Showing posts with label cyber safety. Show all posts
Showing posts with label cyber safety. Show all posts

Tuesday, 16 August 2016

Sage hacked : insider threat and third party liability

Recent news that Sage (the accounting software provider) has been hacked and that staff details of around 300 UK businesses have been accessed (names, addresses, bank details etc) should alarm many SME's who rely on third party technology providers without question.

According to reports internal login details were used so this was less of a high tech hack and more of a walking in through an unlocked door - a disgruntled insider probably.

The Information Commissioners Office are having a look at this and this breach is potentially more serious than TalkTalk as the type of data access looks to be more valuable and personal. But when the fire has been put out who will pick up the tab and compensate the individuals whose data has been taken ?

Sage will no doubt be going through the terms and conditions of standard contracts to determine if they can wriggle out of any liability to their impacted customers. In any event what direct loss does a customer suffer if name, address, bank details etc are published on the open internet ? If a customer is later the victim of internet fraud will it be possible to create a causal link between the breach and the loss ?

Might Sage be insured for cyber breach ? If so does this cover insider threat which might well be viewed as negligent ? Will the insurance extend to pay customers of Sage compensation ?

Given the above complexity it is understandable that Sage should seek to keep as low a profile as possible on this matter but if you are using a Sage solution right now how secure do you feel ?

Anybody can be hacked but the question of who picks up the tab when it happens is far from settled.

Tuesday, 9 August 2016

Cyber safety: separating the wheat from the chaff

It is predicted that the internet of things will see 20 billion devices connected to the internet by 2020. The pace of change is enough to make your eyes bleed and inevitably there will be some major cyber security issues along the way.

Even the insurance community who are generally comfortable with risk are mainly keeping their powder dry - most policies available (AIG, Hiscox, Zurich) are bespoke and assume high levels of pre-existing cyber safety.

Court cases such as Travelers Casualty and Surety co. vs Ignition Studios Inc do not help to identify where liability falls as it was settled out of court.

From an SME perspective it is very tough to penetrate the complex language around cyber safety and absent user friendly insurance policies the market looks likely remain in its early stages. Until a few court cases have shown where liability falls between principals and third party providers and what level of cyber safety is a minimum standard before negligence kicks in sorting the wheat from the chaff will be a tough challenge.