Is a Resident Manager Ideal for Your Self Storage Facility?

Resident managers are not as common as they used to be in the self storage industry. For some self storage facilities, however, a manager living on the premises may be the key to running a successful operation. Though cost is an important factor when deciding whether a self storage facility could benefit from a resident manager, other factors should be considered as well, such as:

Service: Automated facilities may not be enough to create an advantage over the competition. Depending on a self storage facility’s location or specialty, clients may want more than just an access code after signing a contract. Facilities with a resident manager can service clients in ways that others cannot. This is why the existence of a resident manager is often mentioned in promotional and marketing materials.

Security: Even with surveillance cameras and 24-hour monitoring services, it is difficult to deny that resident managers can make a self storage facility even more secure. Their presence alone will likely deter most criminals, and their response time will be quicker than even the fastest police departments.

Operations: Things can and often do go wrong after business hours. Leaking pipes and short-circuits are just two things that can cause significant damage if they are not discovered and fixed quickly. A resident manager can find and fix those problems that cannot wait.

Qualified Candidates: It’s not always easy to find and retain the right people. Providing prospective managers with a place to live may be just the perk required to hire and keep quality talent.

After evaluating all the pros and cons in the context of each facility’s own particular situation, an informed decision can be made about whether a resident manager could improve operations. However, before making a final decision, it is important to understand the ramifications of hiring a resident manager, particularly how doing so may create an unexpected relationship.

In addition to creating an employer-employee relationship, hiring a resident manager can also create a landlord-tenant relationship. While employers can often terminate employees at-will and without advance notice, the same cannot usually be done with tenants. Depending on applicable law, a self storage facility will generally be required to provide advance written notice to terminate the landlord-tenant relationship. As a result, a resident manager may be legally entitled to continue renting the property for a period of time after his or her employment has been terminated.

There are steps that can be taken to minimize the scope and impact of the landlord-tenant aspects of a resident manager’s employment relationship. For example, a self storage facility can address landlord-tenant issues in a written employment agreement or in a separate lease agreement. However, since specific legal requirements must be met, it is advisable to seek the advice of a locally licensed attorney.

As is often the case, it is necessary to understand the risks in order to control them. Since self storage facilities face unique risks, it helps to have an insurance program that is specifically designed for the self storage industry. If you would like more information about Setnor Byer Insurance & Risk’s Self Storage Insurance Program, please contact us.

If you would like to subscribe to our newsletters please click here.

Developing a Cybersecurity Framework

In February 2013, President Obama issued Executive Order 13636 on Improving Critical Infrastructure Cybersecurity. This Order calls for the development of a framework of industry standards and best practices to help organizations manage increasing cybersecurity risks. On February 12, 2014, the National Institute of Standards and Technology (NIST) responded to the President’s order with its Cybersecurity Framework.

The Cybersecurity Framework, which was created in collaboration with the private sector, focuses on using business drivers to guide cybersecurity activities. It is a risk-based approach that uses common language to address and manage cybersecurity risks in a business-specific, cost effective way. This voluntary framework is made up of three parts, each of which reinforces the connection between business drivers and cybersecurity activities.

The Framework Core provides a set of activities designed to achieve specific cybersecurity outcomes. The core is made up of five broad functions that help organizations express their management of cybersecurity risks.

  • Identify: Develop organizational understanding to manage cybersecurity risks to systems, assets, data and capabilities.
  • Protect: Develop and implement appropriate safeguards to ensure delivery of critical infrastructure services.
  • Detect: Develop and implement appropriate activities to identify the occurrence of a cybersecurity event.
  • Respond: Develop and implement appropriate activities to respond to a cybersecurity event.
  • Recover: Develop and implement appropriate activities to maintain operations and restore capabilities or services impaired by a cybersecurity event.

Framework Implementation Tiers provide context on how organizations view cybersecurity risks and the processes in place to manage that risk. Tiers are used to describe an organization’s commitment and sophistication in managing cybersecurity risks. They also describe the extent to which cybersecurity risk management is informed by business needs and integrated into an organization’s overall risk management practices.

The four tiers reflect a progression from informal, reactive responses to cybersecurity risks to approaches that are agile and risk-informed.

  • Tier 1 (Partial)
  • Tier 2 (Risk Informed)
  • Tier 3 (Repeatable)
  • Tier 4 (Adaptive)

Determining which tier applies to an organization depends on current risk management practices, threat environment, regulatory requirements, business objectives and organizational constraints. However, the NIST notes that tiers do not represent maturity levels, so progression to higher tiers is encouraged when it would reduce cybersecurity risks in a cost effective manner.

The Framework Profile is the alignment of an organization’s cybersecurity framework with its business requirements, risk tolerance and resources. Profiles enable organizations to establish a roadmap for reducing cybersecurity risk that meets organizational goals, implements best practices, considers regulatory requirements and reflects priorities.

Profiles can be used to describe an organization’s current state or target state of cybersecurity activities. Comparing current and target profiles can be used to identify gaps in an organization’s cybersecurity risk management practices. Given the need for flexibility, the NIST did not impose or require a specific form or format that must be followed when creating and implementing a profile.

It is important to remember that the Cybersecurity Framework is voluntary and that, according to the NIST, it will not place additional regulatory requirements on businesses. Nevertheless, it should serve as a reminder that data security breaches can happen to any organization.

As we have seen, preventative measures are not foolproof, so organizations should also consider protecting against data security breaches with insurance. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches

If you would like to subscribe to our newsletters please click here.

Insurance for Tech Companies

Since most businesses rely on technology, providing technology services has become big business. Technology companies provide goods, services and expertise that can increase efficiency, productivity and profitability. These businesses may involve:

  • System / network development and administration
  • Application and website programming and design
  • Hardware installation and repair
  • Website hosting, maintenance and optimization
  • Information Technology consulting, staffing and training
  • Project management
  • Consulting

Technology companies face the same risks as other businesses, so traditional insurance coverages are required, such as general liability, property, automobile and workers compensation insurance. However, additional insurance coverage may also be necessary to address the unique risks facing technology companies.

For example, many technology companies do not believe they need Errors & Omissions (Professional Liability) insurance. The reality is that technology companies, just like doctors and lawyers, can be held liable for errors and omissions committed in the performance of their professional services.

Unfortunately, a traditional E&O policy may not protect against many of the risks unique to technology companies. This is why technology-specific insurance is needed to cover technology-specific risks. To ensure adequate insurance coverage, technology companies should look for an E&O policy that, at a minimum:

  • Broadly defines “Computer Technology Services”
  • Provides coverage for failure to prevent unauthorized access to or use of any electronic system or program of a third party
  • Provides coverage for unauthorized, corrupting or harmful pieces of code, including, computer viruses, worms and Trojan Horses
  • Covers personal injury claims alleging wrongful entry, wrongful eviction, wrongful detention, false arrest, false imprisonment, libel, slander or defamation, advertising injury or violation of any right of privacy
  • Provides sufficient coverage limits

The right E&O policy lets technology companies focus on their business knowing that they are protected in the event of a claim. And, since clients are increasingly requiring proof of E&O insurance from their technology vendors, an E&O policy may also create new opportunities.

Given the complexity of the risks facing technology companies, evaluating insurance needs and options is not always easy. For example, in addition to E&O insurance, technology companies may also need coverage for cyber liability claims, including data security breaches, which are becoming more common.

An experienced insurance agent can guide you through the process of protecting your technology company. If you would like to learn more about insuring a technology company, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Implementing a Drug-Free Workplace Program

Though many believe substance abuse is not a problem in their workplace, statistics suggest otherwise. According to the National Institute on Drug Abuse (NIDA), nearly 75% of substance and alcohol abusers are employed. In addition to costing employers billions of dollars per year, substance abusers are more likely to:

  • Change jobs frequently
  • Be late to or absent from work
  • Be less productive
  • Be involved in a workplace accident
  • File a workers’ compensation claim

To help combat the problem, many employers have implemented a Drug-Free Workplace program. These programs incorporate various elements designed to prevent substance abusers from entering the workplace, identify and assist those already in the workplace, and eliminate continuing abusers from the workplace.

According to NIDA, employers with Drug-Free Workplace programs:

  • Report improvements in morale and productivity, and decreases in absenteeism, accidents, downtime, turnover, and theft
  • Report better health status among employees and family members and decreased use of medical benefits by these same groups

Employers can also reduce their workers’ compensation insurance premiums by implementing a Drug-Free Workplace program. For example, a 5% premium credit is available in Alabama, Florida, South Carolina and Virginia. Employers can save up to 7% in Ohio, and 7.5% in Georgia. Additionally, employers with fewer workplace accidents can also see reduced premiums due to an improved experience modification rating.

States have their own requirements for determining whether a Drug-Free Workplace program qualifies for a workers’ compensation premium credit. Since they can be very specific and technical, it is important to consult with a licensed professional prior to implementing a Drug-Free Workplace program.

If you have any questions about implementing a Drug-Free Workplace program or you would like to learn more about reducing your insurance premiums, please contact us.

If you would like to subscribe to our newsletters please click here.   

Let’s Talk About Data Security Breaches

The theft of credit and debit card information from Target’s computer systems should serve as a reminder that the risk of a data security breach must be taken seriously. Every organization must have a plan to not only prevent data security breaches, but to respond to them as well.

The first step is to identify vulnerabilities with a risk assessment. Unfortunately, this can be difficult because data security breaches can come from pretty much anywhere, including employees, laptop computers, copy machines and wireless networks. To make the process easier, organizations can perform a self-audit.

The Online Trust Alliance has come up with a series of risk assessment questions that are designed to help organizations identify vulnerabilities and gauge their level of preparedness. For example:

  • Are there any regulatory requirements that are specifically applicable to your business operations or geographic location?
  • What customer-specific data is collected? How, where and by whom is this data stored, maintained and archived? Can you identify points of vulnerability and risk?
  • Is the kind of customer-specific data you collect necessary for business operations? For example, is it necessary to request drivers’ license information or social security numbers?
  • Do you follow best practices for encryption and de-identification processes?
  • Is there an incident response team in place? Is there a clear reporting process in the event of an accidental data loss or a breach?
  • Is there a plan for communicating to employees, customers, partners, stockholders and the media in the event of a breach?
  • Are generally accepted security and privacy best practices followed? If not, why?
  • Is there a privacy policy reflecting current data collection and sharing practices, including the use of third-party advertisers and cloud service providers? Have systems been audited to confirm compliance with written policies?
  • Is there a contact person in the event of a breach? Has a person been assigned to work with the authorities, such as the FBI, Secret Service and State Attorney General Office?
  • Are you willing to sign off on your Data Incident Plan and represent to board members, investors and regulators that it contains best practices for preventing and responding to data security breaches?

This kind of self-audit should encourage discussion and evaluation of an organization’s specific data security risks. And, since the questions are general in nature, they can be used by most organizations, regardless of industry or location.

As we have seen, preventative measures are not foolproof, so organizations should also consider protecting against data security breaches with insurance. Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws.

Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like a professional audit please contact us to learn more.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Data Security Breaches: Lessons from 2013

They say that those who fail to learn from history are doomed to repeat it, and 2013 provided many lessons for those wishing to avoid a data security breach. Let’s review some of 2013’s data security breaches so that they do not have to be repeated in 2014.

Target. During the peak of the 2013 holiday season, Target suffered what may be one of the largest data security breaches in U.S. retail history. Target’s breach involved the credit and debit card accounts of about 40 million customers. Though Target believes the data remains safe because it was strongly encrypted, it may be used to gain access to customers’ accounts. There are estimates that this breach may end up costing Target billions of dollars.

Adobe. Adobe Systems, Inc. suffered a data security breach that compromised nearly 3 million records. Hackers were able to access customers’ IDs, encrypted passwords, names, encrypted credit or debit card numbers, expiration dates and other information related to their orders.

Facebook. Facebook was targeted in a sophisticated attack when a handful of employees visited a website that was compromised. This website hosted an exploit which allowed malware to be installed on employee laptops, even though they were running up-to-date anti-virus software. Facebook analyzed the source of the attack and discovered a previously unseen way to bypass security measures and to install the malware.

Washington State Courts. The Washington State Administrative Office of the Courts suffered a security breach on its public website. Though no court records were altered and no personal financial information is maintained on the website, the breach may have exposed up to 160,000 social security numbers and 1 million driver license numbers.

Twitter. After detecting unusual access patterns, Twitter discovered unauthorized attempts to access user data. According to Twitter, approximately 250,000 users may have had their information accessed by the attackers, including their usernames, email addresses, session tokens and encrypted/salted versions of passwords. These users had their passwords reset and their session tokens revoked by Twitter.

New York Times. Chinese hackers infiltrated The New York Times’ computer systems and obtained corporate passwords for its reporters and other employees. According to The New York Times, over the course of three months, 45 pieces of custom malware were installed on their network and used to gain access to computers. To get rid of the hackers, The New York Times blocked the compromised outside computers, removed every back door into its network, changed every employee password and wrapped additional security around its systems.

Evernote. Evernote appears to have been the victim of a coordinated attempt to access secure areas of its network. Their investigation revealed that hackers were able to access user information, including usernames, email addresses and encrypted passwords. Though Evernote believes that the passwords remain protected by encryption, all users were required to reset their account passwords.

These incidents show that data security breaches can happen to any organization, and that they can be very costly. Every organization must be proactive in protecting against data security breaches. Though protective measures should cover everything from the wireless network to the copy machine, organizations should also consider protecting against data security breaches with insurance.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Shopping for Insurance: Quality versus Cost

People typically purchase insurance because they have to, not because they want to. For the most part, consumers are happy to obtain the minimum required insurance coverage at the lowest price they can find. That is, until a claim comes along. Only then do they discover that buying the cheapest insurance available wasn’t such a bargain after all.

The quality versus cost argument is nothing new especially when it comes to insurance. Consumers who pay less tend to get less, whether in the form of coverages, limits or financial security. And, when people choose cost over quality, it usually means they are uninformed about what they really need.

As a full-service independent insurance agency, it is our job to help our clients understand their insurance needs. We evaluate, compare and quote various options from multiple insurance companies so that our clients have the right information before making a decision. Though many still choose cost over quality, it is important that they understand what they may be sacrificing.

Low Premiums

Would you rather have automobile insurance that protects you from damage caused by someone who is uninsured or underinsured? Uninsured Motorist Coverage is commonly excluded from a policy to reduce the premium. Rejecting GAP coverage or electing non-stacked coverage are other ways to save money. But these choices come with a risk. When shopping for insurance it’s better to determine what coverage is desired, see how much that coverage would cost, and work with an independent insurance agent to help get the coverage you need at a cost you can afford.

Financial Stability

Although cost is important, the financial strength of an insurance company may be more important. Financially weak insurance companies are more likely to become insolvent or go bankrupt, which means that their policyholders are less likely to get their claims paid. Though purchasing insurance from a financially weak company may be cheaper, how valuable is the money saved on premium if there is no money to pay a claim? An independent insurance agent can help you evaluate the financial stability of the insurance companies you are considering.

Customer Service

Insurance companies don’t typically assign an agent to their customers. Each time you call you speak to a different person which means you have to explain your situation over and over. Look for an agent that offers personalized service. Those are the agents who are willing to go the extra mile to get you what you need. For example, at Setnor Byer Insurance & Risk, our commercial clients enjoy complimentary access to our risk management services to help them manage the risks associated with owning a business.

A solid understanding of your insurance needs is the key to overcoming the quality versus cost argument. An experienced and reputable independent insurance agent can help you purchase insurance that is both economical and effective.

If you would like more information about our insurance products, please contact us.

If you would like to subscribe to our newsletters please click here.

Getting Rid of Consumer Report Information with the Disposal Rule

Businesses commonly use consumer reports when deciding whether to make a job offer or extend a line of credit. In the wrong hands, consumer reports may also be used to commit fraud and identity theft. This is why the Federal Trade Commission (FTC) enacted the Disposal Rule.

The authority for the Disposal Rule comes from the Fair and Accurate Credit Transactions Act (FACTA), which requires proper disposal methods by those who use consumer information from consumer reports for business purposes. As required by FACTA, the FTC’s Disposal Rule requires the use of reasonable disposal measures to protect against unauthorized access to or use of consumer information. Individuals and businesses of any size that use consumer reports for business purposes must comply with this rule

The Disposal Rule applies to consumer reports or information that comes from consumer reports. Under the Fair Credit Reporting Act, consumer reports include information obtained from a consumer reporting company that is used or expected to be used for various reasons, such as establishing a consumer’s eligibility for credit, employment or insurance. Credit reports and credit scores are consumer reports. Reports with information relating to employment, check writing history, insurance claims, residential or tenant history and medical history are also consumer reports.

The Disposal Rule, which simply requires reasonable disposal measures to prevent unauthorized access to or use of consumer information, is designed to be flexible. The rule allows organizations and individuals to determine what measures are reasonable by considering the sensitivity of the information, the costs and benefits of different disposal methods and changes in technology.

Under the rule, reasonable measures may include:

  • burning, pulverizing or shredding of papers containing consumer information so that the information cannot practicably be read or reconstructed.
  • destroying or erasing electronic media containing consumer information so that the information cannot practicably be read or reconstructed.
  • after due diligence, hiring a third party to properly dispose the consumer information. Due diligence could include reviewing an independent audit of the disposal company’s operations and/or its compliance with this rule, checking references, requiring certification by a recognized trade association or taking other appropriate measures to determine the competency and integrity of the disposal company.

According to the FTC, these examples are illustrative only and are not exclusive or exhaustive methods for complying with the Disposal Rule.

The Disposal Rule is but one aspect of protecting against a data security breach. Organizational protective measures should cover everything from the wireless network to the copy machine, and should also include insurance.

Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given their complexity, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

IRS Modifies “Use-or-Lose” Rule for Flexible Spending Accounts (FSAs)

On October 31, 2013, the Internal Revenue Service (IRS) modified the longstanding cafeteria plan “use-or-lose” rule for health Flexible Spending Accounts/Arrangements (FSAs). Under this rule, unused FSA account balances are forfeited at the end of the plan year. Now, up to $500 of unused money may be carried over to the next plan year.

A cafeteria plan FSA, which is offered with other employer-established benefits, reimburses employees for qualified medical expenses. FSAs are usually funded by employees through voluntary salary reductions of up to $2,500 per year, though employers may also contribute. FSA contributions are not included in an employee’s income and reimbursements for qualified medical expenses are not taxed.

For nearly 30 years, FSAs have been subject to the “use-or-lose” rule. However, last year the IRS asked whether the rule should be modified to provide greater flexibility. The overwhelming response was yes. The reasons for increased flexibility include:

  • Difficulties in predicting future medical expenditures
  • Minimizing incentives for unnecessary spending to avoid forfeiture
  • The possibility that lower paid employees are reluctant to participate in FSAs because even modest forfeitures can be significant
  • Easing and simplifying the administration of FSAs

Under the new rule for cafeteria plan FSAs, employers may allow employees to carryover up to $500 of unused FSA money to the next plan year. Any amounts carried over may be used to pay or reimburse medical expenses incurred during that entire plan year. Employers have the option, not the obligation, to let employees carryover unused FSA money. And, since $500 is the maximum amount that can be carried over, employers may choose a lower amount.

Currently, cafeteria plans are allowed to have a “grace period” of up to two months and 15 days after the plan year during which participants may use remaining FSA money from the previous plan year to pay expenses incurred during the grace period. Since this is a popular feature among many plans, it is important to note that plans may provide employees with a carryover option OR a grace period. A health FSA cannot have both.

Employers wishing to utilize the new carryover option must amend their cafeteria plan. The amendment must be adopted on or before the last day of the plan year and may, in some cases, be effective retroactively to the first day of that plan year. Plans must also be amended to eliminate any grace period by no later than the end of that plan year, though the IRS notes that this may be subject to “non-code legal constraints.”

Given the complexity of providing and managing cafeteria plans, as well as the liability for getting it wrong, employers should consult with appropriate professionals to make sure their plans meet their minimum needs and provide maximum benefits.

If you have any questions or would like to speak with one of our Risk Management Professionals, please contact us.

If you would like to subscribe to our newsletters please click here.

Data Security Breaches Can Happen to You

When it comes to data security breaches, many organizations say, “That could never happen to us.” Unfortunately, the increasing frequency of data security breaches means that many of these organizations are wrong. Don’t believe it? Let’s take a look at a few recent security breaches.

Hacking

In October 2013, the multi-billion dollar company, Adobe Systems, Inc., suffered a data security breach that compromised nearly 3 million records. Hackers were able to access customers’ IDs, encrypted passwords, names, encrypted credit or debit card numbers, expiration dates and other information related to their orders.

Laptop Computer

In October 2013, a Wisconsin hospital suffered a data breach when a laptop computer with unencrypted data was stolen out of an employee’s car. As a result, patients may have had their names, dates of birth, medical record and account numbers, providers, departments of service, bed and room numbers, dates and times of services, visit histories, complaints, diagnoses, procedures, test results, vaccines and medications exposed.

Employee Theft

In September 2013, a dishonest hospital employee in Florida accessed patient names, social security numbers, dates of birth and addresses. Even though the employee was fired and will be facing criminal prosecution, this information may have been used to file fraudulent tax returns.

Email Error

In September 2013, Columbia University Medical Center suffered a data security breach when an Excel file containing sensitive medical student information was accidentally attached to an email that was sent to students, faculty and staff.

Programming Error

In September 2013, a financial services firm suffered a data breach when a programming error allowed customers’ names, social security numbers and addresses to be viewed on the firm’s unrestricted website.

These recent incidents show that data security breaches can happen to any organization. This means that every organization must be proactive in protecting against data security breaches. Though protective measures should cover everything from the wireless network to the copy machine, organizations should also consider protecting against data security breaches with insurance.

Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.