Every Business Should be Worried about Cyber Liability

Regardless of industry, cyber attacks and data breaches expose businesses to potentially enormous losses and liabilities. According to a report by the Insurance Information Institute (III), the potential economic fallout from the cyber threat cannot be underestimated, particularly because the number of publicly disclosed data breaches soared from 449 in 2012 to 614 in 2013. This is likely why cyber risk cracked the top 10 list of global business risks in 2014.

According to the III report:

  • The majority of data breaches affected the medical/healthcare industry (43.8%) and business organizations (34.4%).
  • Business organizations accounted for the majority of records exposed by data breaches in 2013 (84%).
  • A report by PWC found that cyber crimes are considered a high-level threat.
  • Cyber attacks have become more frequent and increasingly costly for companies to resolve.
  • The average annualized cost of cyber crime is estimated to be $11.6 million per year.
  • Denial of service is the costliest cyber crime, followed by malicious insiders and web-based attacks.
  • The average time to resolve a cyber attack is 32 days, with an average cost of just over $1 million during this 32-day period.
  • Malicious or criminal attacks, such as malware infections, criminal insiders, phishing/social engineering and SQL injections, cause 42% of data breaches, followed by human error (30%) and system glitches (29%).
  • U.S. organizations have the highest lost business costs at an average of $3.3 million.
  • Businesses may be exposed to even greater risks from new technologies, such as cloud computing, which uses a network of remote servers over the Internet to store, manage and process data, rather than a local server.

The III report notes that upon experiencing a data breach, many businesses turn to their insurance policies to cover their loss. Unfortunately, many of these losses are not covered by traditional insurance policies. To protect against cyber threats, businesses need specific cyber insurance policies that provide a number of specialized coverages, such as:

  • Loss/corruption of data
  • Business income/interruption
  • Liability coverage (first- and third-party coverage)
  • Data breach coverage (including costs of complying with statutory notice requirements)
  • Cyber extortion
  • Crisis management
  • Identity theft

Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

A Contract’s Fine Print: Find the Devil in the Details

Contracts are an essential part of doing business. Regardless of size or industry, contracts with customers, vendors, suppliers, service providers or independent contractors are an important part of a business’s operations. While good contracts can help manage risk and maintain good working relationships, bad contracts can be incredibly harmful. This is why every business must proceed cautiously when negotiating and signing contracts.

Ideally, an attorney will be consulted when negotiating or signing contracts. The reality, however, is that many businesses handle their own contracts. Though it may be easy for some to identify and understand a contract’s main provisions, like cost, volume, part numbers, etc., the devil is in the details, which, in the case of contracts, is the fine print.

Every provision in a contract has a purpose, including those found in the fine print. Despite being underemphasized, they are often important when defining a contractual relationship, particularly when things go wrong. The following provisions, for example, are not only commonly used, but commonly overlooked.

Forum (Jurisdiction) Selection: A contract may require that any lawsuits involving the contract be filed in a specific forum or jurisdiction (county, state, country). This may not be a problem if a business is located in the jurisdiction specified in the contract. However, it may be a huge problem if, for example, a Florida business is required to file a lawsuit in Alaska. Despite having the legal right to enforce the contract, the increased complexity and cost of filing a lawsuit in another jurisdiction makes it practically impossible for many businesses to do so, particularly when relatively small amounts of money are involved.

Choice of Law: Similar to a forum selection clause, a choice of law provision specifies which state’s law will be used to interpret and enforce the contract. These clauses can be significant because laws may vary from state to state. For example, one state may have more favorable consumer protection laws, while another makes it more difficult to recover damages. It is important to know if and how a choice of law provision may affect any contractual rights or remedies.

Integration (Merger) Clause: Contracts typically contain a provision stating that the contract represents the full and final agreement and supersedes any other agreements, oral or written. With an integration clause, any verbal or written conversations, brochures, promises, representations or statements that are not included in the contract are not part of the contract. This may become an issue when a business is not receiving what the salesperson promised before signing the contract. Expectations, obligations and requirements must be included in the contract to be enforceable under the contract.

Assignment: A contract may allow one or both parties to assign their rights, duties or obligations to a third party. This can create a problem if there is an expectation that a specific person or company will be performing under the contract. If, for example, a business wants only a specific vendor to do a job, the contract must state that the vendor cannot assign its obligations under the contract to someone else. Otherwise, a business may find that the person they contracted with isn’t the person they end up working with.

Evergreen Clause: Contracts are typically entered into for a specific period of time (term). A contract with an evergreen clause will automatically renew for a new term unless notice of termination is given by either party, usually within a specific period of time. For example, a one year contract will automatically renew for another year unless written notice of termination is given at least 60 days before the end of the yearly term. Businesses that fail to discover and comply with an evergreen clause may be stuck in a contract they no longer need or want.

Dispute Resolution: Contracts may require that disputes be resolved through arbitration rather than by filing a lawsuit. Depending on the nature of the contract, this requirement can significantly affect the resolution of disputes and the apportionment of damages.

Indemnification Clause: Indemnification clauses are used to allocate risk and responsibility among the parties to a contract by requiring one party to compensate the other for specific liabilities or losses arising out of the contract. Since these clauses commonly require a party to assume liability that would not otherwise exist, they must be reviewed carefully and understood completely. Indemnification clauses often end up being the most significant provision in a contract when something goes wrong.

Insurance Requirements: Many contracts include specific insurance requirements. For example, a contract may require a party to have general liability or workers’ compensation insurance, or it may require that one party be given Additional Insured status under the other party’s insurance policies. Contracts often require proof of insurance before work can begin or payment is made. It is important to identify and comply with any contractual insurance requirements.

Despite the benefits of using an attorney to negotiate and review contracts, particularly complex or high-value contracts, many businesses take a do-it-yourself approach. Nevertheless, given the increased risk of harm caused by bad contracts, businesses should never sign a contract without reading and understanding every provision, including those in fine print.

If you have any questions or would like to discuss how Setnor Byer Insurance & Risk can help identify and protect against various business risks, please contact us.

If you’d like to subscribe to our weekly newsletters please click here.

A Narrow View of Cyber Risks Can Leave You Overexposed

Recent, high-profile incidents show that every business is at risk of suffering a data security breach, regardless of size, resources or sophistication. To combat the risk, many organizations are taking steps to identify and secure organizational vulnerabilities, such as wireless networks, laptop computers, and even the office copy machine. However, a report by Zurich Insurance and the Atlantic Council suggests organizations must look beyond their own operations to truly recognize their exposure to cyber risks.

Businesses are increasingly using the internet and information technology functions to expand their operations and create opportunities. They are also increasing their exposure to external cyber risks that are often beyond their control. This is why businesses need to expand their horizon when evaluating and managing cyber risks. According to the report, businesses must consider these seven aggregations of cyber risk to fully understand their exposure.

  • Internal IT Enterprise: Risks associated with an organization’s internal IT (hardware, software, servers, processes).
  • Counterparties and Partners: Risks from dependence on or interconnection with outside organizations.
  • Outsource and Contract: Risks from contractual relationships with third-parties (IT and cloud providers, legal, accounting).
  • Supply Chain: Risks to supply chains in the IT sector and cyber risks to traditional supply chains and logistics.
  • Disruptive Technologies: Risks caused by unseen effects from, or disruptions to new technologies (smart grids, embedded medical devices, driverless cars), or existing but poorly understood technologies (internet, networks).
  • Upstream Infrastructure: Risks from disruptions to infrastructure relied on by economies and societies (electricity, telecommunications, financial systems).
  • External Shocks: Risks from incidents outside the system (international conflicts, acts of terrorism, malware pandemic).

Despite the external risks resulting from increased outsourcing and interconnectivity, businesses are urged to continue taking steps to control their internal cyber risks. According to the report, there are a relatively small number of actions that every organization can take to protect against most cyber risks, such as:

  • Implementing applicationwhite-listing to prevent systems from running programs that have not been pre-approved, such as malicious software
  • Using standard secure system configurations to keep systems simple and easier to defend.
  • Installing patch software for systems and applications within 48 hours of being released by the software manufacturers
  • Controlling administrative privileges to only those who need it and can be trusted with it

The report also recommends that businesses:

  • Expand their risk horizon to consider the seven aggregations of risk
  • Have cyber insurance, particularly for third-party risks associated with data breaches or business interruption
  • Deal with cyber risks at the board-level

Finally, the report states that resiliency is the key in a world where the number of cyber risks is increasing and the ability to control them is decreasing. To survive cyber threats and limit their impact, the report recommends that every business:

  • Incorporate redundancies in critical systems
  • Implement incident response and business continuity plans
  • Utilize scenario planning and exercises to stay prepared

As we have seen, nothing is foolproof, so businesses should use insurance to protect against cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws.

Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against cyber risks, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

Loss of Business Income Caused by Civil Authority Action

Public safety concerns may prompt civil authorities to take action to protect people and property. For example, a governor can issue a mandatory hurricane evacuation, a mayor can close roads during inclement weather, the police can enforce curfews during riots, or a fire department can restrict access to a neighborhood during a gas leak. Though these actions may be good for public safety, they may be bad for business.

In some cases, a Business Interruption policy’s Civil Authority coverage may offset income losses suffered during a civil authority action. Business Interruption, also known as Business Income, is a type of commercial insurance that protects against loss of income when a covered loss causes a business to reduce or suspend its operations. Civil Authority coverage is an additional protection that may be included in a Business Interruption policy.

A typical Civil Authority clause states: We will pay for the actual loss of Business Income you sustain and necessary Extra Expense caused by action of civil authority that prohibits access to the described premises due to direct physical loss of or damage to property, other than at the described premises, caused by or resulting from any Covered Cause of Loss.

Under this framework, the Civil Authority provision will not provide coverage unless all four of the following conditions are met.

  • The loss of business income must be caused by the civil authority action. There must be a direct relation between a civil authority action and a loss of income.
  • The civil authority action must prohibit access to the insured business. Courts have held that access must be completely prohibited in order to satisfy this requirement. A civil authority action that makes travel to an insured’s business difficult or inconvenient is not enough to trigger Civil Authority coverage.
  • The civil authority action must be caused by direct physical loss of or damage to property away from the insured’s premises. Unlike Business Interruption coverage, which requires loss or damage to the insured’s property, Civil Authority coverage requires loss or damage to property somewhere else. For example, an explosion at a nearby warehouse causes the fire department to shut down the area surrounding an insured business for two weeks.
  • It’s worth noting that claims for Civil Authority coverage often fail to meet this requirement because the decision to take civil authority action is not caused by direct property damage, but by the desire to prevent it. Courts have denied coverage for losses caused by civil authority actions that were designed to prevent future damage rather than address existing property damage, such as pre-hurricane evacuation orders and curfews imposed to prevent looting and rioting. According to one court, Civil Authority coverage is designed to address situations involving civil authority action that is taken after damage occurs.
  • The loss or damage to property away from the insured’s premises must be caused by or result from a loss that is covered under the insured’s policy. A business without hurricane insurance, for example, would not be covered if a civil authority action was caused by hurricane wind damage.

Though many aspects of Civil Authority coverage are relatively standard, there are some variations among insurers and policy forms. For example, some policies provide that coverage will not begin until 24 hours after the civil authority action was taken, and others require 72 hours. The duration of Civil Authority coverage may also be different.

Given the complexity of Civil Authority coverage under a Business Interruption policy, an experienced and reputable insurance agent should be consulted to help identify needs and evaluate options.

If you have any questions or would like to speak with one of our Risk Management Professionals, please contact us.

If you would like to subscribe to our newsletters please click here.

Are You Ready for the 2014 Hurricane Season?

For those living or working in the Atlantic hurricane region, June 1st rarely passes unnoticed. At Setnor Byer Insurance & Risk, we understand that preparing for hurricane season is rarely easy and often stressful. We also understand that a lack of awareness and preparation can lead to disaster, and that the best way to limit the risks posed by hurricanes is to take preventative steps.

The National Oceanic and Atmospheric Administration’s 2014 Atlantic Hurricane Outlook predicts a 50% chance of a below-normal season, a 40% chance of a near-normal season and only a 10% chance of an above-normal season. According to NOAA, the 2014 hurricane season will bring:

  • 8 – 13 Named Storms (winds of 39 mph or higher)
  • 3 – 6 Hurricanes (winds of 74 mph or higher)
  • 1 – 2 Major Hurricanes (winds of 111 mph or higher)

These numbers are near or below the 1981 to 2010 seasonal averages of 12 named storms, six hurricanes and three major hurricanes. “Though we expect El Niño to suppress the number of storms this season,” NOAA administrator, Dr. Kathryn Sullivan, reminds us that, “it’s important to remember it takes only one land falling storm to cause a disaster.”

The 2014 hurricane season will also see changes in the information provided by the National Hurricane Center, including:

  • A smaller tropical cyclone forecast cone
  • The addition of a Potential Storm Surge Flooding Map, which will highlight areas where storm surge inundation could occur and the height above ground level that the water could reach
  • The elimination of the Intensity Probability Table due to misleading estimates of landfall intensity and excessive reliance on these estimates by the public

Though different situations call for different measures, here are some tips that can help you weather a storm.

Before the Storm

  • Monitor the news to allow time to prepare.
  • Identify all tools and equipment that will be needed to secure property before a storm and limit the damage after the storm (flashlights, batteries, caulking, tarpaulins, sandbags, cutting and fastening equipment, etc.).
  • Clear drains and downspouts to minimize the risk of flooding.
  • Move items inside.
  • Unplug electrical equipment and move property away from windows.
  • Check and secure all documents and records.
  • Take or update photographs of real and personal property.
  • Gather insurance policies and agent/insurer contact information.

After the Storm

  • Only after it has been declared safe to do so, take reasonably necessary steps to protect against any further property damage.
  • Report fallen power lines to power company immediately—stay away from them!
  • Check exterior walls and roof for damage from wind, rain, flying objects and rising waters (flood insurance).
  • Check all interior perimeter walls, floors and roof for leaks and water damage.
  • Document all damage with photographs and video.
  • Prepare detailed damage reports.
  • Call your insurer or agent as soon as possible to report damage.

While preparing for Hurricane Season is never easy, our team of experienced and responsive professionals can work with you to make sure that your personal and business property are protected in the event of a hurricane. With over 30 years of experience dealing with tropical storms and hurricanes, Setnor Byer Insurance & Risk has a long history of helping our clients prepare before the storm and, more importantly, providing support through the process of rebuilding after the storm.

If you would like more information about protecting your personal and business property during the 2014 Hurricane Season, please contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Making the Most of National Electrical Safety Month

Protecting your family, home and property is a full time job. Unfortunately, busy schedules often get in the way of making safety a top priority. Since May is National Electrical Safety Month, now is a good time to discuss electrical hazards and review effective safety practices.

According to the Federal Emergency Management Agency (FEMA), electrical malfunctions are a leading cause of residential building fires. In 2011, there were 26,800 residential building fires caused by electrical malfunctions that resulted in 280 deaths, 1,200 injuries and over a billion dollars in property loss. FEMA reports that residential building electrical fires cause more injuries, death and damage than all nonelectrical residential fires combined.

Steps can be taken to avoid becoming another tragic statistic. For example, since the average home in the United States was built in 1974, the Electrical Safety Foundation International (ESFI) recommends installing updated home safety devices that are designed to meet today’s electrical demands. The following items, for example, can greatly increase electrical safety.

Tamper Resistant Receptacles

Curious kids and electrical receptacles (outlets) are a dangerous combination. Tampering with electrical receptacles causes an estimated 6 to12 child fatalities and 2,400 severe shocks and burns every year. Those relying on plastic outlet covers to protect their children should know that a Temple University study found that 100% of 2 to 4-year-old children were able to remove plastic outlet covers in less than ten seconds.

A Tamper Resistant Receptacle (TRR) has spring-loaded shutters that cover the contact openings, or slots, of the receptacles. These shutters only open when both springs are compressed at the same time. The shutters will not open when a child attempts to insert an object into only one contact opening, so there will be no contact with electricity. According to the ESFI, the cost of installing TRRs in new homes is about 50 cents more than installing traditional receptacles, and the cost of retrofitting existing homes can be done for about $2 per outlet.

Ground Fault Circuit Interrupter

A ground-fault occurs when there is a break in the grounding path that may cause the electrical current to take an alternative path to the ground through a person, resulting in serious injuries or death. A Ground Fault Circuit Interrupter (GFCI) is a fast-acting circuit breaker designed to shut off electric power within as little as 1/40 of a second in the event of a ground-fault. It works by comparing the amount of current going to and returning fromequipment along the circuit conductors. If there is a measurable difference between the two, the GFCI interrupts the current.

Arc Fault Circuit Interrupter

An arc fault is an unintentional discharge of electricity in a circuit that can be caused by damaged, overheated or stressed electrical wiring or devices. Sparking or arcing caused by loose or corroded wires making intermittent contact generates heat and can damage insulation of the wires, which can trigger an electrical fire. Since arcing may not trip a circuit breaker, an Arc Fault Circuit Interrupter (AFCI) is needed to shut off the electricity before a fire can start.

The ESFI also recommends conducting a home electrical safety checkup by asking a number of questions designed to identify potential safety hazards, such as:

  • Are all switches and outlets working properly?
  • Are any switches or outlets warm to the touch?
  • Are any outlets or switches discolored?
  • Do any switches or outlets make crackling or buzzing sounds?
  • Do plugs fit snugly into all outlets?
  • Are any cords cracked, frayed or damaged?
  • Are any cords pinched by furniture, doors or windows?
  • Are cords attached to anything with nails or staples?
  • Are cords placed under carpets?
  • Are any extension cords being used on a permanent basis?
  • Are cords kept tied up while being used?
  • Are appropriate wattage light bulbs being used in all lights?
  • Are all appliance cords placed so they will not come in contact with hot surfaces?
  • Do you have recurring tripped circuit breakers or blown fuses?
  • Are electrical safety devices, such as GFCIs and AFCIs, tested every month?

If potential electrical safety hazards are discovered, the ESFI cautions against taking a do-it-yourself approach and strongly recommends leaving electrical work to the professionals. Nevertheless, the ESFI recommends the following precautions before doing any electrical work:

  • Turn off the power by switching off the correct circuit breaker in the main service panel.
  • Unplug lamps, appliances, etc. that are being worked on.
  • Test wires before touching them to confirm power has been turned off.
  • Never touch plumbing or gas pipes when performing an electrical project.
  • Never attempt a project that is beyond your skill level.

Since completely eliminating the risk of electrical damage is impossible, homeowners and renters should check with their insurance agent to make sure they are adequately protected. In some cases, a personal property floater or ordinance and law coverage may be necessary.

If you would like information about how insurance can play a valuable role in protecting your home from electrical safety hazards, please contact us.

If you would like to subscribe to our newsletters please click here.

Is a Resident Manager Ideal for Your Self Storage Facility?

Resident managers are not as common as they used to be in the self storage industry. For some self storage facilities, however, a manager living on the premises may be the key to running a successful operation. Though cost is an important factor when deciding whether a self storage facility could benefit from a resident manager, other factors should be considered as well, such as:

Service: Automated facilities may not be enough to create an advantage over the competition. Depending on a self storage facility’s location or specialty, clients may want more than just an access code after signing a contract. Facilities with a resident manager can service clients in ways that others cannot. This is why the existence of a resident manager is often mentioned in promotional and marketing materials.

Security: Even with surveillance cameras and 24-hour monitoring services, it is difficult to deny that resident managers can make a self storage facility even more secure. Their presence alone will likely deter most criminals, and their response time will be quicker than even the fastest police departments.

Operations: Things can and often do go wrong after business hours. Leaking pipes and short-circuits are just two things that can cause significant damage if they are not discovered and fixed quickly. A resident manager can find and fix those problems that cannot wait.

Qualified Candidates: It’s not always easy to find and retain the right people. Providing prospective managers with a place to live may be just the perk required to hire and keep quality talent.

After evaluating all the pros and cons in the context of each facility’s own particular situation, an informed decision can be made about whether a resident manager could improve operations. However, before making a final decision, it is important to understand the ramifications of hiring a resident manager, particularly how doing so may create an unexpected relationship.

In addition to creating an employer-employee relationship, hiring a resident manager can also create a landlord-tenant relationship. While employers can often terminate employees at-will and without advance notice, the same cannot usually be done with tenants. Depending on applicable law, a self storage facility will generally be required to provide advance written notice to terminate the landlord-tenant relationship. As a result, a resident manager may be legally entitled to continue renting the property for a period of time after his or her employment has been terminated.

There are steps that can be taken to minimize the scope and impact of the landlord-tenant aspects of a resident manager’s employment relationship. For example, a self storage facility can address landlord-tenant issues in a written employment agreement or in a separate lease agreement. However, since specific legal requirements must be met, it is advisable to seek the advice of a locally licensed attorney.

As is often the case, it is necessary to understand the risks in order to control them. Since self storage facilities face unique risks, it helps to have an insurance program that is specifically designed for the self storage industry. If you would like more information about Setnor Byer Insurance & Risk’s Self Storage Insurance Program, please contact us.

If you would like to subscribe to our newsletters please click here.

Insurance for Tech Companies

Since most businesses rely on technology, providing technology services has become big business. Technology companies provide goods, services and expertise that can increase efficiency, productivity and profitability. These businesses may involve:

  • System / network development and administration
  • Application and website programming and design
  • Hardware installation and repair
  • Website hosting, maintenance and optimization
  • Information Technology consulting, staffing and training
  • Project management
  • Consulting

Technology companies face the same risks as other businesses, so traditional insurance coverages are required, such as general liability, property, automobile and workers compensation insurance. However, additional insurance coverage may also be necessary to address the unique risks facing technology companies.

For example, many technology companies do not believe they need Errors & Omissions (Professional Liability) insurance. The reality is that technology companies, just like doctors and lawyers, can be held liable for errors and omissions committed in the performance of their professional services.

Unfortunately, a traditional E&O policy may not protect against many of the risks unique to technology companies. This is why technology-specific insurance is needed to cover technology-specific risks. To ensure adequate insurance coverage, technology companies should look for an E&O policy that, at a minimum:

  • Broadly defines “Computer Technology Services”
  • Provides coverage for failure to prevent unauthorized access to or use of any electronic system or program of a third party
  • Provides coverage for unauthorized, corrupting or harmful pieces of code, including, computer viruses, worms and Trojan Horses
  • Covers personal injury claims alleging wrongful entry, wrongful eviction, wrongful detention, false arrest, false imprisonment, libel, slander or defamation, advertising injury or violation of any right of privacy
  • Provides sufficient coverage limits

The right E&O policy lets technology companies focus on their business knowing that they are protected in the event of a claim. And, since clients are increasingly requiring proof of E&O insurance from their technology vendors, an E&O policy may also create new opportunities.

Given the complexity of the risks facing technology companies, evaluating insurance needs and options is not always easy. For example, in addition to E&O insurance, technology companies may also need coverage for cyber liability claims, including data security breaches, which are becoming more common.

An experienced insurance agent can guide you through the process of protecting your technology company. If you would like to learn more about insuring a technology company, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Let’s Talk About Data Security Breaches

The theft of credit and debit card information from Target’s computer systems should serve as a reminder that the risk of a data security breach must be taken seriously. Every organization must have a plan to not only prevent data security breaches, but to respond to them as well.

The first step is to identify vulnerabilities with a risk assessment. Unfortunately, this can be difficult because data security breaches can come from pretty much anywhere, including employees, laptop computers, copy machines and wireless networks. To make the process easier, organizations can perform a self-audit.

The Online Trust Alliance has come up with a series of risk assessment questions that are designed to help organizations identify vulnerabilities and gauge their level of preparedness. For example:

  • Are there any regulatory requirements that are specifically applicable to your business operations or geographic location?
  • What customer-specific data is collected? How, where and by whom is this data stored, maintained and archived? Can you identify points of vulnerability and risk?
  • Is the kind of customer-specific data you collect necessary for business operations? For example, is it necessary to request drivers’ license information or social security numbers?
  • Do you follow best practices for encryption and de-identification processes?
  • Is there an incident response team in place? Is there a clear reporting process in the event of an accidental data loss or a breach?
  • Is there a plan for communicating to employees, customers, partners, stockholders and the media in the event of a breach?
  • Are generally accepted security and privacy best practices followed? If not, why?
  • Is there a privacy policy reflecting current data collection and sharing practices, including the use of third-party advertisers and cloud service providers? Have systems been audited to confirm compliance with written policies?
  • Is there a contact person in the event of a breach? Has a person been assigned to work with the authorities, such as the FBI, Secret Service and State Attorney General Office?
  • Are you willing to sign off on your Data Incident Plan and represent to board members, investors and regulators that it contains best practices for preventing and responding to data security breaches?

This kind of self-audit should encourage discussion and evaluation of an organization’s specific data security risks. And, since the questions are general in nature, they can be used by most organizations, regardless of industry or location.

As we have seen, preventative measures are not foolproof, so organizations should also consider protecting against data security breaches with insurance. Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws.

Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like a professional audit please contact us to learn more.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Vehicle Sales Can Be Risky Business for Self Storage Facilities

Dealing with delinquent tenants is an unavoidable part of operating a self storage facility. Strict legal requirements make enforcing storage liens and selling tenants’ property a risky proposition. The risk is even greater for those facilities that permit the storage of motor vehicles.

Unlike other kinds of personal property, certificates of title are used to establish ownership of motor vehicles. This means that operators of self storage facilities must take the right steps to make sure the certificate of title will reflect the transfer of ownership from the delinquent tenant to the buyer. Unfortunately, re-titling a vehicle may not be quick or easy, particularly because the process isn’t always obvious and it can vary significantly from state to state.

For example, Florida requires an Application for Certificate of Title with/without Registration, though this requirement is not found in the self storage statute. By contrast, California requires an Application for Lien Sale Authorization and Lienholder’s Certification, a Certification of Lien Sale, an Application for Title or Registration, a Notice of Pending Lien Sale, a DMV letter of authorization to conduct the sale, postal receipts of all notices sent, and a Notice of Transfer and Release of Liability.

The lack of a uniform process for re-titling motor vehicles means that operators of self storage facilities must refer to and abide by their state-specific laws and requirements. However, regardless of what the process involves, operators can still take steps to make things easier while reducing the risk. For example, operators can collect vehicle-specific information and documentation when the tenant signs the lease, such as:

  • Vehicle Identification Number (VIN)
  • Vehicle registration information
  • Copy of Certificate of Title
  • License plate/tag number
  • Lien and lienholder information
  • Name and contact information for all owners of the vehicle

Operators of self storage facilities need to understand the increased effort and risk that come from storing and disposing of motor vehicles. Various insurance options specifically designed for the self storage industry are available, such as Sale and Disposal Liability Coverage.

If you would like more information about Setnor Byer Insurance & Risk’s Self Storage Insurance Program can help protect your facility, please contact us.

If you would like to subscribe to our newsletters please click here.