Half of large UK businesses have been impacted by a major crisis event in the last 12 months. This is one of the key findings from a report – Combatting crisis complacency: large businesses’ approach to crisis management— by Gallagher, one of the world’s largest insurance broking, risk management and consulting services companies. According to a poll of 100 UK business leaders, commissioned by Gallagher, more than a quarter (27%) of those surveyed have already been impacted by a data breach or cyberattack, and nearly a fifth (18%) by industrial espionage, in the last year alone.
Gallagher’s research indicates that industrial espionage — which involves the illegal and unethical theft of business trade secrets for use by a competitor — is a significant growing risk to businesses. Nearly a third (30%) of those surveyed expects to be affected by this practice in some way over the next 12 months. There is currently limited indemnity available for this risk. This necessitates a company placing a greater focus on crisis prevention and response if it can’t be effectively transferred from a company’s balance sheet.
A high number of large businesses are using social media as a tool for proactive prevention and protection purposes. The majority (71%) of large UK corporates polled say they currently use social media, digital monitoring or ‘social listening’ – monitoring conversations on specific topics, phrases or brands, via Twitter or virtual geo-fences – to gain actionable insights on potential crisis issues. However, nearly a third (31%) admitted to having no social media protocols in place to help them respond to a crisis and only 16% of those polled have a back-up social media communications channel in place in the event of a systemic IT or telephony failure.
Cover confusion and complacency
The report also highlights that businesses are leaving themselves potentially exposed through significant gaps in their crisis coverage and incident support. Although 73% of businesses polled have reviewed their crisis planning following recent high-profile events, only 30% have reviewed their associated insurance cover, despite the growing prevalence, range and sophistication of crisis incidents. Furthermore, while 99% of respondents had conducted comprehensive risk assessments linked to crisis situations, less than a fifth (19%) have included a broker in this process. This may go some way to explain the uncertainty or misunderstanding surrounding the scope of different forms of crisis insurance cover that could be effective in specific scenarios.
For example, although the majority of businesses surveyed (85%) are correct in their belief that Pool Re, the government-backed terrorism reinsurance programme, provides cover in the event of financial loss relating to a terrorist incident, nearly two-thirds (64%) mistakenly believe that loss of data is covered by Pool Re – when it is not – and a similar number (61%) are incorrect in their view that reputational damage also falls within this remit.
Commenting on the findings, Paul Bassett, Managing Director of Crisis Management at Gallagher, said: “Large businesses across the UK are aware of the heightened dangers, new risks and emergent challenges flowing from the fast-evolving security threat landscape, which are increasingly complex and unpredictable in their nature.
“Yet despite the encouraging focus on protocols, risk assessments and mapping exercises, which are taking place across UK corporates, there is a significant blind spot when it comes to insurance. Many businesses are yet to review their insurance cover in the aftermath of the recent high-profile crisis events, which may explain the crisis cover complacency that seems to have crept in, which threatens to leave businesses dangerously exposed.
“There will never be a fool-proof way of preventing data breaches, major terrorist attacks or industrial espionage – but preparedness and response is everything. Businesses can build resilience to withstand the mounting threats of crisis incidents.”