Our clients take cyber resilience seriously!
Our client Cervus Belastingadvies is aware of the potential damage that can occur to both themselves and their clients following cyber incidents and considered taking out a cybersecurity insurance policy.
Assistance with Cybersecurity Insurance Application
Cervus has now taken out a cybersecurity insurance policy. Prior to this, they asked us as their ICT partner to help meet the requirements to obtain the insurance. Additionally, we assist in structurally maintaining and monitoring security measures and raising employee awareness about the consequences of cybercrime and how they can contribute to security.
What Are the Weak Points in an Organization?
Before a cyber risk insurance policy can be obtained, an assessment is conducted to identify vulnerabilities and opportunities to improve cyber resilience. Infracom helped Cervus address these weaknesses.
What Could Be the Damage from a Cyberattack?
- A virus or intrusion can lead to network hijacking. Ransomware blocks computers and servers and encrypts files, causing damage because business operations come to a halt.
- Costs can escalate, as ransom may need to be paid to cybercriminals to regain access to data after an attack.
- Expenses for specialists needed to investigate the cause of a cyberattack.
- Liability claims from clients if personal data is exposed due to a breach or attack.
- Fines from the Data Protection Authority if data and personal information are leaked.
- Costs for legal support, which is often necessary.
- Time spent communicating with clients and employees after a cyber incident.
Preventive Measures
To qualify for cybersecurity insurance, various (basic) security measures must be properly implemented. Even after obtaining the insurance, structural security measures must continue to be enforced. We assisted Cervus with, among other things:
- Encrypting all confidential and personal information.
- Structurally backing up electronic data outside the network.
- Storing backups offline.
- Regularly testing backups.
- Installing permanent antivirus software and firewalls and applying updates as soon as possible.
- Regularly updating systems and applications.
- Providing company-wide awareness training on privacy and security.
- Granting external access only with MFA (multi-factor authentication).