Showing posts with label cyber insurance. Show all posts
Showing posts with label cyber insurance. Show all posts

Thursday, 18 August 2016

Stormy weather for healthcare providers (and others) not protecting personal data - $5.55 million fine

The recent fine of $5.55 million dollars levied on Advocate Health Care Networks (AHCN) starts to sketch out liability levels for failing to protect sensitive personal information. This will be of great interest to insurance companies looking to calculate risk premiums and to IT providers looking to limit liability.

AHCN is the largest health care provider in the Chicago area and between July and November 2013 they suffered 3 data breaches. 4 million records went missing but there has been no indication that these records have been used or published. So no loss to date for the victims.

2 of the 3 breaches were straighforward theft of hardware (4 desktops / 1 laptop) rather than the more exotic type of cyber attack.

The areas of failure were identified as follows;

failure to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to all of its ePHI;

failure to implement policies and procedures and facility access controls to limit physical access to the electronic information systems housed within a large data support center;

failure to obtain satisfactory assurances in the form of a written business associate contract that its business associate would appropriately safeguard all ePHI in its possession; and

failure to reasonably safeguard an unencrypted laptop when left in an unlocked vehicle overnight.

No doubt AHCN will have attempted to present itself as the victim of crime, which it was, but was fined nevertheless even though the data does not appear to have been misused.

How many handlers of personal data would currently pass the tests above ?

Tuesday, 9 August 2016

Cyber safety: separating the wheat from the chaff

It is predicted that the internet of things will see 20 billion devices connected to the internet by 2020. The pace of change is enough to make your eyes bleed and inevitably there will be some major cyber security issues along the way.

Even the insurance community who are generally comfortable with risk are mainly keeping their powder dry - most policies available (AIG, Hiscox, Zurich) are bespoke and assume high levels of pre-existing cyber safety.

Court cases such as Travelers Casualty and Surety co. vs Ignition Studios Inc do not help to identify where liability falls as it was settled out of court.

From an SME perspective it is very tough to penetrate the complex language around cyber safety and absent user friendly insurance policies the market looks likely remain in its early stages. Until a few court cases have shown where liability falls between principals and third party providers and what level of cyber safety is a minimum standard before negligence kicks in sorting the wheat from the chaff will be a tough challenge.

Friday, 19 February 2016

Cyber attacks; Who carries the liability ?

It is clear that the volume of cyber / hacking attacks is rapidly increasing whether very low tech (but effective) phishing scams or much more advanced activity.

What is less clear is who is picking up the tab when things go wrong. Given that most companies tend to outsource hosting and webdesign and frequently work with freelance IT contractors liability may be limited at the contractual level. There is also a strong incentive for existing technical providers to insist all is well to avoid clients digging too deep and realizing that they are carrying all the liability.

Insurance has a part to play here but the insurance industry seems to be struggling to determine risk premiums and the policies available are awash with exclusions.

It was widely reported that TalkTalk suffered substantial loss from being hacked but not made clear whether this was an insured risk.

If private data is held on a third party shared server and that data is stolen partly through the failure of the hosting company to implement reasonable levels of security who pays ?

Arguably none of this has really mattered in hard financial terms because losses have been difficult to quantify. This is set to change if the legislation which can fine companies up to 4% of turnover comes into force in 2017.

One way or another the  issue will be clarified and whether the liability rests with the client or IT / hosting contractors. With the average cost to an SME of a cyber attack being @£190,000 the cost is material.

Wednesday, 17 February 2016

CERT-UK shines a light on internet safety in 2015/16

CERT-UK the excellent UK government sponsored cyber resilience entity  has released its overview of cyber risk in 2015.

It pulls together data from a range of sources and listed below are some key extracts;

1. The 2015 Information Security Breaches survey found that 74% of small businesses suffered a breach 38% of which was from an external attacker. So the disgruntled employee / freelancer is alive, kicking and armed with a USB stick. The average cost of breach was between £75,000 and £311,000.

2. The cyber insurance market is set for rapid expansion from £1.7 billion to £5 billion in 5 years. There is a caveat here that as the risk level is poorly understood there is some doubt in respect of whether cyber policies will prove effective until the market is more mature.

3. Top malware types (most common first were)

conficker
zeroaccess
ramnit
xcodeghost
sality
gameover zeus
neverquest
bamital
tinba
bedep

Conficker was the clear winner and represents a very serious threat for anyone still running XP or other unsupported software.

4. DDoS as a service is one to watch in 2016 potentially in combination with Ransomware.