Businesses Need Cyber Insurance – Now!

The major risk to businesses victimised by cyber breaches is the reputational damage that can follow, damage that often comes from US government regulators out to make a name for themselves, according to a former FBI agent who works in the private sector now.

Reputational damage is also the area where businesses most need insurance protection, Jason Smolanoff, head of global cyber security at Kroll Associates, told insurance executives attending the Super Regional Property/Casualty Insurer Conference in Lake Geneva, Wis.

“These days, what’s going on is the federal government and local governments are now coming up with cyber security regulatory frameworks, which they are imposing upon companies that do business within their states,” he said.

He said after an incident, government officials will show up to perform an investigation, what he calls a “look-back,” to “see if the company performed reasonable data security measures on the information they had. If they didn’t have reasonable measures, they then get fined.”

He said the fines aren’t limited to just one state. “It’s not like if you have a problem in one state, it obviates, or negates, or cancels all the other states. They can all come after you, individually. The federal government can all come after you,” he said.

The Kroll security expert said he has clients dealing with breach lawsuits from seven different federal and state agencies.

“These are the things that people are going to be looking for coverage on from folks like you,” he told the audience of carrier executives.

“That I think is where the real risk lies. It’s not so much the computer intrusion. It’s not so much on the technical side. The major risk really is coming to a company from a reputational standpoint, from a financial standpoint, from a legal standpoint after the intrusion happens. It’s mostly by our governments who are going after these companies who are victims to begin with,” he said.

Make Their Mark

Smolanoff, whose FBI work encompassed cyber security and, before that, organized crime, maintains that regulators are trying to “make their mark so that they can then jump out into private industry.”

He cited California and Massachusetts as two of the most aggressive states vying to justify the heaviest fines against companies they determine lacked adequate security.

“Whatever side of the fence you’re on in the insurance industry, as you start to write more policies, this is ultimately going to become part of what those payouts are going to be and part of what the claims are going to be. You may not pay them out but they’ll be part of the claim at some point,” he told the insurance audience.

He offered what he acknowledged might be a cynical view of the trend.

“Most of these federal and state agencies are seeing this as a way to generate revenue because of the huge budget, true or false,” he said. “I have seen them staff up state AG offices for cyber compliance at a rate that’s just unbelievable. They’re doing that because they’re seeing there’s huge revenue to be generated here. It’s sad, in my opinion, because it’s after the fact and it’s a victim.”

Simply because a company has been audited or certified for cyber security does not mean it is a better risk, according to Smolanoff. He said most large companies that have suffered breaches have been ones that spent millions of dollars on information security and were audited or certified yet they still became victims.

Defending Against Government

He said his firm is working with clients and insurance underwriters on ways to minimize the risk posed by these government actions, developing questions that can help determine how good or how poor a particular insured’s cyber security posture is.

It comes down to companies being able to demonstrate “reasonable security” so that they can differentiate themselves from other similar firms.

Cyber Security Narrative

Smolanoff recommended that every company prepare a narrative outlining its cyber security, the steps it has taken, and what its response capabilities are.

“When you have a computer intrusion and you go before anybody, whether it’s an insurance company to file a claim, a state AG, a client, a business partner, what you want to be able to say is, ‘We as a company did a threat based analysis and we understand the data that we have would be interesting to the following threats. We took reasonable security measures to protect that data based upon the size of the company we are and the amount of revenue that we’re generating each year. If somebody came in and got to this data, they would have had to have taken extraordinary measures to do so.”

A statement like that can be “very powerful” in helping to “differentiate the company from about 90 percent of the other companies that are out there. It helps to minimise fines.”

He said while there are many theories about information security, the measure of a good information security strategy and program is a “company’s ability to rapidly detect and effectively respond” to an incident. It starts with assuming a breach will happen.

“It’s not really about stopping incidents anymore. It’s about how quickly can you identify when there’s anomalous behavior and do something about that anomalous behavior to stop it,” he said.

“It’s where you assume that an attacker is going to get into your network. They will get in but as a result of that attack, you will be able to detect them and stop them before they get to something that’s important.”

Thus, if an intruder gets into to the executive administrator’s computer but they can’t get any further, that’s fine. “We can deal with that. That’s not a big deal. That’s a low risk. We move on,” he said. However, “if they get in and they’re able to then move to your crown jewels within the network and get there and take the data without anyone knowing, that’s a big problem.”

Pay No Ransom

Should an insured or carrier become a victim of a ransomware attack, the former FBI agent strongly advises against paying any ransom money to the attackers.

“You have about 50 percent chance of getting your data back after you pay. Once you pay, then they know who you are and they know that you have money and they know that you pay. They keep coming after you even more. It’s a vicious cycle,” he warned.

He said Kroll has been asked but refuses to participate when an insurance company decides to pay a ransom on behalf of a client.

“Making the payment is almost assuredly going to some type of criminal organization. It would support anything from drug trafficking to human trafficking to more financial crimes, or something like that,” he said.

“I think it just puts us in a bad place and I think it puts, potentially your insured, and maybe even the insurance company, or anyone who’s in that chain with some type of risk. That’s just our company position that we will not be in escrow and we don’t advise that people make the payments.”

Insurance Journal:      Image: Nick Youngson:

You Might Also Read:

Making Sense Of Cyber Insurance:

Insurers Are Handling 'hundreds' Of Breach Claims:

 

« Trump's Top Cybersecurity Advisors Resign
Uber’s U-Turn On User Watching »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Exponential-e

Exponential-e

Exponential-e provide Cloud and Unified Communications services and world-class Managed IT Services including Cybersecurity.

Identifi Global Recruitment

Identifi Global Recruitment

Identifi Global is one of the UK's leading Cyber Security & IT Recruitment specialists.

Trusted Objects

Trusted Objects

Trusted Object's mission is to provide state of the art security solutions and services enabling a strong root of trust for the IoT ecosystem.

CryptoSec.info

CryptoSec.info

CryptoSec.info is a web resource focused on educating the beginners in the cryptocurrency space on how to properly secure their online assets from hackers and scammers.

Sabat Group

Sabat Group

Sabat Group provide relationship-driven information security & cyber security recruiting services.

RealCISO

RealCISO

RealCISO is a CISO grade cloud platform to help companies understand, manage, and mitigate their cyber risk.

Stairwell

Stairwell

Stairwell is building a new approach to cybersecurity around a vision that all security teams should be able to determine what’s good, what’s bad, and why.

Corellium

Corellium

Corellium are dedicated to supporting our peers in the ARM community who seek to build more secure, performant, and accessible software and devices.

CIBR Warriors

CIBR Warriors

CIBR Warriors are a leading cyber security and networking staffing company that provides workforce solutions with businesses nationwide in the USA.

SEIRIM

SEIRIM

SEIRIM delivers cybersecurity solutions in Shanghai China specializing in Web Application Security, Network Security for SME's, Vulnerability Management, and serving as Managed Security as a Service.

BreachQuest

BreachQuest

BreachQuest brings together cybersecurity experts with decades of experience identifying security flaws, penetrating networks, and responding to incidents.

SolidRun

SolidRun

SolidRun is a leading provider of computing and network technology designed to streamline the deployment of edge computing infrastructure and support embedded and IoT markets.

Secfix

Secfix

Secfix helps companies get secure and compliant in weeks instead of months. We are on a mission to automate security and compliance for small and medium-sized businesses.

Accelerynt

Accelerynt

Accelerynt was founded with a singular purpose: help teams like yours build cybersecurity resilience.

IndoSec

IndoSec

IndoSec is an annual cybersecurity summit that powers an in-person gathering of cybersecurity leaders from Indonesia’s major corporations, leading businesses and key government entities.

Scope AI

Scope AI

Scope AI is an innovative technology company specializing in quantum security and machine learning.