Two-thirds of Irish businesses have experienced at least one cyber attack in the last year
Two thirds (66%) of Irish businesses have experienced at least one cyber-attack in the last year, while more than a third have been hit with over three attacks over the last 12 months. According to a poll of 250 businesses by insurance broker Gallagher and the Centre for Economics and Business Research (CEBR) almost a third (30%) said they had incurred legal costs; almost three in 10 (29%) lost revenue.
The survey also found that more than one in five (22%) of those who experienced a cyber attack were fined by a regulator, and a third (32%) said they were unable to service customers in the downtime that arose following a cyber incident.
Despite the significant number of businesses that have experienced a cyber-attack, most (95%) were confident that they could detect and contain a breach, even if the intruder remains hidden for some time, with more than half (55%) of Irish businesses saying they were ‘very confident’ of this.
Michael Cunningham, head of financial lines at Gallagher said: “The frequency, severity and intensity of cyber attacks has increased in recent years and our research reflects that… The huge repercussions that these can have on businesses should not be underestimated. Businesses can face substantial hits to their profit, or even bankruptcy, after a breach.
“Legal costs that arise from a cyber attack can put a huge financial strain on businesses, as can reputational damage. As well as leading to a loss of trust and confidence in the company amongst customers, investors and partners, reputational damage can lead to negative media attention. Revenue can be lost when customers cancel contracts, reduce spending, or switch to alternative suppliers after a cyber-attack. It can take a company years to rebuild trust – and revenue – after an incident.”
The research also found that businesses were keenly aware that they could face litigation following a cyber attack. Seven in ten (70%) respondents said they expected a serious cybercrime incident to lead to legal or shareholder/investor action for their company – a prospect considered ‘very likely’.
The vast majority (84%) of respondents said they were aware that company directors could face personal liability or legal actions in the event of a cyber breach.
Cunningham added: “Shareholder litigation costs are emerging as one of the costliest consequence of cyber-attacks for businesses. This is something which Irish businesses need to be increasingly mindful of and to prepare for.
“As the high-profile attacks on high street retailers last year show, the legal, financial and reputational fallout from cyber-attacks can drag on for months, even years. In the US, breaches have gone even further, triggering costly shareholder lawsuits focused entirely onboard oversight and disclosure.
The research also showed that Irish businesses have taken steps to combat cybercrime, with more than seven in ten (72%) Irish businesses having a standalone cyber-insurance policy in place. However, with costs emerging from cyber-attacks, evolving businesses need to be aware of what these policies do and don’t cover.
Business costs
According to the survey, the main costs covered by the cyber insurance policies held by Irish businesses. More than half (56%) said business interruption costs were covered by their cyber insurance policy, followed by data recovery and forensic payments (46% of respondents), and ransomware payments (42%).
Cunningham said: “While it’s encouraging to see businesses investing in cyber insurance, directors need to understand this does not cover every single aspect of a cyber attack. Cyber insurance covers the operational fallout, system damage, and liability caused by a digital attack. Directors & officers (D&O) insurance will usually be needed to cover costs relating to directors not adequately protecting the business and being held liable by shareholders, whilst commercial crime insurance reimburses firms for direct financial losses resulting from theft and fraud. Firms should engage the support of a specialist insurance broker who can advise them how to protect against the fallout from cyber issues such as those we see today.
“It is important for firms to remember security measures should also go beyond just financial protection. Many businesses are still vulnerable due to gaps in employee training, system monitoring, and access controls. For Irish businesses to be able to withstand and recover from cyber attacks, putting all the necessary guardrails in place ahead of time is paramount.”
TechCentral Reporters






Subscribers 0
Fans 0
Followers 0
Followers