Cyber claims examples: what small businesses can learn from real incidents
A cyber incident can feel like a technology problem at first.
Then the business impact starts to show. Staff cannot access systems. Payments are redirected. Customer information may be exposed. A website stops taking bookings.
For Australian small businesses, cyber claims examples can show where costs may come from and why planning matters.
The examples below show how different cyber incidents can affect day-to-day business operations, from payments and systems access to data recovery and response costs.
For a broader overview of cover, read Marsh’s cyber insurance for Australian businesses.
What you should know
Cyber risk is not only about large companies.
Many smaller businesses use digital systems every day. They may use email for invoices, cloud tools for client records, booking software, or accounting systems for cash flow.
The Australian Signals Directorate reported that ASD’s ACSC “Received over 84,700 cybercrime reports to ReportCyber” and that the average self-reported cost of cybercrime per report for businesses included “small business: $56,600 (up 14%)”.1
Those figures are not specific to any one industry. They show the wider cost pressure cybercrime can place on Australian businesses.
A cyber claim may involve investigation, system recovery, data recovery, lost income, legal support, privacy support or payment fraud.
A real estate office faced a large response cost
A real estate office in regional South Australia experienced a cyber attack.
The office did not have cyber insurance in place.
After the incident, external support was arranged so the business could understand its response options. The business then received a quote for investigation and legal services only. That quote was just under $200,000.
The lesson is not that every real estate business will face the same cost.
The lesson is that a smaller office can still face a cyber event that needs urgent external help. Real estate businesses may handle personal information and business records, depending on how they operate.
Ransomware can affect everyday operations
In a CFC case study, a small electrical contracting firm was hit by ransomware after an employee opened an attachment that looked like a résumé. The ransomware encrypted the business’s computer programs and demanded $5,000 to restore access.
The business did not rely only on computers to perform electrical work. But the office relied on systems for calls, work orders, invoices and financial accounts.
For four days, office staff worked manually while systems were restored. Later, one older program still did not work properly. Staff had to move data into a new system, which took 1,562 overtime hours and 521 temporary staff hours. The total claim cost came to $81,387.
Backups need to be checked
In another CFC case study, a small engineering firm was affected by WannaCry ransomware. The attack encrypted files on its server and on a local hard drive. The files included technical drawings, design specifications and project records.
The business expected to restore the files from a cloud backup.
When it tried to do that, it found the cloud backup had been failing since 2014. Several years of documents could not be recovered. The cost of data re-creation alone came to over $270,000.2
The Australian Signals Directorate says, “The best recovery method from a ransomware attack is to restore from an unaffected backup”, and “Backing up and checking that backups restore your files offers peace of mind.”4
Email fraud can look very normal
A CFC case study involving a construction firm showed how invoice fraud can start with one compromised email account. A fraudster gained access to an employee’s inbox through a phishing email, watched the account, and found an invoice from a subcontractor.
The fraudster then created a lookalike email address, used the same invoice template and changed only the bank details.
The business had a process to verify bank account changes by phone. In this case, that step was missed. The loss was $93,425.
This lines up with the Australian government guidance on business email compromise. The Australian Signals Directorate says business email compromise is when malicious actors “use email to abuse trust in business processes to scam organisations out of money or goods”.
Clubs and hospitality businesses can be exposed too
A semi-professional Australian rules football team had a virus spread to its point of sale server, taking tills offline. The total cost of dealing with the incident came to $36,911, with $31,814 payable under the club’s cyber policy with CFC.
A NSW golf club lost $198,274 after a finance manager received emails that appeared to come from the CEO. The CEO had been impersonated.
A cyber incident may affect payments, tills, bookings and supplier payments.
What could create claim costs?
A cyber claim may include investigation, legal support, system restoration, data recovery, lost income, privacy support and fraudulent payment loss.
Cyber insurance may help with some of these costs, depending on the cover arranged and the policy terms.
If a business handles personal information, privacy obligations may also need to be considered. Business.gov.au says, “If your business has an annual turnover of more than $3 million, you must comply with the Privacy Act”, and “Some businesses with smaller turnovers still need to comply with the Privacy Act.”5
The Office of the Australian Information Commissioner says, “The NDB scheme requires regulated entities to notify particular individuals and the Commissioner about ‘eligible data breaches’” and “A data breach is eligible if it is likely to result in serious harm to any of the individuals to whom the information relates.”6
What small businesses can take from these examples
The examples are different, but the practical lessons are similar.
A small business can reduce cyber pressure by checking a few basics:
- Confirm bank account changes by phone using a known number
- Turn on multi-factor authentication for email and key systems
- Keep systems and software updated
- Back up important data and test that it can be restored
These steps cannot remove every risk. They can make some incidents less likely and may help the business respond faster.
It is also worth reviewing cyber insurance before an incident happens. Once a business is in the middle of a cyber event, it may need to make decisions quickly.