Beware of Business Email Compromise (Whaling) Cyber Attacks in 2016

Business Email Compromise (BEC) attacks are sophisticated scams that compromise legitimate business e-mail accounts to conduct unauthorized fund transfers. These attacks are also called ‘whaling’ because they are similar to phishing, but on a larger scale. BEC attacks have grown in popularity in recent years, and are expected to pose a significant risk to businesses in 2016.

The FBI reported a 270% increase in BEC victims since January 2015, and nearly $750 million of actual and attempted U.S. losses since August 2015. Research conducted by Mimecast, an email security provider, found that 55% of organizations have seen an increase in BEC attacks over the last three months.

Using complaint data, the FBI identified four general versions of BEC attacks.

  • The Supplier Swindle. A business is asked by a current supplier to wire an invoice payment to a fraudulent account. Hackers use spoofed e-mails that appear very similar to a legitimate account.
  • CEO Fraud. Spoofed or hacked e-mail accounts of high-level business executives are used to request a wire transfer from an employee within the company who is normally responsible for processing these requests.
  • Fraudulent Invoices. An employee’s personal e-mail account is hacked and used to request invoice payments from multiple vendors identified in the employee’s contact list.
  • Attorney Scam. An employee is asked to quickly transfer funds by someone posing as an attorney who is handling a confidential or time-sensitive matter for the business.

BEC attacks are not random. Victims are specifically targeted by hackers using information that is made readily available on company websites and social media sites like Facebook, LinkedIn and Twitter. For example, LinkedIn can be used to map entire departments and reporting structures. Websites may also provide valuable information, such as email addresses, titles, responsibilities and even biographical information.

According to Mimecast, a BEC attack can be broken down into five phases.

  • Research: Criminals identify a target organization and its employees. Open source intelligence, social media and corporate websites are then used to build an accurate picture of the organization and identify key executives and finance team members.
  • Similar Domain Names: Criminals may then register a domain name that sounds or appears similar to that of the target company. For example, the domain ajaxcornpany.com could be used to spoof ajaxcompany.com. Were you able to spot the difference between the two?
  • Whale Emails: Criminals make initial contact by posing as a high-level executive and sending an innocuous email to a member of the finance team. These emails are typically innocuous, brief and to the point, such as “I need you to complete a task ASAP, are you in the office?”
  • Victim Tricked: Due to the research done before the attack, victims are likely to believe the email is genuine and respond accordingly. Criminals may then engage in email ‘small talk’ prior to requesting a wire transfer.
  • Wire Transfer: Victims, typically those with authority to initiate or approve financial transactions, are asked to transfer funds. Having no reason to doubt the authenticity of the request, the funds are transferred.

BEC attacks can be very difficult to identify. Since criminals don’t rely on emails with attachments or links, current barriers are often inadequate. Nevertheless, steps can be taken to protect against BEC attacks. For example, in addition to increased awareness, the FBI identified various preventative measures, such as:

 

  • Create detection system to flag e-mails with extensions that are similar to company e-mail.
  • Register all domains that are similar to the company’s actual domain.
  • Verify changes in vendor payment with two-factor authentication, like requiring secondary approval.
  • Confirm requests to transfer funds. If verifying over the phone, use previously known numbers, not the numbers provided in the e-mail request.
  • Know your customers.
  • Carefully scrutinize all e-mail requests to transfer funds.

 

Businesses should also consider cyber insurance coverage to protect against cyber attacks that could not be prevented. Unlike traditional commercial insurance, Cyber Liability and Security Breach (Cyber Perils) Insurance policies protect against privacy injuries, such as identity theft, and cover the cost of complying with data breach notice laws.

We would be happy to provide you with more information about insurance for existing and emerging cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.

Perhaps these predictions explain the growing number of businesses purchasing new cyber insurance policies or increasing coverage under existing cyber policies.

What Cyber Threats Should Businesses Expect in 2016?

Cyber security has become a game of cat and mouse. Security evolves and criminals adapt. Or is it the other way around? Either way, cyber threats pose a significant risk to businesses. And, according to the McAfee Labs 2016 Threats Predictions Report, businesses should be prepared for another year of cyber threats, some old and some new.

McAfee Labs predicts that cyber threats will expand and evolve in 2016, and beyond. The changing landscape is due in part to a billion more users by 2019, 2.6 billion more smartphone connections by 2020, and 35 more zettabytes by 2020. (A zettabyte — 1 followed by 21 zeros— is roughly equivalent to 36 million years of HD video.) With this in mind, McAfee Labs made a number of predictions about cyber threat in 2016, including:

Hardware: Hackers often use intimate knowledge of a manufacturer’s firmware and code to develop sophisticated and persistent malware. In 2016, the trend of hardware attacks will continue, so recognizing how system components below the operating system can be exploited will remain critical to defending against attacks.

Ransomware: Ransomware is a permanent denial-of-service attack that makes certain files unusable, despite leaving systems operational and maintaining data. Ransomware will remain a major and rapidly growing threat in 2016, and the Mac OSX (operating system) will increasingly be targeted.

Employee Systems: Hackers will increasingly turn to the relatively insecure home systems of a business’s employees. In 2016, businesses are expected to provide more advanced security technology for employees to install on their personal systems, and to spend more on personnel training and security awareness initiatives.

Cloud Services: According to the report, the level of sensitive and confidential company data shared on business-oriented cloud services and platforms is alarming. Many businesses are at the mercy of their provider’s security controls and have little insight into their provider’s security posture. As a result, cybercriminals will increasingly hack into cloud services platforms.

Wearable Devices: The growing number of wearable devices, particularly their Bluetooth connection to a smartphone, is creating a target-rich environment for hackers. Breaches involving control apps for wearable devices, which are expected to increase in the next 12 to 18 months, will provide valuable data for spear-phishing attacks. For example, GPS data from a running app tied to a fitness tracker can be used to craft an email that is more likely to be opened. If a user visits a coffee shop after the gym, an attacker could write an email saying “I think you dropped this at the coffee shop this morning,” and attach a link to an infected image file.

Automobiles: Attacks on automobile systems will increase in 2016 because much of the hardware lacks foundational security principles. Without adequate security, cybercriminals may create transportation deadlocks, impact road safety and threaten people’s lives.

Stolen Data Warehouses: The accumulation of stolen data over the years is predicted to develop a robust market for stolen sensitive information in 2016. Specialized underground warehouses will surface, offering stolen personal data, compromised credentials and infrastructure details from multiple sources, which can be used to bypass standard security components.

Perhaps these predictions explain the growing number of businesses purchasing new cyber insurance policies or increasing coverage under existing cyber policies. Unlike traditional commercial insurance policies, Cyber Liability and Security Breach (Cyber Perils) Insurance policies protect against privacy injuries, such as identity theft, and cover the cost of complying with data breach notice laws.

We would be happy to provide you with more information about insurance for existing and emerging cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.

Why Are Risk Managers Increasingly Relying on Cyber Liability Insurance?

We hoped Anthem’s January data breach would be the last large-scale event of 2015. Our hopes were dashed by the Office of Personnel Management’s massive breach that exposed personal information of more than 20 million current, former and prospective federal employees and contractors. This is yet another reminder that every organization is at risk of suffering a data security breach.

Organizations should also know that the costs of a data security breach can be devastating. Consider the following results from NetDiligence’s 2014 analysis of 111 data breach insurance claims:

  • Most frequently exposed data: personally identifiable information (41%), private health information (21%) and payment card information (19%)
  • Most frequent cause: hackers (30%) and staff mistakes (14%)
  • Typical claims range: $30,000 to $400,000
  • Average claim payout: $733,109
  • Average per-record cost: $956.21
  • Average cost for crisis services: $366,484
  • Average cost for legal defense: $698,797
  • Average cost for legal settlement: $558,520

These staggering figures may explain the results of a 2015 survey of risk managers conducted by the Risk Management Society (RIMS). According to the survey, the top three first-party exposures are reputational harm (79%), business interruption (78%) and data breach response and notification (73%). Fifty-one percent of respondents purchased cyber insurance policies, while 74% are considering obtaining cyber coverage in the next 12 to 24 months.

The RIMS survey found that risk managers are buying the following coverages:

  • Breach notification costs (91%)
  • Cyber extortion (80%)
  • Network/business interruption (80%)
  • Data recovery (75%)
  • Fines and penalties (75%)
  • Reputational harm (44%)
  • Professional liability (43%)
  • Theft of trade secrets (29%)

The RIMS survey shows that risk managers are taking data security very seriously. Interestingly, the growing prevalence of cyber insurance suggests that preventative measures may not be enough. Even the most sophisticated security measures don’t always prevent data breaches.

The right Cyber Perils coverage can help organizations survive the continuing data breach epidemic. The key is finding a policy that meets organizational needs without unnecessary coverages. The complexity of cyber insurance makes it difficult to evaluate and compare various options, so an experienced insurance agent should be consulted to find coverage that is both adequate and affordable.

If you would like to learn more about insuring against cyber risks, contact us.

If you would like to subscribe to our newsletters please click here.

Is Anonymous Credit Card Data Really Anonymous?

Every business needs to be concerned about data security and cyber liability, which is why many are taking steps to protect their data and reduce the likelihood of experiencing a data security breach. Unfortunately, not every business believes they are at risk of experiencing a data security breach. Perhaps a recent study of credit card data will help these businesses realize that the risk of cyber liability is very real and can be very costly.

Researchers at the Massachusetts Institute of Technology found that anonymous credit card data isn’t so anonymous after all. According to the MIT study, removing personally identifiable information from credit card transaction data does not make it anonymous and does not make it safe for release to the public or to third parties.

The study analyzed credit card data of 1.1 million users in 10,000 stores over a 3-month period. Each credit card transaction was time-stamped and associated with a specific store. However, the data was ‘anonymized’ by stripping names, account numbers and obvious identifiers, such as addresses, phone numbers or other personally identifiable information.

Despite being ‘anonymized’, MIT researchers found that knowing four random spatiotemporal points (an individual’s location at a specific time) is enough to uniquely identify 90% of individuals and uncover their records. Consider the following example included in the study:

Let’s say that we are searching for Scott in a simply anonymized credit card data set. We know two points about Scott: he went to the bakery on 23 September and to the restaurant on 24 September. Searching through the data set reveals that there is one and only one person in the entire data set who went to these two places on these two days. Scott is re-identified, and we now know all of his other transactions, such as the fact that he went shopping for shoes and groceries on 23 September, and how much he spent.

Researchers also discovered that an additional piece of ‘anonymized’ data significantly increases the chances of being identified.

Although knowing the location of my local coffee shop and the approximate time I was there this morning helps to re-identify me, knowing the approximate price of my coffee significantly increases the chances of re-identifying me. In fact, adding the approximate price of the transaction increases, on average, the [risk of being identified] by 22%.

MIT researchers also studied the effects of gender and income on the likelihood of being identified. According to their results:

  • The odds of women being identified are 1.2 times greater than for men.
  • The odds of high-income people being identified are 1.7 times greater than for low-income people.
  • The odds of medium-income people being identified are 1.1 times greater than for low-income people.

Since individuals may be relatively easily identified by anonymous credit card data, MIT researchers suggest that simply removing names, home addresses, phone numbers, or other personally identifiable information may not be sufficient to protect the privacy of individuals. From a policy perspective, MIT researchers believe data protection mechanisms must move beyond the concepts of personally identifiable information and anonymity toward a more quantitative assessment of the likelihood that data can be used to identify individuals.

Until then, businesses should do everything in their power to protect their data and obtain insurance to manage their cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws.

If you would like to learn more about insuring against cyber risks, contact us.

If you would like to subscribe to our newsletters please click here.

Are You Protecting Customers’ Credit and Debit Card Data?

It’s hard to ignore the fact that data security breaches seem to be increasing in frequency and severity, particularly those involving credit and debit card data. Just ask Home Depot, Michaels Stores, Neiman Marcus, or their 50+ million customers whose payment card data may have been compromised in 2014. To reduce the chances of making the list in 2015, preventative measures must be taken by every business that accepts credit and debit card payments.

The PCI Security Standards Council developed the Payment Card Industry Data Security Standard (PCI DSS) to encourage and enhance cardholder data security. This standard includes 12 requirements.

Build and Maintain a Secure Network and Systems

  • Install and maintain a firewall to protect cardholder data.
  • Do not use defaults for system passwords or security parameters.

Protect Cardholder Data

  • Protect stored cardholder data.
  • Encrypt transmission of cardholder data.

Maintain a Vulnerability Management Program

  • Protect systems against malware and regularly update anti-virus software.
  • Develop and maintain secure systems and applications.

Implement Strong Access Control Measures

  • Restrict access to cardholder data to those who need to know.
  • Identify and authenticate system access.
  • Restrict physical access to cardholder data.

Regularly Monitor and Test Networks

  • Track and monitor all access to networks and cardholder data.
  • Regularly test security systems and processes.

Maintain an Information Security Policy

  • Maintain a policy that addresses information security for all personnel.

The PCI Security Standards Council also provides a number of tips and strategies to increase the security of payment card data, such as:

  • Never store Sensitive Authentication Data, such as the full track contents on the magnetic stripe or chip, card verification codes/values, or PINs.
  • Ask point-of-sale vendors about the security of payment card systems.
  • Do not store cardholder data that is not needed.
  • Consolidate and isolate cardholder data that is needed.

The Council notes that the PCI DSS provides minimum security requirements that may be enhanced by additional controls and practices. Various laws, rules or regulations may also require enhanced security measurers. For example, under the Fair and Accurate Credit Transaction Act (FACTA), electronically printed credit and debit card receipts given to customers cannot include a card’s expiration date or more than the last five digits of the card number.

Sometimes security measures aren’t enough to prevent a data security breach, so businesses should use insurance to manage their cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws. However, given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

A solid understanding of your insurance needs is the key to overcoming the quality versus cost argument. An experienced and reputable independent insurance agent can help you purchase insurance that is both economical and effective.

If you would like to learn more about insuring against cyber risks, contact us.

If you would like to subscribe to our newsletters please click here.

Protecting Against Emerging Data Security Threats

Cyber threats continue to top the list of concerns for individuals and businesses alike. With breaches becoming more common and more expensive, businesses are now discovering that steps must be taken to protect against data security breaches. Since understanding the risk is the first step to controlling it, let’s take a look at some observations made by Georgia Institute of Technology’s Information Security Center and Research Institute in their 2015 Emerging Cyber Threats Report.

Users are the greatest weakness to information security.

  • Though software vulnerabilities continue to be exploited, users remain the link most often exploited in attacks as cybercriminals continue to successfully abuse their trust.
  • Users often allow attackers to circumvent security measures.
  • Social engineering, which is also known as hacking humans, is a common and extremely effective way to attack systems. Sixty-seven percent of cyber attacks start with a phishing electronic communication sent by an attacker posing as a trustworthy person or business.
  • Training is an important piece of the security puzzle and one that businesses do not employ often enough. Forty-nine percent of businesses that do not perform employee security-awareness training pay the price — their annual losses are four times greater than those with a training process in place.

Attackers are increasingly targeting mobile devices.

  • As consumers and employees increasingly rely on mobile devices, their phones and linked cloud repositories have become treasure troves of information.
  • Increasing mobile app popularity and the proliferation of free apps relying on advertising for revenue have driven many developers to use vulnerable code that can be exploited. According to the report, in 2014, 91% of the top 200 iOS apps and 83% of the top 200 Android apps had some risky behavior.
  • Attackers follow the money, so the increasing use of mobile devices to make payments will draw their attention.
  • Android devices continue to bear the brunt of attackers’ focus. Since Android devices are targeted by malware 99% of time, users of these devices require better security measures and increased education about the risks.
  • Apple’s iOS ecosystem is not a safe haven. Researchers at Georgia Tech note that attackers have found ways around security measures, and that additional attacks should be expected.

Rogue workers can cause significant damage to a business.

  • The involvement of an insider causes the costs of data breaches to rise quickly.
  • Companies generally require more time to detect and respond to insider attacks, nearly 260 days, compared to 170 days for other attacks.
  • Incidents involving malicious insiders cost an average of $210,000 more to resolve.
  • Businesses should focus on protecting their “crown jewels” before expanding data-protection programs to cover broader kinds of information.
  • Businesses face a significant challenge looking for behavioral indicators that could detect the activities of a rogue insider.
  • Outreach to employees and access restrictions, such as splitting access rights to valuable data between two or more people, can make it much less likely for a single rogue insider to cause damage.

According to the report, the growing ‘Internet of Things’, which is the interconnection of uniquely identifiable devices (phones, tablets, etc.) to the Internet, will only make security issues more important in the future. By 2020, there could be 50 billion interconnected devices, so securing these devices and the data passed between them will be an ongoing challenge.

Since the risk of suffering a data security breach is likely to continue in the foreseeable future, businesses should consider insurance to protect against cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws. However, given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

If you would like to learn more about insuring against cyber risks, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

How Can You Prevent Identity Theft?

According to the Federal Trade Commission, identity theft continues to top the list of consumer complaints. In 2013, American consumers reported losing more than $1.6 billion to fraud, which is approximately $2,294 per incident. The highest reported age group for identity theft is 20-29, and the most common form of identity theft is tax- or wage-related, followed by credit card fraud, utilities fraud and bank fraud. Florida has the highest per capita rate of reported identity theft complaints, followed by Georgia and California.

Since October is National Cyber Security Awareness Month, now is the perfect time to learn about preventing identity theft. Here are some tips from the Insurance Information Institute.

  • Don’t carry unnecessary personal information (social security card, passport, etc.).
  • Prevent ‘shoulder surfers’ from seeing credit card numbers or PINs.
  • Always take credit card or ATM receipts.
  • Don’t give out personal information, whether on the phone, via mail or online, unless you initiated contact or you know the transmission will be secure.
  • Only use authenticated websites to conduct business online. Check for the locked padlock image or look for ‘https://’ rather than ‘http://’ in your browser window.
  • Be aware of phishing and pharming scams that use fake emails and websites to impersonate legitimate organizations. Exercise caution when opening emails and instant messages from unknown sources.
  • Never send personal, financial or password-related information via email.
  • Use up-to-date firewall, anti-spyware and anti-virus programs.
  • Monitor all financial accounts and review monthly statements to make sure all transactions are accurate.
  • Immediately contact your credit card or bank if you suspect a problem.
  • Order your credit report from the three major credit bureaus to make sure it’s accurate and includes only authorized activities. You are entitled to one free credit report per year.
  • Place passwords on your credit card, bank and phone accounts.
  • Don’t use passwords containing easily available information (mother’s maiden name, birth date, phone number, etc.) or any series of consecutive numbers.
  • Change passwords if you suspect a problem.
  • Shred documents containing personal information such as credit card numbers, bank statements, charge receipts or credit card applications.

In the event of identity theft, early detection is the key to limiting the damage. Here are some clues from the FTC that someone may have stolen your identity.

  • You see withdrawals from your bank account that you can’t explain.
  • You stop getting bills or other mail.
  • Debt collectors call you about debts that aren’t yours.
  • You find unfamiliar accounts or charges on your credit report.
  • The IRS notifies you that a tax return was already filed in your name.
  • A company where you do business or have an account suffers a data security breach.

Despite taking preventative measures, identity theft can still happen. However, insurance may be purchased to help victims of identity theft through the often expensive and time consuming battle to clear their name. Depending on the insurance company, identity theft coverage may be included under a homeowners’ policy, or it may be added by endorsement or obtained under a separate, stand-alone policy.

If you would like to learn more about identity theft insurance coverage, please contact us.

If you would like to subscribe to our newsletters please click here.

Here We Go Again with Another Massive Data Security Breach

Before the dust could settle on Target’s data security breach, news of a potentially larger one has surfaced. On September 18, 2014, Home Depot confirmed that it suffered a data breach involving the debit and credit card information of approximately 56 million customers. Target’s breach involved approximately 40 million cards.

Home Depot’s breach involved payment card information for purchases made at U.S. and Canadian Home Depot stores from April to September, 2014. According to Home Depot, criminals used unique, custom-built malware not seen previously in other attacks to breach payment card systems. Though their investigation is ongoing, Home Depot said names, card numbers, expiration dates, cardholder verification values and service codes may have been compromised.

Seeing yet another large business with substantial resources suffer a massive data security breach should be more than enough to confirm that data security breaches can happen to any organization. Though preventing data breaches is becoming more difficult, businesses can take steps to reduce the risk.

A subsidiary of Reinsurer Munich Re recently held a presentation with cybersecurity experts and risk managers to show how cybercriminals choose their targets and access their systems. This presentation provided several key takeaways for businesses.

  • Businesses are not only viewed as targets by cybercriminals, but also as conduits to attack a business’s clients.
  • Businesses must identify any data that may be valuable to others, and keep only what is needed.
  • Most hackers use email and browsers to access a business’s systems.

The cybersecurity presentation identified 10 ways for businesses to prevent a data breach.

  • Outsource payment processing (point-of-sale, web payments) to take advantage of their sophisticated and dedicated security measures.
  • Separate social media from financial activity by using a dedicated device for online banking and a different device for email and social media.
  • Don’t reuse passwords and don’t trust websites to store them for you. Set up a two-factor authentication process that verifies identity by sending a secret code to your phone.
  • Train employees to protect sensitive and confidential information. Remind employees that most malicious attacks involve email, and that they should alert others when suspicious emails are received.
  • Identify risks by evaluating systems and networks, including email infrastructure and browser vulnerability. Learn how business associates (vendors, suppliers, partners) handle data security.
  • Mandate encryption for all data that is stored (at rest) and transmitted (in motion), and avoid the use of Wi-Fi networks if possible.
  • Use the latest web browser version that is available rather than relying on individual patches and updates.
  • Update operating systems to take advantage of built-in security improvements.
  • Secure routers connecting business computers to the Internet. Set strong administrator passwords and, if Wi-Fi is necessary, use a WPA2 password.
  • Encrypt backup data and store it off-site.

Home Depot is currently dealing with the consequences of its data security breach by investigating the breach, updating data security systems, notifying potential victims, providing free identity theft protection and adjusting its public relations to minimize the damage to its reputation. The costs of these efforts can be staggering. For businesses lacking the resources of the Target’s and Home Depot’s, these costs can be devastating.

As we have seen, nothing is foolproof, so businesses should use insurance to protect against cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws. However, given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

If you would like to learn more about insuring against cyber risks, contact us.

If you would like to subscribe to our newsletters please click here.

Understanding Business Insurance: What is BOP?

Many businesses take a piecemeal approach to buying insurance. One policy for property insurance, another for liability insurance, and so on. Unfortunately, this approach can be difficult and time consuming, particularly for small- and medium-sized businesses. For these businesses, a Business Owners Policy, a BOP, may be an attractive alternative.

A BOP is a pre-packaged bundle of coverages that insurance companies offer to eligible small- and medium-sized businesses. BOPs are designed to provide a number of essential insurance coverages in a convenient and cost effective manner. BOPs typically provide:

  • Property insurance to cover damage to buildings and contents;
  • Business income (business interruption) insurance to cover the loss of income resulting from a covered loss that Disrupts business operations; and
  • Liability insurance to protect against liability claims for bodily injury and property damage occurring on a business’s premises or arising out of its operations.

Depending on the insurance company, additional coverages may be included in a BOP, or added for an additional premium, such as:

  • Cyber Liability
  • Employment Practices Liability
  • Valuable Papers and Records
  • Personal and Advertising Liability
  • Liquor Liability
  • Equipment Breakdown
  • Sale and Disposal Liability coverage for self storage facilities

Though BOP eligibility requirements can vary significantly among insurance companies, BOPs are typically limited to small- and medium-sized businesses, which are generally those with fewer than 100 employees and annual revenues of less than $5 million. BOPs may also not be available to businesses operating in specific industries or those with highly specialized or high-risk operations.

Alternatively, BOPs may not be the solution for some businesses, even those that are eligible for them. For example, some businesses may require higher limits or broader coverage forms that are not available in a BOP. There are also a number of coverages that BOPs do not provide, such as workers compensation, commercial automobile and professional liability insurance. Even with a BOP, additional insurance policies may still be necessary.

Since BOPs are customized insurance products, it is important to note that coverage options and features (limits, exclusions, etc.) can vary significantly among insurers. Unfortunately, the lack of uniform eligibility requirements, coverage options and policy features makes it difficult to understand and compare the various BOP options that may be available. An experienced insurance agent should be consulted throughout the process.

If you would like to learn more about BOPs or the various options that may be available to insure your business, contact us.

If you would like to subscribe to our newsletters please click here.

Every Business Should be Worried about Cyber Liability

Regardless of industry, cyber attacks and data breaches expose businesses to potentially enormous losses and liabilities. According to a report by the Insurance Information Institute (III), the potential economic fallout from the cyber threat cannot be underestimated, particularly because the number of publicly disclosed data breaches soared from 449 in 2012 to 614 in 2013. This is likely why cyber risk cracked the top 10 list of global business risks in 2014.

According to the III report:

  • The majority of data breaches affected the medical/healthcare industry (43.8%) and business organizations (34.4%).
  • Business organizations accounted for the majority of records exposed by data breaches in 2013 (84%).
  • A report by PWC found that cyber crimes are considered a high-level threat.
  • Cyber attacks have become more frequent and increasingly costly for companies to resolve.
  • The average annualized cost of cyber crime is estimated to be $11.6 million per year.
  • Denial of service is the costliest cyber crime, followed by malicious insiders and web-based attacks.
  • The average time to resolve a cyber attack is 32 days, with an average cost of just over $1 million during this 32-day period.
  • Malicious or criminal attacks, such as malware infections, criminal insiders, phishing/social engineering and SQL injections, cause 42% of data breaches, followed by human error (30%) and system glitches (29%).
  • U.S. organizations have the highest lost business costs at an average of $3.3 million.
  • Businesses may be exposed to even greater risks from new technologies, such as cloud computing, which uses a network of remote servers over the Internet to store, manage and process data, rather than a local server.

The III report notes that upon experiencing a data breach, many businesses turn to their insurance policies to cover their loss. Unfortunately, many of these losses are not covered by traditional insurance policies. To protect against cyber threats, businesses need specific cyber insurance policies that provide a number of specialized coverages, such as:

  • Loss/corruption of data
  • Business income/interruption
  • Liability coverage (first- and third-party coverage)
  • Data breach coverage (including costs of complying with statutory notice requirements)
  • Cyber extortion
  • Crisis management
  • Identity theft

Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.