The importance of cyber security for small businesses

ARTICLE BY

SHARE THIS POST

During the past two years all businesses, and in particular small enterprises and entrepreneurs had to step up the way they protect their digital and data assets. According to an Accenture report, South African businesses experience 577 cyber-attacks per hour at a cost South Africa R2.2 billion per year.

Philippa Wild from Santam says, “Apart from the obvious impact of COVID-19 on businesses operations, another C-word – Cyber Security – has become critical for small businesses, especially in the light of increasingly remote work forces.”

According to last year’s KnowBe4 African Cybersecurity & Awareness Report 2021, 32% of respondents were affected by cybercrime while working from home and one third of the attacks were social engineering, which proves the increased importance of managing cyber threats effectively.

With the transition to a digitally seamless world, a higher acceptance of e-commerce and the premium on consumer data driven in part by POPIA legislation, cyber security has become a focus for many companies. According to the Santam 2021 Insurance Barometer Report, cyber risk is now widely recognised as a global emerging risk, with 40% of Small Medium Enterprises surveyed relying on free anti-virus software for cyber protection and up to 27% not backing up their data. In the same report, it was found that 45% of commercial intermediaries ranked cybercrime as their third-highest business risk with 36% of small businesses ranking it their fourth-biggest risk.

Wild explains, “Contrary to popular belief, cyber threats are not limited to big corporations and governments.  Compared with larger companies, however, many small businesses have fewer resources to dedicate to cyber security which leaves them vulnerable to the ever-evolving tactics of cyber criminals. Companies need to continuously ask themselves if their business is adequately protected and fortunately Santam understand this need and developed comprehensive Cyber Cover that can be added to existing commercial policies.”

Dealing with the consequences of a cyber-attack can be seriously detrimental to a business’s bottom line, costing up to half a million or even more in some instances.

Wild says, “The reality is that when it comes to starting a small business, new owners have many decisions to make and often leave cybersecurity measures by the wayside.”

This is a massive risk, which of course is something that Santam understands. As such, the company offers bespoke cyber insurance cover that is specifically curated for businesses that employ up to 100 people with a turnover of up to R20 million. The four areas covered include:

  1. Data breach and restoration
    After a breach, the business may incur legal costs and pay damages to third parties. This extension provides cover for legal defence costs and damages if the case is unsuccessfully defended. 
  2. Third party liability
    This covers your business against any claims that your clients or intermediaries make towards your business should they experience a cyber-attack on your system.
  3. Business interruption
    The offering is designed to assist small to medium business owners to get their business back on track after a breach.
  4. Cyber extortion and cybercrime
    This extension helps get businesses running as soon as possible after a cyber-attack and manages the financial implications because of the ransomware.

Wild explains, “Provided the client has selected the core cover being a data breach; they can adjust the remaining limits accordingly or add and remove the remaining covers as necessary. The Cyber cover provides an end-to-end service to the Small Medium Enterprises of South Africa by allowing potential clients to acquire vulnerability scans, pre and post policy inception.”

She continued to share some frequently asked questions relating to Santam’s cyber cover:

Is the cover optional or mandatory as part of general business cover?
Yes, it is optional and only available in South Africa

What are the dependencies?

  • The cover is only for businesses with Annual turnover up to R20,000,000
  • The cover is only for businesses with up to 100 employees
  • Certain business types are excluded such as state-owned enterprises, financial institutions, hospitals, and municipalities.

Wild concludes, “The best way to protect and manage any risk is to get business insurance that is tailor-made to suit your business needs and operations. As the largest insurer in South Africa, Santam wants to partner with small businesses to cater for their unique insurance needs and threats of which cyber-attacks are becoming more and more prominent.”  

*For more information on cyber insurance, please visit http://www.santam.co.za/

Subscriber Terms and Conditions

  1. APPLICATION OF TERMS
    • These terms and conditions (“Subscriber Terms”) apply to the subscription by any qualifying member of the South African Underwriting Managers Association NPC (“SAUMA”) to the services and benefits offered by FIA Services (Pty) Ltd (“FIA Services”) under the SAUMA affiliation arrangement (“Subscription”).

  2. NATURE OF SUBSCRIPTION
    • A Subscription under this arrangement:
      • does not constitute membership of FIA NPC;
      • does not confer any voting rights or governance participation in FIA NPC; and
      • is governed solely by the contractual relationship between the Subscriber and FIA Services.

  1. ELIGIBILITY
    • To qualify for the Subscription, the applicant must, at the time of application, be a current paid-up member of SAUMA.
    • FIA Services will verify the applicant’s SAUMA membership status with SAUMA prior to activation, and may re-verify such status periodically.
    • If a Subscriber ceases to be a paid-up member of SAUMA, the Subscription will correspondingly be terminated.
    • Applicants are required to authorise FIA Services to confirm their SAUMA membership status with SAUMA as part of the application process.

  1. SERVICES
    • The Subscription entitles the Subscriber to the following benefits:
      • Complimentary access to the FIA CPD Platform;
      • Complimentary access to the FIA Insight Magazine (digital edition);
      • Advertising opportunities on FIA platforms at a discounted rate of 15% (fifteen percent) off the prevailing published rates; and
      • Invitations to attend FIA Technical Webinars annually.
    • FIA Services reserves the right to update, vary or substitute the Services from time to time, provided that the overall value and nature of the benefits remain materially the same.

  1. FEES AND PAYMENT
    • The monthly subscription fee is R260.00 (two hundred and sixty rand) for up to seven registered individuals (Key Individuals and Representatives), and R36.00 (thirty-six rand) per additional registered individual thereafter, excluding VAT.
    • The Subscriber shall provide FIA Services with the required details of each individual to be registered under the Subscription for the purposes of activation and billing.
    • All fees are exclusive of VAT, which shall be charged at the prevailing statutory rate.
    • Subscription fees are reviewed annually in March and may be adjusted with effect from 1 April.
    • Any changes to the Subscription, including but not limited to the number of Representatives and Key Individuals registered under the Subscription, may only be effected once annually during the annual review period in March of each year, with such changes taking effect from 1 April.
    • Subscription fees shall be billed monthly in arrears, unless the Subscriber elects an annual billing cycle at the time of application.
    • The Subscriber shall ensure that all billing information (including contact details, authorised signatories and bank account details) is kept accurate and up to date.
    • Non-payment of subscription fees may result in suspension of access to the Services until such fees are brought up to date.
    • The Subscriber acknowledges and agrees that all subscription fees payable under these Subscriber Terms may be collected by way of debit order, which shall be processed by the holding company, FIA NPC (The Financial Intermediary Association of South Africa), on behalf of FIA Services. Payment to FIA NPC shall be deemed to constitute valid and sufficient discharge of the Subscriber’s payment obligations to FIA Services under these Subscriber Terms.

  1. ONBOARDING
    • Onboarding will be conducted as a Subscription with FIA Services under the SAUMA affiliation arrangement.
    • Onboarding will not confer FIA NPC membership status or any associated rights.
    • Onboarding is conditional on confirmation of the Subscriber’s current SAUMA membership at the time of application

  1. DATA PROTECTION
    • FIA Services will process all personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) as set out in our POPIA policies.
    • By subscribing, the Subscriber authorises FIA Services to confirm their SAUMA membership status with SAUMA and to process personal information for the purposes of fulfilling the Subscription.

  1. TERMINATION
    • The Subscriber may terminate the Subscription by giving FIA Services one calendar month’s written notice.
    • FIA Services may terminate the Subscription on one calendar month’s written notice, or immediately if the Subscriber breaches these Subscriber Terms and fails to remedy such breach within 14 (fourteen) days of receiving written notice.
    • Termination of the SAUMA–FIA Services affiliation agreement shall not automatically terminate these Subscriber Terms.
    • Termination by the Subscriber shall not relieve the Subscriber of liability for any subscription fees accrued up to the effective date of termination.
    • FIA Services may suspend or terminate the Subscription with immediate effect in the event of non-payment of fees by the Subscriber.

  1. GENERAL
    • These Subscriber Terms are governed by the laws of the Republic of South Africa.
    • Any disputes arising under these Subscriber Terms shall be dealt with in accordance with the dispute resolution provisions contained in the FIA NPC membership terms and conditions, as modified to reflect that the contractual relationship is with FIA Services.
    • Any notices required under these Subscriber Terms may be validly delivered by email to the addresses provided in the Subscriber’s application form, and such notices shall be deemed received on the day of transmission if sent during business hours.
    • The Subscriber may not assign, cede or transfer any of its rights or obligations under these Subscriber Terms without the prior written consent of FIA Services.
    • No variation of these Subscriber Terms shall be of any force or effect unless reduced to writing and signed by both FIA Services and the Subscriber.