Cyber Liability: A BIG Risk for Small Businesses

Did you know that small businesses experience cyber incidents at roughly the same rate as drivers experience car accidents? Though most of us would never go without auto insurance, a majority of small businesses don’t have cyber liability insurance coverage. According to the 2018 Small Business Cyber Insurance and Security Spotlight Survey conducted by the Insurance Information Institute and J.D. Power:

  • 10 percent of the small businesses surveyed suffered at least one cyber incident in the prior year.
  • The average cyber-related loss was $188,400. In 2016, the average loss was $73,000.
  • Nearly 60 percent of small businesses are very concerned about cyber incidents.
  • 59 percent do not have cyber insurance coverage.

The potential impacts of a cyber incident that most concern small businesses include:

  • financial loss (47 percent);
  • information breach / theft (35 percent);
  • reputation / brand image issues (14 percent); and
  • regulatory / governance and legal issues (4 percent).

According to the survey, businesses with cyber insurance often had similar coverages, including coverage for:

There is one last thing to consider if your small business still doesn’t have cyber insurance coverage. According to the survey, 97 percent of the insured small businesses that experienced a cyber incident indicated that their cyber insurance policies adequately covered their losses. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Did you know that small businesses experience cyber incidents at roughly the same rate as drivers experience car accidents? Though most of us would never go without auto insurance, a majority of small businesses don’t have cyber liability insurance coverage. According to the 2018 Small Business Cyber Insurance and Security Spotlight Survey conducted by the Insurance Information Institute and J.D. Power:

Don’t Lose Sight of Security Among the Internet of Things

Did you know that there will be nearly 21 billion devices connected to the Internet by 2020?

According to Gartner, an information technology research company, 5.5 million new devices are connecting every day. This rapidly growing network of Internet-enabled physical devices capable connecting, communicating and identifying with other devices is commonly referred to as the Internet of Things. Not surprisingly, businesses are looking for ways to harness its power and potential. Unfortunately, hackers are too.

The Internet of Things adds a new security dimension that businesses must consider. A single insecure connection could expose not only sensitive information transmitted by a device, but everything else on a business’s network. Though there isn’t a one-size-fits-all approach, the Federal Trade Commission has identified various security measures that businesses can generally adopt to help minimize the risks created by the Internet of Things.

Encourage a culture of security. Designate senior executives who are responsible for security. Since most security breaches are avoidable, train staff to recognize and report vulnerabilities. Address security expectations and requirements in contracts with service providers.

Adopt a risk-based approach. Direct attention and allocate resources to protect network connections that are most vulnerable and sensitive information.

Consider (and reconsider) the need to collect or retain sensitive information. Steps must be taken to protect sensitive information that is collected and retained out of business necessity. Unnecessary sensitive information should not be collected or retained at all.

Manage passwords.Implement an effective way to manage passwords. Do not rely on default passwords.

Take advantage of readily available security tools.There’s a tool out there for a number of basic security testing tasks, such as scanning networks for open ports, reverse engineering of programming code or decompiling, checking password strength and scanning for known vulnerabilities. Many of these tools are free, and some of them work automatically.

Protect interfaces between devices and servers. Weaknesses are often found at the point where a device communicates with servers. The interface between a mobile device and the cloud, for example, could create an opening for hackers to access an entire network. There are a number of ways to test entry points for weaknesses. “Fuzzing” is a method that sends a device or system unexpected input data to detect possible defects. Businesses should use manual and automated tools to test interfaces.

Limit permissions. Access to sensitive information should be limited to only those who actually need it. Limiting access to the lowest level that will allow for normal functioning is known as the principle of least privilege. To maximize effectiveness, permission limits must strike a balance between utility and security.

Utilize encryption. Standard encryption techniques are available to protect sensitive data that is stored on devices and transmitted to networks. Not all encryption is created equal, so stronger encryption methods should be selected over weaker ones.

Emphasize authentication. Security starts by making sure people are who they say they are. The importance of proper authentication has magnified the Internet of Things. An authentication failure involving a single connected device could expose the entire network to which the device connected. Depending on the nature of a business or its sensitive information, additional authentication measures may be necessary. For example, a two-factor authentication process that requires a password and a secure token.

Finally, businesses must remember that data security is a dynamic process that requires constant attention and frequent adjustments. Since hackers are constantly adapting, so must security measures. Nevertheless, it’s impossible to protect against every cyber threat or prevent every data breach, so business should seriously consider Cyber Liability Insurance. Unlike traditional business insurance policies, Cyber Liability and Security Breach (Cyber Perils) Insurance policies protect against privacy injuries, such as identity theft, and cover the cost of complying with data breach notice laws.

Given the complexity of the risk and the absence of one-size-fits-all coverage, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.

Beware of Business Email Compromise (Whaling) Cyber Attacks in 2016

Business Email Compromise (BEC) attacks are sophisticated scams that compromise legitimate business e-mail accounts to conduct unauthorized fund transfers. These attacks are also called ‘whaling’ because they are similar to phishing, but on a larger scale. BEC attacks have grown in popularity in recent years, and are expected to pose a significant risk to businesses in 2016.

The FBI reported a 270% increase in BEC victims since January 2015, and nearly $750 million of actual and attempted U.S. losses since August 2015. Research conducted by Mimecast, an email security provider, found that 55% of organizations have seen an increase in BEC attacks over the last three months.

Using complaint data, the FBI identified four general versions of BEC attacks.

  • The Supplier Swindle. A business is asked by a current supplier to wire an invoice payment to a fraudulent account. Hackers use spoofed e-mails that appear very similar to a legitimate account.
  • CEO Fraud. Spoofed or hacked e-mail accounts of high-level business executives are used to request a wire transfer from an employee within the company who is normally responsible for processing these requests.
  • Fraudulent Invoices. An employee’s personal e-mail account is hacked and used to request invoice payments from multiple vendors identified in the employee’s contact list.
  • Attorney Scam. An employee is asked to quickly transfer funds by someone posing as an attorney who is handling a confidential or time-sensitive matter for the business.

BEC attacks are not random. Victims are specifically targeted by hackers using information that is made readily available on company websites and social media sites like Facebook, LinkedIn and Twitter. For example, LinkedIn can be used to map entire departments and reporting structures. Websites may also provide valuable information, such as email addresses, titles, responsibilities and even biographical information.

According to Mimecast, a BEC attack can be broken down into five phases.

  • Research: Criminals identify a target organization and its employees. Open source intelligence, social media and corporate websites are then used to build an accurate picture of the organization and identify key executives and finance team members.
  • Similar Domain Names: Criminals may then register a domain name that sounds or appears similar to that of the target company. For example, the domain ajaxcornpany.com could be used to spoof ajaxcompany.com. Were you able to spot the difference between the two?
  • Whale Emails: Criminals make initial contact by posing as a high-level executive and sending an innocuous email to a member of the finance team. These emails are typically innocuous, brief and to the point, such as “I need you to complete a task ASAP, are you in the office?”
  • Victim Tricked: Due to the research done before the attack, victims are likely to believe the email is genuine and respond accordingly. Criminals may then engage in email ‘small talk’ prior to requesting a wire transfer.
  • Wire Transfer: Victims, typically those with authority to initiate or approve financial transactions, are asked to transfer funds. Having no reason to doubt the authenticity of the request, the funds are transferred.

BEC attacks can be very difficult to identify. Since criminals don’t rely on emails with attachments or links, current barriers are often inadequate. Nevertheless, steps can be taken to protect against BEC attacks. For example, in addition to increased awareness, the FBI identified various preventative measures, such as:

 

  • Create detection system to flag e-mails with extensions that are similar to company e-mail.
  • Register all domains that are similar to the company’s actual domain.
  • Verify changes in vendor payment with two-factor authentication, like requiring secondary approval.
  • Confirm requests to transfer funds. If verifying over the phone, use previously known numbers, not the numbers provided in the e-mail request.
  • Know your customers.
  • Carefully scrutinize all e-mail requests to transfer funds.

 

Businesses should also consider cyber insurance coverage to protect against cyber attacks that could not be prevented. Unlike traditional commercial insurance, Cyber Liability and Security Breach (Cyber Perils) Insurance policies protect against privacy injuries, such as identity theft, and cover the cost of complying with data breach notice laws.

We would be happy to provide you with more information about insurance for existing and emerging cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.

Perhaps these predictions explain the growing number of businesses purchasing new cyber insurance policies or increasing coverage under existing cyber policies.

What Cyber Threats Should Businesses Expect in 2016?

Cyber security has become a game of cat and mouse. Security evolves and criminals adapt. Or is it the other way around? Either way, cyber threats pose a significant risk to businesses. And, according to the McAfee Labs 2016 Threats Predictions Report, businesses should be prepared for another year of cyber threats, some old and some new.

McAfee Labs predicts that cyber threats will expand and evolve in 2016, and beyond. The changing landscape is due in part to a billion more users by 2019, 2.6 billion more smartphone connections by 2020, and 35 more zettabytes by 2020. (A zettabyte — 1 followed by 21 zeros— is roughly equivalent to 36 million years of HD video.) With this in mind, McAfee Labs made a number of predictions about cyber threat in 2016, including:

Hardware: Hackers often use intimate knowledge of a manufacturer’s firmware and code to develop sophisticated and persistent malware. In 2016, the trend of hardware attacks will continue, so recognizing how system components below the operating system can be exploited will remain critical to defending against attacks.

Ransomware: Ransomware is a permanent denial-of-service attack that makes certain files unusable, despite leaving systems operational and maintaining data. Ransomware will remain a major and rapidly growing threat in 2016, and the Mac OSX (operating system) will increasingly be targeted.

Employee Systems: Hackers will increasingly turn to the relatively insecure home systems of a business’s employees. In 2016, businesses are expected to provide more advanced security technology for employees to install on their personal systems, and to spend more on personnel training and security awareness initiatives.

Cloud Services: According to the report, the level of sensitive and confidential company data shared on business-oriented cloud services and platforms is alarming. Many businesses are at the mercy of their provider’s security controls and have little insight into their provider’s security posture. As a result, cybercriminals will increasingly hack into cloud services platforms.

Wearable Devices: The growing number of wearable devices, particularly their Bluetooth connection to a smartphone, is creating a target-rich environment for hackers. Breaches involving control apps for wearable devices, which are expected to increase in the next 12 to 18 months, will provide valuable data for spear-phishing attacks. For example, GPS data from a running app tied to a fitness tracker can be used to craft an email that is more likely to be opened. If a user visits a coffee shop after the gym, an attacker could write an email saying “I think you dropped this at the coffee shop this morning,” and attach a link to an infected image file.

Automobiles: Attacks on automobile systems will increase in 2016 because much of the hardware lacks foundational security principles. Without adequate security, cybercriminals may create transportation deadlocks, impact road safety and threaten people’s lives.

Stolen Data Warehouses: The accumulation of stolen data over the years is predicted to develop a robust market for stolen sensitive information in 2016. Specialized underground warehouses will surface, offering stolen personal data, compromised credentials and infrastructure details from multiple sources, which can be used to bypass standard security components.

Perhaps these predictions explain the growing number of businesses purchasing new cyber insurance policies or increasing coverage under existing cyber policies. Unlike traditional commercial insurance policies, Cyber Liability and Security Breach (Cyber Perils) Insurance policies protect against privacy injuries, such as identity theft, and cover the cost of complying with data breach notice laws.

We would be happy to provide you with more information about insurance for existing and emerging cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.

Why Are Risk Managers Increasingly Relying on Cyber Liability Insurance?

We hoped Anthem’s January data breach would be the last large-scale event of 2015. Our hopes were dashed by the Office of Personnel Management’s massive breach that exposed personal information of more than 20 million current, former and prospective federal employees and contractors. This is yet another reminder that every organization is at risk of suffering a data security breach.

Organizations should also know that the costs of a data security breach can be devastating. Consider the following results from NetDiligence’s 2014 analysis of 111 data breach insurance claims:

  • Most frequently exposed data: personally identifiable information (41%), private health information (21%) and payment card information (19%)
  • Most frequent cause: hackers (30%) and staff mistakes (14%)
  • Typical claims range: $30,000 to $400,000
  • Average claim payout: $733,109
  • Average per-record cost: $956.21
  • Average cost for crisis services: $366,484
  • Average cost for legal defense: $698,797
  • Average cost for legal settlement: $558,520

These staggering figures may explain the results of a 2015 survey of risk managers conducted by the Risk Management Society (RIMS). According to the survey, the top three first-party exposures are reputational harm (79%), business interruption (78%) and data breach response and notification (73%). Fifty-one percent of respondents purchased cyber insurance policies, while 74% are considering obtaining cyber coverage in the next 12 to 24 months.

The RIMS survey found that risk managers are buying the following coverages:

  • Breach notification costs (91%)
  • Cyber extortion (80%)
  • Network/business interruption (80%)
  • Data recovery (75%)
  • Fines and penalties (75%)
  • Reputational harm (44%)
  • Professional liability (43%)
  • Theft of trade secrets (29%)

The RIMS survey shows that risk managers are taking data security very seriously. Interestingly, the growing prevalence of cyber insurance suggests that preventative measures may not be enough. Even the most sophisticated security measures don’t always prevent data breaches.

The right Cyber Perils coverage can help organizations survive the continuing data breach epidemic. The key is finding a policy that meets organizational needs without unnecessary coverages. The complexity of cyber insurance makes it difficult to evaluate and compare various options, so an experienced insurance agent should be consulted to find coverage that is both adequate and affordable.

If you would like to learn more about insuring against cyber risks, contact us.

If you would like to subscribe to our newsletters please click here.