Simple explanations of cyber threats, their impact and the role of insurance protection.
It’s an issue that most brokers will have come up against. Cyber insurance is genuinely important, but it can be wrapped in so much technical jargon that it feels like a different language.
Terms like phishing, push payment fraud and betterment can be baffling when you’re not an expert.
And our research identified a significant “confidence gap” among SMEs, with only a quarter (26%) reporting feeling “very confident” in their data and cyber protection strategies, suggests that business owners know they are at risk, but feel underequipped to address it.
The language used isn't designed to baffle businesses, it’s because cyber risk is genuinely complex. But businesses don't need to understand all the technical detail, just what it means for their business. That creates an opportunity to cut through by translating jargon into transparent language.
Here's a handful of examples:
Ransomware: "Files are locked down and criminals want money to unlock them"
Imagine someone encrypts all your business files, like your customer records, invoices and operational data, and you can't access them until you pay a ransom. Ransomware is designed to do exactly that, paralysing a business until either they pay up or restore everything from their backups. If it happens, cyber insurance can cover the recovery costs, a follow up forensic investigation and the cost of downtime.
Phishing: "A fake email designed to trick your staff into handing over passwords or click malicious links"
It’s a con, but it can look exactly like an email from the bank, a longstanding supplier or even a trusted colleague. And one successful phishing email can give criminals control over all an organisation’s systems. That’s why cyber insurance can include staff training and breach prevention services.
Business email compromise: "A criminal impersonating a trusted contact to authorise fraudulent payments"
Unlike mass phishing emails, BEC scams are more targeted. Cybercriminals hack the email account of a trusted contact to trick employees into sending them money or data. All too often, the request is actioned before anyone realises it's fraud.
Data breach: "Customer or business information is stolen by someone unauthorised"
When systems are compromised, criminals can copy valuable customer data, financial records or trade secrets. Once personal data is stolen, firms have a duty to report a breach within 72 hours. Cyber insurance can provide the expertise to manage the fallout, including notification costs, credit monitoring services to spot things like loan applications or new bank accounts opened using stolen details, and PR crisis management.
Denial of Service (DoS) attack: "Criminals flood systems with so much traffic that they overload and crash"
Imagine thousands of fake requests hammering a website at the same time, causing chaos, stopping customers from placing orders and colleagues from doing their jobs. Systems aren't breached but they are overwhelmed and forced offline so a business can't trade. This is why cyber insurance covers business interruption, not just data theft.
The language that works
What these translations have in common is that they all connect to business outcomes, not technical processes.
By using plain-English explanations instead of jargon, cyber stops being abstract and feels more real.