top of page

ASOS Hack Claims Highlight Why Cyber Insurance Matters for Every Business

1 day ago
4 min read

Thousands of ASOS customers received a worrying notification today claiming that the online fashion retailer had been hacked and that its Snowflake instance had been compromised.

The message reportedly threatened to leak information unless the company engaged with the attackers. ASOS has said it is aware of the reports and is investigating, but has not confirmed that its systems or customer data have been compromised.

Whatever the eventual outcome, the incident provides another timely reminder for businesses across the UK:

Cyber attacks aren't simply an IT problem. They are a business risk.

And increasingly, businesses need to consider not only how they would prevent an attack, but how they would respond financially and operationally if one happened.

You don't have to be ASOS to be a target

It's easy for smaller businesses to look at an incident involving a major online retailer and think:

"We're nowhere near that size. Why would anyone target us?"

Unfortunately, cyber criminals don't only target household names.

Businesses of all sizes can be exposed to ransomware, phishing, business email compromise, data theft, fraudulent payments and attacks on IT systems.


The Association of British Insurers says businesses of all sizes can suffer cyber attacks and data breaches and describes cyber insurance as an important part of managing and improving cyber risk.

For an SME, the financial impact of an incident can be particularly significant.

A few days without access to critical systems could affect sales, production, customer service and cash flow. A data breach could create legal, notification and investigation costs. A fraudulent payment could result in a direct financial loss.

And that's before considering the potential reputational damage.

Cyber insurance isn't just about paying a claim

One of the biggest misconceptions about cyber insurance is that it is simply a financial safety net.

The right policy can provide access to specialist support when a business is dealing with a cyber incident.\


Depending on the policy, cyber insurance can help with areas including:

  • Incident response

  • Forensic investigation

  • Data restoration

  • Cyber extortion and ransomware

  • Business interruption

  • Cyber theft and fraud

  • Legal assistance

  • Regulatory costs

  • Notification of affected customers or employees

  • Public relations and communications support

  • Liability arising from a data or security breach

The ABI highlights both first-party losses -  such as damage to systems, data theft and business interruption -  and third-party liabilities arising from cyber events.

That means cyber insurance can form part of a wider business continuity and risk management strategy, rather than simply being another policy sitting in a filing cabinet.

The cost of a cyber attack can extend far beyond the IT department

Imagine your business is hit by ransomware on a Monday morning.

Your systems are unavailable.

Your staff can't access essential information.

Customers can't place orders.

Your finance team can't process payments.

Your IT provider is trying to establish what happened.

And you're faced with the difficult question of whether customer or employee data has been compromised.

How quickly could your business recover?

More importantly, who would you call?

Cyber insurance can provide access to specialist incident response teams and other expertise to help businesses manage the aftermath of an attack. The ABI notes that cyber policies can include significant assistance with managing incidents before and after an event.

Cyber security and cyber insurance need to work together

Insurance isn't a substitute for good cyber security.

Businesses should already be taking sensible steps to protect their systems, including strong passwords and multi-factor authentication, staff training, regular backups, software updates and appropriate access controls.

The ABI stresses that insurance is only one part of the toolkit and that businesses also need strong cyber security measures.

In fact, the security measures your business has in place can also be relevant when arranging cyber insurance.

That's why a cyber insurance review shouldn't simply involve asking:

"How much does it cost?"

It should involve understanding how your business operates, what information and systems are critical, where your vulnerabilities may lie and what financial consequences an incident could create.

When did you last review your cyber insurance?

If your business has changed since your cyber policy was arranged, it may be worth revisiting your cover.

For example:

  • Has your turnover increased?

  • Are you holding more customer data?

  • Have you moved more of your operations online?

  • Are you increasingly dependent on cloud-based systems?

  • Have you introduced new technology or AI?

  • Are more employees working remotely?

  • Have you changed IT providers?

  • Are you more dependent on third-party suppliers?

  • Has your business's reliance on technology increased?

If the answer to any of these is yes, your cyber risk may have changed too.

And if you don't currently have cyber insurance, it's worth understanding what protection is available and whether it is appropriate for your business.

Don't wait for your own "ASOS moment"

Today's reports involving ASOS are still developing, and the full picture is not yet known.

But businesses don't need to wait for a confirmed cyber attack to start asking questions.

Could we continue operating if our systems went down tomorrow?

How would we respond if customer data was compromised?

Who would help us investigate the incident?

What would the financial impact be?

Would our existing insurance actually respond?

These are questions worth answering before an incident occurs.

At Vista NW, we help businesses review their commercial insurance arrangements and understand whether their existing protection reflects the risks they face today.

If you haven't reviewed your cyber insurance recently - or you're not sure whether you have the right protection - talk to the Vista NW team.


A cyber attack might be unpredictable.

Being prepared for one doesn't have to be.

 

 
 
bottom of page