What is Multi-Factor Authentication and Why Should Everyone Be Using It?

By Anita Byer, Setnor Byer Insurance & Risk

Did you know that the majority of data breaches are driven by credential theft? Hackers are constantly probing the Internet trying to steal login credentials. One uninformed or unsuspecting user or one careless act, and that’s it. Your world is now their oyster. Fortunately, there is a simple way to keep this from happening. It’s called multi-factor authentication, and it’s very effective. In fact, according to Microsoft, MFA can block over 99.9 percent of account compromise attacks.

Multi-factor authentication (MFA) is a security process that requires more than one method of authentication from independent sources to verify a user’s identity. In other words, a person cannot access a system or account without first providing two or more authentication factors (credentials) that uniquely identify that person. These credentials can be:

  • Something You Know (password, PIN, security question)
  • Something You Have (security token/app, verification via text, call or email)
  • Something You Are (fingerprint, facial recognition, voice recognition)

A common form of MFA requires users to enter their username and password (first factor). The system will then generate and send a unique one-time code (second factor) to the user’s phone or email. If this code is not entered before it expires, account access will be denied. The level of security increases with each authentication factor added to the login process. As you can see, MFA requires hackers to steal more than just your password to access your accounts, like your phone or your thumb(print).

Small and medium-sized businesses should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws.

According to the Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA), MFA should be used whenever possible, particularly for systems, networks and accounts containing sensitive financial, business or personal data. MFA should also be deployed to Internet-facing systems, such as email, remote desktop and Virtual Private Network (VPNs).

MFA makes it very difficult for hackers to access personal or business systems, networks and accounts, like remote access technology, email, ACH and billing systems, even with the password. While some accounts require MFA, others make it optional. If you have the option to enable MFA, do it now. Systems that still don’t have MFA capabilities are way behind the curve, and should probably be avoided.

Please contact us to learn about insurance coverage that is specifically designed to protect against cyber threats, data security and identity theft.

Identity Theft Alert: FBI, HHS Warn of Emerging Fraud Schemes Involving COVID-19 Vaccines

Cyber criminals routinely incorporate the “crisis-du-jour” into scams to increase their likelihood of success. COVID-19, it seems, is no exception. In a single week, Google saw 18 million coronavirus-related malware and phishing emails…per day! It’s gotten so bad that the Federal Bureau of Investigation, the Department of Health and Human Services and the Centers for Medicare & Medicaid Services found it necessary to warn the public about emerging fraud schemes related to COVID-19, particularly those involving COVID-19 vaccines.

According to the HHS Office of Inspector General, criminals are using calls, text messages, social media and even door-to-door visits to perpetrate their crimes. They offer vaccine-related benefits in exchange for personal information. HHS warns, however, that these benefits are unapproved and illegitimate and that scammers use your personal information to fraudulently bill federal health care programs and commit medical identity theft.

To protect against these schemes, authorities urge everyone to be on the lookout for potential indicators of fraud, including the following.

  • Advertisements or offers for early access to a vaccine upon payment of a deposit or fee.
  • Requests for cash payments to get vaccinated or to be put on a COVID-19 vaccine waiting list.
  • Offers to undergo additional medical testing or procedures when obtaining a vaccine.
  • Offers to sell or ship doses of a vaccine (domestically or internationally) in exchange for payment of a deposit or fee.
  • Unsolicited emails, texts, calls or personal contact from someone claiming to be from a medical office, insurance company or COVID-19 vaccine center requesting personal or medical information to determine eligibility to participate in clinical vaccine trials or obtain the vaccine.
  • Claims of FDA approval for a vaccine that cannot be verified.
  • Advertisements for vaccines through social media, email, phone, texts, online or from unsolicited or unknown sources.
  • Individuals contacting you in person, by phone or by email to tell you the government requires you to receive a COVID-19 vaccine.

Cyber criminals are nothing if not creative. They are constantly hatching new schemes to stay a step ahead of the authorities. Fortunately, HHS offers a simple, yet effective tip for protecting you and your family from cyber criminals and identity thieves—do not share your personal information with those who are unknown or unsolicited.

When preventative measures fail, insurance is available to help victims through the expensive and time-consuming process of recovery. Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Scam Alert: Tax Season Is Identity Theft Season

Should you be concerned about taxpayer identity theft? Here’s a hint. Tax Identity Theft Awareness Week starts February 3, 2020. As a general rule, anything worthy of having its own dedicated Awareness Week deserves your full attention.

Tax-related identity theft occurs when someone uses stolen personal information to file a tax return claiming a fraudulent refund. The problem has become so serious that the Internal Revenue Service has issued numerous publications about safeguarding taxpayer data and preventing identity theft. According to the IRS, you should be alert to possible tax-related identity theft if:

  • you get a letter from the IRS inquiring about a suspicious tax return that you did not file;
  • you can’t e-file your tax return because of a duplicate Social Security number;
  • you get a tax transcript in the mail that you did not request;
  • you get an IRS notice that an online account has been created in your name or that your existing account has been accessed or disabled when you took no action;
  • you get an IRS notice that you owe additional tax or refund offset, or that you have had collection actions taken against you for a year you did not file a tax return; or
  • IRS records indicate you received wages or other income from an employer you didn’t work for.

To protect against taxpayer identity theft, the IRS recommends that taxpayers:

  • Use current security software (firewalls, virus/malware protection, file encryption). Make sure it updates automatically.
  • Treat personal information like cash. Don’t leave it lying around.
  • Use strong, unique passwords and 2-Factor Authentication.
  • Avoid phishing scams and malware that often come in emails that appear to come from a trusted source and emails with urgent messages.

Finally, the IRS wants everyone to know that they will never:

  • initiate contact by email, text or social media to request personal or financial information;
  • call taxpayers with threats of lawsuits or arrests; or
  • call, email or text to request taxpayers’ Identity Protection PINs.

When preventative measures fail, insurance is available to help victims through the often expensive and time-consuming process of recovery. Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Cyber Liability: A BIG Risk for Small Businesses

Did you know that small businesses experience cyber incidents at roughly the same rate as drivers experience car accidents? Though most of us would never go without auto insurance, a majority of small businesses don’t have cyber liability insurance coverage. According to the 2018 Small Business Cyber Insurance and Security Spotlight Survey conducted by the Insurance Information Institute and J.D. Power:

  • 10 percent of the small businesses surveyed suffered at least one cyber incident in the prior year.
  • The average cyber-related loss was $188,400. In 2016, the average loss was $73,000.
  • Nearly 60 percent of small businesses are very concerned about cyber incidents.
  • 59 percent do not have cyber insurance coverage.

The potential impacts of a cyber incident that most concern small businesses include:

  • financial loss (47 percent);
  • information breach / theft (35 percent);
  • reputation / brand image issues (14 percent); and
  • regulatory / governance and legal issues (4 percent).

According to the survey, businesses with cyber insurance often had similar coverages, including coverage for:

There is one last thing to consider if your small business still doesn’t have cyber insurance coverage. According to the survey, 97 percent of the insured small businesses that experienced a cyber incident indicated that their cyber insurance policies adequately covered their losses. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Did you know that small businesses experience cyber incidents at roughly the same rate as drivers experience car accidents? Though most of us would never go without auto insurance, a majority of small businesses don’t have cyber liability insurance coverage. According to the 2018 Small Business Cyber Insurance and Security Spotlight Survey conducted by the Insurance Information Institute and J.D. Power:

Have Data Security Breaches Become the New Normal?

It has gotten to the point where we can barely keep up with all the data security breaches. We are no longer surprised to hear that another data breach exposed the sensitive personal information exposed of thousands (or millions!) of people. What’s worse is that many of us are no longer concerned. We have become complacent.

Taking a callous attitude toward data breaches can be risky. Just because data breaches are more common doesn’t make them less harmful. According to a study by Javelin Strategy & Research, 15.4 million U.S. consumers had $16 billion stolen in 2016. Identity thieves have stolen nearly $110 billion in the past six years.

Things got worse in July 2017, when Equifax, one of the three major credit reporting agencies, discovered a massive data breach that could impact approximately 143 million U.S. consumers. Equifax reports that the exposed information:

  • Social security numbers;
  • Birth dates;
  • Addresses;
  • Driver’s license numbers; and
  • Credit card numbers for approximately 209,000 consumers.

How significant is this? According to the Federal Trade Commission (FTC), if you have a credit report, there is a good chance that you’re one of the 143 million American consumers who had their sensitive personal information exposed. If so, the FTC recommends taking the following protective measures.

  • Check your credit reports from all three credit reporting agencies (including Equifax). You can do this for free by visiting annualcreditreport.com. Accounts or activity that you don’t recognize could indicate identity theft.
  • Consider placing a credit freeze on your files. A credit freeze makes it harder for someone to open a new account in your name, but it won’t prevent a thief from making charges to existing accounts.
  • If you decide against a credit freeze, consider placing a fraud alert on your files. This warns creditors that you may be an identity theft victim and that they should verify that anyone seeking credit in your name really is you.
  • Monitor credit card and bank accounts closely for charges you don’t recognize.
  • File your taxes early, so an identity thieve uses your Social Security number to get a tax refund or a job. Respond right away to letters from the IRS.

Taking measures to protect against identity theft are important, but they’re not always enough. That’s why you should consider insurance that is specifically designed to protect both individuals and businesses against identity thieves and hackers. For example, identity theft coverage can help individuals cover the cost of clearing their name. Cyber Liability and Security Breach (Cyber Perils) coverage can protect businesses against various cyber threats, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Additional information is also available in our weekly Risk Management Newsletters.

How Can You Limit the Damage Caused by Identity Theft?

What’s worse than filing your taxes? Finding out that your return was already filed and your refund check was already cashed. Yep, that’s definitely worse. Unfortunately, tax season has become the time of year when many first discover that their identities have been stolen.

According to Javelin Strategy & Research’s 2017 Identity Fraud Study, there were 15.4 million U.S. victims of identity theft in 2016, which is 16 percent higher than 2015. It was the highest rate since Javelin began tracking identity fraud in 2003.

So, what should you do if your identity has been stolen? According to the Federal Trade Commission (FTC), you must take immediate action to limit the damage.

What to do right away.

Contact the fraud department of each company (retailer, bank, etc.) where you know fraud occurred. Explain that someone stole your identity and ask them to close or freeze the accounts so no one can add new charges unless you agree. Change logins, passwords and PINS for your accounts.

Contact one of the three credit bureaus to place a free 90-day fraud alert. That company must tell the other two. A fraud alert makes it harder for someone to open new accounts in your name. When you have an alert on your report, a business must verify your identity before it issues new credit in your name.

Get your credit reports from Equifax, Experian and TransUnion. Review your reports and note any accounts or transactions you don’t recognize.

Report identity theft to the FTC. The FTC will create an Identity Theft Report and recovery plan. An identity theft report proves to businesses that someone stole your identity. It also guarantees you certain rights.

File a report with your local police department. Tell the police someone stole your identity and that you need to file a report. Ask for a copy of the police report.

What to do next.

Close new accounts. Ask the fraud department of each business where an account was opened to close the account. Request a confirmation letter and keep a record of who you contacted and when.

Remove fraudulent charges from your accounts. Let the fraud department know which charges are fraudulent and ask that they be removed from your account. Request a confirmation letter and keep a record of who you contacted and when.

Correct your credit report. Write each of the three credit bureaus. Identify what information on your report came from identity theft and ask them to block that information. You have the right to block fraudulent information so that it won’t show up on your credit report and companies can’t try to collect the debt from you. If you have an Identity Theft Report, credit bureaus must honor your request to block this information.

Consider an extended fraud alert or credit freeze. Both can help prevent further misuse of your personal information, but there are important differences between the two. For example, an extended fraud alert allows access to your credit reports as long as steps are taken to verify your identity. A credit freeze stops all access until it’s removed. Though fraud alerts are free to place and remove, there may be small fees associated with credit freezes.

Protective measures to protect against identity theft are important, but they’re not always enough. However, there is insurance that is specifically designed to protect both individuals and businesses against identity thieves and hackers. For example, identity theft coverage can help individuals cover the cost of clearing their name. Cyber Liability and Security Breach (Cyber Perils) coverage can protect businesses against various cyber threats, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Additional information is also available in our weekly Risk Management Newsletters.

Are You Protecting Customers’ Credit and Debit Card Data?

It’s hard to ignore the fact that data security breaches seem to be increasing in frequency and severity, particularly those involving credit and debit card data. Just ask Home Depot, Michaels Stores, Neiman Marcus, or their 50+ million customers whose payment card data may have been compromised in 2014. To reduce the chances of making the list in 2015, preventative measures must be taken by every business that accepts credit and debit card payments.

The PCI Security Standards Council developed the Payment Card Industry Data Security Standard (PCI DSS) to encourage and enhance cardholder data security. This standard includes 12 requirements.

Build and Maintain a Secure Network and Systems

  • Install and maintain a firewall to protect cardholder data.
  • Do not use defaults for system passwords or security parameters.

Protect Cardholder Data

  • Protect stored cardholder data.
  • Encrypt transmission of cardholder data.

Maintain a Vulnerability Management Program

  • Protect systems against malware and regularly update anti-virus software.
  • Develop and maintain secure systems and applications.

Implement Strong Access Control Measures

  • Restrict access to cardholder data to those who need to know.
  • Identify and authenticate system access.
  • Restrict physical access to cardholder data.

Regularly Monitor and Test Networks

  • Track and monitor all access to networks and cardholder data.
  • Regularly test security systems and processes.

Maintain an Information Security Policy

  • Maintain a policy that addresses information security for all personnel.

The PCI Security Standards Council also provides a number of tips and strategies to increase the security of payment card data, such as:

  • Never store Sensitive Authentication Data, such as the full track contents on the magnetic stripe or chip, card verification codes/values, or PINs.
  • Ask point-of-sale vendors about the security of payment card systems.
  • Do not store cardholder data that is not needed.
  • Consolidate and isolate cardholder data that is needed.

The Council notes that the PCI DSS provides minimum security requirements that may be enhanced by additional controls and practices. Various laws, rules or regulations may also require enhanced security measurers. For example, under the Fair and Accurate Credit Transaction Act (FACTA), electronically printed credit and debit card receipts given to customers cannot include a card’s expiration date or more than the last five digits of the card number.

Sometimes security measures aren’t enough to prevent a data security breach, so businesses should use insurance to manage their cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws. However, given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

A solid understanding of your insurance needs is the key to overcoming the quality versus cost argument. An experienced and reputable independent insurance agent can help you purchase insurance that is both economical and effective.

If you would like to learn more about insuring against cyber risks, contact us.

If you would like to subscribe to our newsletters please click here.

How Can You Prevent Identity Theft?

According to the Federal Trade Commission, identity theft continues to top the list of consumer complaints. In 2013, American consumers reported losing more than $1.6 billion to fraud, which is approximately $2,294 per incident. The highest reported age group for identity theft is 20-29, and the most common form of identity theft is tax- or wage-related, followed by credit card fraud, utilities fraud and bank fraud. Florida has the highest per capita rate of reported identity theft complaints, followed by Georgia and California.

Since October is National Cyber Security Awareness Month, now is the perfect time to learn about preventing identity theft. Here are some tips from the Insurance Information Institute.

  • Don’t carry unnecessary personal information (social security card, passport, etc.).
  • Prevent ‘shoulder surfers’ from seeing credit card numbers or PINs.
  • Always take credit card or ATM receipts.
  • Don’t give out personal information, whether on the phone, via mail or online, unless you initiated contact or you know the transmission will be secure.
  • Only use authenticated websites to conduct business online. Check for the locked padlock image or look for ‘https://’ rather than ‘http://’ in your browser window.
  • Be aware of phishing and pharming scams that use fake emails and websites to impersonate legitimate organizations. Exercise caution when opening emails and instant messages from unknown sources.
  • Never send personal, financial or password-related information via email.
  • Use up-to-date firewall, anti-spyware and anti-virus programs.
  • Monitor all financial accounts and review monthly statements to make sure all transactions are accurate.
  • Immediately contact your credit card or bank if you suspect a problem.
  • Order your credit report from the three major credit bureaus to make sure it’s accurate and includes only authorized activities. You are entitled to one free credit report per year.
  • Place passwords on your credit card, bank and phone accounts.
  • Don’t use passwords containing easily available information (mother’s maiden name, birth date, phone number, etc.) or any series of consecutive numbers.
  • Change passwords if you suspect a problem.
  • Shred documents containing personal information such as credit card numbers, bank statements, charge receipts or credit card applications.

In the event of identity theft, early detection is the key to limiting the damage. Here are some clues from the FTC that someone may have stolen your identity.

  • You see withdrawals from your bank account that you can’t explain.
  • You stop getting bills or other mail.
  • Debt collectors call you about debts that aren’t yours.
  • You find unfamiliar accounts or charges on your credit report.
  • The IRS notifies you that a tax return was already filed in your name.
  • A company where you do business or have an account suffers a data security breach.

Despite taking preventative measures, identity theft can still happen. However, insurance may be purchased to help victims of identity theft through the often expensive and time consuming battle to clear their name. Depending on the insurance company, identity theft coverage may be included under a homeowners’ policy, or it may be added by endorsement or obtained under a separate, stand-alone policy.

If you would like to learn more about identity theft insurance coverage, please contact us.

If you would like to subscribe to our newsletters please click here.