users to connect to the desktop of another computer through a network connection and is typically used by organisations to allow employees to access their networks while they are working remotely. If the port an organisation uses for RDP access is exposed directly to the internet, it can be easy for cyber criminals to find it, where they can then attempt to gain access to the organisation’s computer systems. This is exactly what happened in this scenario.
Having identified this vulnerability, the hacker initiated a brute-force attack to obtain credentials to the organisation’s local administrator account. A brute-force attack is where a hacker uses a computer program to crack passwords by trying numerous possible password combinations in quick succession, with the program typically trying a long list of the most commonly used passwords. Generally speaking, the longer and more complex the password, the more difficult and time consuming it is for the program. Unfortunately, in this scenario, the business’s local administrator account had a weak password in place; a default password that had never been changed. With the password lacking in complexity, the brute-force program was able to crack the password with ease.
Furthermore, the business didn’t have multi-factor authentication enabled for RDP access meaning that as soon as the password was cracked, the hacker was able to gain access to the organisation’s network without having to go through a second verification procedure (such as inputting a verification code).
Once the hacker was logged in, they downloaded password scraping software that allowed them to obtain the insured’s domain administrator account credentials, giving them greater access. With the preliminary work done, the hacker then went on to launch their encryption software across multiple servers, leaving a ransom note for the business and requesting that a payment of 40 bitcoin be made in return for the decryption key.
How cyber insurance helped
Upon discovering the ransom note and realising that its computer systems and data were no longer accessible, the business notified their insurer’s (CFC) incident response team. The incident response team’s first priority was to establish the status of the organisation’s back-ups. Fortunately, the auto-dealer did have offline back-ups stored on a USB flash drive that it could look to restore from. Given the high cost of the ransom demand and the fact that back-ups were in place, the business decided to eschew paying the ransom demand and recover from back-ups instead.
The policyholder’s IT team, working with the insurer’s incident response team, then went about restoring the system from the offline back-ups; this was a time-consuming process involving the rebuilding of all affected servers and workstations, and it took nearly two weeks for the system to be restored fully.
During this time, the auto dealer faced significant operational problems; this disruption was felt most acutely in the part of the business focused on the selling of new and used car parts.
The company used a software program to manage this section of the business; this ERP system was used to manage the stock inventory of new and used car parts, to create quotes for customers, modify pricing and apply discounts, manage currency, tax and transaction issues for exports to foreign countries, arrange billing and delivery for customers, and provide real time sales data for senior management. In short, access to the ERP system was an essential part of the auto dealer’s business operations.
Unfortunately, during the ransomware attack, this system was rendered inaccessible, resulting in problems for call centre and warehouse staff. Although the organisation’s phone systems were unaffected and call centre staff could still take calls from prospective customers, without access to the ERP system, it wasn’t possible to automatically check whether an item was in stock or not. The only option would be to note the customer’s contact details, call one of the warehouses and get a member of the warehouse staff to physically check if an item was in stock or not. What’s more, even if an item was in stock, it wasn’t possible to send over formal quote documents to the customer as the normal process for creating quotes was dependent on the system, so call centre staff had to resort to giving indicative prices over the phone to the customer instead.
Not only this, without access to previous quotes and customer details on the ERP database, call centre staff were unable to chase up quotes with prospective customers and secure new orders. If a customer did get in touch to confirm that they would like to go ahead with purchasing a particular car part, staff weren’t able to simply process the order and arrange delivery access like they normally would. Now, they had to explain to the customer that they could make a note of the customer’s intention to buy, but that delivery and invoice processing would be delayed due to the system being unavailable.
Procurement was also impacted. Without access to the most recent stock and sales data, the management team did not have an accurate overview of which items were low in stock and needed to be re-ordered from suppliers, resulting in a shortage of popular items.
Operational difficulties such as these were significantly slowing down the sales process and dissuading customers from buying. The policyholder’s customer base was primarily made up of small, infrequent purchasers of car parts as opposed to consistent purchasers with long term arrangements in place with the business. As a result, customer loyalty is low and if the business didn’t have an item in stock or if there were likely to be delays with purchase or delivery, customers would simply look elsewhere, with little opportunity for the organisation to claw back business once it had gone elsewhere.
In the immediate aftermath of the ransomware attack, the auto dealer’s revenue dropped below 5% of its usual level and even though the computer systems were fully operational again within two weeks of the attack, it still took several weeks to re-engage suppliers and gain traction with customers once more. In total, over the course of an 8-week period, the business saw its revenue drop from an expected £4,450,027 to £3,401,978 – a shortfall of £1,048,049. After the application of the business’s rate of gross profit of 58%, this represented a business interruption loss of £607,868.
This came on top of an additional £183,045 incurred to restore impacted servers and workstations from back-up and carry out forensic investigations to establish the root cause of the attack, a full scan to remove any residual malware from the insured’s computer systems, and some post-breach remediation in order to reduce the likelihood of the attack happening again. Thankfully for the business in question, they had a cyber insurance policy in place with CFC and were able to recover these losses under the policy.
Case Study takeaways
It is important to ensure you have the right IT security policies in place to protect your organisation from becoming victim to cyber crime, such as Multi Factor Authentication.
Dependency on computer systems is high for most businesses today but it is important to consider what you would do and how you would operate in the event of a cyber event, for example in the form of a business continuity plan.
The importance of having a cyber insurance policy, even if a business has prudent risk management controls in place, can be invaluable as costs can wrack up quickly when it comes to recovery, rectification, and remediation. By having a cyber insurance policy in place, companies can have a valuable safety net.
We hope we have provided context on cyber-related risk and demonstrated how a robust insurance policy can help manage those risks effectively. With access to a number of cyber liability products which can be tailored to your needs, McClarrons can help find the right cyber policy and cover for your business, giving you peace of mind around your protection.
For more information, or if you would like a complimentary insurance review, please do not hesitate to contact our Commercial Team on tel:01653 609151 or by emailing commercial@mcclarroninsurance.com.