Counting Employees under the Affordable Care Act’s Pay-or-Play Provisions

Employers subject to the Affordable Care Act’s Employer Shared Responsibility provisions may be assessed a penalty if they do not offer affordable health coverage that provides a minimum level of coverage to their full-time employees and their dependents. Whether an employer is subject to these pay-or-play provisions depends on the number of people it employs. When counting employees, however, there are specific rules that must be followed.

An employer is generally considered an “Applicable Large Employer” subject to the pay-or-play provisions if it employed an average of at least 50 full-time employees, including full-time equivalent employees (FTEs), on business days during the preceding calendar year. To determine whether an employer is considered an Applicable Large Employer for a calendar year:

  • Add the total number of full-time employees for each calendar month in the preceding calendar year, and the total number of Full Time Equivalent employees for each calendar month in the preceding calendar year.
  • Divide the sum by 12.
  • If the result is not a whole number, round it down to the next lowest whole number

If the result of this calculation is less than 50, the employer is not considered an Applicable Large Employer for the current calendar year. If the result is 50 or more, the employer is an Applicable Large Employer for the current calendar year.

[Note that transition relief was provided to qualifying employers with an average of 50-99 full-time and full-time equivalent employees on business days during 2014, so that they will not be assessed a penalty in 2015.]

The first step to counting employees is identifying full-time and full-time equivalent employees. A full-time employee, with respect to a calendar month, is an employee who works an average of at least 30 hours per week, or 130 hours in a calendar month. A full-time equivalent employee isn’t an actual person. Rather, it’s a term used to describe the combination of all non-full-time employees who are counted as the equivalent of a full-time employee.

The number of FTEs for each calendar month in the preceding calendar year is determined by calculating the aggregate number of hours of service for that calendar month for non-full-time employees (but not more than 120 hours of service for any employee) and dividing that number by 120. Fractions may be rounded to the nearest one hundredth.

For example, assume that during each calendar month of 2015, Employer W has 25 employees averaging 35 hours of service per week and 40 employees each of whom averages 90 hours of service per calendar month. Each of the 25 employees averaging 35 hours of service per week count as one full-time employee, so Employer W has 25 full-time employees for each calendar month in 2015.

To determine the number of FTEs for each calendar month, combine the hours of service of the 40 non-full-time employees (40 employees x 90 hours) and divide that number by 120. This calculation (40 x 90 = 3,600, and 3,600 / 120 = 30) shows that Employer W has 30 FTEs for each calendar month in 2015. Since Employer W had 55 full-time and full-time equivalent employees during each calendar month in 2015, Employer W will be considered an Applicable Large Employer for 2016.

The regulations contain a number of specific rules, methods and exceptions that must be considered when counting employees. For example, in some cases an employer may not have to include seasonal workers when counting employees. Given the complexity of some of these rules, methods and exceptions, employers should consult with an attorney to make sure they’ve counted correctly.

At Setnor Byer Insurance & Risk, we are committed to guiding you through the changes coming in 2014. Check back with us periodically for future informational updates about the Affordable Care Act. If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

SEC Commissioner Emphasizes the Importance of Cyber Insurance

Cyber risks are a growing concern among businesses of all kinds. In a recent speech given at the New York Stock Exchange, SEC Commissioner Luis A. Aguilar emphasized that cyber security should be a number one priority of businesses and regulators alike and warned companies, and more specifically their directors, to “take seriously their obligation to make sure that companies are appropriately addressing those risks.”

The New York Stock Exchange’s Governance Services Department hosted the Cyber Risks and the Boardroom Conference where Commissioner Aguilar expounded on the responsibility of corporate directors to consider and address the risk of cyber-attacks. The commissioner made it clear that despite all efforts to prevent a cyber-attack, companies should prepare “for the inevitable cyber-attack and the resulting fallout.”

In 2014, there have been high-end data breaches of large companies, with data, personal records and financial information stolen and sold on the black market before the company has even discovered a breach occurring. In May, eBay discovered that hackers had infiltrated their system and stole personal records of 233 million users.

Domino’s Pizza was also hacked, with over 600,000 Belgian and French customers’ records affected. These hackers demanded $40,000 in ransom from the pizza chain in exchange for not selling the data, which included names, addresses, emails, and phone numbers.

Just last week, August 5, 2014, the largest data breach in history occurred when a Russian crime ring stole more than 1.2 billion Internet usernames and passwords.

While many companies are concerned about the threat of cyber-attacks, and have implemented security protocols to reduce them, it is clear to security experts that all vulnerabilities are nearly impossible to eliminate. For this reason, a growing segment of companies that collect personal data are including Data Breach and Cyber Peril insurance in their risk financing strategy. These insurance contracts are complex and vary by insurer, but are worth considering given the financial costs associated with notification expenses, litigation and harm to one’s reputation.

If you have any questions or would like to discuss your insurance options, please contact us.

If you’d like to subscribe to our weekly newsletters please click here

A Contract’s Fine Print: Find the Devil in the Details

Contracts are an essential part of doing business. Regardless of size or industry, contracts with customers, vendors, suppliers, service providers or independent contractors are an important part of a business’s operations. While good contracts can help manage risk and maintain good working relationships, bad contracts can be incredibly harmful. This is why every business must proceed cautiously when negotiating and signing contracts.

Ideally, an attorney will be consulted when negotiating or signing contracts. The reality, however, is that many businesses handle their own contracts. Though it may be easy for some to identify and understand a contract’s main provisions, like cost, volume, part numbers, etc., the devil is in the details, which, in the case of contracts, is the fine print.

Every provision in a contract has a purpose, including those found in the fine print. Despite being underemphasized, they are often important when defining a contractual relationship, particularly when things go wrong. The following provisions, for example, are not only commonly used, but commonly overlooked.

Forum (Jurisdiction) Selection: A contract may require that any lawsuits involving the contract be filed in a specific forum or jurisdiction (county, state, country). This may not be a problem if a business is located in the jurisdiction specified in the contract. However, it may be a huge problem if, for example, a Florida business is required to file a lawsuit in Alaska. Despite having the legal right to enforce the contract, the increased complexity and cost of filing a lawsuit in another jurisdiction makes it practically impossible for many businesses to do so, particularly when relatively small amounts of money are involved.

Choice of Law: Similar to a forum selection clause, a choice of law provision specifies which state’s law will be used to interpret and enforce the contract. These clauses can be significant because laws may vary from state to state. For example, one state may have more favorable consumer protection laws, while another makes it more difficult to recover damages. It is important to know if and how a choice of law provision may affect any contractual rights or remedies.

Integration (Merger) Clause: Contracts typically contain a provision stating that the contract represents the full and final agreement and supersedes any other agreements, oral or written. With an integration clause, any verbal or written conversations, brochures, promises, representations or statements that are not included in the contract are not part of the contract. This may become an issue when a business is not receiving what the salesperson promised before signing the contract. Expectations, obligations and requirements must be included in the contract to be enforceable under the contract.

Assignment: A contract may allow one or both parties to assign their rights, duties or obligations to a third party. This can create a problem if there is an expectation that a specific person or company will be performing under the contract. If, for example, a business wants only a specific vendor to do a job, the contract must state that the vendor cannot assign its obligations under the contract to someone else. Otherwise, a business may find that the person they contracted with isn’t the person they end up working with.

Evergreen Clause: Contracts are typically entered into for a specific period of time (term). A contract with an evergreen clause will automatically renew for a new term unless notice of termination is given by either party, usually within a specific period of time. For example, a one year contract will automatically renew for another year unless written notice of termination is given at least 60 days before the end of the yearly term. Businesses that fail to discover and comply with an evergreen clause may be stuck in a contract they no longer need or want.

Dispute Resolution: Contracts may require that disputes be resolved through arbitration rather than by filing a lawsuit. Depending on the nature of the contract, this requirement can significantly affect the resolution of disputes and the apportionment of damages.

Indemnification Clause: Indemnification clauses are used to allocate risk and responsibility among the parties to a contract by requiring one party to compensate the other for specific liabilities or losses arising out of the contract. Since these clauses commonly require a party to assume liability that would not otherwise exist, they must be reviewed carefully and understood completely. Indemnification clauses often end up being the most significant provision in a contract when something goes wrong.

Insurance Requirements: Many contracts include specific insurance requirements. For example, a contract may require a party to have general liability or workers’ compensation insurance, or it may require that one party be given Additional Insured status under the other party’s insurance policies. Contracts often require proof of insurance before work can begin or payment is made. It is important to identify and comply with any contractual insurance requirements.

Despite the benefits of using an attorney to negotiate and review contracts, particularly complex or high-value contracts, many businesses take a do-it-yourself approach. Nevertheless, given the increased risk of harm caused by bad contracts, businesses should never sign a contract without reading and understanding every provision, including those in fine print.

If you have any questions or would like to discuss how Setnor Byer Insurance & Risk can help identify and protect against various business risks, please contact us.

If you’d like to subscribe to our weekly newsletters please click here.

A Narrow View of Cyber Risks Can Leave You Overexposed

Recent, high-profile incidents show that every business is at risk of suffering a data security breach, regardless of size, resources or sophistication. To combat the risk, many organizations are taking steps to identify and secure organizational vulnerabilities, such as wireless networks, laptop computers, and even the office copy machine. However, a report by Zurich Insurance and the Atlantic Council suggests organizations must look beyond their own operations to truly recognize their exposure to cyber risks.

Businesses are increasingly using the internet and information technology functions to expand their operations and create opportunities. They are also increasing their exposure to external cyber risks that are often beyond their control. This is why businesses need to expand their horizon when evaluating and managing cyber risks. According to the report, businesses must consider these seven aggregations of cyber risk to fully understand their exposure.

  • Internal IT Enterprise: Risks associated with an organization’s internal IT (hardware, software, servers, processes).
  • Counterparties and Partners: Risks from dependence on or interconnection with outside organizations.
  • Outsource and Contract: Risks from contractual relationships with third-parties (IT and cloud providers, legal, accounting).
  • Supply Chain: Risks to supply chains in the IT sector and cyber risks to traditional supply chains and logistics.
  • Disruptive Technologies: Risks caused by unseen effects from, or disruptions to new technologies (smart grids, embedded medical devices, driverless cars), or existing but poorly understood technologies (internet, networks).
  • Upstream Infrastructure: Risks from disruptions to infrastructure relied on by economies and societies (electricity, telecommunications, financial systems).
  • External Shocks: Risks from incidents outside the system (international conflicts, acts of terrorism, malware pandemic).

Despite the external risks resulting from increased outsourcing and interconnectivity, businesses are urged to continue taking steps to control their internal cyber risks. According to the report, there are a relatively small number of actions that every organization can take to protect against most cyber risks, such as:

  • Implementing applicationwhite-listing to prevent systems from running programs that have not been pre-approved, such as malicious software
  • Using standard secure system configurations to keep systems simple and easier to defend.
  • Installing patch software for systems and applications within 48 hours of being released by the software manufacturers
  • Controlling administrative privileges to only those who need it and can be trusted with it

The report also recommends that businesses:

  • Expand their risk horizon to consider the seven aggregations of risk
  • Have cyber insurance, particularly for third-party risks associated with data breaches or business interruption
  • Deal with cyber risks at the board-level

Finally, the report states that resiliency is the key in a world where the number of cyber risks is increasing and the ability to control them is decreasing. To survive cyber threats and limit their impact, the report recommends that every business:

  • Incorporate redundancies in critical systems
  • Implement incident response and business continuity plans
  • Utilize scenario planning and exercises to stay prepared

As we have seen, nothing is foolproof, so businesses should use insurance to protect against cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws.

Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against cyber risks, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

Loss of Business Income Caused by Civil Authority Action

Public safety concerns may prompt civil authorities to take action to protect people and property. For example, a governor can issue a mandatory hurricane evacuation, a mayor can close roads during inclement weather, the police can enforce curfews during riots, or a fire department can restrict access to a neighborhood during a gas leak. Though these actions may be good for public safety, they may be bad for business.

In some cases, a Business Interruption policy’s Civil Authority coverage may offset income losses suffered during a civil authority action. Business Interruption, also known as Business Income, is a type of commercial insurance that protects against loss of income when a covered loss causes a business to reduce or suspend its operations. Civil Authority coverage is an additional protection that may be included in a Business Interruption policy.

A typical Civil Authority clause states: We will pay for the actual loss of Business Income you sustain and necessary Extra Expense caused by action of civil authority that prohibits access to the described premises due to direct physical loss of or damage to property, other than at the described premises, caused by or resulting from any Covered Cause of Loss.

Under this framework, the Civil Authority provision will not provide coverage unless all four of the following conditions are met.

  • The loss of business income must be caused by the civil authority action. There must be a direct relation between a civil authority action and a loss of income.
  • The civil authority action must prohibit access to the insured business. Courts have held that access must be completely prohibited in order to satisfy this requirement. A civil authority action that makes travel to an insured’s business difficult or inconvenient is not enough to trigger Civil Authority coverage.
  • The civil authority action must be caused by direct physical loss of or damage to property away from the insured’s premises. Unlike Business Interruption coverage, which requires loss or damage to the insured’s property, Civil Authority coverage requires loss or damage to property somewhere else. For example, an explosion at a nearby warehouse causes the fire department to shut down the area surrounding an insured business for two weeks.
  • It’s worth noting that claims for Civil Authority coverage often fail to meet this requirement because the decision to take civil authority action is not caused by direct property damage, but by the desire to prevent it. Courts have denied coverage for losses caused by civil authority actions that were designed to prevent future damage rather than address existing property damage, such as pre-hurricane evacuation orders and curfews imposed to prevent looting and rioting. According to one court, Civil Authority coverage is designed to address situations involving civil authority action that is taken after damage occurs.
  • The loss or damage to property away from the insured’s premises must be caused by or result from a loss that is covered under the insured’s policy. A business without hurricane insurance, for example, would not be covered if a civil authority action was caused by hurricane wind damage.

Though many aspects of Civil Authority coverage are relatively standard, there are some variations among insurers and policy forms. For example, some policies provide that coverage will not begin until 24 hours after the civil authority action was taken, and others require 72 hours. The duration of Civil Authority coverage may also be different.

Given the complexity of Civil Authority coverage under a Business Interruption policy, an experienced and reputable insurance agent should be consulted to help identify needs and evaluate options.

If you have any questions or would like to speak with one of our Risk Management Professionals, please contact us.

If you would like to subscribe to our newsletters please click here.

Florida’s New Data Breach Notice Law

Florida has a new law to combat the recent surge of data security breaches involving sensitive personal information. On July 1, 2014, Florida’s current data breach notification statute will be replaced by the Florida Information Protection Act of 2014 (Act). Though similar to Florida’s current statute, the Act makes some significant changes that businesses must incorporate into their data security practices and procedures.

Under the Act, sole proprietors, partnerships, corporations, trusts, estates, cooperatives, associations and other commercial entities that acquire, maintain, store or use personal information (Covered Entities) are required to take reasonable measures to protect and secure such personal information. The Act broadens the definition of Personal Information to include:

  • An individual’s first name or first initial and last name in combination with that individual’s social security number, driver license or identification card number, passport number, military identification number, or other similar number issued on a government document used to verify identity. (Broader)
  • Financial account, credit and debit card numbers, in combination with any security code, access code or password.
  • Information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional. (New)
  • An individual’s health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual. (New)
  • A user name or e-mail address, in combination with a password or security question and answer that would permit access to an online account. (New)

Like the current statute, Personal Information does not include information that is encrypted, secured or modified by any other method or technology that removes personally identifying elements or that otherwise renders the information unusable.

In the event of a breach, Covered Entities must follow one or more of the Act’s various notice requirements. The Act generally defines a breach as unauthorized access of electronic data containing personal information. Covered Entities must notify each individual in Florida whose Personal Information was, or is reasonably believed to have been, breached no later than 30 days after the Covered Entity determines that a breach occurred or has reason to believe a breach occurred. Under the current statute, Covered Entities had 45 days to provide notice.

This notice, which may be sent by mail or e-mail, must include:

  • The date, estimated date or estimated date range of the breach
  • A description of the Personal Information that was or may have been accessed during the breach
  • Contact information that individuals can use to inquire about the breach

If a Covered Entity is required to notify more than 1,000 individuals at a single time, the Covered Entity must also provide notice to all national consumer reporting agencies. If a breach affects 500 or more individuals in Florida, the Department of Legal Affairs must be notified no later than 30 days after the Covered Entity determines that a breach occurred or had reason to believe a breach occurred. This is a new notice requirement.

If a Covered Entity uses a third-party vendor to maintain, store or process Personal Information, then that third-party agent must notify the Covered Entity no later than 10 days after the third-party agent determines that a breach occurred or had reason to believe a breach occurred. Though a third-party agent may provide the required notices, the Covered Entity is ultimately responsible for compliance with the Act.

The Act also requires Covered Entities and their third-party agents to take all reasonable measures to dispose, or arrange for the disposal, of customer records containing Personal Information within its custody or control when they are no longer retained. Disposal shall involve shredding, erasing, or otherwise modifying the records to make Personal Information unreadable or undecipherable through any means.

Unlike the general descriptions provided in this article, the Act is highly technical and very specific. Though the Act does not create a private cause of action, civil penalties of up to $500,000 should be enough motivation for Covered Entities to learn more about Florida’s new law and ways to limit the new risks with insurance.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Affordable Care Act Update

Despite becoming law over four years ago, the Affordable Care Act continues to make headlines. Since it’s not easy to keep track of all the changes, let’s take a look at some of the more significant recent developments.

Elimination of Small Group Deductible Limits

A significant ACA change scheduled to take effect in 2014 involves annual deductible limits for small groups. Under this provision, small group health plan deductibles could not be more than $2,000 for individuals or $4,000 for families. Those who were concerned about the lack of flexibility caused by these deductible limits no longer have to worry.

The small group deductible limits were rather unceremoniously eliminated by the Protecting Access to Medicare Act, which was signed into law on April 1, 2014. Since these limits were retroactively eliminated back to the day the ACA was originally enacted, it’s almost like they never existed. This is welcome news for many small groups, which are typically those employers with up to 50 employees, but which may be employers with up to 100 employees.

However, it is important to note that the ACA’s annual out-of-pocket cost-sharing limits have not changed. Since these cost-sharing limits specifically apply to deductibles, among other things, employers must still be aware of indirect deductible limitations. The 2014 annual out-of-pocket limit is $6,350 for individuals and $12,700 for families.

Updated Model COBRA Notices

Under the Consolidated Omnibus Budget Reconciliation Act (COBRA), employees and their families may have the option of staying on their former employer’s health insurance plan for a limited period of time after their employment ends. Despite having to pay the entire premium, including any portion previously paid by their employer, COBRA coverage has typically been cheaper than individual or family coverage because the premiums are based on the employer’s group rates. However, with the new Health Insurance Marketplace created by the ACA, this may no longer be the case.

Phyllis C. Borzi, Assistant Secretary of Labor for Employee Benefits Security, said that, “in many cases, workers eligible for COBRA continuation coverage can save significant sums of money by instead purchasing health insurance through the Marketplace…It is important that workers know that in some cases there is a Marketplace option as well.”

To let employees know they may have an alternative to continuing their health care coverage under COBRA, the Department of Labor updated its Model COBRA General Notice and Model COBRA Election Notice. According to the Department of Labor, these updated notices make it clear to workers that if they are eligible for COBRA continuation coverage when leaving a job, they may choose to instead purchase coverage through the Health Insurance Marketplace.

Employer Mandate

In February 2014, the Internal Revenue Service provided transition relief from the ACA’s employer responsibility provisions. Employers with 100 or more employees wanting to avoid the penalty must offer coverage to 70% of their full-time employees in 2015, and 95% in 2016 and beyond. Large employers that do not meet these standards will have to make employer responsibility payments beginning in 2015. Employers with 50 to 99 full time employees will not be subject to a penalty until 2016, provided they meet certain conditions.

At Setnor Byer Insurance & Risk, we are committed to guiding you through the changes coming in 2014. Check back with us periodically for future informational updates about the Affordable Care Act. If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Why Did I Get a Reservation of Rights Letter?

Upon receiving notice of a claim, an insurance company must determine whether it is covered by a policy. If a claim is clearly covered, the insurance company will begin the process of defending or indemnifying the insured. Alternatively, claims that are clearly not covered will be denied. A Reservation of Rights letter is used when the insurance company isn’t sure whether a claim is covered.

Assume a customer files a lawsuit after being injured by a falling box. If the box fell because it was carelessly placed on a high shelf, a general liability policy would likely cover the claim. Coverage would be unlikely, however, if the box was intentionally dropped on the customer.

Though it may take months to find out what happened, the insurance company may only have days to take action. Rather than risk denying a covered claim, the insurance company can send the insured a Reservation of Rights letter, which gives the insurance company time to investigate the claim, and defend it, if necessary, without waiving its right to deny all or part of a claim at a later time if the facts ultimately establish a lack of coverage.

A Reservation of Rights letter also puts the insured on notice that all or part of a claim may not be covered. According to the California Supreme Court, by providing a Reservation of Rights letter, “the insurer gives the insured notice of how it will, or at least may, proceed and thereby provides it an opportunity to take any steps that it may deem reasonable or necessary in response–including whether to accept defense at the insurer’s hands and under the insurer’s control or, instead, to defend itself as it chooses.”

Reservation of Rights letters are used when the facts or the policy language may justify denying coverage for a claim. For example, insurance companies may use a Reservation of Rights letter when:

  • An exclusion in the policy does or may apply
  • The allegations in a lawsuit may be beyond the scope of coverage under a policy
  • Some or all of the damages are not covered by the policy
  • The insured may have failed to satisfy their obligations under the policy

A Reservation of Rights letter will typically:

  • Identify the specific policy covered by the letter
  • Summarize relevant facts
  • Quote relevant policy language
  • Identify and explain coverage and policy defenses

Though a Reservation of Rights letter does not necessarily mean that a claim will be denied, it must still be taken seriously. Depending on the nature of the claim and the potential exposure, professional guidance may be necessary when responding to a Reservation of Rights letter. An experienced and reputable insurance agent can help identify concerns, evaluate options and prepare a response.

If you have any questions or would like to speak with one of our Risk Management Professionals, please contact us.

If you would like to subscribe to our newsletters please click here.

Developing a Cybersecurity Framework

In February 2013, President Obama issued Executive Order 13636 on Improving Critical Infrastructure Cybersecurity. This Order calls for the development of a framework of industry standards and best practices to help organizations manage increasing cybersecurity risks. On February 12, 2014, the National Institute of Standards and Technology (NIST) responded to the President’s order with its Cybersecurity Framework.

The Cybersecurity Framework, which was created in collaboration with the private sector, focuses on using business drivers to guide cybersecurity activities. It is a risk-based approach that uses common language to address and manage cybersecurity risks in a business-specific, cost effective way. This voluntary framework is made up of three parts, each of which reinforces the connection between business drivers and cybersecurity activities.

The Framework Core provides a set of activities designed to achieve specific cybersecurity outcomes. The core is made up of five broad functions that help organizations express their management of cybersecurity risks.

  • Identify: Develop organizational understanding to manage cybersecurity risks to systems, assets, data and capabilities.
  • Protect: Develop and implement appropriate safeguards to ensure delivery of critical infrastructure services.
  • Detect: Develop and implement appropriate activities to identify the occurrence of a cybersecurity event.
  • Respond: Develop and implement appropriate activities to respond to a cybersecurity event.
  • Recover: Develop and implement appropriate activities to maintain operations and restore capabilities or services impaired by a cybersecurity event.

Framework Implementation Tiers provide context on how organizations view cybersecurity risks and the processes in place to manage that risk. Tiers are used to describe an organization’s commitment and sophistication in managing cybersecurity risks. They also describe the extent to which cybersecurity risk management is informed by business needs and integrated into an organization’s overall risk management practices.

The four tiers reflect a progression from informal, reactive responses to cybersecurity risks to approaches that are agile and risk-informed.

  • Tier 1 (Partial)
  • Tier 2 (Risk Informed)
  • Tier 3 (Repeatable)
  • Tier 4 (Adaptive)

Determining which tier applies to an organization depends on current risk management practices, threat environment, regulatory requirements, business objectives and organizational constraints. However, the NIST notes that tiers do not represent maturity levels, so progression to higher tiers is encouraged when it would reduce cybersecurity risks in a cost effective manner.

The Framework Profile is the alignment of an organization’s cybersecurity framework with its business requirements, risk tolerance and resources. Profiles enable organizations to establish a roadmap for reducing cybersecurity risk that meets organizational goals, implements best practices, considers regulatory requirements and reflects priorities.

Profiles can be used to describe an organization’s current state or target state of cybersecurity activities. Comparing current and target profiles can be used to identify gaps in an organization’s cybersecurity risk management practices. Given the need for flexibility, the NIST did not impose or require a specific form or format that must be followed when creating and implementing a profile.

It is important to remember that the Cybersecurity Framework is voluntary and that, according to the NIST, it will not place additional regulatory requirements on businesses. Nevertheless, it should serve as a reminder that data security breaches can happen to any organization.

As we have seen, preventative measures are not foolproof, so organizations should also consider protecting against data security breaches with insurance. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches

If you would like to subscribe to our newsletters please click here.

Insurance for Tech Companies

Since most businesses rely on technology, providing technology services has become big business. Technology companies provide goods, services and expertise that can increase efficiency, productivity and profitability. These businesses may involve:

  • System / network development and administration
  • Application and website programming and design
  • Hardware installation and repair
  • Website hosting, maintenance and optimization
  • Information Technology consulting, staffing and training
  • Project management
  • Consulting

Technology companies face the same risks as other businesses, so traditional insurance coverages are required, such as general liability, property, automobile and workers compensation insurance. However, additional insurance coverage may also be necessary to address the unique risks facing technology companies.

For example, many technology companies do not believe they need Errors & Omissions (Professional Liability) insurance. The reality is that technology companies, just like doctors and lawyers, can be held liable for errors and omissions committed in the performance of their professional services.

Unfortunately, a traditional E&O policy may not protect against many of the risks unique to technology companies. This is why technology-specific insurance is needed to cover technology-specific risks. To ensure adequate insurance coverage, technology companies should look for an E&O policy that, at a minimum:

  • Broadly defines “Computer Technology Services”
  • Provides coverage for failure to prevent unauthorized access to or use of any electronic system or program of a third party
  • Provides coverage for unauthorized, corrupting or harmful pieces of code, including, computer viruses, worms and Trojan Horses
  • Covers personal injury claims alleging wrongful entry, wrongful eviction, wrongful detention, false arrest, false imprisonment, libel, slander or defamation, advertising injury or violation of any right of privacy
  • Provides sufficient coverage limits

The right E&O policy lets technology companies focus on their business knowing that they are protected in the event of a claim. And, since clients are increasingly requiring proof of E&O insurance from their technology vendors, an E&O policy may also create new opportunities.

Given the complexity of the risks facing technology companies, evaluating insurance needs and options is not always easy. For example, in addition to E&O insurance, technology companies may also need coverage for cyber liability claims, including data security breaches, which are becoming more common.

An experienced insurance agent can guide you through the process of protecting your technology company. If you would like to learn more about insuring a technology company, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.