Every Month Should Be Cybersecurity Awareness Month

By Anita Byer, Setnor Byer Insurance & Risk

October may officially be Cybersecurity Awareness Month, but that doesn’t mean businesses can afford to take the rest of the year off. Gone are the days when cybersecurity was seen as an ancillary function. Today, businesses should be thinking of cybersecurity as an essential core function, because that’s precisely what it has become. A single cybersecurity incident can threaten a business’s operations, reputation, bottom line, and in some cases, its very survival.

Protecting against cyber risks, like other operational risks, requires a holistic approach. According to the Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA), businesses need to develop and maintain a culture of cyber readiness. This is obviously easier said than done, but it’s not impossible. CISA recommends incorporating the following essential elements to increase the likelihood of successfully creating a culture of cyber readiness.

Your Leaders. Workplace culture often reflects leadership, so any changes must start at the top. Ownership and management must invest the time, money and resources needed to effectively drive cybersecurity strategies, policies and procedures.

Your People. Making people part of the first line of defense against cyberattacks reduces vulnerabilities and drives a culture of ownership. Personnel must be trained to recognize cybersecurity risks, like phishing, password hacks and malware.

Your Systems. Cybersecurity requires knowing which devices are connected to your network, which applications are in use, who has access to these, and the security measures in place. A cyber-ready business proactively keeps its systems up-to- date and secure.

Your Surroundings. Access to your digital environment, like access to your physical workplace, must be limited. Setting access privileges and establishing operational procedures requires knowing who operates on your technology and with what level of authorization and accountability. User and access management is a complex, yet crucial component of cybersecurity.

Your Data. Information that is stored, processed or transmitted must be protected. Identify and backup all critical and sensitive data and have plans in place to recover and restore systems, networks and data in the event of an attack.

Your Crisis Response. Plan, prepare and conduct drills for cyber-attacks and incidents, like a fire drill. This involves having incident response plans and procedures, trained staff, assigned roles and responsibilities, and incident communications plans.

While a culture a cyber readiness can significantly enhance cybersecurity, it isn’t foolproof. Every business should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Identity Theft Alert: FBI, HHS Warn of Emerging Fraud Schemes Involving COVID-19 Vaccines

Cyber criminals routinely incorporate the “crisis-du-jour” into scams to increase their likelihood of success. COVID-19, it seems, is no exception. In a single week, Google saw 18 million coronavirus-related malware and phishing emails…per day! It’s gotten so bad that the Federal Bureau of Investigation, the Department of Health and Human Services and the Centers for Medicare & Medicaid Services found it necessary to warn the public about emerging fraud schemes related to COVID-19, particularly those involving COVID-19 vaccines.

According to the HHS Office of Inspector General, criminals are using calls, text messages, social media and even door-to-door visits to perpetrate their crimes. They offer vaccine-related benefits in exchange for personal information. HHS warns, however, that these benefits are unapproved and illegitimate and that scammers use your personal information to fraudulently bill federal health care programs and commit medical identity theft.

To protect against these schemes, authorities urge everyone to be on the lookout for potential indicators of fraud, including the following.

  • Advertisements or offers for early access to a vaccine upon payment of a deposit or fee.
  • Requests for cash payments to get vaccinated or to be put on a COVID-19 vaccine waiting list.
  • Offers to undergo additional medical testing or procedures when obtaining a vaccine.
  • Offers to sell or ship doses of a vaccine (domestically or internationally) in exchange for payment of a deposit or fee.
  • Unsolicited emails, texts, calls or personal contact from someone claiming to be from a medical office, insurance company or COVID-19 vaccine center requesting personal or medical information to determine eligibility to participate in clinical vaccine trials or obtain the vaccine.
  • Claims of FDA approval for a vaccine that cannot be verified.
  • Advertisements for vaccines through social media, email, phone, texts, online or from unsolicited or unknown sources.
  • Individuals contacting you in person, by phone or by email to tell you the government requires you to receive a COVID-19 vaccine.

Cyber criminals are nothing if not creative. They are constantly hatching new schemes to stay a step ahead of the authorities. Fortunately, HHS offers a simple, yet effective tip for protecting you and your family from cyber criminals and identity thieves—do not share your personal information with those who are unknown or unsolicited.

When preventative measures fail, insurance is available to help victims through the expensive and time-consuming process of recovery. Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Don’t Let Weak Site Security Compromise Your Business’s Cybersecurity

Setnor Byer Insurance & Risk

Small businesses spend a lot of time and money to protect their sensitive and confidential information, and rightfully so. Data breaches can lead to crippling, often insurmountable financial and reputational harm. Unfortunately, many businesses overlook the most basic security measures. Cyber criminals, for example, pose the biggest threat to data security, so most businesses focus almost exclusively on cybersecurity while paying little or no attention to physical (site) security. This can prove disastrous because sophisticated firewalls and advanced security software cannot stop someone from stealing a flash drive or paper file containing sensitive information.

According to the Federal Trade Commission, cybersecurity begins with strong physical security that effectively protects sensitive or confidential information in paper files and electronic devices (hard drives, flash drives, laptops, point-of-sale devices, etc.). The FTC offers the following tips for maintaining physical security.

  • Store paper files and electronic devices containing sensitive information in a locked cabinet or room to keep them secure.
  • Train employees to put paper files in locked file cabinets, log out of networks and applications before leaving and never leave files or devices with sensitive data unattended.
  • Limit physical access to records or devices containing sensitive data to only those who need it.
  • Keep track of documents and devices containing sensitive data so they can be handled accordingly.

To protect sensitive data stored on devices,

  • Require passwords that are long, complex and unique.
  • Require multi-factor authentication, like a password and a temporary code, to access sensitive information.
  • Limit the number of incorrect login attempts allowed to unlock devices.
  • Encrypt portable media, including laptops and thumb drives, that contain sensitive information.

Sensitive and confidential business data can be stolen online or onsite, so businesses must make physical (site) security a key component of their cybersecurity protocols. Since security measures aren’t always enough, small and medium-sized businesses should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches

Ransomware Attacks Are Becoming More Common and More Expensive

Setnor Byer Insurance & Risk

Did you know that the average ransomware demand in the first quarter of 2020 was $111,605? Ransomware is a type of malware that encrypts critical data so it cannot be accessed without a decryption key. Victims must, you guessed it, pay a ransom to get the key. The costs associated with a successful attack, which can far exceed the ransom, typically include investigation and remediation expenses and lost revenue due to downtime. Ransomware can also inflict insurmountable brand damage and reputational harm.

According to the Federal Trade Commission (FTC), hackers try to exploit network or server vulnerabilities to access a target’s data, but the malicious code used to launch ransomware attacks is often installed on devices and networks by:

  • scam (phishing) emails that appear legitimate;
  • infected websites; and
  • online ads, which often appear on websites you know and trust.

The FTC recommends the following measures to reduce the risk of a successful ransomware attack.

  • Have a Plan. Businesses need a plan to remain operational after a ransomware attack. Plans should be written and shared with those needing to know.
  • Back up Data. Regularly save important data to a drive or server that’s not connected to a network. Make this part of your routine business operations.
  • Update Security Software. Always install the latest patches and updates. Consider adjusting your settings to update automatically.
  • Train Staff. Train all employees how to identify and avoid common threats. Provide examples of the most common ways devices and networks become infected.

If your business experiences a ransomware attack, the FTC recommends taking the following steps.

  • Limit the damage. Immediately disconnect infected devices from your network.
  • Contact Authorities. Immediately report the attack to local and federal authorities (local FBI office).
  • Provide Required Notices. If data has been exposed, compromised or stolen, notify authorities and affected individuals pursuant to any applicable data breach notification laws.

Preventative measures can effectively reduce the risk of a ransomware attack, but they’re not foolproof. Every business should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

October is National Cybersecurity Awareness Month

Cybersecurity Awareness Month was launched in 2004 to promote online safety and security. This is particularly important in 2020 because so many things took a back seat when coronavirus disease 2019 arrived. COVID-19 may dominate the headlines, but data security breaches continue to pose a serious threat to small businesses nationwide. According to the Federal Trade Commission, cyber criminals target businesses of all sizes, so all are encouraged to take advantage of Cybersecurity Awareness Month 2020.

This year’s theme, “Do Your Part. #BeCyberSmart,” is intended to empower individuals and organizations to own their role in maintaining cybersecurity. The key message in 2020 emphasizes the importance of doing your part. “If you connect it, protect it.” Small businesses can reduce the risk of a cybersecurity incident by educating employees about basic cybersecurity measures and putting them in practice. The FTC suggests various measures that every small business should have in place.

  • Update Software. This includes apps, web browsers and operating systems. Set updates to happen automatically.
  • Back Up Files. Regularly back-up important files (offline, external hard drive, in the cloud, etc.).
  • Require Strong Passwords. All devices should be password protected. A strong password is at least 12 characters that includes numbers, symbols and capital and lowercase letters. Never reuse or share passwords.
  • Encrypt Devices. Encryption protects information from unauthorized access. Any devices containing sensitive information should be encrypted. This includes laptops, tablets, smartphones, removable drives, backup tapes and cloud storage solutions.
  • Use Multi-Factor Authentication. Require multi-factor authentication to access sensitive information. This requires additional steps beyond logging in with a password, like entering a temporary code or providing additional identifying information.
  • Secure Routers and Wireless Networks. Change the default name and password, turn off remote management and log out as the administrator once the router is set up. Make sure your router offers WPA2 or WPA3 encryption, and that it’s turned on.
  • Train Employees. Create a culture of security by implementing a regular schedule of mandatory employee training. Update employees about new risks or vulnerabilities.
  • Have a Plan. A response plan should be in place before a data breach happens. It should include plans for protecting and saving data, maintaining operations and notifying customers affected by the beach.

Implementing, maintaining and updating security policies and procedures is important, but it’s not always enough. Small and medium-sized businesses should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Cybersecurity Tips for Small Businesses

When it comes to data security breaches, things aren’t getting any better. According to Risk Based Security’s 2019 MidYear QuickView Data Breach Report, more than 3,800 data security breaches were reported in the first six months of 2019. More than 4.1 billion records were compromised. When compared to midyear 2018, the number of reported breaches is up 54%. The number of exposed records is up 52%.

Breaches involving big businesses make the headlines, but small businesses are at risk too. According to the Federal Communications Commission, every small business needs a cybersecurity strategy to protect their business, their customers and their data from constantly growing and evolving cybersecurity threats. The FCC has the following tips for small businesses.

Train Employees. Educate employees about data security. Establish basic security practices, policies and Internet use guidelines that include specific penalties for violations.

Protect Data, Devices and Networks. Using the latest security software, web browsers and operating systems can help defend against viruses, malware and other threats. Set antivirus software to run a scan after each update. Install other key software updates as soon as they are available.

Protect Mobile Devices. Mobile devices, particularly those with sensitive data or network access, can create significant security risks. Require employees to password-protect devices, encrypt data and install security apps to protect data on public networks. Implement and enforce reporting procedures for lost or stolen equipment.

Backup Sensitive Data. Require regular backups of critical data, including documents, spreadsheets, databases, financial files, human resources files and accounting files. Backup data automatically if possible, or at least weekly. Store backups offsite or in the cloud.

Secure Wi-Fi Networks. Make sure networks are secure, encrypted and hidden. Network names should not be broadcast. Routers should be password protected.

Limit Access and Authority. Employees should only have access to data needed to do their jobs. Employees should not be able to install any software without permission.

Passwords and Authentication. Require employees to use unique passwords and change passwords every three months. Consider implementing multi-factor authentication that requires additional information beyond a password to gain access.

Data security threats have become a constant concern for small businesses. Implementing, maintaining and updating security policies and procedures is important, but it’s not always enough. Small and medium-sized businesses should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Every Small Business Needs a Cyber Security Strategy

Did you know that more than 50 percent of small and medium-sized businesses (SMBs) experienced a cyber-attack in the previous year? Cybercriminals tend to be opportunistic. They target the unprepared. Unfortunately, far too many SMBs don’t have a plan to prevent or respond to cyber-attacks.

SMBs can significantly reduce the likelihood of falling victim to cybercriminals by preparing a cyber security strategy. Let’s look at the essential elements of an effective strategy.

Prevention. The primary goal of every cyber security strategy should be prevention. An effective prevention strategy requires:

Detection. SMBs must be able to detect cyberattacks when they happen. An effective detection strategy requires:

  • Technology. Cyberattacks are so sophisticated that SMBs need quality intrusion detection systems that are routinely updated to remain current with evolving threats.
  • Real-Time Alerts. Tracking attacks provides data that can be used to generate real-time alerts.
  • Documentation. Records make it easier to evaluate attack trends and characteristics and update strategies accordingly.

Mitigation. A rapid response to a cyberattack is critical to limiting the damage. An effective mitigation strategy includes:

  • Response Plans. Once an attack is detected, SMBs must be ready to contain, assess and respond to the threat. A response plan should specifically identify personnel and designate responsibilities in the event of an attack.
  • Periodic Evaluations. Remediation and mitigation strategies must be reviewed and updated periodically to remain current with constantly evolving cyber threats.

Insurance. Preparation is important, but it isn’t always enough. SMBs should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Did You Know…Data Breaches Exposed More Than 18 Million Records PER DAY?

It looks like 2018 is going to be a record year for data breaches…in a bad way. Gemalto, a global digital security provider, released its Breach Level Index for the first half of 2018. It revealed a mix of good, bad and ugly. When compared to the first half of 2017, the number of data breaches worldwide actually went down. Unfortunately, the number of lost, stolen or compromised data records went up. Now for the ugly. This number went up 72 percent!

During the first six months of 2018, there were 944 data breaches worldwide, nearly 60 percent occurred in North America. As a result of these breaches, more than 3.3 billion data records were compromised or exposed. That works out to 18.5 million records per day. Nearly three quarters of a million records per hour!

According to the Breach Level Index:

  • More than 76 percent of the records breached involved social media, including breaches at Facebook (2.1 billion records) and Twitter (336 million records).
  • Malicious outsiders caused 56 percent of the data breaches.
  • Attacks by malicious insiders fell by 60 percent.
  • 879 million data records were lost by accident.
  • Identity theft remains the leading type of data breach.
  • The number of records stolen through identity theft breaches increased by 757 percent.
  • Financial access incidents decreased in frequency but increased in severity.
  • The healthcare industry experienced the most data breaches of any industry (27 percent).
  • 20 percent of all breaches had an unknown number of compromised data records.
  • Only one percent of the compromised data records were encrypted.

Data security has become a universal concern. Every business is at risk. None are immune. This explains the growing popularity of cyber liability insurance policies. Businesses can purchase Cyber Perils coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Do Standard Crime Insurance Policies Cover Business Email Compromise (BEC) Attacks?

Business Email Compromise (BEC) attacks are sophisticated scams that commonly use social engineering, phishing and spoofing to compromise legitimate business e-mail accounts. In 2017, the FBI reported receiving 15,690 BEC complaints with BEC losses topping $675 million. The FBI warns small, medium and large businesses alike that constantly expanding and evolving BEC attacks put them all at risk.

Businesses can and should take preventative measures to protect against BEC attacks, but what happens when they fail? Are BEC attacks considered a type of Computer Fraud that is covered under a standard crime insurance policy? Well…it depends.

Losses and claims associated with BEC attacks are relatively new. Standard crime insurance policies are not. Like Über and Airbnb, BEC attacks don’t fit neatly into standard insurance policies, so coverage isn’t always clear. As expected, this coverage confusion produced coverage disputes that became coverage lawsuits.

Lawsuits can provide clarity because they require courts to interpret and apply specific insurance policies and provisions. But, that’s not necessarily the case with BEC attacks because some federal appellate courts don’t necessarily agree on whether a BEC attack constitutes Computer Fraud under a standard crime policy.

Since coverage isn’t obvious one way or the other, courts must dig deep into the policy and relevant case law to determine whether coverage exists. As the following cases illustrate, this can create conflicting case law.

Apache Corporation (5th Circuit 2016). A BEC attack was part of a scam to change the account number used to pay a legitimate vendor. Apache was unaware of the fraud until the vendor told them payments were overdue. By then, approximately $7 million had been diverted to the fraudulent account.

The Fifth Circuit ruled that Apache’s losses are not covered because the BEC attack was merely incidental to an overall scheme to defraud. According to the court, most fraudulent schemes involve some form of computer-facilitated communication, and interpreting Computer Fraud to include any fraudulent scheme that uses email would convert a crime policy’s computer-fraud provision into one for general fraud. Regrettably, the court concluded, Apache sent payment for a legitimate invoice to the wrong bank account.

American Tooling Center (6th Circuit 2018). American Tooling filed a Computer Fraud claim after a BEC attack tricked the Treasurer to wire $834,000 to a fraudulent account. The Sixth Circuit ruled that American Tooling’s losses are covered because the BEC attack constituted Computer Fraud under the crime insurance policy.

According to the court, an impersonator used a computer to send fraudulent emails that fraudulently caused American Tooling to transfer money to the impersonator. The Computer Fraud provision, the court noted, does not require that the fraud cause any computer to do anything. The court said that if the insurance company wanted to limit Computer Fraud coverage to hacking or unauthorized computer access it could have done so in the policy.

These cases didn’t involve identical facts or policy forms, yet they reveal potentially significant conceptual differences about the nature of BEC attacks and the scope of Computer Fraud coverage. Though the circumstances were quite similar, the outcomes were very different.

As a result, determining whether a BEC attack is covered under a standard crime policy may depend, at least in part, on where it occurred. This can make it difficult for businesses to effectively evaluate, mitigate and insure against the serious risk posed by BEC attacks.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats.

To receive regular insurance and risk management informational updates, please subscribe to our newsletter.

Social Engineering Fraud: What is It?

Social Engineering Fraud is the process through trick or scheme of gaining the confidence of someone, and inducing them to part with money or something valuable. This infographic shows you what to look for and some tips to avoid Social Engineering Fraud in your business. 

Continue reading “Social Engineering Fraud: What is It?”