<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Risk &amp; Insurance | Clear Insurance</title>
	<atom:link href="https://clearinsurance.com.au/category/cyber-insurance-risk/feed/" rel="self" type="application/rss+xml" />
	<link>https://clearinsurance.com.au</link>
	<description>We make business insurance easy for you.</description>
	<lastBuildDate>Thu, 27 Aug 2026 05:50:56 +0000</lastBuildDate>
	<language>en-AU</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://clearinsurance.com.au/wp-content/uploads/2024/05/cropped-Lolly-for-Website-Favicon-1-32x32.png</url>
	<title>Cyber Risk &amp; Insurance | Clear Insurance</title>
	<link>https://clearinsurance.com.au</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>5 Business Risks to Consider When Using Artificial Intelligence (AI)</title>
		<link>https://clearinsurance.com.au/5-business-risks-to-consider-when-using-artificial-intelligence-ai/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=5-business-risks-to-consider-when-using-artificial-intelligence-ai</link>
					<comments>https://clearinsurance.com.au/5-business-risks-to-consider-when-using-artificial-intelligence-ai/#respond</comments>
		
		<dc:creator><![CDATA[Tara Burke]]></dc:creator>
		<pubDate>Wed, 20 Nov 2024 06:01:44 +0000</pubDate>
				<category><![CDATA[Cyber Risk & Insurance]]></category>
		<guid isPermaLink="false">https://clearinsurance.com.au/?p=17892</guid>

					<description><![CDATA[Most businesses are already using AI in some form: a customer-facing chatbot, an AI-assisted productivity tool, or a platform that uses machine learning behind the scenes. The benefits are real. So are the risks. This article outlines five risk areas worth understanding before and during AI integration in your business. None of these should put [...]]]></description>
										<content:encoded><![CDATA[<p>Most businesses are already using AI in some form: a customer-facing chatbot, an AI-assisted productivity tool, or a platform that uses machine learning behind the scenes. The benefits are real. So are the risks.</p>
<p>This article outlines five risk areas worth understanding before and during AI integration in your business. None of these should put you off using AI. But knowing what to look for helps you make smarter decisions and avoid being caught off guard.</p>
<p><span data-contrast="auto">Here are five risks to consider when integrating AI tools into your business.</span></p>
<h2>Five AI Risks Every Business Owner Should Know</h2>
<p><img fetchpriority="high" decoding="async" class="size-full wp-image-18541 aligncenter" src="https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-2.jpg" alt="Business professional holding a yellow warning sign and blue AI microchip, representing artificial intelligence risks Clear Insuracne" width="900" height="500" srcset="https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-2-100x56.jpg 100w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-2-200x111.jpg 200w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-2-300x167.jpg 300w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-2-400x222.jpg 400w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-2-600x333.jpg 600w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-2-768x427.jpg 768w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-2-800x444.jpg 800w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-2.jpg 900w" sizes="(max-width: 900px) 100vw, 900px" /></p>
<h3>1. You&#8217;re Only as Secure as the Tools You Rely On</h3>
<p>When you use a third-party AI solution, you&#8217;re not just buying a product. You&#8217;re taking on a dependency. If that vendor&#8217;s platform goes down, gets hacked, or changes its terms, your business feels it too.</p>
<p>It is sometimes called software supply chain risk, and AI tools have introduced new versions of that risk.</p>
<p>Consider what happened in late 2022, when a popular machine learning library called PyTorch was compromised through a supply chain attack. A malicious package was uploaded to a public code repository under the same name as a legitimate dependency. Before it was caught, it had been downloaded approximately 2,300 to 3,000 times, with each download capable of silently harvesting credentials and sensitive files from the affected machine.</p>
<p>More visibly, ChatGPT (used by millions of businesses globally) experienced multiple significant outages across 2023 and 2024, including a March 2023 incident where a bug in a third-party library briefly exposed fragments of other users&#8217; chat histories, and a December 2024 outage lasting around nine hours following a power failure at a Microsoft data centre.</p>
<p><span style="color: #008c95;"><strong>What this means for your insurance position:</strong> </span>Dependence on third-party AI platforms is a risk exposure. When you speak with your insurance adviser, it&#8217;s worth discussing how your policy responds to losses caused by a vendor outage or compromise, rather than a direct attack on your own systems.</p>
<h3>2. AI Tools Can Become Entry Points for Attack</h3>
<p>Any AI tool that sends and receives information (a chatbot on your website, an AI calculator, an automated assistant) creates a channel that can, in some cases, be manipulated.</p>
<p>One technique is known as <em>jailbreaking</em>: prompting an AI model to behave outside its intended parameters. This isn&#8217;t always a dramatic hack. Sometimes it&#8217;s as simple as a customer asking questions in an unexpected sequence that lead to responses the business did not authorise.</p>
<p>The consequences can range from the embarrassing to the legally significant. In a case decided by the British Columbia Civil Resolution Tribunal in February 2024 (<em>Moffatt v Air Canada</em> [2024 BCCRT 149]), a passenger successfully claimed damages after Air Canada&#8217;s website chatbot gave him incorrect information about bereavement fares. The tribunal found Air Canada responsible for the chatbot&#8217;s output. The argument that the chatbot was a &#8220;separate entity&#8221; whose errors Air Canada couldn&#8217;t be held liable for was rejected outright.</p>
<p>The practical takeaway isn&#8217;t that chatbots are dangerous. It&#8217;s that businesses are responsible for the information their AI tools provide. If your AI tool gives a customer incorrect pricing, policy terms, or advice, the fact that a machine said it is unlikely to be a defence.</p>
<p><span style="color: #008c95;"><strong>What this means for your insurance position:</strong></span> Liability for what your AI tools say or do can land with your business, not the vendor. That&#8217;s worth understanding when reviewing your professional indemnity and public liability cover.</p>
<div class="content-container">
<h3>3. Training AI Requires Data and That Creates Exposure</h3>
<p><img decoding="async" class="size-full wp-image-18542 aligncenter" src="https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai.jpg" alt="Two business professionals discussing AI risks while reviewing neural network graphics on a laptop Clear Insurance" width="900" height="500" srcset="https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-100x56.jpg 100w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-200x111.jpg 200w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-300x167.jpg 300w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-400x222.jpg 400w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-600x333.jpg 600w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-768x427.jpg 768w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai-800x444.jpg 800w, https://clearinsurance.com.au/wp-content/uploads/2024/11/5-business-risks-to-consider-when-using-ai.jpg 900w" sizes="(max-width: 900px) 100vw, 900px" /></p>
<p>AI tools get better by learning from data. A lot of data. That means vendors often centralise and aggregate large volumes of information, sometimes including data belonging to their customers, to train and improve their systems.</p>
<p>This concentration of data is a risk in its own right.</p>
<p>In September 2023, Microsoft&#8217;s AI research team accidentally exposed approximately 38 terabytes of internal data (including private keys, passwords, and tens of thousands of internal messages) through a misconfigured access token on a public code repository. The misconfiguration had existed undetected for around three years before being discovered by security researchers.</p>
<p>In 2024, cloud data platform Snowflake was at the centre of a major breach affecting around 165 organisations, after attackers used stolen credentials to access customer accounts. The exposed data spanned hundreds of millions of individuals across companies including AT&amp;T, Ticketmaster, and Santander.</p>
<p>Neither incident involved a sophisticated zero-day exploit. Both came down to access controls that weren&#8217;t tight enough.</p>
<p><span style="color: #008c95;"><strong>What this means for your insurance position:</strong> </span>The concentration of data in AI vendor environments is a risk exposure. It&#8217;s worth discussing with your insurance adviser how your cyber policy responds to a breach originating from a third-party vendor, not just your systems.</p>
<h3 class="heading icon-left"> 4. AI-Powered Security Tools Carry Their Own Risks</h3>
<div class="content-container">
<p>AI is increasingly used within cybersecurity itself. Tools that monitor networks, detect anomalies, and respond to threats automatically can be genuinely effective. They can also cause problems when they get things wrong.</p>
<p>Because these tools operate at a high level of system access, an error (whether from a misconfiguration, a false positive, or an unexpected interaction with other software) can lock legitimate users out of their own systems, reset credentials without warning, or quarantine infrastructure in ways that make recovery from an actual incident harder, not easier.</p>
<p>On 30 July 2024, Microsoft Azure experienced a significant outage triggered by a Distributed Denial of Service (DDoS) attack. The attack itself was initially contained by Azure&#8217;s automated defences, but an error in how those defences disengaged caused traffic to be misrouted, resulting in an outage of approximately eight hours that affected banking, business operations, and Microsoft 365 services globally. The disruption wasn&#8217;t caused by the attack getting through. It was caused by the automated response to the attack misfiring.</p>
<p><span style="color: #008c95;"><strong>What this means for your insurance position:</strong></span> AI security tools that operate with high system access create a distinct exposure. An error or misconfiguration in one of these tools could itself trigger a business interruption event. It&#8217;s worth reviewing whether your policy covers losses caused by your security systems, not just external attacks.</p>
<div class="content-container">
<h3>5. How You Use AI Affects Your Insurance Position</h3>
<p>How AI affects your insurance is often an area that surprises many business owners: how you integrate AI into your operations is increasingly relevant to your insurance coverage.</p>
<p>When insurers assess cyber and technology-related risks, they&#8217;re looking at the whole picture, including whether the businesses they cover have taken reasonable steps to manage AI-related exposures. They will typically want to understand:</p>
<ul>
<li>The protection measures you have in place</li>
<li>Whether AI tools are being developed, deployed, or tested within the business</li>
<li>Whether the AI tools or developers centralise data in ways that could increase your risk exposure</li>
<li>What level of access the AI systems have to your business infrastructure</li>
<li>How you manage and monitor access, permissions, and user accounts</li>
</ul>
<p>The answers to these questions can affect whether a policy is offered, on what terms, and at what cost. Introducing a new AI tool, particularly one with access to customer data or core systems, is a good moment to review your existing insurance arrangements.</p>
<p>As AI adoption grows, so does the need for comprehensive cyber insurance. For details on coverage options and how cyber insurance protects organisations using AI systems, see our <a href="https://clearinsurance.com.au/clear-services/cyber-insurance/" target="_blank" rel="noopener noreferrer">Cyber Insurance Guide</a>.</p>
<h2>Speak with an Insurance Adviser</h2>
<p>Every business&#8217;s risk exposure is different. If you&#8217;d like to understand how your use of AI tools impacts your risk exposure and insurance program, contact the <a href="https://clearinsurance.com.au/about-us/our-team/">Clear Insurance team</a> and ask about our no-obligation <a href="https://clearinsurance.com.au/clear-services/risk-insurance-review/">risk and insurance review</a>.</p>
<div style="padding: 20px 20px 10px; border: #7dc0c3 1px solid; margin-top: 60px;">
<p><strong><em>General Advice Warning: </em></strong><em>This advice is general and does not take into account your objectives, financial situation or needs. You should consider whether the advice is appropriate for you and your personal circumstances. Before you make any decision about whether to acquire a certain product, you should obtain and read the relevant product disclosure statement.</em></p>
<p><em>Clear Insurance Pty Ltd. ABN. 41 601 916 689. AFSL No. 548953.</em></p>
</div>
<p><em>Last updated: 25 June 2026</em></p>
</div>
</div>
</div>The post <a href="https://clearinsurance.com.au/5-business-risks-to-consider-when-using-artificial-intelligence-ai/">5 Business Risks to Consider When Using Artificial Intelligence (AI)</a> appeared first on <a href="https://clearinsurance.com.au">Clear Insurance</a>.]]></content:encoded>
					
					<wfw:commentRss>https://clearinsurance.com.au/5-business-risks-to-consider-when-using-artificial-intelligence-ai/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What is Social Engineering and why is it so effective?</title>
		<link>https://clearinsurance.com.au/what-is-social-engineering-and-why-is-it-so-effective/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-is-social-engineering-and-why-is-it-so-effective</link>
					<comments>https://clearinsurance.com.au/what-is-social-engineering-and-why-is-it-so-effective/#respond</comments>
		
		<dc:creator><![CDATA[Lisa Carter]]></dc:creator>
		<pubDate>Wed, 11 Oct 2023 01:01:30 +0000</pubDate>
				<category><![CDATA[Cyber Risk & Insurance]]></category>
		<guid isPermaLink="false">https://clearinsurance.com.au/?p=2364</guid>

					<description><![CDATA[Social engineering fraud is deceiving people to divulge sought-after information to commit fraud, identity theft, access a secured network, determine trade secrets, sales and marketing plans, customer and supplier information, financial data, or simply disrupt business operations. Social engineering is more effective than any hacking method because it relies on human error rather than finding [...]]]></description>
										<content:encoded><![CDATA[<p>Social engineering fraud is deceiving people to divulge sought-after information to commit fraud, identity theft, access a secured network, determine trade secrets, sales and marketing plans, customer and supplier information, financial data, or simply disrupt business operations.</p>
<section class="elementor-section elementor-top-section elementor-element elementor-element-2c594959 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-particle_enable="false" data-particle-mobile-disabled="false" data-id="2c594959" data-element_type="section">
<div class="elementor-container elementor-column-gap-default">
<div class="elementor-row">
<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-71ca6ba0" data-id="71ca6ba0" data-element_type="column">
<div class="elementor-column-wrap elementor-element-populated">
<div class="elementor-widget-wrap">
<div class="elementor-element elementor-element-316bca06 elementor-widget elementor-widget-text-editor" data-id="316bca06" data-element_type="widget" data-widget_type="text-editor.default">
<div class="elementor-widget-container">
<div class="elementor-text-editor elementor-clearfix">
<p>Social engineering is more effective than any hacking method because it relies on human error rather than finding and exploiting vulnerabilities in computer systems. It typically happens through email, text messages, online chat and phone calls.</p>
<p>With <em>advancements in technology and </em>modern <a href="https://essentialtech.com.au/services/security/" rel=" noopener">security</a> systems in place, <em>hackers</em> can’t break into systems easily. That’s why they target the weakest link in the security chain – the user. It’s much easier to trick someone into providing confidential information such as passwords, bank information and credit card numbers.</p>
<p>The world’s most notorious hacker, Kevin Mitnick, helped popularise the term ‘social engineering’ in the 90s with his book “The Art of Deception”. It contains real stories on why attacks are successful and how to prevent them.</p>
<p>Hackers use different social engineering tactics to manipulate their target depending on how they implement the attack. For example, they may use email, web, phone, USB drives, or other means. So, here are the some of the social engineering tactics:</p>
<p>There are two major types of Social Engineering attack; remote or in-person.</p>
<h2>Types Of Social Engineering Attacks</h2>
<h3 class="fusion-responsive-typography-calculated" data-fontsize="30" data-lineheight="45px">1. Remote Attacks (Phishing)</h3>
<p>Phishing is one of the most popular social engineering tactics attackers use to get sensitive information from their target. It’s usually via email, text messages and phone calls.</p>
<h3 class="fusion-responsive-typography-calculated" data-fontsize="30" data-lineheight="45px">– Email Attacks</h3>
<p>Attackers send a well-crafted email with a deceptive subject line to trick the recipient into believing the email is from a trusted source. The email may contain seemingly legitimate documents, logos, contact details or a link to a cloned website to trick their target. The attack aims to create a sense of urgency and immediate action from the user. For example, you may receive an email prompting a password change or invoice for payment, which sends the attacker information or money once submitted.</p>
<h3 class="fusion-responsive-typography-calculated" data-fontsize="30" data-lineheight="45px">– Phone Call Attacks (Vishing)</h3>
<p>A social engineer who attacks over the phone, often called “vishing” for voice phishing, usually pretends to be someone, e.g., an account holder, business partner, staff or a trusted provider of your organisation. They typically gather necessary background information before making the call to avoid suspicion.</p>
<h3 class="fusion-responsive-typography-calculated" data-fontsize="30" data-lineheight="45px">– Spear Phishing</h3>
<p>Spear Phishing has the highest success rate. For example, the attacker sends a personalised spear phishing email or calls the target based on their job title or technical skills. The attacker may pretend to be a colleague within the organisation or an IT consultant who coerces the target for confidential information. Spear phishing attacks require months of preparation, making them harder to detect.</p>
<h3 class="fusion-responsive-typography-calculated" data-fontsize="30" data-lineheight="45px">– Scareware</h3>
<p>Scareware manipulates users through fear by deceiving the target with notifications of a malware infection. It suggests the user buy or download a fake antivirus software to get rid of it. However, the antivirus is a potentially dangerous software that can steal your personal information once installed. It’s common to encounter this type of social engineering attack while browsing the internet or via email. Rogue security software and crypto miner lock are two of the most popular scareware tactics cybercriminals use.</p>
<h3 class="fusion-responsive-typography-calculated" data-fontsize="30" data-lineheight="45px">2. In-Person/Onsite Attacks</h3>
<p>In-person social engineering techniques are less common than remote attacks. Yet, they’re very effective because businesses usually focus on IT security, not physical threats.</p>
<h3 class="fusion-responsive-typography-calculated" data-fontsize="30" data-lineheight="45px">– Shoulder Surfing</h3>
<p>Shoulder surfing is a physical social engineering attack that uses direct observation techniques to steal information. The attacker stands beside someone and watches them enter their login credentials or PIN at an ATM.</p>
<h3 class="fusion-responsive-typography-calculated" data-fontsize="30" data-lineheight="45px">– Tailgating</h3>
<p>Tailgating is another onsite social engineering technique used by attackers seeking entry to restricted areas where biometrics, RFID cards, or any electronic access control is present. The attacker waits for the perfect opportunity to walk in behind an authorised person or determines when the next scheduled maintenance may be and arrives dressed like one to get past the front desk successfully.</p>
<h3 class="fusion-responsive-typography-calculated" data-fontsize="30" data-lineheight="45px">– Key Loggers</h3>
<p>Hardware and network devices often need technical services, so hackers usually take this opportunity. They may impersonate a third-party onsite tech support and install a key logger on shared computer systems to obtain usernames and passwords. It provides the hacker with access rights to control the workstations remotely.</p>
<h3 class="fusion-responsive-typography-calculated" data-fontsize="30" data-lineheight="45px">– Baiting</h3>
<p>Baiting is the equivalent of a Trojan horse in social engineering. The attacker will leave a malware-infected flash drive in a public place, hoping someone will pick it up and plug it into their computers. Distributed USBs are usually labelled as “Confidential” or “Salary info” to entice the victim to use it, giving access rights to the hacker once opened. Hackers also use online baiting to attract their target with free goods in exchange for personal information.</p>
<h2 class="fusion-responsive-typography-calculated" data-fontsize="40" data-lineheight="56px">How To Prevent Social Engineering Attacks</h2>
<ul>
<li>Educate staff on social engineering techniques with regular training.</li>
<li>Review company policies and processes for handling transactions and other essential business activities to ensure staff understand and follow the correct procedures.</li>
<li><span data-preserver-spaces="true">Set spam filters high and regularly monitor the spam folder for any essential emails caught by accident.</span></li>
<li><span data-preserver-spaces="true">Verify the sender’s email address and treat unsolicited emails as suspicious.</span></li>
<li>Increase device security with regular system updates and keep antivirus software up to date.</li>
<li>Enable multi-factor authentication (MFA), two-factor authentication (2FA) or two-step verification for an additional layer of security.</li>
<li><span data-preserver-spaces="true">Always check website URLs are correct when visiting websites. Online banking websites use extended validation SSL to prove the legal entity of the website</span>.</li>
<li>Ensure staff know how to identify phishing emails or other scams received via text and email.</li>
<li>Ensure staff download files from trusted websites. Ensure to scan files using up to date antivirus software.</li>
<li>Be wary of file attachments from unsolicited emails.</li>
<li>Be wary of any tempting offers online, such as free giveaways.</li>
<li>Encourage staff to be aware of their surroundings and tailgaters for possible onsite attacks.</li>
</ul>
<p>Social engineering can target anyone, regardless of business size or industry. Therefore, educating your team on social engineering and the tactics cybercriminals use can help manage risk exposure.</p>
<h2>Next Steps</h2>
<p>If you would like to discuss your cyber insurance needs with an experienced insurance adviser, you can contact Clear Insurance on 1300 721 132 or email <a href="mailto:info@clearinsurance.com.au">info@clearinsurance.com.au</a> or <a href="https://clearinsurance.com.au/contact-us/">complete our online enquiry form</a>.</p>
<p>For comprehensive cyber insurance coverage including business email compromise and social engineering attack protection, see our <a href="https://clearinsurance.com.au/clear-services/cyber-insurance/" target="_blank" rel="noopener noreferrer">Cyber Insurance Guide</a>.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</section>
<div style="padding: 20px 20px 10px; border: #7dc0c3 1px solid; margin-top: 60px;">
<p><strong><em>General Advice Warning: </em></strong><em>This advice is general and does not take into account your objectives, financial situation or needs. You should consider whether the advice is appropriate for you and your personal circumstances. Before you make any decision about whether to acquire a certain product, you should obtain and read the relevant product disclosure statement.</em></p>
<p><em>Clear Insurance Pty Ltd. ABN. 41 601 916 689. AFSL No. 548953.</em></p>
</div>
<p>&nbsp;</p>The post <a href="https://clearinsurance.com.au/what-is-social-engineering-and-why-is-it-so-effective/">What is Social Engineering and why is it so effective?</a> appeared first on <a href="https://clearinsurance.com.au">Clear Insurance</a>.]]></content:encoded>
					
					<wfw:commentRss>https://clearinsurance.com.au/what-is-social-engineering-and-why-is-it-so-effective/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>4 Reasons to Manage Cyber Security Risk</title>
		<link>https://clearinsurance.com.au/4-reasons-to-manage-cyber-security-risk/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=4-reasons-to-manage-cyber-security-risk</link>
					<comments>https://clearinsurance.com.au/4-reasons-to-manage-cyber-security-risk/#respond</comments>
		
		<dc:creator><![CDATA[Tara Burke]]></dc:creator>
		<pubDate>Wed, 12 Jul 2023 00:56:35 +0000</pubDate>
				<category><![CDATA[Cyber Risk & Insurance]]></category>
		<guid isPermaLink="false">https://clearinsurance.com.au/?p=15118</guid>

					<description><![CDATA[Cyber risk is increasingly a governance issue, not just a technical one. Regulators, stakeholders, and customers now expect boards and business leaders to demonstrate they understand and manage cyber risk. Here are four key reasons why. 1. Regulatory Enforcement Australian regulators, including the Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission [...]]]></description>
										<content:encoded><![CDATA[<p>Cyber risk is increasingly a governance issue, not just a technical one. Regulators, stakeholders, and customers now expect boards and business leaders to demonstrate they understand and manage cyber risk. Here are four key reasons why.</p>
<h2>1. Regulatory Enforcement</h2>
<p>Australian regulators, including the Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission (ASIC), now actively oversee cyber risk management. When organisations experience serious data breaches, regulators may impose capital requirements, enforcement action, or public statements requiring remediation.</p>
<p>In 2026, regulatory expectations around cyber governance are higher than ever. APRA and ASIC expect organisations holding financial or personal information to have:</p>
<ul>
<li>Board-level accountability for cyber risk</li>
<li>Documented incident response plans</li>
<li>Regular cyber risk assessments</li>
<li>Evidence of adequate security controls</li>
</ul>
<p>Regulators view cyber risk as a business continuity issue. If your systems go down due to a cyberattack, your ability to serve customers is directly affected. Compliance with regulatory cyber expectations is no longer optional; it&#8217;s expected practice.</p>
<h2>2. Financial Impact of Cyber Incidents</h2>
<p>Data breaches are common and costly. In 2025, Australian organisations reported over 1,200 data breaches to regulators; the highest number since mandatory notification began in 2018.</p>
<p>The financial impact varies significantly by organisation size and incident severity:</p>
<ul>
<li>Small businesses typically face incident costs around $56,600</li>
<li>Medium and large organisations in serious incidents face costs of $180,000 to $400,000+</li>
<li>Very serious incidents can exceed $400,000</li>
</ul>
<p>These costs include forensic investigation, system restoration, notifying affected individuals, regulatory investigation responses, and business interruption during recovery. Many businesses do not recover from incidents of this magnitude.</p>
<h2>3. Reputational Risk</h2>
<p>A cyber incident affects more than systems; it affects trust. Customers, suppliers, and stakeholders expect your business to protect their data and maintain system availability. When a breach occurs, the reputational damage can take years to rebuild.</p>
<p>The damage extends beyond immediate customer loss. Long-term impacts include loss of competitive advantage, difficulty attracting talented employees, and damage to supplier relationships.</p>
<h2>4. Legal and Regulatory Liability</h2>
<p>When personal information is exposed, individuals and regulators may take legal action. Claims may arise under:</p>
<ul>
<li>Privacy law (if you fail to protect personal information as required)</li>
<li>Contract law (if supply chain partners or customers claim damages)</li>
<li>Negligence law (if affected parties claim you failed in your duty of care)</li>
</ul>
<p>Additionally, under Australia&#8217;s Privacy Act, if you experience a data breach likely to cause &#8220;serious harm,&#8221; you must notify the Office of the Australian Information Commissioner and affected individuals within 30 days of assessment. Failure to comply can result in civil penalties.</p>
<h2>Managing Cyber Risk: Prevention and Insurance</h2>
<p>Managing cyber risk involves two complementary approaches: <strong>prevention</strong> and <strong>financial protection through insurance</strong>.</p>
<h3>Prevention and Governance</h3>
<p>Organisations typically manage cyber risk through security practices, staff training, regular system updates, incident response planning, and governance frameworks. These are best developed in consultation with your IT security adviser or IT service provider, who can assess your specific operational risks and recommend appropriate controls.</p>
<p>Insurers assess whether organisations have basic security measures in place. They expect to see evidence of multi-factor authentication, regular backups, endpoint detection on critical systems, and documented incident response plans. Strong security practices often result in better insurance terms and lower premiums.</p>
<p>However, even well-protected organisations can experience breaches through human error, novel attack methods, or supply chain compromise. Prevention alone cannot eliminate cyber risk entirely.</p>
<h3>Financial Protection Through Insurance</h3>
<p>This is where cyber insurance plays a critical role. Cyber insurance transfers the financial impact of cyber incidents from your business to an insurer. It covers costs that prevention cannot avoid:</p>
<ul>
<li>Forensic investigation and incident response</li>
<li>Notifying affected individuals and credit monitoring services</li>
<li>System restoration and data recovery</li>
<li>Business interruption (lost revenue during downtime)</li>
<li>Legal defence and regulatory investigation costs</li>
<li>Potential damages or settlements</li>
</ul>
<p>Combined with strong prevention practices, cyber insurance is an essential part of managing cyber risk in 2026. For comprehensive details on cyber insurance coverage, claims process, and how policies respond to data breaches and business interruption, see our <a href="https://clearinsurance.com.au/clear-services/cyber-insurance/" target="_blank" rel="noopener noreferrer">Cyber Insurance Guide</a>.</p>
<h2>Next Steps</h2>
<p>If you&#8217;d like to understand your cyber risk exposure and explore insurance options, Clear Insurance can help. We conduct risk and insurance reviews that assess your cyber exposure and recommend appropriate coverage limits and policy terms.</p>
<p>If you&#8217;d like advice or a no-obligation <a href="https://clearinsurance.com.au/clear-services/risk-insurance-review/">risk and insurance review</a> tailored to your business, contact Clear Insurance on 1300 721 132 or email <a href="mailto:info@clearinsurance.com.au">info@clearinsurance.com.au</a>.</p>
<p><em>Last updated: 26 August 2026</em></p>
<div style="padding: 20px 20px 10px; border: #7dc0c3 1px solid; margin-top: 60px;">
<p><strong><em>General Advice Warning: </em></strong><em>This advice is general and does not take into account your objectives, financial situation or needs. You should consider whether the advice is appropriate for you and your personal circumstances. Before you make any decision about whether to acquire a certain product, you should obtain and read the relevant product disclosure statement.</em></p>
<p><em>Clear Insurance Pty Ltd. ABN. 41 601 916 689. AFSL No. 548953.<br />
</em></p>
</div>The post <a href="https://clearinsurance.com.au/4-reasons-to-manage-cyber-security-risk/">4 Reasons to Manage Cyber Security Risk</a> appeared first on <a href="https://clearinsurance.com.au">Clear Insurance</a>.]]></content:encoded>
					
					<wfw:commentRss>https://clearinsurance.com.au/4-reasons-to-manage-cyber-security-risk/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Ransomware: 5 Ways to Protect Your Business</title>
		<link>https://clearinsurance.com.au/ransomware-5-ways-to-protect-your-business/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ransomware-5-ways-to-protect-your-business</link>
					<comments>https://clearinsurance.com.au/ransomware-5-ways-to-protect-your-business/#respond</comments>
		
		<dc:creator><![CDATA[Tara Burke]]></dc:creator>
		<pubDate>Tue, 27 Jun 2023 01:31:06 +0000</pubDate>
				<category><![CDATA[Cyber Risk & Insurance]]></category>
		<guid isPermaLink="false">https://clearinsurance.com.au/?p=14440</guid>

					<description><![CDATA[Ransomware attacks are increasingly common in Australia. While no organisation can guarantee prevention, there are practical steps you can take to reduce risk. And when prevention fails, cyber insurance provides financial protection to cover recovery costs and business interruption. The Ransomware Threat Ransomware attacks are targeting Australian organisations at an accelerating rate. Key facts: Ransomware [...]]]></description>
										<content:encoded><![CDATA[<p>Ransomware attacks are increasingly common in Australia. While no organisation can guarantee prevention, there are practical steps you can take to reduce risk. And when prevention fails, cyber insurance provides financial protection to cover recovery costs and business interruption.</p>
<h2>The Ransomware Threat</h2>
<p>Ransomware attacks are targeting Australian organisations at an accelerating rate. Key facts:</p>
<ul>
<li>Ransomware attacks are occurring every 6 minutes globally, with Australian organisations increasingly targeted</li>
<li>Average incident costs for small businesses are around $56,600; serious incidents can exceed $180,000 to $400,000+</li>
<li>Business email compromise (where attackers impersonate colleagues or suppliers) accounts for 58% of cyber insurance claims globally</li>
<li>Since 30 May 2025, organisations with annual turnover over $3 million must report ransomware payments to the Australian Signals Directorate within 72 hours</li>
</ul>
<p>Importantly, many business leaders believe their data is safe because it&#8217;s stored in the cloud or managed by an IT service provider. However, ransomware typically enters organisations through phishing emails containing genuine-looking links or attachments sent directly to staff. Criminals often impersonate trusted colleagues, familiar website domains, or known suppliers, making it easy for staff to be caught off-guard.</p>
<h2>5 Ways to Reduce Ransomware Risk</h2>
<h3>1. Implement Core Device Protection</h3>
<p>Organisations typically implement security software including antivirus protection, firewalls, spam filters, and regular security patches kept up to date. Equally important are regular data backups with copies stored securely offline, separate from production systems.</p>
<p>Insurers assess whether organisations have these basic controls in place when underwriting cyber policies. Strong implementation often results in better insurance terms.</p>
<h3>2. Staff Awareness and Phishing Training</h3>
<p>Employees can inadvertently expose organisations to ransomware by clicking suspicious links or opening attachments that appear genuine. Many organisations conduct phishing awareness training for all staff, with annual refreshers to keep cyber security front of mind.</p>
<p>Practical training should cover what phishing emails and ransomware look like, their impact, and what staff should do if they receive suspicious emails. Early reporting of suspicious activity is critical; the sooner a breach is detected, the faster and less expensive it is to resolve.</p>
<p>Your IT security adviser or managed service provider can recommend appropriate training programs suited to your organisation&#8217;s specific risks.</p>
<h3>3. Use Real-World Examples to Train Staff</h3>
<p>One of the most effective training approaches is showing staff real examples of phishing emails or ransomware warnings they might encounter. This helps team members recognise warning signs and understand what to do if they receive a suspicious email.</p>
<p>Importantly, staff should feel comfortable reporting suspected breaches without fear. Early reporting significantly reduces the time and cost of incident response.</p>
<p><strong>Real-World Case Study:</strong></p>
<p>An employee clicked a link in an email and found a ransom note on their screen. Four of the company&#8217;s systems were encrypted, and attackers demanded payment. After negotiation, the encryption password was provided, but the company had to rebuild their entire IT infrastructure due to the breach.</p>
<p><strong>Insurance Outcome:</strong> The company had cyber insurance. The total claim was $146,000, covering:</p>
<ul>
<li>Ransom fee: $17,000</li>
<li>Cyber response and investigation costs: $18,000</li>
<li>Business interruption payout: $111,000</li>
</ul>
<p><em>(Real-world claim example from Emergence)</em></p>
<p>Without cyber insurance, this organisation would have faced the full $146,000 cost plus ongoing reputational damage and potential regulatory investigation.</p>
<h3>4. Encourage Staff Feedback on Internal Systems</h3>
<p>If company systems are too restrictive or slow, employees may bypass security controls, download unapproved applications, or use less secure workarounds. This can inadvertently introduce vulnerabilities.</p>
<p>Creating safe channels for staff to provide feedback on system usability helps IT teams find solutions that balance security with practicality.</p>
<h3>5. Review Your Cyber Insurance Cover</h3>
<p>Ransomware incidents can generate costs that exceed many organisations&#8217; budgets. With incident costs rising annually, it&#8217;s worth reviewing your cyber insurance cover to ensure you have adequate protection.</p>
<p>Cyber insurance often sits outside standard business insurance policies and must be purchased separately. Coverage typically includes:</p>
<ul>
<li>Forensic investigation and incident response costs</li>
<li>Ransom negotiation and, in some cases, ransom payment (subject to policy terms and regulatory requirements)</li>
<li>System restoration and data recovery</li>
<li>Business interruption (lost revenue during downtime)</li>
<li>Notification and credit monitoring services for affected individuals</li>
<li>Legal defence and regulatory investigation costs</li>
</ul>
<p>For comprehensive details on ransomware coverage, claims process, and how cyber policies respond to incidents, see our <a href="https://clearinsurance.com.au/clear-services/cyber-insurance/" target="_blank" rel="noopener noreferrer">Cyber Insurance Guide</a>.</p>
<h2>Next Steps</h2>
<p>If you&#8217;d like to review your cyber insurance cover or discuss ransomware risk with an adviser, contact Clear Insurance on 1300 721 132, email <a href="mailto:info@clearinsurance.com.au" target="_blank" rel="noopener noreferrer">info@clearinsurance.com.au</a> or <a href="https://clearinsurance.com.au/contact-us/">complete our online enquiry form</a>. We can assess your current coverage and help ensure you have appropriate protection for your business.</p>
<p><em>Last updated: 27 August 2026</em></p>
<div style="padding: 20px 20px 10px; border: #7dc0c3 1px solid; margin-top: 60px;">
<p><strong><em>General Advice Warning: </em></strong><em>This advice is general and does not take into account your objectives, financial situation or needs. You should consider whether the advice is appropriate for you and your personal circumstances. Before you make any decision about whether to acquire a certain product, you should obtain and read the relevant product disclosure statement.</em></p>
<p><em>Clear Insurance Pty Ltd. ABN. 41 601 916 689. AFSL No. 548953.</em></p>
</div>The post <a href="https://clearinsurance.com.au/ransomware-5-ways-to-protect-your-business/">Ransomware: 5 Ways to Protect Your Business</a> appeared first on <a href="https://clearinsurance.com.au">Clear Insurance</a>.]]></content:encoded>
					
					<wfw:commentRss>https://clearinsurance.com.au/ransomware-5-ways-to-protect-your-business/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>10 Biggest Cyber Attacks in History</title>
		<link>https://clearinsurance.com.au/10-biggest-cyber-attacks-in-history/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=10-biggest-cyber-attacks-in-history</link>
					<comments>https://clearinsurance.com.au/10-biggest-cyber-attacks-in-history/#respond</comments>
		
		<dc:creator><![CDATA[Lisa Carter]]></dc:creator>
		<pubDate>Mon, 27 Sep 2021 04:06:41 +0000</pubDate>
				<category><![CDATA[Cyber Risk & Insurance]]></category>
		<guid isPermaLink="false">https://clearinsurance.com.au/?p=4502</guid>

					<description><![CDATA[Cyber attacks are on the rise. Whilst modern technology presents many conveniences and benefits, there are people who misuse it which poses a threat to businesses and data privacy globally. When data breaches happen, it can have a far-reaching impact. It goes beyond the target company, affecting customers, suppliers and more. Scarily, experts expect the [...]]]></description>
										<content:encoded><![CDATA[<section class="elementor-section elementor-top-section elementor-element elementor-element-5d0efa2 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-particle_enable="false" data-particle-mobile-disabled="false" data-id="5d0efa2" data-element_type="section" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
<div class="elementor-container elementor-column-gap-no">
<div class="elementor-row">Cyber attacks are on the rise. Whilst modern technology presents many conveniences and benefits, there are people who misuse it which poses a threat to businesses and data privacy globally.</div>
</div>
</section>
<div></div>
<div>When data breaches happen, it can have a far-reaching impact. It goes beyond the target company, affecting customers, suppliers and more. Scarily, experts expect the cost of cybercrime to reach around <strong>$10.5 trillion</strong> by 2025.</div>
<div></div>
<h2>We can always learn from the past, so let&#8217;s take a look at some of history&#8217;s biggest cyber attacks:</h2>
<h3><strong>1. The Melissa Virus</strong></h3>
<div>One of the earliest and biggest cyber threats came from the Melissa Virus in 1999 by programmer David Lee Smith. He sent users a file to open via Microsoft Word, which held a virus. Once opened the virus activated causing severe damage to hundreds of companies, including Microsoft. It is estimated it cost $80 million to repair the affected systems.</div>
<div></div>
<h3><strong>2. NASA Cyber Attack</strong></h3>
<div>In 1999, 15-year-old James Jonathan hacked and shutdown NASA&#8217;s computers for 21 days! There were around 1.7 million software downloads during the attack, which cost the space giant around $41,000 in repairs.</div>
<div></div>
<h3><strong>3. The 2007 Estonia Cyber Attack</strong></h3>
<div>In April 2007, Estonia witnessed what is thought to be the first cyber attack on an entire county. Chiefly, it saw around 58 Estonian websites go offline, including government, bank and media websites.</div>
<div></div>
<h3><strong>4. A Cyber Attack on Sony&#8217;s PlayStation Network</strong></h3>
<div>A cyber attack on Sony&#8217;s PlayStation Network in April 2011 compromised the personal information of 77 million users.</div>
<div></div>
<h3><strong>5. Adobe Cyber Attack</strong></h3>
<div>The Adobe cyber attack was first thought to have breached the data of 2.9 million users. Moreover, it compromised the personal data of up to 38 million users! Adobe claims that only the passwords and credit card information of the first 2.9 million users were compromised, however, the remaining 35.1 million suffered the loss of their passwords and user IDs.</div>
<div></div>
<h3><strong>6. The 2014 Cyber Attack on Yahoo</strong></h3>
<div>In 2014, Yahoo was subject to one of the biggest cyber attacks of the year when 500 million accounts were compromised. During the attack, basic information and passwords were stolen, whereas bank information was not.</div>
<div></div>
<h3><strong>7. Ukraine&#8217;s Power Grid Attack</strong></h3>
<div>The Ukraine&#8217;s power grid attack in 2015 was the first cyberattack on a power grid. As a result of the attack, around half of the homes in the Ivano-Frankivsk region of the Ukraine were without power for a few hours.</div>
<div></div>
<h3><strong>8. 2017 WannaCry Ransomware Cyber Attack</strong></h3>
<div>One of the biggest ransomware attacks of all time took place in 2017. Furthermore, it affected around 200,000 computers in over 150 countries. To sum up, the ransomware had a huge impact on several industries with a global cost of around 6 billion pounds to fix!</div>
<div></div>
<h3><strong>9. A Cyber Attack on Marriott Hotels </strong></h3>
<div>A cyber attack on the Marriott hotels and Starwood hotels group went undetected for years, which only came to light in 2018.  Thus, by the time they became aware of the attack, an estimated 339 million guests had their data compromised. Consequently, the UK&#8217;s data privacy watchdog fined the Marriott Hotels 18.4 million pounds.</div>
<div></div>
<h3><strong>10. The biggest password leak yet</strong></h3>
<div>In June 2021, we saw a compilation of about 8.4 billion passwords leaked in the RockYou2021 attack. In fact, it was the largest breach since the RockYou site in 2009 which affected 32 million accounts.</div>
<div></div>
<div></div>
<div>While technology and data security tools continue to evolve, so do the tactics that cyber criminals use to trick business and employees into clicking on links and documents within emails. Therefore, to help businesses prepare, our blog on <a href="https://clearinsurance.com.au/10-ways-to-help-protect-your-business-against-cybercrime/">10 steps to protect your business from cybercrime</a> highlights easy ways to protect your business from cybercrime.</div>
<div></div>
<section class="elementor-section elementor-top-section elementor-element elementor-element-5d0efa2 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-particle_enable="false" data-particle-mobile-disabled="false" data-id="5d0efa2" data-element_type="section" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
<div class="elementor-container elementor-column-gap-no">
<div class="elementor-row">
<div class="elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-dd88e8b" data-id="dd88e8b" data-element_type="column">
<div class="elementor-column-wrap elementor-element-populated">
<section class="elementor-section elementor-top-section elementor-element elementor-element-2c594959 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-particle_enable="false" data-particle-mobile-disabled="false" data-id="2c594959" data-element_type="section">
<div class="elementor-container elementor-column-gap-default">
<div class="elementor-row">
<h2 class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-71ca6ba0" data-id="71ca6ba0" data-element_type="column">Next Steps</h2>
</div>
</div>
</section>
</div>
</div>
</div>
</div>
</section>
<p>If you would like to discuss your insurance program with an experienced adviser, you can contact Clear Insurance on 1300 721 132 or <a href="https://clearinsurance.com.au/contact-us/">complete our online enquiry form</a>.</p>
<p>These incidents demonstrate why cyber insurance is essential. For details on how insurance covers incident response, recovery costs, and business interruption, see our <a href="https://clearinsurance.com.au/clear-services/cyber-insurance/" target="_blank" rel="noopener noreferrer">Cyber Insurance Guide</a>.</p>
<div style="padding: 20px 20px 10px; border: #7dc0c3 1px solid; margin-top: 60px;">
<p><strong><em>General Advice Warning: </em></strong><em>This advice is general and does not take into account your objectives, financial situation or needs. You should consider whether the advice is appropriate for you and your personal circumstances. Before you make any decision about whether to acquire a certain product, you should obtain and read the relevant product disclosure statement.</em></p>
<p><em>Clear Insurance Pty Ltd. ABN 41 601 916 689. AFSL No. 548953.</em></p>
</div>The post <a href="https://clearinsurance.com.au/10-biggest-cyber-attacks-in-history/">10 Biggest Cyber Attacks in History</a> appeared first on <a href="https://clearinsurance.com.au">Clear Insurance</a>.]]></content:encoded>
					
					<wfw:commentRss>https://clearinsurance.com.au/10-biggest-cyber-attacks-in-history/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What is Human Operated Ransomware?</title>
		<link>https://clearinsurance.com.au/what-is-human-operated-ransomware/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-is-human-operated-ransomware</link>
					<comments>https://clearinsurance.com.au/what-is-human-operated-ransomware/#respond</comments>
		
		<dc:creator><![CDATA[Lisa Carter]]></dc:creator>
		<pubDate>Wed, 16 Jun 2021 01:10:04 +0000</pubDate>
				<category><![CDATA[Cyber Risk & Insurance]]></category>
		<guid isPermaLink="false">https://clearinsurance.com.au/?p=2875</guid>

					<description><![CDATA[Ransomware Attacks With the number of cyber attacks on the rise, particularly ransomware attacks, it is important more now than ever that organisation's have ample protection in place to prevent attacks happening. What is Human Operated Ransomware? There's a cyber threat that should be at the forefront of most organisations' cyber security efforts: human operated [...]]]></description>
										<content:encoded><![CDATA[<section class="elementor-section elementor-top-section elementor-element elementor-element-5d0efa2 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-particle_enable="false" data-particle-mobile-disabled="false" data-id="5d0efa2" data-element_type="section" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
<h2 class="elementor-container elementor-column-gap-no">Ransomware Attacks</h2>
</section>
<div data-id="f269f0e" data-element_type="widget" data-settings="{&quot;_animation&quot;:&quot;fadeIn&quot;,&quot;_animation_delay&quot;:&quot;200&quot;}" data-widget_type="heading.default">
<p>With the number of cyber attacks on the rise, particularly ransomware attacks, it is important more now than ever that organisation&#8217;s have ample protection in place to prevent attacks happening.</p>
<h3>What is Human Operated Ransomware?</h3>
<p>There&#8217;s a cyber threat that should be at the forefront of most organisations&#8217; cyber security efforts: human operated ransomware. It consists of hands-on-keyboard attacks by financially motivated malicious actors, accessing internal corporate networks and deploying ransomware. They then use these to encrypt the organisation&#8217;s data, extorting them to pay a ransom to get their data and systems restored.</p>
<h3>Why human operated ransomware attacks are so dangerous?</h3>
<p>Long-running downtime is often a result of these attacks, while ransoms are negotiated and the data is held hostage. Unfortunately, when it comes to these attacks, having backup and recovery strategies in place is not sufficient. This is because they don&#8217;t prevent the theft of the data in the first place, which can then be leaked to the public or used for extortion. Organisations need to place a strong priority on preventing the attacks from happening in the first place.</p>
<h3>How an attack works?</h3>
<p>Typically, a campaign begins with an unsophisticated and mass-scale technique such as a large deployment of phishing emails. These can be effective because they’re often designated as unimportant, so remedies aren’t put into place and investigations aren’t carried out.</p>
<p>What makes an organisation vulnerable to these attacks?</p>
<ul>
<li>older operation systems</li>
<li>poorly configured technology</li>
<li>low security on privileged accounts</li>
<li>ineffectual detection</li>
</ul>
<p>What practical steps can an organisation take to improve their security?</p>
<ul>
<li>Improve employee awareness</li>
<li>Ensure adequate email security</li>
<li>Use web filters</li>
<li>Focus on strong passwords</li>
</ul>
<p>Human-operated ransomware poses significant financial risk. For information on ransomware coverage, ransom negotiation support, and business interruption protection, see our <a href="https://clearinsurance.com.au/clear-services/cyber-insurance/" target="_blank" rel="noopener noreferrer">Cyber Insurance Guide</a>.</p>
<p>Smile IT have also set out what you can do to help prevent a ransomware attack on their blog titled &#8216;<a href="https://www.smileit.com.au/human-operated-ransomware/">Human Operated Ransomware: How to Keep Your Business Safe</a>&#8216;.</p>
<h2>Next Steps</h2>
<p>If you would like to talk to a risk and insurance adviser about your current insurance program or would like to consider a <a href="https://clearinsurance.com.au/clear-services/risk-insurance-review/">no-obligation risk and insurance review</a>, you can contact the <a href="https://clearinsurance.com.au/about-us/our-team/">Clear Insurance team</a> on 1300 721 132 or <a href="https://clearinsurance.com.au/contact-us/">complete our online enquiry form</a> and an experienced adviser will be in touch.</p>
</div>
<div style="padding: 20px 20px 10px; border: #7dc0c3 1px solid; margin-top: 60px;">
<p><strong><em>General Advice Warning: </em></strong><em>This advice is general and does not take into account your objectives, financial situation or needs. You should consider whether the advice is appropriate for you and your personal circumstances. Before you make any decision about whether to acquire a certain product, you should obtain and read the relevant product disclosure statement.</em></p>
<p><em>Clear Insurance Pty Ltd. ABN 41 601 916 689. AFSL No. 548953.</em></p>
</div>The post <a href="https://clearinsurance.com.au/what-is-human-operated-ransomware/">What is Human Operated Ransomware?</a> appeared first on <a href="https://clearinsurance.com.au">Clear Insurance</a>.]]></content:encoded>
					
					<wfw:commentRss>https://clearinsurance.com.au/what-is-human-operated-ransomware/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cyber attack shuts down global meat processing giant</title>
		<link>https://clearinsurance.com.au/cyber-attack-shuts-down-global-meat-processing-giant/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cyber-attack-shuts-down-global-meat-processing-giant</link>
					<comments>https://clearinsurance.com.au/cyber-attack-shuts-down-global-meat-processing-giant/#respond</comments>
		
		<dc:creator><![CDATA[Lisa Carter]]></dc:creator>
		<pubDate>Wed, 16 Jun 2021 00:51:02 +0000</pubDate>
				<category><![CDATA[Cyber Risk & Insurance]]></category>
		<guid isPermaLink="false">https://clearinsurance.com.au/?p=2876</guid>

					<description><![CDATA[Cyber attack on JBS Foods The world's largest meat processing company, JBS Foods, has fallen victim to cyber attacks that have shut down production around the world, including in Australia. JBS has 47 facilities across Australia and operates the largest network of production facilities and feedlots in the country. The company also has a meat [...]]]></description>
										<content:encoded><![CDATA[<section class="elementor-section elementor-top-section elementor-element elementor-element-5d0efa2 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-particle_enable="false" data-particle-mobile-disabled="false" data-id="5d0efa2" data-element_type="section" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
<div class="elementor-container elementor-column-gap-no">
<h2 data-id="f269f0e" data-element_type="widget" data-settings="{&quot;_animation&quot;:&quot;fadeIn&quot;,&quot;_animation_delay&quot;:&quot;200&quot;}" data-widget_type="heading.default">Cyber attack on JBS Foods</h2>
</div>
</section>
<p>The world&#8217;s largest meat processing company, JBS Foods, has fallen victim to cyber attacks that have shut down production around the world, including in Australia.</p>
<p>JBS has 47 facilities across Australia and operates the largest network of production facilities and feedlots in the country. The company also has a meat processing facilities in North and South America, Brazil and Canada. Thousands of meat-workers across Australia have been sent home as a result of the recent cyber attacks, according to the Australian Meat Industry Employees&#8217; Union.</p>
<p>The company&#8217;s information systems were the main target of the cyberattack which sent the organisation into chaos globally. The five-day shutdown threatened Australia&#8217;s meat supply chain, with temporary staff lay-offs at some of the company&#8217;s plants and reports from farmers that their shipments of livestock were cancelled.</p>
<p>In a statement, a JBS spokesperson said the company took immediate action by contacting authorities and enlisting the help of IT experts across the globe to help fix the issue.</p>
<p>&#8220;All of the animals coming into the system, and all the meat going out of the system are all done by computers, whereas in the old days it was done with the labelling and tagging system,&#8221; Tasmanian Secretary Andrew Foden said.</p>
<p>The situation is also having big implications for farmers elsewhere in the country. Gabrielle Coupland farms on the southern NSW border and delivers sheep to the JBS plant at Brooklyn just outside of Melbourne. She said deliveries were cancelled on Monday and the shutdown had caused huge disruption to the supply chain in the region.</p>
<p>Federal Agriculture Minister David Littleproud confirmed the government was investigating the hack and working to get the company back online.</p>
<p>.</p>
<p>.</p>
<p>.</p>
<p>.</p>
<p><strong>At the time of publishing it has been confirmed that JBS paid the equivalent of $US11 million ($14.2 million) to a criminal gang to end a five-day cyber attack that halted its operations around the world, including Australia. The company said it paid the money to mitigate any unforeseen issues related to the attack and ensure no data was exfiltrated. The ransom was paid in bitcoin.</strong></p>
<p>&nbsp;</p>
<p>If you would like to discuss your insurance program with an experienced adviser, you can call Clear Insurance on 1300 721 132 or <a href="https://clearinsurance.com.au/contact-us/">complete our online enquiry form</a> and an adviser will be in touch.</p>
<section class="elementor-section elementor-top-section elementor-element elementor-element-2c594959 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-particle_enable="false" data-particle-mobile-disabled="false" data-id="2c594959" data-element_type="section">
<div class="elementor-container elementor-column-gap-default">
<div class="elementor-row">
<p>&nbsp;</p>
</div>
</div>
</section>
<div style="padding: 20px 20px 10px; border: #7dc0c3 1px solid; margin-top: 60px;">
<p><strong><em>General Advice Warning: </em></strong><em>This advice is general and does not take into account your objectives, financial situation or needs. You should consider whether the advice is appropriate for you and your personal circumstances. Before you make any decision about whether to acquire a certain product, you should obtain and read the relevant product disclosure statement.</em></p>
<p><em>Clear Insurance Pty Ltd. ABN 41 601 916 689. AFSL No. 548953.</em></p>
</div>The post <a href="https://clearinsurance.com.au/cyber-attack-shuts-down-global-meat-processing-giant/">Cyber attack shuts down global meat processing giant</a> appeared first on <a href="https://clearinsurance.com.au">Clear Insurance</a>.]]></content:encoded>
					
					<wfw:commentRss>https://clearinsurance.com.au/cyber-attack-shuts-down-global-meat-processing-giant/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to avoid online scams</title>
		<link>https://clearinsurance.com.au/how-to-avoid-online-scams/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-to-avoid-online-scams</link>
					<comments>https://clearinsurance.com.au/how-to-avoid-online-scams/#respond</comments>
		
		<dc:creator><![CDATA[Clear Insurance]]></dc:creator>
		<pubDate>Thu, 16 Jan 2020 03:16:55 +0000</pubDate>
				<category><![CDATA[Cyber Risk & Insurance]]></category>
		<guid isPermaLink="false">https://ci.whitespacemarketing.com.au/?p=742</guid>

					<description><![CDATA[How to watch out for scams We've all been there. Packed car parks, long queues, pushy crowds. If you want to avoid the stress and mayhem of your local shopping centre, online shopping has considerable upsides. The only trouble is, there are plenty of scammers waiting to take advantage of online shoppers. There's also the [...]]]></description>
										<content:encoded><![CDATA[<h2><strong>How to watch out for scams</strong></h2>
<p>We&#8217;ve all been there. Packed car parks, long queues, pushy crowds. If you want to avoid the stress and mayhem of your local shopping centre, online shopping has considerable upsides. The only trouble is, there are plenty of scammers waiting to take advantage of online shoppers.</p>
<p>There&#8217;s also the potentially expensive issue of getting stuck with online purchases that fail to meet your expectations, are dangerous and/or illegal, or perhaps don&#8217;t even work.</p>
<p>To ensure you and your family don&#8217;t fall prey to scammers, here are some things to keep in mind.</p>
<h3><strong>1. Shop only on secure websites</strong></h3>
<p>Clearly some websites are a lot easier to identify as being secure than others. However all secure websites will have two key markers:</p>
<ol>
<li>An image of a closed padlock &#8211; this is usually located in the top left of your browser URL</li>
<li>A web address that begins with &#8216;https://&#8217; &#8211; if the URL leaves out the &#8216;s&#8217; and begins only with &#8216;http://&#8217; be very careful.</li>
</ol>
<p>For a website to be truly secure, it must have both of these important markers. If you can&#8217;t see them, never give out personal information such as your credit card details, account numbers or passwords.</p>
<h3><strong>2. Only provide relevant information</strong></h3>
<p>Is a website asking you for personal information that doesn&#8217;t seem relevant to your purchase? If so, there&#8217;s good reason to be suspicious about continuing. It might sound tedious, but it&#8217;s also worth taking a look at the website&#8217;s privacy policy and making sure you&#8217;re cool with its stipulations.</p>
<h3><strong>3. Keep records &amp; keep checking them</strong></h3>
<p>It may seem a little unnecessary. But be sure to always take note of any reference numbers associated with your purchases and either print or take screen shots of your receipts. If you don&#8217;t receive either of these things at the time of purchase, follow up with the business concerned immediately. A day or two later it&#8217;s also excellent online protocol to check the receipt against the amount that is actually charged to your credit card or debited from your account to make sure they match.</p>
<h3><strong>4. Employ a healthy dose of digital suspicion</strong></h3>
<p>You&#8217;d be amazed just how sophisticated scammers have become and the incredible lengths they&#8217;ll often go to in pursuit of their illegal gains. While it can be very difficult to tell some online scams from legitimate business offers, it pays to keep your wits about you at all times and employ a healthy dose of digital suspicion. As they say, if it seems too good to be true it probably is.</p>
<p>To help, <a href="https://www.scamwatch.gov.au/" target="_self" rel="noopener noreferrer"><strong>scamwatch.gov.au</strong></a> is a great resource for staying up-to-date with the latest online scams to watch out for.</p>
<h3><strong>5. Shop only with reputable businesses</strong></h3>
<p>True, just because you&#8217;ve never heard of a business before doesn&#8217;t mean it&#8217;s bogus. But until you&#8217;re confident it isn&#8217;t, be careful. How can you tell if a business is reputable? Some of the better indicators include:</p>
<ul>
<li>You&#8217;ve heard of the business</li>
<li>It&#8217;s been trading for some time</li>
<li>Independent online reviews are positive, especially from other sites and sources you trust</li>
<li>You or someone you know has used them in the past with no problems</li>
<li>The company has an actual office including a listed physical street address (i.e. not just a PO Box).</li>
</ul>
<h3><strong>6. Check the terms &amp; conditions</strong></h3>
<p>One of the biggest downsides of shopping online happens when something goes wrong. For example, what if the product you buy turns out to be faulty? Breaks in transit? Doesn&#8217;t fit? Isn&#8217;t what you ordered? Or maybe doesn&#8217;t even arrive at all? It&#8217;s often far more complicated than shopping in the real-word, so before making an online purchase make sure you understand the seller&#8217;s terms and conditions. Be particularly aware of the processes/costs for returning an item and how to go about getting a refund should you need one. As they say, buyer beware.</p>
<h3><strong>7. Watch out for hidden costs</strong></h3>
<p>There are plenty of bargains to be found online. But always be careful to look beyond the purchase price alone. While the actual product might seem cheap, hidden charges like shipping and postage fees, import taxes, service fees and currency conversion rates if you&#8217;re shopping overseas can add up fast. In some cases you may find it&#8217;s much cheaper to buy from a local shop after all.</p>
<h3><strong>8. Be careful if you&#8217;re buying from an overseas site</strong></h3>
<p>When you shop with an overseas website you&#8217;re largely on your own. You&#8217;re unlikely to be protected by Australia&#8217;s consumer laws, so in order to protect yourself there are plenty of questions to consider.</p>
<ul>
<li>Is the product legal in Australia?</li>
<li>Will the manufacturer&#8217;s warranties apply in this country?</li>
<li>Does it meet current Australian safety standards?</li>
<li>Do you need an import permit to bring it into the country?</li>
<li>Will any import taxes apply when it arrives?</li>
</ul>
<p>If you&#8217;re unsure, especially if the value of the product you&#8217;re buying is quite significant, it&#8217;s an excellent idea to double check long before you click on the &#8216;BUY NOW&#8217; button. For questions relating to the importing of goods visit <a href="http://www.border.gov.au/" target="_self" rel="noopener noreferrer"><strong>www.border.gov.au</strong></a>.</p>
<p>If you would like to discuss your insurance program with an experienced adviser, you can call Clear Insurance on 1300 721 132 or <a href="https://clearinsurance.com.au/contact-us/">complete our online enquiry form</a> and an adviser will be in touch.</p>
<div style="padding: 20px 20px 10px; border: #7dc0c3 1px solid; margin-top: 60px;">
<p><strong><em>General Advice Warning: </em></strong><em>This advice is general and does not take into account your objectives, financial situation or needs. You should consider whether the advice is appropriate for you and your personal circumstances. Before you make any decision about whether to acquire a certain product, you should obtain and read the relevant product disclosure statement.</em></p>
<p><em>Clear Insurance Pty Ltd. ABN 41 601 916 689. AFSL No. 548953.</em></p>
</div>The post <a href="https://clearinsurance.com.au/how-to-avoid-online-scams/">How to avoid online scams</a> appeared first on <a href="https://clearinsurance.com.au">Clear Insurance</a>.]]></content:encoded>
					
					<wfw:commentRss>https://clearinsurance.com.au/how-to-avoid-online-scams/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
