How do you know if your identity has been stolen?

By Anita Byer, Setnor Byer Insurance & Risk

The likelihood of identity theft seems to increase daily. With so many identities being stolen, many believe it’s a matter of when, not if. Taking preventative measures is crucial to reducing the likelihood of being a victim, but nothing is foolproof. When identity theft does happen, early detection is the key to limiting the damage. The sooner you know, the better. But, how do you know when your identity has been stolen? It can be harder than you think.

Fortunately, the Federal Trade Commission offered some helpful advice during this year’s Identity Theft Awareness Week. According to the FTC, you need to understand how thieves might use your stolen identity and be on the lookout for signs.  

An identity thief could use your information to get credit or service in your name.

How to spot it: Get your free credit report at AnnualCreditReport.com. Review it for accounts you didn’t open or inquiries you don’t recognize. A new credit card, a personal loan or a car loan will appear as a new account. A new cell phone plan or utility service (water, gas, electric) will show up as an inquiry.

An identity thief could use your credit card or take money out of your bank account.

How to spot it: Check your credit card or bank statement when you get it. Look for purchases or withdrawals you didn’t make. Sign up to get text or email alerts from your credit card or bank whenever there’s a new transaction. This could help you spot unauthorized or fraudulent activity on your account.

An identity thief could steal your tax refund or use your Social Security number to work.

How to spot it: A notice from the IRS that there’s more than one tax return filed in your name could be a sign of tax identity theft. So could a notice that you have income from an employer you don’t work for.

An identity thief could use your health insurance to get medical care.

How to spot it: Review your medical bills and Explanation of Benefits statements for services you didn’t get. They could be a sign of medical identity theft.

An identity thief could use your information to file a claim for unemployment benefits.

How to spot it: A notice from your state unemployment office or employer about unemployment benefits that you didn’t apply for could be a sign of fraud.

When preventative measures fail, insurance is available to help victims through the expensive and time-consuming process of recovery. Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Business Insurance 101: Certificates of Insurance

Certificates of Insurance make the business world go round and round. General contractors demand them from subcontractors. Commercial lenders request them from borrowers. Landlords require them from tenants. Virtually every business will request or will be asked to provide a Certificate of Insurance at one time or another, which raises an important question. What’s a Certificate of Insurance?

Certificates of Insurance (COIs) are used to verify insurance coverage. They are issued by insurance companies and agents to provide proof of insurance to the person or entity needing verification—the certificate holder. COIs provide specific information about existing insurance coverage, such as:

It’s important to know what COIs are, but so is knowing what they are not. Certificates of Insurance:

  • Are NOT insurance policies.
  • Do NOT provide certificate holders with any rights under the insured’s policy.
  • Do NOT extend or modify the coverage provided by the insured’s policies.
  • Do NOT create a contract between the insurance company and the certificate holder.

COIs are provided for informational purposes only. They offer a superficial snapshot of insurance coverage that is in place at the time it is created. Nothing more. In fact, a COI issued today may be out of date tomorrow. The only way to truly evaluate insurance coverage is by reading the policy itself. Nevertheless, as long as you understand their limitations, Certificates of Insurance provide a quick, easy and efficient way to request or provide proof of insurance coverage.

Please contact us to learn how Setnor Byer Insurance & Risk can help manage your Certificates of Insurance.

Does the Americans with Disabilities Act Apply to Your Website?

A surge in lawsuits has businesses asking about website accessibility requirements under the Americans with Disabilities Act, but there are few answers. Figuring out how websites fit into a law that predates the Internet has proved challenging. Courts are divided and specific regulations don’t exist. However, businesses can use the rapidly developing body of case law as a tool to better understand which websites may be subject to Title III of the ADA.

Is your business a “public accommodation” under Title III of the ADA?

Title III generally prohibits places of public accommodation from discriminating on the basis of disability. Public accommodations include various private entities that affect commerce, like restaurants, bars, hotels, theaters, retail and grocery stores, banks, doctors’ offices and shopping centers. Businesses should consult an attorney to determine Title III’s applicability.

Does the ADA apply to your website?

For web-based businesses, it could depend on your location. Courts are split on whether the ADA applies to websites that are not connected to a physical place. Some apply the ADA regardless of any physical location, while others require a sufficient connection (nexus) between the website and an actual physical place. An attorney should be consulted to determine how the law is interpreted in a specific jurisdiction.

For brick-and-mortar businesses, the Title III of ADA may apply if there is a sufficient connection between a business’s website and its physical location. What is a sufficient connection? Instead of applying a well-established, universal test (there isn’t one), courts consider various factors to find a connection.

  • Does the website provide more than basic information about a physical location?
  • Is the website heavily integrated with a physical location?
  • Does the website operate as a gateway to a physical location?
  • Does the website offer services relative to a physical location?
  • Are consumers required to use the website to access a physical location?

Providing basic information online may not be enough, but case law suggests that as integration, functionality and interactivity increase, so too does the likelihood of finding a sufficient connection under the ADA. For example, can consumers use the website to:

  • find locations?
  • view inventory (information, descriptions, images, etc.)?
  • place orders or pre-orders?
  • fill prescriptions?
  • purchase gift cards?
  • learn about sales or promotions?
  • obtain discount codes?
  • sign-up for member rewards programs?
  • manage store accounts?

So, at what point does a website become sufficiently connected for the ADA to apply? It’s too soon to know where the final line will be drawn, but it’s probably safe to assume that each “Yes” brings you one step closer.

Every Small Business Needs a Cyber Security Strategy

Did you know that more than 50 percent of small and medium-sized businesses (SMBs) experienced a cyber-attack in the previous year? Cybercriminals tend to be opportunistic. They target the unprepared. Unfortunately, far too many SMBs don’t have a plan to prevent or respond to cyber-attacks.

SMBs can significantly reduce the likelihood of falling victim to cybercriminals by preparing a cyber security strategy. Let’s look at the essential elements of an effective strategy.

Prevention. The primary goal of every cyber security strategy should be prevention. An effective prevention strategy requires:

Detection. SMBs must be able to detect cyberattacks when they happen. An effective detection strategy requires:

  • Technology. Cyberattacks are so sophisticated that SMBs need quality intrusion detection systems that are routinely updated to remain current with evolving threats.
  • Real-Time Alerts. Tracking attacks provides data that can be used to generate real-time alerts.
  • Documentation. Records make it easier to evaluate attack trends and characteristics and update strategies accordingly.

Mitigation. A rapid response to a cyberattack is critical to limiting the damage. An effective mitigation strategy includes:

  • Response Plans. Once an attack is detected, SMBs must be ready to contain, assess and respond to the threat. A response plan should specifically identify personnel and designate responsibilities in the event of an attack.
  • Periodic Evaluations. Remediation and mitigation strategies must be reviewed and updated periodically to remain current with constantly evolving cyber threats.

Insurance. Preparation is important, but it isn’t always enough. SMBs should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Did You Know…Data Breaches Exposed More Than 18 Million Records PER DAY?

It looks like 2018 is going to be a record year for data breaches…in a bad way. Gemalto, a global digital security provider, released its Breach Level Index for the first half of 2018. It revealed a mix of good, bad and ugly. When compared to the first half of 2017, the number of data breaches worldwide actually went down. Unfortunately, the number of lost, stolen or compromised data records went up. Now for the ugly. This number went up 72 percent!

During the first six months of 2018, there were 944 data breaches worldwide, nearly 60 percent occurred in North America. As a result of these breaches, more than 3.3 billion data records were compromised or exposed. That works out to 18.5 million records per day. Nearly three quarters of a million records per hour!

According to the Breach Level Index:

  • More than 76 percent of the records breached involved social media, including breaches at Facebook (2.1 billion records) and Twitter (336 million records).
  • Malicious outsiders caused 56 percent of the data breaches.
  • Attacks by malicious insiders fell by 60 percent.
  • 879 million data records were lost by accident.
  • Identity theft remains the leading type of data breach.
  • The number of records stolen through identity theft breaches increased by 757 percent.
  • Financial access incidents decreased in frequency but increased in severity.
  • The healthcare industry experienced the most data breaches of any industry (27 percent).
  • 20 percent of all breaches had an unknown number of compromised data records.
  • Only one percent of the compromised data records were encrypted.

Data security has become a universal concern. Every business is at risk. None are immune. This explains the growing popularity of cyber liability insurance policies. Businesses can purchase Cyber Perils coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Yahoo Data Breach Settlement Highlights Importance of Data Security and Cyber Liability

An inconvenient truth. That’s how a growing number of us view data security breaches. There are victims and soon-to-be-victims. However, despite the seemingly endless stream of data breaches, organizations cannot afford to take a passive approach to data security and cyber threats. Just ask Yahoo!

In 2016, Yahoo announced two separate data breaches that exposed personal information of more than 1.5 billion users. At the time, Verizon Communications was in the process of buying Yahoo’s core Internet businesses. Upon learning of the data breaches, Verizon sliced $350 million off the purchase price. Then, in early March 2018, Yahoo agreed to pay $80 million to settle a breach-related securities class action lawsuit.

Data breaches have become much more than an inconvenient truth in the business world. They are a very costly reality. Fortunately, a growing number of businesses are realizing that if they don’t adapt today, they may not be around tomorrow.

Microsoft participated in a 2018 Global Cyber Risk Perception Survey that found most organizations now rank cybersecurity among their highest risk management priorities. Companies of all sizes have started to estimate the financial impact of a cyber event. According to the survey, organizations were most concerned about:

Business Interruption
Reputational Damage
Breach of Customer Information
Data / Software Damage
Extortion / Ransomware
Liability to Third Parties
Disruption / Interruption of Systems
Loss / Theft of Intellectual Property
Organizations that conducted the following cybersecurity activities were more confident in their ability to manage cyber risk.

Cybersecurity assessments
Penetration testing
Benchmarking (peers / industry-wide)
Modeling potential cyber loss scenarios
Phishing awareness training for employees
Encryption and multi-factor authentication
Reduced external system connectivity
Improved vulnerability and patch management
The survey also revealed that organizations are more confident in their ability to understand and assess cyber risk than their ability to mitigate or respond to it. Perhaps this explains why cyber liability insurance continues to play an important role in protecting against cyber liabilities. According to the survey, organizations:

increased coverage limits under existing cyber liability insurance policies;
re-structured existing cyber liability policies; or
purchased broader cyber liability insurance coverage.
Please contact us if you would like more information about insurance specifically designed to protect against cyber threats.

To receive regular insurance and risk management informational updates, please subscribe to our newsletter.

Have Data Security Breaches Become the New Normal?

It has gotten to the point where we can barely keep up with all the data security breaches. We are no longer surprised to hear that another data breach exposed the sensitive personal information exposed of thousands (or millions!) of people. What’s worse is that many of us are no longer concerned. We have become complacent.

Taking a callous attitude toward data breaches can be risky. Just because data breaches are more common doesn’t make them less harmful. According to a study by Javelin Strategy & Research, 15.4 million U.S. consumers had $16 billion stolen in 2016. Identity thieves have stolen nearly $110 billion in the past six years.

Things got worse in July 2017, when Equifax, one of the three major credit reporting agencies, discovered a massive data breach that could impact approximately 143 million U.S. consumers. Equifax reports that the exposed information:

  • Social security numbers;
  • Birth dates;
  • Addresses;
  • Driver’s license numbers; and
  • Credit card numbers for approximately 209,000 consumers.

How significant is this? According to the Federal Trade Commission (FTC), if you have a credit report, there is a good chance that you’re one of the 143 million American consumers who had their sensitive personal information exposed. If so, the FTC recommends taking the following protective measures.

  • Check your credit reports from all three credit reporting agencies (including Equifax). You can do this for free by visiting annualcreditreport.com. Accounts or activity that you don’t recognize could indicate identity theft.
  • Consider placing a credit freeze on your files. A credit freeze makes it harder for someone to open a new account in your name, but it won’t prevent a thief from making charges to existing accounts.
  • If you decide against a credit freeze, consider placing a fraud alert on your files. This warns creditors that you may be an identity theft victim and that they should verify that anyone seeking credit in your name really is you.
  • Monitor credit card and bank accounts closely for charges you don’t recognize.
  • File your taxes early, so an identity thieve uses your Social Security number to get a tax refund or a job. Respond right away to letters from the IRS.

Taking measures to protect against identity theft are important, but they’re not always enough. That’s why you should consider insurance that is specifically designed to protect both individuals and businesses against identity thieves and hackers. For example, identity theft coverage can help individuals cover the cost of clearing their name. Cyber Liability and Security Breach (Cyber Perils) coverage can protect businesses against various cyber threats, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Additional information is also available in our weekly Risk Management Newsletters.

How Can You Limit the Damage Caused by Identity Theft?

What’s worse than filing your taxes? Finding out that your return was already filed and your refund check was already cashed. Yep, that’s definitely worse. Unfortunately, tax season has become the time of year when many first discover that their identities have been stolen.

According to Javelin Strategy & Research’s 2017 Identity Fraud Study, there were 15.4 million U.S. victims of identity theft in 2016, which is 16 percent higher than 2015. It was the highest rate since Javelin began tracking identity fraud in 2003.

So, what should you do if your identity has been stolen? According to the Federal Trade Commission (FTC), you must take immediate action to limit the damage.

What to do right away.

Contact the fraud department of each company (retailer, bank, etc.) where you know fraud occurred. Explain that someone stole your identity and ask them to close or freeze the accounts so no one can add new charges unless you agree. Change logins, passwords and PINS for your accounts.

Contact one of the three credit bureaus to place a free 90-day fraud alert. That company must tell the other two. A fraud alert makes it harder for someone to open new accounts in your name. When you have an alert on your report, a business must verify your identity before it issues new credit in your name.

Get your credit reports from Equifax, Experian and TransUnion. Review your reports and note any accounts or transactions you don’t recognize.

Report identity theft to the FTC. The FTC will create an Identity Theft Report and recovery plan. An identity theft report proves to businesses that someone stole your identity. It also guarantees you certain rights.

File a report with your local police department. Tell the police someone stole your identity and that you need to file a report. Ask for a copy of the police report.

What to do next.

Close new accounts. Ask the fraud department of each business where an account was opened to close the account. Request a confirmation letter and keep a record of who you contacted and when.

Remove fraudulent charges from your accounts. Let the fraud department know which charges are fraudulent and ask that they be removed from your account. Request a confirmation letter and keep a record of who you contacted and when.

Correct your credit report. Write each of the three credit bureaus. Identify what information on your report came from identity theft and ask them to block that information. You have the right to block fraudulent information so that it won’t show up on your credit report and companies can’t try to collect the debt from you. If you have an Identity Theft Report, credit bureaus must honor your request to block this information.

Consider an extended fraud alert or credit freeze. Both can help prevent further misuse of your personal information, but there are important differences between the two. For example, an extended fraud alert allows access to your credit reports as long as steps are taken to verify your identity. A credit freeze stops all access until it’s removed. Though fraud alerts are free to place and remove, there may be small fees associated with credit freezes.

Protective measures to protect against identity theft are important, but they’re not always enough. However, there is insurance that is specifically designed to protect both individuals and businesses against identity thieves and hackers. For example, identity theft coverage can help individuals cover the cost of clearing their name. Cyber Liability and Security Breach (Cyber Perils) coverage can protect businesses against various cyber threats, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Additional information is also available in our weekly Risk Management Newsletters.

Don’t Lose Sight of Security Among the Internet of Things

Did you know that there will be nearly 21 billion devices connected to the Internet by 2020?

According to Gartner, an information technology research company, 5.5 million new devices are connecting every day. This rapidly growing network of Internet-enabled physical devices capable connecting, communicating and identifying with other devices is commonly referred to as the Internet of Things. Not surprisingly, businesses are looking for ways to harness its power and potential. Unfortunately, hackers are too.

The Internet of Things adds a new security dimension that businesses must consider. A single insecure connection could expose not only sensitive information transmitted by a device, but everything else on a business’s network. Though there isn’t a one-size-fits-all approach, the Federal Trade Commission has identified various security measures that businesses can generally adopt to help minimize the risks created by the Internet of Things.

Encourage a culture of security. Designate senior executives who are responsible for security. Since most security breaches are avoidable, train staff to recognize and report vulnerabilities. Address security expectations and requirements in contracts with service providers.

Adopt a risk-based approach. Direct attention and allocate resources to protect network connections that are most vulnerable and sensitive information.

Consider (and reconsider) the need to collect or retain sensitive information. Steps must be taken to protect sensitive information that is collected and retained out of business necessity. Unnecessary sensitive information should not be collected or retained at all.

Manage passwords.Implement an effective way to manage passwords. Do not rely on default passwords.

Take advantage of readily available security tools.There’s a tool out there for a number of basic security testing tasks, such as scanning networks for open ports, reverse engineering of programming code or decompiling, checking password strength and scanning for known vulnerabilities. Many of these tools are free, and some of them work automatically.

Protect interfaces between devices and servers. Weaknesses are often found at the point where a device communicates with servers. The interface between a mobile device and the cloud, for example, could create an opening for hackers to access an entire network. There are a number of ways to test entry points for weaknesses. “Fuzzing” is a method that sends a device or system unexpected input data to detect possible defects. Businesses should use manual and automated tools to test interfaces.

Limit permissions. Access to sensitive information should be limited to only those who actually need it. Limiting access to the lowest level that will allow for normal functioning is known as the principle of least privilege. To maximize effectiveness, permission limits must strike a balance between utility and security.

Utilize encryption. Standard encryption techniques are available to protect sensitive data that is stored on devices and transmitted to networks. Not all encryption is created equal, so stronger encryption methods should be selected over weaker ones.

Emphasize authentication. Security starts by making sure people are who they say they are. The importance of proper authentication has magnified the Internet of Things. An authentication failure involving a single connected device could expose the entire network to which the device connected. Depending on the nature of a business or its sensitive information, additional authentication measures may be necessary. For example, a two-factor authentication process that requires a password and a secure token.

Finally, businesses must remember that data security is a dynamic process that requires constant attention and frequent adjustments. Since hackers are constantly adapting, so must security measures. Nevertheless, it’s impossible to protect against every cyber threat or prevent every data breach, so business should seriously consider Cyber Liability Insurance. Unlike traditional business insurance policies, Cyber Liability and Security Breach (Cyber Perils) Insurance policies protect against privacy injuries, such as identity theft, and cover the cost of complying with data breach notice laws.

Given the complexity of the risk and the absence of one-size-fits-all coverage, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.

Best Practices for Avoiding (Most) Data Security Breaches

Did you know that 93% of data breaches could have been avoided? Everyone should be interested in this somewhat shocking statistic because cyber threats and data security remain primary concerns among virtually every organization, regardless of size, industry or purpose. It’s true that some cyber threats simply cannot be avoided, which is why businesses should do everything in their power to avoid those that can.

The first step is recognizing and addressing some of the more common avoidable causes of security breaches and data loss. According to the Online Trust Alliance, these include:

  • Employee errors (lost data, files, drives or devices and improper disposal);
  • Accidental disclosures (via email and public postings);
  • Business Email Compromises (socially engineered exploits like phishing and whaling);
  • Unencrypted data and disclosed keys;
  • Improperly configured systems, networks and devices;
  • Failing to update or patch systems against known vulnerabilities; and
  • Using end of life devices, operating systems and applications.

The next step is implementing security processes and procedures. When it comes to defending against cyber threats and ensuring data security, business-specific circumstances and operations typically determine which essential preventative measures are most likely to be effective. Nevertheless, there are various baseline security best practices recommended by the Online Trust Alliance that most businesses can easily implement and manage, such as:

  • Encrypting data at rest, in storage and in transit. Without the corresponding cryptographic keys, encryption renders data useless to hackers. It may also exempt businesses from having to comply with various state data breach notification laws.
  • Managing passwords. Use password managers to generate and store passwords. Multi-factor authentication (smartcards and PINs in addition to passwords) can also be required to access sensitive information or accounts.
  • Adopting the least-privilege user account (LUA) strategy. User accounts should be given the least amount of privilege (access) required to perform their necessary functions.
  • Auditing security measures. Periodically conduct penetration tests and vulnerability scans to identify and mitigate vulnerabilities.
  • Monitoring emails. Require email authentication of all inbound and outbound mail servers to detect malicious and spoofed emails.
  • Managing mobile devices. Require authentication to unlock devices, lock out devices after numerous failed login attempts, encrypt communications and storage, and enable remote wiping of mobile devices that are lost or stolen.
  • Managing wireless networks. Only authorized wireless devices should be given network access. “Guest” network access should be kept on separate servers.
  • Implementing a data breach response plan. Conduct a post-mortem after every incident and make necessary adjustments. Practice by regularly testing response plans and personnel.

Since it’s impossible to protect against every cyber threat or prevent every data breach, the final step is obtaining Cyber Liability Insurance. According to PricewaterhouseCoopers’ 2016 Global State of Information Security Survey, 59% of businesses surveyed purchased cyber security insurance to mitigate the financial impact of data breaches and cyber incidents when they do occur. Businesses are increasingly realizing that what can’t be protected or prevented must be insured.

Unlike traditional business insurance policies, Cyber Liability and Security Breach (Cyber Perils)Insurance policies protect against privacy injuries, such as identity theft, and cover the cost of complying with data breach notice laws. Given the complexity of the risk and the absence of one-size-fits-all coverage, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.