6. Alliance Partners

AU/NZ: PI insurance is not cyber insurance
👓 1 minute read
Our recent report on the cyberattack that brought a South Australian member’s business to a standstill should serve as a warning to every principal: Professional Indemnity insurance is not adequate protection against a serious cyber breach.
PI insurance is primarily designed to respond to claims arising from professional advice, errors or omissions. It should not be relied upon to cover the broader consequences of a cyberattack, which can include forensic investigation, system restoration, specialist legal advice, notification obligations, business interruption, data recovery and extortion-related costs.
In the South Australian incident, the office was unable to operate normally for approximately three weeks and an initial remediation cost quote exceeded $200,000. That is the scale of exposure principals need to consider - not simply the cost of replacing a computer or restoring a backup.
Every office holds valuable personal, financial and property-related information. Even businesses with strong security controls remain vulnerable to phishing, credential theft, ransomware and attacks on third-party suppliers.
Principals should review their insurance arrangements now and confirm that they hold dedicated Cyber Insurance, rather than assuming their PI policy will respond.
First National’s Alliance Partner Marsh can assist members with assessing their exposure and arranging appropriate cyber cover. The cost of protection is modest compared with the financial and operational consequences of discovering - after an attack - that your existing insurance does not cover the loss.
NZ: Turn to GSI Insurance for your cyber cover
👓 30 second read
New Zealand based members should contact Alliance Partner, GSI Insurance for your cyber insurance needs.
Download more information using the button below.
AU: People don’t rally behind rules, they rally behind reasons
👓 1 minute read
When it comes to AML/CTF training, it's easy to focus on what the legislation requires. But according to Alliance Partner FirstAML, the agencies that build lasting compliance are those that help staff understand why the rules exist in the first place. Without that context, training risks becoming little more than an annual box-ticking exercise that's quickly forgotten.
FirstAML’s recent article argues that effective training should be built around three principles: structure, variety and relevance. Rather than trying to cover every obligation in a single session, firms should deliver training at the right time—during induction, before new obligations commence and through regular refreshers—and tailor it to each person's role and responsibilities.
Real-world examples also matter. Case studies, practical scenarios and discussions about how money laundering affects communities are far more engaging than simply reading legislation. Different people learn in different ways, so a combination of webinars, online modules, videos and interactive sessions is more likely to keep staff engaged and improve knowledge retention.
The central message is one worth remembering as Australia's Tranche 2 reforms take effect. The legislation tells organisations what they must do. Good training explains why it matters. When staff understand the purpose behind customer due diligence, suspicious matter reporting and other AML obligations, they're far more likely to recognise risks and apply the rules confidently in their day-to-day work.



