Marsh Africa shares real lessons from a cyber breach

post-title

During a session titled 'From risk to reality: Lessons learnt from an actual cyber liability insurance claim', Marsh Africa’s Teri Solomon and Chris Shorter shared real-world insights on managing cybersecurity in a borderless environment.

Cyber risk remains one of the most significant threats facing South African and global businesses. According to Marsh, data risks and ransomware continue to dominate, followed by phishing and social engineering, supply chain attacks, zero day exploits and cloud misconfigurations.

“Although some industries are at more risk than others, no one is immune to a cyber breach. If you’re faced with a breach, the first priority should always be to protect the people and then the data,” said Marsh Africa’s head of claims advocacy, Teri Solomon.

Chris Shorter, senior client executive for cyber risk and commercial crime, added that threat actors are increasingly making physical threats to senior management and their families, as they often have personal information such as home addresses and cellphone numbers. “We recommend not engaging with this type of threat actor and rather contacting an insurance broker like Marsh or your ransomware negotiator,” he said. In response to these developments, Marsh has evolved its policy considerations to include physical security coverage.

Teri emphasised that when it comes to cyber risk, preparation is vital. “An insurance policy is not the ultimate protection or a panacea. Preparedness is essential and time is of the essence. Organisations that are prepared, practiced and coordinated fare far better in managing cyber incidents,” she said.

Teri and Chris presented a practical case study involving a global manufacturing client that experienced a sophisticated ransomware attack. The company responded within the first hour by following this plan:

  • The CIO and CISO shut down the network immediately.
  • Marsh and the insurer’s emergency hotline were notified.
  • The incident response vendors were deployed within four hours.

These early actions and accurate notifications helped protect coverage and ensured the insurer could not repudiate the claim on technical grounds.

Key players in a cyber claim

Teri’s first recommendation for CIOs and CISOs is to ensure they have a robust, cross functional incident response plan that aligns with the business continuity plan and can be accessed easily in an emergency. She advises printing the plan to ensure it is available when systems are down.

“The incident response plan should include clear roles and responsibilities, including who the executive sponsor is, defined communication protocols, notification procedures for internal and external teams and steps for containment and evidence preservation,” she explained.

Once all relevant parties have been notified and the hotline has been triggered, IT leaders should mobilise a breach coach from legal, forensic IT experts, ransomware negotiators, public relations and crisis communications teams and brokers. “Over and above the professionals that are required during a cyber breach, it’s essential for CIOs and CISOs to stay calm and maintain a collaborative spirit under pressure. Cyber incidents are chaotic, stressful and emotional, and empathy and cooperation are critical to quickly achieving a good outcome,” said Teri.

Teri and Chris urged IT leaders not to underestimate the business interruption losses that result from cyber breaches and to ensure detailed evidence and documentation are kept to accelerate claim resolution. Teri also advised organisations to review their cyber insurance policies annually to confirm that their networks still comply with the conditions, exclusions and obligations of the contract.

In cyber risk, preparedness, clarity and calm collaboration can turn a potential catastrophe into a recoverable incident.

Related articles

CIOs, your attackers may already be inside

CIOs still approach cybersecurity as if attackers are trying to “break in”. That thinking is outdated. Modern cybercriminals are not smashing through firewalls wearing hoodies in dark rooms. They are logging in through the front door using stolen credentials, hijacked Microsoft 365 accounts and employees who unknowingly hand over access every single day.

CTIO Hans Zachar puts people first

Hans Zachar, 2025 CIO Awards Cybersecurity award-winner, built Nutun’s international technology platform with the same quiet discipline that shaped his life growing up in Edenvale. For the group chief technology and information officer, global scale, trust and innovation have always been about people first – and systems second.

CIOs discuss AI, automation and the fight to protect our data

As AI and automation continue to proliferate in workplaces, there is growing tension in boardrooms across South Africa as cyber threats become an increasingly pressing issue for CIOs. IT leaders unpack how they are building cyber resilience while enabling innovation in their organisations.

Top