Cyber Incident at 7am? What Happens Next
What does a cyber incident look like for a tech business?
Your phone buzzes at 6:52am. It’s a client. Their systems are down, and when you log in, so are yours.
You know your systems inside out, and it still happened. Building and running technology for a living doesn’t make you immune, and when you look after other people’s systems, a bad morning rarely stays yours alone.
What happens in the first 30 minutes of a cyber incident?
If you hold cyber insurance, your first call is to your insurer’s incident line, the number on your policy. Your second call is to us. While the response team works on your systems, we’re there to walk you through what comes next. You can also report the incident to the Australian Cyber Security Centre at cyber.gov.au.
What happens next is the part most people don’t realise they’ve paid for. A notified incident sets a specialist response team in motion, often within 30 minutes: lawyers, forensic IT specialists, ransomware negotiators, and communications and regulatory experts. People who handle this every week, working for you, while the clock is ticking.
What does a cyber incident cost without insurance?
One of our customers decided against cyber cover. The premium was around $42,000. When an incident hit, bringing in incident response on day one cost them $100,000. That’s more than two years of premium, gone in a single day, before anything else had unfolded.
They hadn’t done anything wrong. They were hiring the same specialists the policy would have provided, at full rate, in a hurry, on the worst morning of their year.
What happens in the days after a cyber incident?
An incident rarely stays in one place. You look after other people’s systems, so one bad morning can reach your clients, your contracts and more than one policy at once.
That’s where we come in. We know your business and your policy, so we can tell you what happens next. We walk you through it step by step, chase the claim, and stay with you until you’re out the other side.
One tip while the phones are ringing: be careful what you promise your clients in those first calls. Talk to us before you accept any blame.
It's the kind of thinking that comes from working with managed service providers, systems integrators, managed security providers, data centres and vendors every day. Tech and IT businesses are the only ones we work with.
Who does what in a cyber claim?
You, the customer
What they own:The risk
What they do:Run the business, know the contracts and the exposures, and say when something changes
Your SherpaTech broker
What they own:The advice
What they do:Understand the business, shape the program, build the submission, negotiate with insurers, manage the changes, and run the claim
The insurer
What they own:The money
What they do:Assess the risk, set the terms and the price, issue the policy, and pay covered claims
Three things tech and IT businesses should check this week
Do your contracts match your cover? It’s easy for a contract to promise more than your policy will pay, and the gap usually shows up when a client makes a claim. Check that the liability you’ve agreed to lines up with the limit on your professional indemnity policy.
Do your clients hold their own cyber cover? If they do, their policy can be the first line of response. It’s Hannah’s golden question, and you can read more about it in Meet the Sherpas: Hannah.
Do you know your incident number? Does your team know who to call, and can they find the number if your systems are down? Keep a copy somewhere offline.
The bottom line
A cyber policy gets the right people on the phone fast. A broker who knows tech and IT knows your business, knows your policy, and stays with you until it’s sorted.
Already insured? Good. The question is whether your cover was set up by someone who knows how your business really works. Send us your standard client contract and we’ll check it against your cover, with a clear written outcome you can act on. Or just have a chat with Tim or Andrew.
Frequently Asked Questions
What's the difference between cyber insurance and professional indemnity insurance for IT businesses?
Cyber insurance covers incidents involving your own systems and data, such as a data breach or ransomware attack, and can include response costs and liability to others. Professional indemnity insurance responds when a client claims your advice or services caused them a financial loss. For IT businesses, one incident can trigger both policies. Wordings vary, so check yours with your broker.
How much does cyber insurance cost for an IT business?
The cost of cyber insurance for an IT business depends on the business itself. Insurers look at revenue, the services you provide, the clients and data you handle, your security controls and your claims history. A SherpaTech broker builds a submission that shows insurers how your business works, which helps you get terms that fit.
What do insurers look at before offering cyber insurance to a tech business?
Insurers want to see how well a tech business protects its own systems and its clients' systems. Expect questions on multi-factor authentication, backups, patching, access controls and whether you have an incident response plan. They'll also ask about the services you deliver and any past incidents. Clear, accurate answers shape the terms you're offered.
How much cyber cover does a tech business need?
The right amount of cyber cover depends on what your business could be responsible for after an incident. Start with your client contracts, the size of your clients, the data you hold and how long you could operate with systems down. Your SherpaTech broker can map those exposures and recommend limits that match them.
Can I get cyber insurance after an incident has happened?
You can usually still get cyber insurance after an incident. A new policy is unlikely to cover an incident you already know about. Insurers will ask about past incidents and what you've changed since, so be upfront. Showing the steps you've taken to strengthen your systems helps your application.
What should I tell my broker when my business changes?
Tell your broker about any change that affects your risk. That includes a new service line, a large new client, an acquisition, new locations or a jump in revenue. Changes like these can affect whether your cover still fits. At SherpaTech, managing those changes is part of the job, and a quick call keeps your program up to date.
How often should a tech business review its insurance?
Review your insurance at least once a year at renewal, and any time your business changes. Tech and IT businesses grow and shift quickly, so cover set up two years ago may no longer match your contracts, clients or services. A regular review with your broker keeps the gaps small.
Does my business need an incident response plan?
Yes. An incident response plan tells your team who to call, what to do and where to find key details when systems are down. Include your insurer's incident number, your broker's details and your key client contacts, and keep a copy offline. Insurers often ask whether you have one.
Who is SherpaTech?
SherpaTech is an Australian insurance broker that works only with tech and IT businesses, including managed service providers, systems integrators, managed security providers, data centres and technology vendors. That specialist focus means SherpaTech understands how tech businesses run, how their client contracts work and where their risks sit.