In the cybersecurity world, not all attacks involve sophisticated code or brute-force hacking. Some of the most successful breaches begin with a simple email, a phone call, or even a text message. That’s the power—and danger—of social engineering.
And today’s phishing scams? They’re not just crude "Nigerian prince" emails anymore. They are targeted, convincing, and deeply sophisticated.
What is Social Engineering?
At its core, social engineering is about manipulating people into giving up confidential information—credentials, financial data, or access to systems. It preys not on system vulnerabilities, but on human nature.
Phishing is the most common form of social engineering, but others include:
· Phishing: Fake emails or websites
· Vishing & Smishing – Fake phone calls or messages
· Spear Phishing – Personal information used
· Pretexting: Trusted personnel impersonated
How sophisticated have these attacks become?
Today's attackers use:
· AI to write flawless, convincing messages that mimic real employees or executives
· Deep research on targets using LinkedIn and other social platforms
· Lookalike domains and spoofed emails that are almost indistinguishable from the real thing
· Urgency tactics that pressure users to act before thinking
Example: Imagine receiving a message from your “CEO” asking for a wire transfer to close a last-minute deal. The tone is right. The signature matches. The domain looks legit. In a busy workday, it’s easy to fall for.
And that’s exactly what attackers are counting on.
How can businesses protect themselves?
The good news? You don’t need a massive cybersecurity budget to make a big difference. Here’s what works:
1. Ongoing Staff Training
· Educate employees to spot red flags: unexpected attachments, requests for sensitive info, or odd language.
· Run regular phishing simulations to test awareness in a safe environment.
· Train teams to slow down and verify—especially when money or credentials are involved.
2. Establish Clear Protocols
· Implement multi-step verification for financial requests or system changes.
· Create clear reporting processes for suspicious emails or interactions.
· Use email banners to flag external senders.
3. Layered Technical Defenses
· Email filtering & threat detection tools can block many phishing attempts.
· Enable multi-factor authentication (MFA) across all systems.
· Keep systems updated to reduce technical vulnerabilities.
The human firewall is your first line of defense
No matter how advanced your tech stack is, your people are your strongest defense—or your weakest link. Building a culture of cyber awareness is no longer optional. It’s essential.
Contact our underwriting enthusiasts to chat through any opportunity at cyber@360uw.com.au

This content is brought to you by 360 Underwriting Solutions Pty Ltd and 360 Financial Lines Pty Ltd (“360”) as a convenience to readers and is not intended to constitute advice (professional or otherwise) or recommendations upon which a reader may rely. Any references to insurance cover are general in nature only and may not suit your particular circumstances. Reference in this content (if any) to any specific commercial product, process, or service, and links from this content to other third-party websites, do not constitute or imply an endorsement or recommendation by 360.
Artificial Intelligence is no longer a futuristic concept—it’s now deeply woven into our personal lives and business ecosystems. From automating customer service to detecting fraud in real time, AI has become an indispensable tool in our digital toolkit. But like any powerful tool, it comes with risks.
So the question isn’t just “How can AI help?”—it’s also “What vulnerabilities does it introduce?”
AI as a Cybersecurity Ally
Let’s start with the good news. AI is revolutionizing cybersecurity with:
· Threat Detection at Scale: Machine learning can analyse massive datasets to identify abnormal patterns in seconds—far faster than any human.
· 24/7 Monitoring: AI-powered systems don’t sleep. They can continuously monitor networks, endpoints, and user behaviours.
· Incident Response Automation: AI can help neutralise threats before they cause real damage, reducing response time drastically.
In short, AI helps us stay ahead of the curve in an ever-evolving cyber threat landscape.
AI as a Cybersecurity Risk
But here’s the flip side—and it’s a serious one.
· Deepfakes & Social Engineering: AI-generated audio and video can convincingly impersonate trusted individuals, opening new doors for fraud and phishing.
· AI-Powered Attacks: Hackers are using AI too. From malware that adapts in real-time to AI models trained to bypass detection, the bad guys are getting smarter.
· Data Privacy Concerns: AI systems need data—lots of it. And if not properly secured, that data can become a goldmine for cybercriminals.
· Algorithmic Bias & Exploitation: Poorly trained AI can be manipulated or make flawed decisions, especially if attackers poison training data.
What Does This Mean for Businesses and Individuals?
For businesses, it’s crucial to:
· Conduct regular AI risk assessments
· Invest in explainable AI to ensure transparency and accountability
· Enhance employee training to recognise AI-powered scams
For individuals, awareness is key. Ask questions about the AI tools you interact with. Be cautious of what you share online. And remember—if it seems too good to be true, it probably is.
Final Thought
AI is neither inherently good nor evil. It’s a tool. A powerful one. Whether it becomes our greatest ally or our worst adversary depends on how we design it, use it, and defend against its misuse.
Let’s embrace the potential—but not without vigilance. Cybersecurity in the age of AI is a shared responsibility.

This content is brought to you by 360 Underwriting Solutions Pty Ltd and 360 Financial Lines Pty Ltd (“360”) as a convenience to readers and is not intended to constitute advice (professional or otherwise) or recommendations upon which a reader may rely. Any references to insurance cover are general in nature only and may not suit your particular circumstances. Reference in this content (if any) to any specific commercial product, process, or service, and links from this content to other third-party websites, do not constitute or imply an endorsement or recommendation by 360.
Identity Theft: A Growing Threat to Individuals and Businesses
Identity theft is one of the most pervasive and damaging cyber threats in today's digital world. Whether targeting individuals or businesses, identity theft can lead to financial losses, reputational damage, and severe emotional distress. But what exactly is identity theft, and how can we protect ourselves from becoming victims?
What Is Identity Theft?
Identity theft occurs when someone fraudulently acquires and uses another person's personal or financial information—such as Social Security numbers, bank account details, or login credentials—without their permission. This stolen information is often used to commit fraud, make unauthorised.
The Impacts of Identity Theft
On Individuals:
- Financial Losses: Stolen credentials can be used to drain bank accounts, open fraudulent credit lines, or make unauthorised purchases.
- Credit Score Damage: Fraudulent financial activity can severely impact credit scores, making it difficult to secure loans, mortgages, or credit cards.
- Emotional and Psychological Distress: The stress and anxiety caused by identity theft can be overwhelming, as victims struggle to reclaim their identities and restore their financial security.
- Legal Consequences: In some cases, identity thieves commit crimes in the victim's name, leading to false accusations and legal complications.
On Businesses:
- Financial Fraud and Data Breaches: Companies that fall victim to identity theft-related fraud may face significant financial losses.
- Reputational Damage: A breach of customer or employee information can erode trust and result in lost business opportunities.
- Regulatory Penalties: Failure to protect sensitive data may lead to hefty fines and legal actions from regulatory authorities.
- Operational Disruptions: Identity theft incidents often require extensive investigations and mitigation efforts, diverting resources from business operations.
What to Do If You Suspect Identity Theft
For Individuals:
- Monitor Your Accounts Regularly: Check your bank statements, credit reports, and online accounts for suspicious activity.
- Report Fraudulent Activity Immediately: Contact your bank, credit card provider, and relevant authorities to report any unauthorised transactions.
- Freeze Your Credit: A credit freeze can prevent identity thieves from opening new accounts in your name.
- Change Passwords and Secure Your Accounts: Update passwords for compromised accounts and enable multi-factor authentication (MFA) for added security.
- File a Police Report: Reporting identity theft to law enforcement and credit agencies can help in mitigating further damage.
For Businesses:
- Implement Robust Cybersecurity Measures: Use encryption, firewalls, and multi-factor authentication to secure sensitive data.
- Train Employees on Security Best Practices: Educate staff on how to recognize phishing attempts, social engineering attacks, and other identity theft tactics.
- Monitor for Unusual Transactions: Regularly review financial transactions and user activity for potential fraud.
- Establish Incident Response Plans: Have a clear protocol for handling identity theft incidents to minimize damage and recover quickly.
- Comply with Data Protection Regulations: Ensure adherence to laws such as GDPR and CCPA to protect customer and employee information.
How to Protect Yourself from Identity Theft
For Individuals:
- Be Cautious with Personal Information: Avoid sharing sensitive data on unsecured websites or social media.
- Use Strong, Unique Passwords: A password manager can help generate and store secure passwords for different accounts.
- Enable Multi-Factor Authentication (MFA): Adding an extra layer of security makes it harder for cybercriminals to access your accounts.
- Shred Sensitive Documents: Properly dispose of documents containing personal information to prevent dumpster diving attacks.
- Stay Alert to Phishing Scams: Be wary of unsolicited emails, texts, or calls asking for personal information.
For Businesses:
- Conduct Regular Security Audits: Identify vulnerabilities and ensure systems are up to date with the latest security patches.
- Invest in Identity Verification Solutions: Advanced authentication technologies can help detect and prevent fraudulent activities.
- Secure Customer and Employee Data: Encrypt sensitive information and limit access to authorised personnel only.
- Partner with Cybersecurity Experts: Collaborate with specialists to strengthen your organisation's security posture.
- Have a Data Breach Response Plan: Being prepared to respond to data breaches can minimize damage and restore trust quickly.
Identity theft is a growing threat that affects both individuals and businesses, but proactive measures can help mitigate the risks. By staying vigilant, adopting strong security practices, and educating ourselves about identity theft tactics, we can better protect our personal and financial information. Whether you're an individual or a business leader, taking the right precautions today can prevent devastating consequences in the future.
For further information please contact the Cyber Underwriting Team via cyber@360uw.com.au or visit our website 360uw.com.au.
This content is brought to you by 360 Underwriting Solutions Pty Ltd and 360 Financial Lines Pty Ltd (“360”) as a convenience to readers and is not intended to constitute advice (professional or otherwise) or recommendations upon which a reader may rely. Any references to insurance cover are general in nature only and may not suit your particular circumstances. Reference in this content (if any) to any specific commercial product, process, or service, and links from this content to other third-party websites, do not constitute or imply an endorsement or recommendation by 360.
Deepfakes: The Rising Threat to Individuals and Businesses
In an era where digital technology is evolving at an unprecedented pace, deepfakes have emerged as one of the most concerning cybersecurity threats. But what exactly are deepfakes, and why should individuals and businesses be worried about them? More importantly, how can we protect ourselves from their potential harm?
What Are Deepfakes?
Deepfakes are hyper-realistic synthetic media created using artificial intelligence (AI) and machine learning (ML) techniques. These technologies can manipulate audio, video, and images to convincingly depict someone saying or doing something they never actually did. While deepfake technology has some legitimate applications in entertainment and media, its potential for misuse poses serious risks.
The Threats Deepfakes Pose
To Individuals:
- Identity Theft and Reputation Damage: Deepfake technology can be used to create fake videos or audio recordings of individuals, making it appear as though they have said or done things they never did. This can be used to damage reputations, manipulate personal relationships, or even commit fraud.
- Financial Scams and Fraud: Cybercriminals can use deepfake voices to impersonate family members, business executives, or public figures to trick people into transferring money or divulging sensitive information.
- Misinformation and Manipulation: Deepfakes can be used to spread false information, influencing public opinion and decision-making, especially in political and social contexts.
To Businesses:
- Corporate Fraud and Impersonation: Fraudsters can use deepfake audio or video to impersonate executives, authorising fraudulent transactions or misleading employees into revealing sensitive data.
- Market Manipulation and Brand Damage: False videos of company executives making misleading statements or engaging in unethical behaviour can significantly impact stock prices and brand reputation.
- Cybersecurity Risks: Deepfakes can be used to bypass biometric security measures such as voice or facial recognition systems, posing a significant challenge for corporate security teams.
How Can We Protect Ourselves?
For Individuals:
- Be Skeptical of Unverified Content: If a video or audio clip seems suspicious, verify it through trusted sources before believing or sharing it.
- Enhance Digital Literacy: Educate yourself about the signs of deepfake manipulation, such as unnatural facial expressions, mismatched lip-syncing, or inconsistent shadows.
- Use Multi-Factor Authentication (MFA): Protect sensitive accounts with multiple layers of authentication rather than relying solely on voice or facial recognition.
For Businesses:
- Implement Deepfake Detection Technology: AI-driven detection tools can analyse videos and audio for signs of manipulation.
- Strengthen Cybersecurity Policies: Establish protocols to verify high-risk communications, such as requiring secondary confirmations for financial transactions.
- Train Employees to Identify Deepfake Threats: Cybersecurity awareness programs should include training on recognizing and mitigating deepfake risks.
- Legal and Regulatory Advocacy: Advocate for stronger laws and regulations against the malicious use of deepfake technology.
Deepfake technology is advancing rapidly, and while it offers innovative possibilities, it also presents significant risks. As individuals and businesses, we must remain vigilant, educate ourselves, and leverage technology to counteract the threat. The fight against deepfakes is an ongoing challenge, but with awareness and proactive measures, we can mitigate their impact and protect ourselves from digital deception.
For further information please contact the Cyber Underwriting Team via cyber@360uw.com.au or visit our website 360uw.com.au.
This content is brought to you by 360 Underwriting Solutions Pty Ltd and 360 Financial Lines Pty Ltd (“360”) as a convenience to readers and is not intended to constitute advice (professional or otherwise) or recommendations upon which a reader may rely. Any references to insurance cover are general in nature only and may not suit your particular circumstances. Reference in this content (if any) to any specific commercial product, process, or service, and links from this content to other third-party websites, do not constitute or imply an endorsement or recommendation by 360.
360 Cyber partners with KYND for Cyber Risk Vulnerability Reports
We’re excited to announce our new partnership with KYND, cyber risk management experts. Through this collaboration, we’re providing you with access to KYND’s Cyber Risk Vulnerability Reports, designed to help your customers better understand their cyber vulnerabilities and exposures.
KYND non-invasively scans for publicly visible software and services that are owned by an organisation, visible on the internet, grouping any threats as Red or Amber. With this information, it will give you recommended actions, both essential and advisable ones.
Linked Below is a Guide that explains some of the risk indicators to help your clients use the report to understand and mitigate the cyber vulnerabilities posing a risk to their organisation. The reports come at zero cost to you or your client and can be run for as many clients as you like.
Please view the Kind Risk Indicators here
Requesting a KYND Report
To request a report choose “Yes” to “Would you like a Kynd Report run for this client?” on the limits screen on Compass, or on the proposal form.
We will still be underwriting based on the answers provided to the underwriting questions, however, for accounts over $30M or high risk industries we may use the KYND report in conjunction with your answers.
If you have any questions relating to our new Kynd offering, please do not hesitate to get in contact with our 360 Cyber Team.
For further information please contact the Cyber Underwriting Team via cyber@360uw.com.au or visit our website 360uw.com.au
In today's fast-paced digital world, cybersecurity threats are more aggressive and sophisticated than ever. Did you know that 1 in 5 critical vulnerabilities were exploited within the 48 hours of their discovery according to the ASD Cyber Threat Report 2022-2023? This was despite patching or mitigation advice being available. Malicious cyber actors used these critical flaws to cause significant incidents and compromise networks, aided by inadequate patching. This alarming statistic highlights the urgent need for businesses to prioritise the application of critical patches.
Why the rush?
Attackers act fast, Cybercriminals monitor for newly disclosed vulnerabilities, and they waste no time in developing exploits. The first 48 hours are a critical window where businesses are most vulnerable. By applying patches quickly, you drastically reduce the attack surface and minimise the chances of a breach.
What can you do?
Stay informed: Keep up-to-date with the latest security advisories and ensure your IT team is aware of newly released patches.
Automate where possible: Implement automated patch management tools that can quickly apply critical updates across your infrastructure.
Prioritize and act: Ensure that critical patches are at the top of your priority list and act within the first 48 hours to safeguard your business.
This content is brought to you by 360 Underwriting Solutions Pty Ltd and 360 Financial Lines Pty Ltd (“360”) as a convenience to readers and is not intended to constitute advice (professional or otherwise) or recommendations upon which a reader may rely. Any references to insurance cover are general in nature only and may not suit your particular circumstances. Reference in this content (if any) to any specific commercial product, process, or service, and links from this content to other third-party websites, do not constitute or imply an endorsement or recommendation by 360.
The farming and agriculture industry in Australia is increasingly embracing digital transformation to enhance productivity, efficiency, and sustainability. This shift involves the integration of advanced technologies such as Internet of Things (IoT) devices, precision farming tools, and automated machinery. The growth of precision agriculture and smart farming has rapidly increased the number of Internet enabled devices in the agriculture sector, which increases the cyber attack surface or the number of potential entry points for a cyber attacker. Ransomware is a particular concern. Easily deployable ransomware attacks, in which cybercriminals threaten to destroy farmers’ data and systems unless a ransom is paid, will become more common on critical data and equipment, particularly during time-sensitive windows for planting and harvesting. Understanding these risks and learning from recent cyber incidents is vital for protecting the industry and ensuring its continued growth and resilience.
Main Cyber Risk Exposures
1.Data Breaches and Theft:
Sensitive Data: The move to smart farming and precision agriculture generates significant data, which is also open to cyber risks. The growing use of automated machinery, high resolution multispectral imagery, drones, soil sensors, and IoT technologies in the agriculture and food security sector is generating large amounts of data. This renders the sector highly vulnerable to data theft and manipulation, creating a wide range of possible threat vectors. Cybercriminals could steal, manipulate, and then publish false and harmful agricultural data to undermine local industry. Foreign governments can use another country’s agricultural data to give themselves an advantage in trade negotiations or commodities markets. In some cases, the agricultural applications and databases might not be the ultimate target of the attacker.
2. Ransomware Attacks:
Operational Disruption: Ransomware can encrypt vital systems and data, bringing farming operations to a standstill. Given the time-sensitive nature of agricultural activities, such disruptions can lead to substantial financial losses and food supply chain interruptions. Imagine your GPS or automated tractor is hacked, and you can’t plant your crop until you pay to get your access back (like ransomware). And given that timing for planting/spraying/harvesting is critical this is a major threat.
Financial Extortion: Ransom payments, often demanded in cryptocurrency, represent a direct financial loss. Even after paying, there’s no guarantee that data will be fully restored.
3. Phishing and Social Engineering:
Credential Theft: Phishing attacks can trick farmers and agribusiness employees into disclosing login credentials, providing cybercriminals with access to critical systems.
Fraudulent Transactions: Social engineering tactics can lead to unauthorised financial transactions or the manipulation of critical operational decisions.
4. IoT and Operational Technology (OT) Vulnerabilities:
Connected Devices: The use of IoT devices (including drones) for monitoring soil conditions, crop health, and livestock can create numerous entry points for cyber attacks if not properly secured.
5. Supply Chain Risks:
Third-Party Access: Agricultural operations often rely on third-party vendors for software, machinery, and other services. Cyber attacks on these vendors can cascade down the supply chain, affecting the entire agricultural operation.
Integration Vulnerabilities: The integration of various digital systems can create vulnerabilities that cybercriminals can exploit.
Recent Incidents
1. JBS Foods:
In 2021, JBS Foods, a major meat processing company with operations in Australia, suffered a ransomware attack that disrupted its global operations. The attack led to the temporary closure of processing plants and had a significant impact on the meat supply chain. This incident highlighted the vulnerability of the food and agriculture sector to ransomware and its potential to disrupt food supply. Whilst the full cost of the loss is unknown they did confirm paying an $11million USD ransom to the hackers.
2. GrainCorp:
GrainCorp, a leading Australian agribusiness, faced a cyber attack in 2022 that targeted its grain handling and logistics systems. The attack caused significant operational disruptions and highlighted the importance of securing critical infrastructure within the agriculture sector.
Risk Mitigation Strategies
To address these risks, Australian farming and agribusiness companies should consider the following strategies:
1. Device Management: When enabling a new sensor or device, take a few minutes to understand all the different ways these devices connect to your network and the Internet. Adhere to the following guidance to protect yourself and your systems:
- Avoid leaving connection points open when not in use.
- Choose IoT tools that can be updated easily.
- Always keep IoT systems up to date with current versions of the firmware.
- For non-IoT systems, ensure the operating system, firmware, security software, and web browsing tools are patched. Use currently supported systems capable of receiving updates.
- Using two-factor authentication is now considered a best practice—be sure to turn it on if your devices support it.
- For mobile devices, take the time to understand your devices’ security settings. Wireless features such as Wi-Fi, cellular, Bluetooth, near-field communication, location tracking (GPS), and media sharing can all be potential breach points if left unsecured.
2. Enhanced Cybersecurity Training: Regular training sessions for employees on recognising phishing attempts, safe internet practices, and the importance of password security.
3. Robust Access Controls: Implementing strict access controls to ensure that only authorised personnel have access to sensitive data and critical systems.
4. Incident Response Plans: Developing and testing comprehensive incident response plans to ensure a swift and effective response to cyber incidents.
5. Secure Supply Chain Practices: Ensuring that third-party vendors adhere to stringent cybersecurity standards to prevent supply chain vulnerabilities.
6. Advanced Cybersecurity Technologies: Investing in advanced cybersecurity technologies such as intrusion detection systems, endpoint protection, and secure communication tools.
This content is brought to you by 360 Underwriting Solutions Pty Ltd and 360 Financial Lines Pty Ltd (“360”) as a convenience to readers and is not intended to constitute advice (professional or otherwise) or recommendations upon which a reader may rely. Any references to insurance cover are general in nature only and may not suit your particular circumstances. Reference in this content (if any) to any specific commercial product, process, or service, and links from this content to other third-party websites, do not constitute or imply an endorsement or recommendation by 360.
References:
Cyber Risks in the Construction Industry
The construction industry in Australia, like many sectors, has undergone significant digital transformation. With this shift comes an increase in cyber risk exposures. The industry's increasing reliance on technology for project management, communication, and operational efficiency creates numerous vulnerabilities that can be exploited by cybercriminals. Understanding these risks and learning from recent incidents is crucial for mitigating potential damages and ensuring the industry's resilience against cyber threats.
Main Cyber Risk Exposures
1. Data Breaches and Theft:
+ Sensitive Information: Construction firms handle a vast amount of sensitive data, including personal information of employees, financial records and project plans. Unauthorised access to this data can lead to identity theft, financial loss, and reputational damage.
+ Insider Threats: Employees or contractors with access to sensitive data might intentionally or unintentionally cause data breaches. Lack of proper access controls can exacerbate this risk.
2. Ransomware Attacks:
+ Operational Disruption: Ransomware can encrypt critical project files and halt operations, leading to project delays and financial losses. Construction timelines are often strict, and any delay can have significant repercussions.
+ Financial Extortion: Paying ransoms to regain access to data doesn’t guarantee that the data will be fully restored even after payment and there are also significant impacts if you are found to be paying a ransom to an entity listed on sanctions lists.
3. Phishing and Social Engineering Leading to Significant Financial Loss:
+ Credential Theft: Phishing attacks can trick employees into revealing login details, which can be used to access company systems and sensitive data.
+ Business Email Compromise (BEC): Fraudulent emails that appear to come from trusted sources can result in unauthorised financial transactions or the sharing of confidential information.
+ Misdirected funds and financial loss: Fraudulent emails associated with a BEC or another type of systems breach frequently deceive businesses into sending large sums of money to fraudulent bank accounts. Increasingly, we have seen criminals breach a director’s mailbox and use this access to send internal emails to accounts staff requesting that fraudulent invoices be paid. The construction industry is often targeted because of the large amount of money that flows between businesses, individuals and suppliers.
4. Supply Chain Vulnerabilities:
+ Third-Party Risks: Construction projects involve numerous third-party suppliers and contractors. A cyber-attack on any party within the supply chain can compromise the entire project’s security.
+ Integration Issues: Different systems used by various stakeholders may have integration vulnerabilities that can be targeted by cybercriminals.
5. Internet of Things (IoT) and Operational Technology (OT) Risks:
+ Connected Devices: The use of IoT devices on construction sites for monitoring and control purposes increases the attack surface. These devices often lack robust security measures leaving them vulnerable to a cyber-attack.
+ Industrial Control Systems (ICS): ICS used in construction for managing critical functions can be targeted to disrupt operations or cause physical damage.
Claims Examples
1. Design & Fitout Specialist
In 2024, the accountant of a design & fitout specialist suffered a breach which allowed an unauthorised third party to access the Insured’s accounts payable system and change supplier bank account details. As a result, the Insured processed two payments totalling $106,000 to fraudulent bank accounts. As two weeks passed before the Insured realised that the incident had occurred, only one of the transactions was able to be recovered. Their Cyber Insurance responded for Incident Response, Forensic Investigation, Legal and regulatory assistance and also the Funds recovery. Total claim $150,000.
2. Waterproofer
In 2023, a waterproofer was alerted by a supplier that it had received suspicious emails from the Insured requesting their bank account payment details be updated. The Insured notified Clyde & Co and the Incident Response kicked in to investigate the potential unauthorised access to the Insured’s system. It was discovered that a phishing email was initially interacted with by the Insured, granting an unauthorised third-party access to one of the Insured’s mailboxes. The mailbox was then used to try and trick suppliers into changing the Insured’s bank details. Luckily no suppliers acted on the change of details request. Their Cyber Insurance responded for Incident Response, Forensic Investigation, Data review and Privacy advice. Total claim $30,000.
Risk Mitigation Strategies
1. Invest in Employee Training:
Educating employees about cybersecurity best practices, such as identifying phishing scams and maintaining strong passwords, can significantly reduce the risk of successful cyber-attacks.
2. Double down on call back verification:
As part of your employee training, ensure that all accounts staff know to contact the supplier by phone for any new supplier invoices or any change in bank details. Also ensure staff know to apply the same rigour to internal emails – for example, to contact the boss/management before actioning an email from them requesting payment be made to a supplier (as well as verifying the supplier). Put this policy in writing and educate staff.
3. Implement Multi-Factor Authentication (MFA):
MFA adds an extra layer of security by requiring users to provide multiple forms of identification before accessing sensitive systems or data.
4. Backup Data Regularly:
Regularly backing up critical data to secure offsite locations can mitigate the impact of ransomware attacks or data
breaches by enabling quick data recovery.
5. Secure Supply Chain Relationships:
Collaborate with suppliers and partners to ensure they adhere to robust cybersecurity practices and regularly assess the security of third-party vendors.
6. Stay Updated on Cyber Threats:
Continuously monitor emerging cyber threats and trends to proactively identify and address potential vulnerabilities within your business. The construction industry in Australia is increasingly becoming a target for cyber-attacks due to its reliance on digital technologies, the valuable data it holds and the large sums of money that circulate the industry. By understanding the main cyber risk exposures and learning from recent incidents, construction companies can implement effective measures to protect their operations, data, and reputation.
Email. cyber@360uw.com.au Tel. 1800 411 580 Web. 360uw.com.au/cyber
This content is brought to you by 360 Underwriting Solutions Pty Ltd and 360 Financial Lines Pty Ltd (“360”) as a convenience to readers and is not intended to constitute advice (professional or otherwise) or recommendations upon which a reader may rely. Any references to insurance cover are general in nature only and may not suit your particular circumstances. Reference in this content (if any) to any specific commercial product, process, or service, and links from this content to other third-party websites, do not constitute or imply an endorsement or recommendation by 360.
Common Objections to Buying Cyber Insurance
The Cyber threat landscape is constantly evolving, with cyber attacks becoming more sophisticated and prevalent than ever before. Despite the rising risks, many businesses hesitate to invest in cyber insurance, leaving themselves vulnerable to potentially enormous consequences. Here are the top five reasons why businesses may be reluctant to purchase cyber insurance:
1. Cost Concerns
One of the primary reasons businesses avoid cyber insurance is the perceived cost. Some organisations may believe that the premiums associated with cyber insurance are too high and simply think it won’t happen to them. However, the cost of recovering from a cyber incident, including legal fees, regulatory fines, and reputational damage, can far exceed the expense of cyber insurance premiums. Overcoming this concern involves demonstrating the potential cost savings in the event of a cyber incident compared to the financial fallout of not having insurance. Sharing some statistics from the recent Clyde & Co whitepaper on average costs:


2. "My IT team have it covered"
Many businesses mistakenly believe that their existing cyber security measures and IT team (including MSP's) are are
sufficient to protect them from cyber threats. They may have invested in firewalls, AV software, and employee training
programs, leading them to believe they are adequately protected. However, cyber criminals are continuously devising
new techniques to exploit vulnerabilities, making it essential for businesses to have comprehensive insurance
coverage as an additional layer of protection. Emphasising that cyber insurance complements, rather than replaces,
effective cybersecurity measures can help them understand its importance.
3. Uncertainty of Coverage
Uncertainty of coverage: There is often confusion surrounding what cyber insurance covers and what it does not.
Some businesses may believe that their other insurance policies already provide adequate coverage for cyber
incidents, failing to recognize the specific risks addressed by cyber insurance, such as data breaches, ransomware
attacks, and business interruption due to cyber events. Clear communication about the scope of coverage offered by
cyber insurance can help dispel these misconceptions.
4. Lack of Awareness
Many small business owners are not fully aware of the extent of cyber risks or the insurance options available to
them. Providing clear and accessible information about the types of cyber threats they may face and how insurance
can mitigate those risks can increase awareness and understanding.
5. "They won't target us!"
Some businesses may believe that they are unlikely to experience a cyber incident or be underestimating the severity
of potential consequences. This optimism can lead to complacency and a reluctance to invest in proactive risk
mitigation strategies such as cyber insurance. However, cyber threats can affect businesses of all sizes and
industries, educating them about the increasing frequency and sophistication of cyber threats, as well as the
potential impact on their business, can help dispel this misconception.
While there are several reasons why businesses may hesitate to purchase cyber insurance, the importance of
mitigating cyber risks cannot be overstated. By addressing these concerns and understanding the value that cyber
insurance provides, businesses can better protect themselves, their assets, reputation, and ensure continuity of
operations.
Email. cyber@360uw.com.au Tel. 1800 411 580 Web. 360uw.com.au/cyber
This content is brought to you by 360 Underwriting Solutions Pty Ltd and 360 Financial Lines Pty Ltd (“360”) as a convenience to readers and is not intended to constitute advice (professional or otherwise) or recommendations upon which a reader may rely. Any references to insurance cover are general in nature only and may not suit your particular circumstances. Reference in this content (if any) to any specific commercial product, process, or service, and links from this content to other third-party websites, do not constitute or imply an endorsement or recommendation by 360.
Over the years, Christmas scams have traditionally targeted individuals. However, in more recent times the risks to business have risen significantly. Driven by changes in the way workforces rely upon technology to stay connected, the way individual employees use their devices and, of course, the increasing sophistication of cyber criminals.
Australian businesses are now exposed to greater cyber risks than ever before, which can be especially significant during the Christmas period. Whether it’s doing some online gift shopping in your lunch break, receiving an e-card from a customer, or expecting a parcel delivery in the office using your work email as the contact address, many employees are unconsciously making their employers vulnerable to a cyber incident.
Whilst it’s by no means an exhaustive list, here are three examples of common scams to watch out this festive season, together with tips to protect yourself from falling victim to them.
1. Christmas e-card Scams
Christmas e-cards are fast becoming the new norm, as more and more people switch from traditional paper Christmas cards. Most are entirely genuine, however, scammers have been catching on to this trend by sending out their own nefarious e-cards.
These emails can contain viruses and malware that are embedded into your device without your knowledge. Which then steal valuable data from your device, such as personal information, financial and banking details, as well as usernames and passwords. The fraudsters can then use this data to defraud you, commonly by accessing bank accounts in your personal or business name (if you’re opening them on a business device).
Protect yourself
- Never open unsolicited emails. Delete them immediately!
- As fun as they may look, exercise caution when opening e-cards even if they appear to have come from someone you know. Never click on any links or open any attachments in these emails.
- Keep your computer updated with the latest anti-virus and anti-spyware software, combined with an up-to-date firewall.
2. Online Shopping Scams
Shopping scams are big business for cyber criminals. How big? According to a report by the ACCC, in 2019 alone the reported losses from online shopping scams in Australia were well over $4 million!
Scammers often try to take advantage of busy times, such as people doing their Christmas shopping as well as the upcoming Black Friday and Cyber Monday sales. Commonly targeted items include shoes, smartphones and other electronic goods.
One of the ways they do this is by creating fake websites, where they advertise goods and services which are poor quality or unsafe, or goods that will never be delivered. To get attention, they’ll often advertise with images of well-known products at much cheaper prices than usual, luring customers to go to their site.
These scammers will often advertise their websites on social media platforms, especially Facebook, so they’ll be seen and shared by a vast majority of people. It’s also quite common for scammers to send out a link to the site through phishing emails.
Once you make a ‘purchase’ on the website, the scammers will use your personal information and card details you enter which can then be used to steal money or commit identity theft. Chances are you’ll never receive the item you bought or, if you do, it will be of very poor quality or broken.
Protect yourself
- Never pay for anything online via a bank or wire transfer. Only pay through a secure method such as a credit card or PayPal. This way your payment is protected.
- If the seller takes you to a separate website for payment, check the URL in the address bar. For example, if you’re using eBay and the domain name is anything other than ebay.com.au, it’s fake
- Check for a green secure padlock in the address bar. Any secure payment site should have this.
- Make sure you read the website’s terms and conditions regarding payments to see if and how your purchase is protected.
3. Parcel Delivery/Phishing Email Scams
Parcel delivery and phishing email scams are a regular occurrence for businesses throughout the year. But the risk typically rises towards Christmas with the increase in online gift shopping.
With people expecting so many deliveries during this busy period, it can be easy to lose track. Most companies will contact their customers via email to keep them informed on the delivery process, and when their parcel is expected to be delivered.
Scammers take advantage of this by sending out thousands of phishing emails advising that an individual has a package to collect, and importantly including a link or attachment within the email. Before thinking, many people click on these links – which often contain viruses or malware designed to lock you out of your computer or log your usernames and passwords for sensitive sites, providing hackers with either your personal information or your banking details.
Protect Yourself
- The display name in emails is easy to change, so make sure you always check the sender’s email address. If it looks unfamiliar or doesn’t have a legitimate domain name, delete it immediately.
- Pay attention to the warning signs – scammer’s email addresses and messages often have spelling mistakes or obvious grammatical errors.
- Legitimate companies will address their customers by their first name. If the email begins with ‘Dear Customer’, ‘Dear’, or something very generic, be suspicious. Scammers send out thousands of phishing emails at a time so they are normally generalised.
- Check for the company’s contact information – in phishing emails, there are either minimal details or none at all.
- If you think you’ve been scammed, contact your bank as soon as possible to report it.
CLICK HERE for more information on 360 Cyber Insurance.
References:
https://www.scamwatch.gov.au/news-alerts/watch-out-for-holiday-season-scams
https://www.scamwatch.gov.au/news-alerts/the-12-scams-of-christmas
https://www.smartcompany.com.au/technology/three-common-christmas-scams/
https://www.accc.gov.au/media-release/tis-the-season-for-online-shopping-scams
https://www.kisbridgingloans.co.uk/guide-to-fraud-prevention/ultimate-guide-to-christmas-scams/
