Showing posts with label Cyber Insurance. Show all posts
Showing posts with label Cyber Insurance. Show all posts

Wednesday, 11 April 2018

Cyber Risk & Data Breach Insurance

Cyber Risk, Data Breach, Cyber Insurance

CYBER RISK INSURANCE GUIDE


With data breaches occurring on a weekly basis, cyber security has consistently ranked among the top risk concerns for executives over the past few years. And cyber criminals are only becoming more sophisticated with intrusions becoming more frequent. While there is no substitute for a strong cyber framework and security controls, cyber liability insurance often serves as an organizations last line of defense when all else fails. However cyber policies are often misunderstood.

WHAT IS CYBER INSURANCE?


Simply put, cyber risk insurance (also known as data breach insurance) provides protection for cyber risk and cyber related events. Data breaches and theft of personal information are simply one segment of cyber risk, there are many. Cyber policies provide 2 main coverage components. The first component is first party coverage, which is essentially balance sheet protection – the organization suffers financial damage such as lost income, an extortion demand, required notification costs (or credit monitoring costs), or network/data restoration costs, and the insurer reimburses the company for the damages sustained. The second coverage component is third party coverage, which provides defense costs (attorney’s fees), damages, and settlements for claims and lawsuits that result from errors and security failures (among other incidents). These damages can result from employee or privacy violations, transmission of a virus to another party or in the form of a regulatory action, to name a few. Cyber policies can either be purchased as a basic endorsement added onto a general liability policy, providing limited coverage, or they can be purchased as a stand-alone policy which provides significantly broader coverage. When purchasing a stand-alone policy, companies can select their coverages of interest in order to match their risk profile. Available insuring agreements include.

◈ NETWORK SECURITY & PRIVACY LIABILITY: This agreement provides coverage for defense costs, damages, and expenses arising from theft or improper disclosure of confidential information in your care, custody or control (or in the custody of a cloud provider). Contrary to what many companies think, that data is not limited to credit cards and social security numbers, it also includes employee information (such as tax forms), health information, and corporate confidential information such as intellectual property and financial data. The data also also does not always have to be in digital form and stolen by hackers, a privacy incident may arise from paper records being improperly disposed of. In fact, human error accounts for a large percentage of privacy incidents. Lastly, coverage can also be included for failing to disclose a breach and claims related to improper privacy policies or data collection practices.

◈ MEDIA LIABILITY: A form of coverage for advertising and publishing injury, this insurance provides defense costs and damages for claims asserting copyright infringement and negligent publication of media (among others) while publishing content online and via social media channels.

◈ ERRORS AND OMISSIONS (E&O): While not included in all cyber policies, some carriers include an E&O insurance component which provides coverage for financial damages sustained by third parties (such as clients and customers) when your services fail. Examples might include software and service failures or poor advice by IT consultants. It is however important to note that E&O coverage differs greatly. Well structured E&O policies should extend coverage to include claims resulting from breach of warranty, breach of contract and/or claims asserting failure to deliver.

◈ REGULATORY DEFENSE AND PENALTIES: This insuring agreement provides attorney’s fees and costs associated with formal regulatory or administrative investigations. It also provides coverage for any resulting fines or penalties. With regulators such as the FTC, SEC and OCR increasing cyber enforcement, regulatory defense coverage is increasingly important. Enforcement actions can result from any of the below.

Cyber Risk, Data Breach, Cyber Insurance

◈ Security failures such as failure to protect data (including employee information)
◈ Improper data collection practices
◈ Failure to disclose a breach
◈ Deceptive privacy practices

◈ EXTORTION / RANSOMWARE: Provides coverage for associated costs, lost income and extortion demands resulting from ransomware attacks that might hold a website, data or software “hostage”.

◈ DATA BREACH RESPONSE COSTS: The costs incurred with responding to a data breach can be significant. Some figures estimate between $100 and $200 per infected record. Data breach response coverage provides coverage for the costs of any required forensic investigation, identity restoration costs, notification costs and credit monitoring costs.

◈ CRISIS MANAGEMENT EXPENSES: Data breaches can inflict significant damage to a company’s reputation. Restoring consumer confidence can be difficult. As a form of reputation insurance, this agreement provides coverage for the organization to hire a PR firm in order to help rebuild the organization’s brand and reputation. It should be noted that lost income resulting from brand damage is however, never covered.

◈ BUSINESS INTERRUPTION & DATA RESTORATION: Data breaches, DDOS attacks, ransom attacks and system failures can often result in lost profits, especially if sustained for a prolonged period. These attacks can also result in the theft or corruption of critical data and network damage which may need to be restored. This insurance agreement provides coverage for the resulting lost income and costs to restore data and networks. Some insurers limit this coverage only to security incidents, while others will also provide coverage for lost income resulting from a system outage. Some will limit coverage only to attacks directly affecting your networks, while others will extend coverage to incidents that might affect a cloud provider or business service provider.

WHAT TYPE OF CLAIMS ARE COVERED BY CYBER LIABILITY INSURANCE?


◈ Extortion and Ransomware attacks resulting in lost income, extortion demands and data and restoration costs
◈ Virus infections of computer systems that destroy or corrupt data and networks requiring restoration.
◈ DDOS attacks resulting in lost income and financial damages to clients that might not be able to access data or utilize services.
◈ Data breaches and/or clerical errors (such as loss of a laptop with protected data) resulting in notification costs, credit monitoring, identity restoration costs, potential regulatory investigation and penalties, and potential consumer or shareholder class action.
◈ Improper privacy policies and/or data collection practices resulting in regulatory investigation and penalties and potential consumer or shareholder class action.
◈ Transmission of a virus or malware to a client or vendor resulting in defense costs and damages sustained by the injured party.


HOW DO CYBER POLICIES DIFFER?


Network insurance contains too many variables to outline here. Some provide only third party coverage, where others include full first party coverage. Some contain numerous exclusions where others are more liberal. Exclusions also do not have be explicitly scheduled, often exclusionary language is contained deep within the definitions and conditions of the policy. Below are just a few examples of some of the coverage variables:

◈ PAPER FILES: All policies provide coverage for digitally stored data, however many companies also may utilize paper files as well, such as applications, tax forms, employee records, health records, etc. Some policies contain exclusions for losses arising from the theft or disclosure of paper records.

◈ ENCRYPTION: While data encryption is a wise recommendation, some companies may choose not to encrypt, or occasionally transmit or store data that is unencrypted. Some policies contain an encryption requirement, precluding coverage for any claims that arise from breaches that affect unencrypted data.

◈ SECURITY STANDARDS: Some cyber risk insurance policies contain a condition precedent to coverage, requiring that the organization employ a certain level of security measures. Failure to do so can nullify coverage.

◈ VIRUSES: Viruses can wreak havoc on a network resulting in lost income and significant restoration costs. Some coverage contains a specific exclusion for damage caused by viruses and/or any “self-propagating code”

◈ BODILY INJURY AND PROPERTY DAMAGES: Many cyber policies contain broad exclusions for any intrusions that result in bodily injury or property damage. These exclusions can be particularly problematic for the healthcare, technology and manufacturing sectors. If your company has any such exposure it is important to seek coverage with a carrier that provides coverage for any contingent BI/PD claims.

◈ VENDORS & OFFSITE COMPUTERS: Most companies rely on third party software in one form or another. Whether it be a cloud provider, SAAS software or compliance program. Security incidents that affect your business service provider or off site computer systems can result in claims against your company. Ranging from lost profits to privacy violations. It can also result in lost business income. Some carriers include within their definitions, coverage for breaches that affect service providers and offsite computer systems while others intentionally preclude such language.

◈ DATA: The definition of data is an important consideration. Especially for organizations that work more with corporate information. Some policies take an extremely narrow stance on defining data, simply as, drivers license information, dates of birth and social security information. Others contain more liberal definitions which include health information and corporate confidential information. Purchasing a policy with a narrow definition can significantly compromise coverage.

◈ FAILURE TO DISCLOSE A BREACH: Your employee lost a laptop with thousands of records on it, do you report it? With all of the breach notification laws differing state by state, and cross border laws posing an even greater challenge, knowing when a breach must be disclosed can be difficult. However, failing to do so can result in additional damages and regulatory enforcement. Some policies provide coverage for such claims, others do not.

◈ UNAUTHORIZED COLLECTION OF DATA: Most companies collect some degree of consumer data. But ensuring that your privacy policies and opt-in and opt-out practices are all accurate and transparent can be difficult. When data is collected improperly, claims can be close behind. Most policies contain some sort of exclusion for claims arising out of data collection practices, however a few insurers contain no such exclusion. Even when coverage is included terms can vary.

WHAT OTHER COVERAGE DO I NEED?


◈ D&O INSURANCE: When cyber breaches result in consumer or shareholder class actions, a properly structured directors and officers insurance policy may be the best protection. Depending on the claims asserted, policy language, and specifics of the loss, a D&O policy may or may not extend coverage, however due to the wide range of coverage provided by D&O policies, it is generally a wise placement nonetheless.
◈ CRIME & SOCIAL ENGINEERING INSURANCE: An often overlooked component of a strong cyber program is crime coverage. Crime insurance (with a properly structured social engineering endorsement) is particularly critical for protection against social engineering attacks and funds transfer fraud which are increasing in frequency and severity.

RECENT TRENDS INCREASING CYBER RISK


◈ With larger organizations investing more resources into their cyber security frameworks, and smaller organizations lacking proper security, cyber attacks are trickling down to mid -sized and smaller companies with greater frequency.
◈ Ransom demands have historically been on the lower side, however these demands are expected to increase which will result in greater damages for companies affected by extortion attacks.
◈ In addition to attacks becoming more sophisticated, malware is becoming smarter and the underground cyber crime marketplace (dark-web) is growing with more available code and a greater number of users, which will result in an increase in data breaches.
◈ Regulatory agencies such as the SEC and FTC are increasing their oversight of cyber security, bringing a greater number of enforcement actions against companies that: fail to prevent against a breach, fail to disclose a breach, or improperly collect consumer information. They have also voiced interest in pursuing actions against smaller companies.

WHO NEEDS CYBER LIABILITY INSURANCE?


◈ Public companies including micro cap and nano cap companies and those trading OTC.
◈ Professional firms of all sizes - particularly professionals that work with public companies, including consultants, accountants and lawyers
◈ Companies subject to regulatory oversight such as financial institutions and government contractors
◈ Smaller & mid-sized businesses. It is estimated that 60-80% of breaches affected smaller the SME sector. In 2015 alone there were 781 breaches as reported by ITRC.
◈ Higher risk industries such retailers, financial firms, healthcare, technology companies, educational institutions, hotels and hospitality companies, manufacturers and professional service firms.

Saturday, 17 March 2018

The Basics of Cyber Insurance

Cyber Insurance, EC-Council Tutorials and Materials, EC-Council Certifications
I talk a lot about cyber insurance policies on this blog. While many readers will be familiar with those policies, some may not be. While most of you know that cyber policies cover data breaches, you may find yourself wishing you had a deeper understanding of the coverage and how the policies work.  To help with that I’m starting a series of periodic posts that will explore the essentials of cyber coverage.

Let me start by saying that cyber policies are weird.  They aren’t like general and professional liability policies that provide liability coverage, nor are they like property and crime policies that provide first party coverage.  Cyber policies are all over the map.  They cover unusual types of losses too.  All of that can make them hard to understand.

A Very Short History of Cyber Insurance


When trying to understand cyber insurance it is useful to look at its roots.

Cyber insurance developed in the 1990s in conjunction with the rise of “dot.com” businesses. The policies covered lawsuits arising from breaches of the insured’s computer system security. Early policies sometimes also covered business interruption loss resulting from a compromise of computer system security.

Ironically, few companies in the US today would point to those coverages as the reasons they buy cyber insurance. Most US buyers are focused on data privacy risk.

The focus on data privacy risk can be traced to California’s enactment in 2003 of the first law requiring companies to notify affected individuals when their private information has been breached. Many states subsequently followed California’s lead, and today 47 US states, and in some cases the federal government, require individuals to be notified. The costs inherent in providing notice drove insurers to offer privacy liability and breach response coverage. That led to increased interest in cyber insurance.

There are very few mandatory notification laws outside the US. Interest in cyber insurance nevertheless has grown globally. This is being driven by concerns about cyber attacks and increasingly by regulatory regimes that encourage voluntary notification of individuals affected by a data breach.

Cyber threats have continued to multiply and become more serious. Cyber policies have evolved to cover those threats. While cyber policies are very far from being standardized, there are coverages that appear in the vast majority of policy forms.

What Does A Cyber Policy Cover?


A basic “plain vanilla” cyber policy today will cover claims resulting from data privacy and data security risks. Those aren’t the same thing.

Data privacy claims concern the improper disclosure or exposure of private information.  This includes personal information, credit card information, health information, and confidential business information.  Those claims are generally brought by individuals and companies whose information has been compromised, by regulators, and sometimes by law enforcement entities.

Data security claims involve loss arising from a compromise of the insured’s computer systems. This most often is the result of things like hacking into the insured’s systems, introduction of malware (programs designed to obtain unauthorized access to data or to damage data or computer systems), and denial of service attacks.

Typical Insuring Agreements


Although cyber policies can have a dozen or more different insuring agreements, as the graphic below illustrates, there are four that appear in most basic policy forms.

There are three liability coverages: (1) liability to third parties for privacy breaches, (2) liability to regulators for privacy breaches, and (3) liability to third parties for computer system security breaches.

The fourth coverage is a first party coverage that covers the insured’s costs to investigate and respond to a breach event. These include things like forensic investigation costs, costs to notify affected individuals, and costs to provide credit monitoring

Cyber Insurance, EC-Council Tutorials and Materials, EC-Council Certifications

These coverages typically are provided in separate insuring agreements that may each provide a different amount of insurance. For example, a policy that provides $10 million of coverage for privacy liability claims may have a much smaller amount available, known as a sublimit, for privacy regulatory claims.

“A sublimit is not necessarily a good reflection of the amount of coverage a company needs.”

Sublimits under cyber policies need to be very carefully considered. Insurers include sublimits to help them manage their overall exposure and to attractively price policies. A sublimit is not necessarily a good reflection of the amount of coverage a company needs. While lower limits for some coverages might make sense for some companies, I’ve seen a number of claims over the years where companies ended up wishing their sublimits were higher.

I’ll talk about each of these coverages in more detail in later posts in this series.

Coverage Trigger


Like D&O and other professional liability policies, cyber policies are written on a claims made and reported basis. The events that trigger coverage must take place and be reported to the cyber insurer during the same one year period that the policy is in effect. That requires a company to thoroughly understand what events the policy requires to be reported. Companies also must be extremely vigilant and diligent about reporting those events.

Compliance with a policy’s reporting requirements is extremely important to cyber insurers because of the speed at which cyber events can move, and the potential for impactful decisions to be made early in the company’s response to an event. Insurers want to be, and often have the right to be, involved at the earliest possible moment.

Claim Control


Cyber policies differ on the extent to which the insurer will control the response to a breach event or the defense of covered lawsuits. Some policies give the insurer the absolute right to control every aspect of the company’s response to a cyber event. The insurer will retain all necessary vendors, and will appoint defense counsel in the event lawsuits materialize. This is a feature appreciated by many companies that are unfamiliar with cyber event response. Other policies provide much more latitude for companies to select vendors and counsel they are comfortable with and to exercise greater control over the response to the cyber event. These policies appeal to companies that have spent time preparing for a cyber event and that have developed relationships with law firms and vendors that they prefer to use.

Like professional liability policies, defense costs paid under cyber policies reduce the available policy limit and sublimit. There is some divergence in insurers’ approaches to payment of first party breach response costs though. While the majority of policies treat them like defense costs that are paid from the policy limit, some insurers will pay breach response costs outside the policy limit, generally for a specified number of affected individuals.

Thursday, 15 March 2018

Cyber Insurance Basics: System Security Liability Coverage

Cyber Security, Cyber Security, EC-Council Tutorials and Materials

It’s time for another post in my series about the basics of cyber policies. This time I’m going to look at system security liability coverage.

As the graphic below illustrates, security liability coverage is one of the four basic coverages available in typical cyber policies.

Cyber Security, Cyber Security, EC-Council Tutorials and Materials

System security liability coverage exists to respond to the insured’s liability to third parties resulting from cyber attacks on the insured’s computer system or the computer system of a third party operated on behalf of the insured.

So what kind of cyber attacks are covered? Generally speaking, good policies cover loss resulting from:

◈ A third party’s unauthorized access or use of the computer system;
◈ Malware, spyware, viruses, etc. in the computer system (e.g. the NotPetya attack);
◈ A denial of service attack;
◈ The computer system being used to attack computer systems of oth◈ers.

Cyber attacks such as these can give rise to a variety of claims. A few examples:

◈ A company that hosts e-commerce web sites suffers a denial of service attack. Its customers’ web sites become inaccessible and the customers lose money and sue the insured.

◈ On online gaming service is attacked and taken down. Subscribers bring a class action because the system is inaccessible.

◈ A franchisor provides IT infrastructure for its franchisees. A cyber attack impacts the franchisees and causes them to lose business. The franchisees sue.

◈ Malware causes destruction of customer data. Customers sue.

◈ An insured’s computer system is hacked and used to infect a third party’s system with malware. The third party brings suit.

A cyber attack may result in a breach of private data, but such a breach is not necessary to trigger system security liability coverage.

It is important to understand what system security liability coverage won’t do.

System security liability coverage won’t cover the insured for its own losses. If an attack results in a theft of money or other property from the insured the coverage will not respond. Companies typically need to look to their crime policies to cover that loss.

System security liability coverage won’t cover the insured’s cost to recreate lost or corrupted data. While the coverage will respond to losses sustained by a third party if data is lost, it will not cover the insured for amounts spent to recover data. That loss can be covered under another type of cyber coverage that I’ll talk about in a later post.

Finally, system security liability coverage will not cover the insured’s cost to investigate and remediate the cyber attack. A good cyber policy should cover that loss under a breach event cost insuring clause if purchased.