skip to main content

IMPORTANT NOTICE: CNA Hardy would like to place cookies on your computer to improve your use of this website. To find out more about the cookies we use, see our Cookie Policy. By continuing to use this website you shall be deemed to have provided your consent and have accepted our Website Privacy Policy and Cookie Policy.

Select a country
  • Select a country
  • Belgium
  • Canada
  • Denmark
  • France
  • Germany
  • Italy
  • Luxembourg
  • Netherlands
  • United Kingdom
  • USA
Go!
  • About CNA
    • Locations
    • Management
    • Newsroom
    • Corporate Responsibility
  • About Us
  • Careers
  • Contacts
  • CNA Online
  • CNA Hardy – Linkedin
CNA Hardy – link to home page
Industries Products International Solutions Risk Control Claims News, Insights & Events Risk Control

Industries

We provide deep expertise, attentive service and tailored business insurance solutions to help manage exposures and minimize loss across a wide array of industries.

Read More >
  • Construction
  • Financial Institutions
  • Healthcare
  • Life Science
  • Manufacturing
  • Natural Resources
  • Professional Services
  • Technology
  • Wholesale Durable Goods

Products

Our wide range of business insurance products and solutions are specialized to meet the insurance and risk management needs of any business around the world.

Read More >
  • Products
  • Casualty
  • Management Liability
  • Marine
  • Package
  • Professional Indemnity
  • Property

Risk Control

Risk Control

Read More >

Access Download Libraries for:

  • Risk Related to Property, Assets & Products

Additional Tools & Information:

  • PrepWise
  • eSight
CNA Hardy – link to home page
  • About Us
  • Careers
  • Contacts
  • CNA Online
  • Industries
  • Products
  • International Solutions
  • Risk Control
  • Claims
  • News & Insights
  • Main Navigation
  • Construction
  • Energy
  • Financial Institutions
  • Healthcare
  • Life Science
  • Natural Resources
  • Manufacturing
  • Professional Services
  • Technology
  • Wholesale Durable Goods

Products

  • Products
  • Casualty
  • Management Liability
  • Marine
  • Package
  • Professional Indemnity
  • Property
  • Locations
  • Management
  • Access Download Libraries for:

    • Risk Related to Property, Assets & Products

    Additional Tools & Information:

    • PrepWise
    • eSight
    • CNASurety.com
    • eSight

     

    Select a country
    • Select a country
    • Belgium
    • Canada
    • Denmark
    • France
    • Germany
    • Italy
    • Luxembourg
    • Netherlands
    • United Kingdom
    • USA
    Go!
    insights binoculars view sunset horizon scanning
    • Insights
    • SME Cyber Threats 101: Impersonation Fraud
    • facebook
    • twitter
    • linkedin
    • Email

    SME Cyber Threats 101: Impersonation Fraud

    03 April 2019

    Our latest research* revealed that only 36% of small & medium sized businesses are prioritising cyber risk, yet at the same time, SME’s are the victims of cyber-attacks by criminals using increasingly sophisticated impersonation fraud techniques to exploit their staff.

    What is Impersonation Fraud?

    Cyber criminals target the employees of a business, aiming to exploit human habits and weaknesses into breaking standard security policies in order to gain access to personal data, funds or install ransomware. According to Ponemon SME research, 79% of SMEs state that ransomware was released as a result of a social engineering attack.**

    Once a business has been exposed by the initial fraud, the cyber-criminal has access to carry out further breaches such as spreading viruses to customers or suppliers via email, accessing personal data or placing fake invoices for payment.

    Common Ways Employees are Manipulated:

    Spear Phishing
    A targeted attack focusing on a specific employee and uses their personal information and background to gain trust and legitimacy. Spear phishing has a high success rate for tricking victims into passing over sensitive information, trade secrets, personal or financial data. Criminals will research social media accounts and other online activity.

    Fake President:
    An employee is contacted over phone or email by someone pretending to be a director or the CEO and instructed to make an emergency payment for a debt, an invoice or a deposit.

    The cyber-criminal will have researched the market, the business structure, customers and staff giving them detailed, convincing arguments to manipulate the employee.

    Baiting
    The cyber-criminal leaves a malware-infected USB stick or CD in a place where employees will find it. The success relies on the employee plugging the device in and unknowingly installing the malware.

    Tailgating
    Criminals follow employees and monitor their moves and activities. They may gain unauthorised access to buildings by pretending to forgot access cards or borrow a mobile phone to make a quick call and installing a virus instead.

    How to avoid Falling Victim To Impersonation Fraud:

    SME’s need to understand their cyber exposures. Whilst they may not have the same scale of personal data as larger businesses, they still hold valuable information that cyber criminals want, and also have the same exposures and weaknesses that must be addressed.

    Staff training is critical
    A thorough, ongoing cyber awareness programme and training will embed best practice into a company’s culture.

    For advice on Business Continuity Planning read Stuart Kenyon’s blog here.

    At CNA Hardy, we’ve dedicated a lot of time and resource into better understanding these types of attacks and have built our findings into our product offering and services.

    For more information on what our Cyber Policy provides, click here.

    Martyn Janes
    Underwriter, Cyber & Tech
    UK Regions – Birmingham & SW England
    [email protected]

    * Ponemon 2017 sme cyber report.
    ** CNA Hardy Risk & Confidence Survey Autumn 2018 Report.

    • Belgium
    • Canada
    • Denmark
    • France
    • Germany
    • Italy
    • Luxembourg
    • Netherlands
    • United Kingdom
    • USA
    • Cookies
    • Terms & Conditions
    • Privacy & Consent to Use Data
    • Site Map
    • Complaints
    • Modern Slavery Act Statement
    • Gender Pay Gap
    • Board Diversity Policy
    • Legal Entity Details
    • Whistleblowing Policy
    • Procurement Terms & Conditions
    • Cookie Settings