
Episode 53 - Ambassador Focus - Resilience
In episode 53 of CyberVersed, Mandy Haeburn-Little is joined by Tom Egglestone, Head of Claims, International at Resilience. After a short introduction to Resilience from Tom, Mandy and he go on to discuss a range of topics around cyber insurance, the trends the company has witnessed across their client base recently, and some of the issues and challenges Tom predicts companies will face now and in the future. Tom begins by noting that cybercrime trends often align with geopolitics, citing a shift in the nature of cybercrime evident around the start of the war in Ukraine. The conversation then explores insurance cover and how cyber insurance differs from traditional insurance, given its relative newness and the need for the cover to reflect current cybercrime trends. Tom explains the challenges of determining what type of cover you need, but he does offer SMEs guidance on the baseline cover they must consider. Mandy then quizzes Tom on what surprises him about the nature of the claims, to which Tom comments on how quickly trends change and how quickly cybercriminals can act to exploit vulnerabilities. He also talks about the rapid rise in Infostealers that collect information and steal Session Tokens, and how these are being used to help cybercriminals gain entry to systems. Mandy asks Tom whether some of the recent high-profile attacks have influenced insurance uptake, especially among the SME community; Tom believes it has an impact, but he also highlights the low uptake of cyber insurance among smaller companies, and suggests that the cyber insurance industry needs to do more to promote the value of cyber insurance to the SME community. However, he acknowledges that many SMEs still believe it won't happen to them because they mistakenly think cybercriminals focus on large organisations. The conversation then moves to the business lifecycle and whether there are different stages when a business might be more vulnerable. Tom offers some interesting thoughts on this and explains the different types of vulnerabilities a business might encounter as it grows from a micro business to a small business. He also offers valuable advice on the basics and on how following NCSC's guidance can significantly improve an SME's cyber resilience. Tom also discusses reporting and the need to encourage more of it. He shares his thoughts on why the reporting rate is low and on some of the challenges faced by victims of cybercrime. He cites 'Ransomware: Victim Insights on Harms to Individuals, Organisations and Society', a paper by the Royal United Services Institute (RUSI). Tom recommends the paper for valuable insights into the psychological and long-lasting impact of ransomware attacks. Tom also talks about AI attacks and how cybercriminals are currently using AI, especially to make phishing attacks much harder to detect. However, he counters this by once again highlighting why having the basics in place makes a significant difference to your cyber resilience. The conversation rounds off by exploring the supply chain, what SMEs need to do to understand the vulnerabilities in their supply chain, and assessing the impact an attack on a supplier's system would have on their own business.










