How Prepared Is Your Business for a Cyber Attack?

October is Cybersecurity Awareness Month, providing businesses with a timely reminder to review how well prepared they are for the growing range of digital risks they face.
Cyber security is no longer something that only large organisations or technology companies need to consider. Businesses of virtually every size now rely on email, online banking, cloud-based systems, customer data and connected technology as part of their everyday operations.
The latest UK Government Cyber Security Breaches Survey found that 43% of businesses had identified a cyber security breach or attack during the previous 12 months. Among small businesses the figure was 46%, increasing to 65% of medium-sized businesses and 69% of large businesses.
So, how prepared would your organisation be if it became the next target?
Make Cyber Security a Business Issue
Cyber security may involve technology, but responsibility for managing cyber risk should extend beyond the IT department.
A successful attack could potentially disrupt operations, compromise sensitive information, affect customers and suppliers, create unexpected costs and damage a business’s reputation.
Business owners and senior management should therefore understand the cyber risks facing their organisation and ensure appropriate measures are in place to manage them.
Make Sure Employees Understand the Risks
People are an important part of a business’s cyber defences.
Phishing remains the most commonly identified type of cyber attack among UK businesses, accounting for the vast majority of incidents identified in the latest Government survey.
Training employees to recognise suspicious emails, unexpected requests, unusual links and attempts to obtain login details can help reduce the likelihood of an attack succeeding.
Employees should also know how to report something suspicious. The sooner a potential incident is identified, the sooner the business can take appropriate action.
Review Passwords and Account Security
Compromised account credentials can provide criminals with access to email accounts, systems and sensitive business information.
Businesses should consider how passwords are managed across the organisation and whether additional security measures, such as multi-factor authentication, are being used where appropriate.
Access permissions should also be reviewed, particularly when employees change roles or leave the organisation.
Think About Your Backups
If important systems or data suddenly became unavailable, how quickly could your business recover?
Maintaining appropriate backups can form an important part of cyber resilience, but simply having a backup isn’t necessarily enough.
Businesses should understand what information is being backed up, how frequently this happens and whether those backups could be successfully restored following an incident.
Have a Cyber Incident Response Plan
The middle of a cyber attack is not the ideal time to decide who needs to do what.
A response plan can establish responsibilities in advance, including who should contact IT specialists, senior management, insurers, legal advisers and other relevant parties.
The National Cyber Security Centre recommends that organisations have an incident response plan and practise it before an incident occurs.
The plan should also consider how the business would continue communicating if its usual email or IT systems became unavailable.
Understand Your Data Responsibilities
A cyber attack may also result in a personal data breach.
Not every personal data breach needs to be reported to the Information Commissioner’s Office, but organisations need to assess the potential risk to individuals. Where the reporting threshold is met, the ICO requires notification without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Understanding these responsibilities before an incident can help a business respond more effectively when time is important.
Review Your Cyber Insurance
Cyber Insurance can form another part of a business’s wider approach to managing cyber risk.
Depending on the policy, cover may be available for areas such as incident response, data recovery, business interruption, legal costs and liability following a cyber event.
However, Cyber Insurance should work alongside appropriate cyber security measures rather than replacing them.
Businesses should regularly review their insurance to make sure the information provided to insurers remains accurate and the protection arranged continues to reflect their activities, systems and potential exposures.
Make Cybersecurity Awareness Month Count
Cybersecurity Awareness Month is an opportunity to do more than remind employees not to click suspicious links.
It is a chance to review your organisation’s overall preparedness, from employee awareness and account security to backups, incident response procedures and insurance protection.
At W B Baxter, we can help businesses review their Cyber Insurance requirements and explore cover suited to their individual risks.
As part of Adler Fairways, W B Baxter combines personal service with access to wider insurance expertise and markets.
Contact our team today to discuss your Cyber Insurance requirements.
The cover available and policy features will vary between insurers and policy wordings. Specific terms, conditions, limits, exclusions and eligibility criteria apply. Businesses should seek advice regarding their individual requirements.