Small to medium enterprises (SMEs) need to be aware of cybersecurity risks, including social engineering attacks. Knowing the warning signs to look out for could help protect your business from social engineering, as can the right insurance cover.
Sometimes called ‘human hacking’, social engineering refers to manipulating people into divulging sensitive information, granting access to private data, or transferring money.
While hackers in the movies use high-tech tools to break into secure networks, in real life it’s often much simpler to trick someone into handing over a password or account details.
Like other cyber risks, social engineering can not only affect your SME’s bottom line, but your customers’ security and your company’s reputation.
Smaller new businesses and startups are vulnerable to social engineering attacks, for reasons including:
While many hackers target individuals, businesses have been more frequently targeted by cyber threats in recent years.
New Zealand’s Computer Emergency Response Team (CERT NZ) found that in Q2 2023, 144 reported incidents (7% of the total) specifically affected organisations, compared with 111 (6%) in Q1 2023. Of these 144 reported incidents, the finance and insurance sector accounted for 30%, the most of any business sector.
Phishing and credential harvesting was the largest category of incidents reported to CERT NZ in Q2 2023, accounting for 72 (50%) incidents. The media and telecommunications sector reported that over 50% of their incidents related to phishing and credential harvesting.
Software developers have also reported a 742% average annual increase in software supply chain attacks over the past 3 years.
Hackers use a wide variety of social engineering tactics, such as:
Knowing these basic signs of potential social engineering can help to decrease the risk of a successful attack:
Some of the steps that SMEs can take to help minimise social engineering risks include:
Social engineering is often covered as part of your business cybersecurity insurance. As well as the right cover, you may also want expert guidance and support to address social engineering challenges.
For example, Marsh’s dedicated cyber teams and advisory services can:
This website contains general information, does not take into account your individual objectives, financial situation or needs and may not suit your personal circumstances.
Marsh Pty Ltd (ABN 86 004 651 512, AFSL 238 983) (“Marsh”) and Marsh Advantage Insurance Pty Ltd (ABN 31 081 358 303, AFSL 238 369) (“MAI”) arrange the general insurance (i.e. not the Discretionary Trust Arrangement) and are not the insurer.
Discretionary Trust Arrangements are issued by the Trustee, JLT Group Services Pty Ltd (ABN 26 004 485 214, AFSL 417 964) (“JGS”). Any advice or dealing in relation to a Discretionary Trust Arrangement is provided by JLT Risk Solutions Pty Ltd (ABN 69 009 098 864, AFSL 226 827) (“JLT”). The cover provided by a Discretionary Trust Arrangement is subject to the Trustee’s discretion and/or the relevant policy terms, conditions and exclusions.
For full details of the terms, conditions and limitations of the covers and before making any decision about whether to acquire a product, refer to the specific policy wordings and/or Product Disclosure Statements (PDSs) available from the relevant product issuer. Target Market Determinations (TMDs) are available here.
Marsh, MAI, JGS and JLT are all businesses of the Marsh group.
Any statements concerning actuarial, tax, accounting, or legal matters are based solely on our experience as insurance brokers and risk consultants and are not to be relied upon as actuarial, accounting, tax, or legal advice, for which you should consult your own professional advisors.
LCPA 24/316