Crisis control needed as incidents cost UK SMEs £8.8bn in 2018

Crisis control is essential to tackle incidents, such as cyber-attacks and extortion which are costing UK SMEs billions of pounds a year

Crisis control procedures need to be put in place to tackle incidents, such as cyber-attacks, extortion, industrial espionage and terrorism, which are costing UK SMEs billions of pounds a year and subsequent trading paralysis is putting thousands at risk of collapse in their aftermath.

UK SMEs paid out an average £6,416.50 last year, equating to a combined business cost of £8.8bn in 2018, to deal with crisis incidents, according to research by insurance broker and risk management consultants Gallagher,

24% of SMEs confirmed they were affected by a crisis event last year up 5% on the previous year 2017. 17% of SMEs affected by a crisis spent £10,000 or more to combat crises and 9% paid out in excess of £20,000. 23% said they would survive for less than a month if rendered unable to trade by a crisis incident.

This leads Gallagher to conclude that nearly 57,000 UK SMEs could be at risk of collapse this year in the aftermath of a crisis event if they don’t have crisis control in place.

The most prevalent crisis experienced by UK SMEs last year was a cyber-attack, data breach or cyber extortion incident, which accounted for 15% of all events. Financial services sustained the highest number of attacks by a significant margin. 27% of financial services SMEs surveyed were hit by this form of crisis in 2018.

Cyber-attacks, data breaches and cyber extortion also represent the areas of greatest concern for companies in 2019, prompting the call for crisis control. 50% of UK SMEs are most concerned about a cyber crisis taking place this year. Denial of access and business interruption was the second most concerning area, with 11% citing this as a major risk.

Paul Bassett, managing director of Crisis Management at Gallagher, said: “Our research illustrates the scale of the challenge facing UK SMEs. When it comes to crises, cyber and IT security clearly represent a “soft underbelly” of businesses that together account for more than 99% of private sector firms. Given that the UK economy is heavily tilted towards services, cyber-attacks and data breaches evidently present a growing and grave threat to small and medium-sized businesses.

“Alongside regularly reviewing their crisis preparedness, response plans and forms of protection, such as insurance, it is critical UK SMEs also assess their ability to survive in the event of a major crisis incident when the risk of serious disruption and protracted recovery process is very real.

“The cost of a crisis is by no means the only consideration. Duration is key. For companies with tight margins and limited working capital, even a relatively short-term denial of access to premises or systems paralysis could be a crippling, possibly fatal, blow.

“We urge all businesses to ensure they have the crisis cover and plans in place to strengthen their ability to anticipate, prevent, respond and recover from a major security incident —but also have access to emergency funds, 24/7 crisis response consultants, post-incident counselling and business recovery advice, in order to stay solvent and help them and their people recover quickly.”

Tom Draper, cyber practice leader at Gallagher added: “The prevalence of cyber-attacks against UK SMEs has reached a tipping point – companies ignore these risks at their own peril. Ransomware has become relatively commonplace and pay outs to demands are often met simply in order to resume trading. Failure to comply can result in a crippling period of business interruption, which in many cases, leads to businesses collapsing.

“Data breaches leading to compromised customer data are also proving a major issue for small businesses. Such incidents are damaging in themselves, due to possible cyber fraud and the significant reputational fallout from having to inform customers of a data breach, but SMEs may also find themselves facing significant fines under GDPR. The best way to survive – and thrive – in the aftermath of a cyber incident is to have planned ahead, to ensure that you are able to respond swiftly to an emerging crisis, and to purchase effective cover through a broker to protect your assets and provide expert counsel in the event of an incident.”

Further reading: Small business insurance: An essential guide

The importance of cyber security for SMEs in the UK

Related Topics

Contingency plan