Cybersecurity risks relate to the loss of confidentiality, integrity, and availability of information, data, or the systems that are required to support organizational operations. To minimize these risks, there are four paths to treating Cybersecurity risks.
Cyber Insurance is designed to cover consumers of technology services or products from the financial experience in the event of a breach of sensitive data (Personal Identifiable Information, Protected health information, or personal financial information). Cyber liability coverage includes legal costs, forensics and security consulting, identity theft protection services, data restoration services, and any settlement with victims.
Before businesses can transfer this risk to the Insurance company, they are required to have certain controls to protect and limit their exposure. The level of controls the company has implemented is ascertained in a Cyber Liability Questionnaire which must be filled out by the organization. Questions may include the following:
Do you have a process in place to regularly download and install patches?
Do you have an incident response plan to respond to a network intrusion?
Is Multi-factor authentication for remote access to email and other systems and programs containing private or sensitive data in bulk implemented?
To further limit risks insurers may not cover any acts sponsored by nation-states or in conjunction with a traditional physical war. Two recent incidents believed to be caused by nation-states are the Wanna-Cry incident and the Solar Winds cyberattack. Wanna-Cry affected companies throughout the world in May of 2017 for 4 days and is estimated to have caused losses in the billions, while the Solar Winds cyberattack is estimated to have cost around 90 million which under these new requirements would not have been covered.
The Cyber Insurance Underwriters put together a list of controls that are aligned with traffic light colors. Red is the minimum standard required by organizations to implement, Amber being requirements above the minimum and are more attractive to underwriters, while green requirements are the most attractive to underwriters.
We encourage organizations to put in place controls to protect critical data and systems and align them to organizational accepted risk. Obtain Cybersecurity Insurance to transfer these remaining risks and limit the organizational impact. Insurance is not an alternative to implementing good compliance measures, but for many organizations is the motivating factor for implementing these measures.
Contact Morefield to speak with our team of cybersecurity experts or contact us with any help your organization is facing navigating these fragile waters.