Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Monday, July 23, 2018

Why Cyber Insurance?



Before I begin the last segment on cyber risk, I want to thank those of you who are still following this blog.  You may have noticed the posts have been rather sporadic over the past four months and I would like to share why.  I have faced personal tragedy this year with the loss of both parents in close succession.  The inevitably of death is a fact and no matter how prepared one might believe they are, it seems we are never truly ready when the time comes.  These unfortunate events have distracted me from contemplating risk management issues.  I recently remembered a quote by Winston Churchill, “If you are going through hell, keep going.” So here we go. 
In previous posts, we reviewed several different cyber risk exposures and how to develop a strategy to protect against them.  We also looked at how to manage a social media presence and the associated risk.  But even with a well-defined plan, a cyber risk strategy should also include a layer of insurance to fill any gaps and potential exposure.  General liability insurance does not provide adequate protection as most policies exclude losses resulting from a cyber-attack.  Cyber insurance, on the other hand, will cover most of the following:
  • Legal fees and court costs
  • Investigative costs related to a data breach
  • Mandatory customer notification requirements
  • The cost to recover data
  • The cost to repair and restore compromised software and systems


In this post we will address three common questions about cyber liability insurance:
  1. What is cyber liability insurance?
  2. What should you as a business owner or decision maker look for when purchasing cyber liability insurance?
  3. How do insurance companies price cyber liability insurance? 

A cyber insurance policy, also referred to as cyber risk insurance or cyber liability insurance coverage (CLIC), is designed to help an organization mitigate risk exposure by offsetting costs involved with recovery after a cyber-related security breach or similar event. With its roots in errors and omissions insurance, cyber insurance began catching on in 2005 and is still evolving. Cyber risks change frequently, and the true risk of cyber-attacks is not completely understood.
Although there are few standards for underwriting these policies, the following costs are commonly paid or reimbursed:
  • Investigation expense:  After an event, a forensics investigation is necessary to determine what occurred, how to repair damage and how to prevent the same type of breach from occurring in the future. Investigations may involve the services of a third-party security firm, as well as coordination with law enforcement and the FBI.
  • Business interruption and reputational damage: A cyber insurance policy may pay for similar items that are covered by an errors & omissions policy (errors due to negligence and other reasons), as well as monetary losses caused by network downtime, business interruption, data loss recovery and costs involved in managing a crisis, which may also involve repairing reputation damage.
  • Privacy breach notifications: This includes the costs of required data breach notifications to customers and other affected parties, which are mandated by law in many jurisdictions, and credit monitoring for customers whose information was or may have been breached.
  • Lawsuits and extortion: This includes the cost of legal expenses due to the release of confidential information and intellectual property, legal settlements and regulatory fines. This may also include the costs of cyber extortion, such as from ransomware.


While the number of insurance companies that offer cyber liability insurance is growing, there is still no standard form.  Therefore it is important for the buyer to pay closer attention to what is covered and excluded.  Below are some questions to ask and items to consider when discussing cyber liability and reviewing the proposals with your insurance broker. 

  • Does the insurance company offer one or more types of cyber insurance policies? In most cases, a stand-alone policy is best and more comprehensive. Also, ask if the policy is customizable to an organization.
  • What are the deductibles? Be sure to closely compare deductibles among insurers.
  • How do the coverage and limits apply to both first and third parties? For example, does the policy cover third-party service providers? On that note, find out if your service providers have cyber insurance and how it affects your agreement.
  • Does the policy cover any attack to which an organization falls victim or only targeted attacks against that organization in particular?
  • Does the policy cover non-malicious actions taken by an employee?
  • Does the policy cover social engineering as well as network attacks? Social engineering plays a role in all kinds of attacks, including phishing, spear phishing, and advanced persistent threats.
  • Since advanced persistent threats take place over time, does the policy include time frames within which coverage applies? In other words, if an advanced persistent threat is discovered during the current policy period yet the origin was in an earlier policy period or before coverage was secured, is the policy limited to only damages caused during the current policy period?


Many insurance brokers and insurance companies will offer a checklist of items to consider when purchasing cyber insurance.  Gather several examples and compile your own customized list of items important to consider based on your particular operations. 

When pricing cyber liability coverage, an insurance company wants to see that your organization has taken some steps to assess your vulnerability to cyber attacks.  They may ask:
  • Do you follow established best practices enabling defenses and controls?
  • Do you have an established employee education program for security awareness, especially for phishing and social engineering?
  • Have you conducted a cyber threat assessment (even if not required by regulations)?
  • Have you consulted threat intelligence services for the latest information on targeted attacks?
  • Have you engaged the services of ethical hackers to reveal security weaknesses?


A threat assessment and ethical hacking services may be financially out of reach for many small businesses. However, investing in some type of vulnerability assessment tool or engaging the services of a penetration tester to probe external network defenses may go a long way toward improving security and benefit the negotiation of cyber insurance.

As cyber risk evolves, and insurance coverage becomes more standardized, an insurer might request an audit of an organization's processes and procedures as a condition of coverage, although this is not currently a common practice. An insurer may agree to provide coverage but perhaps at a level below what you feel you need. Keep searching for the right fit because the cyber risk is real and there is too much at stake to settle on coverage that leaves you vulnerable.


Until next time, stay safe and be kind to one another.

Monday, April 2, 2018

Phishing anyone?



Digital Treat Management, eCrime, Cyber Security; all terms associated with one of the fastest growing areas of risk facing business operations.  Today, criminals do not need to break through network firewalls to have access to a company’s private information.  In most cases, access through network security can be provided by unsuspecting computer and mobile device users.  In a recent report by APWG (an international coalition of governments, law enforcement sectors, and NGOs to combat cybercrime) the volume of cyber-attacks has continued to increase.  These attacks are most often carried out through phishing scams.

In this post, we will discuss a general overview of phishing and five ways to protect yourself and your firm from a phishing scam.  We will also look at malware and ransomware (usually the result of falling prey to a phishing scam), and five ways to protect against a ransomware attack.  Finally, we review a couple of good resources to get some additional information about cybercrime.

What is Phishing?


Phishing is when someone uses fraudulent emails, texts or copycat websites to get valuable user information or to gain access to your computer or company network.  Once inside the network, these people can install programs like ransomware that will lock out users from important files.  Phishing scammers lure their targets into a false sense of security by spoofing the familiar, trusted logos of established, legitimate companies. Or they pretend to be a friend or co-worker.

In a 2017 survey conducted by Wombat Security, 70% of the working Americans surveyed knew what a phishing scam was, but only 37% of the same group knew about ransomware.  Education is the best defense against phishing since phishing requires the user to take some sort of action.  While awareness will allow the user to recognize a potential threat and take the appropriate precautions, here are five other things you can do to protect against a phishing scam. 
  1. Be suspicious of any email or communication (including text messages) with urgent requests for personal financial information.
  2. Avoid clicking on links. Instead, go to the website by typing the Web address directly into your browser or by searching for it in a search engine. Calling the company to verify the legitimacy of a request is also an option.
  3. Don’t send personal financial information via email and avoid filling out forms in an email that ask for your information.
    1. You should only communicate information such as credit card numbers or account information via a secure website or telephone if you have called the company requesting the information.
  4. Use a secure website (https:// and a security “lock” icon) when submitting credit card or other sensitive information online.
    1. Never use public, unsecured WiFi for banking, shopping or entering personal information online, even if the website is secure.
    2. When in doubt, 3/4G or LTE connection is always safer than using public WiFi.  Most computer security software programs will offer a virtual private network (VPN) option for mobile devices, or they will recommend a VPN app. 
  5. Typically, phisher emails are not personalized, but they can be. Messages from the bank and eCommerace institutions are usually personalized. When in doubt, call the company directly to see if the email is in fact from them.

What is Ransomware?

Even with education and vigilance, there is still the chance that your computer or company network will receive malware.  Malware (malicious software) is any program or file that is harmful to a computer user. Malware includes computer viruses, worms, Trojan horses, and spyware. There are ever increasing news reports about a type of malware called ransomware.  Ransomware is a type of malware that accesses a victim’s files, locks and encrypts them and then demands the victim to pay a ransom to get them back. Cybercriminals trick users to click on attachments or links that appear legitimate but contain malicious code to attack the system. Under a ransomware attack, the victim has a certain amount of time to pay to get “the code” that will unlock and release the files.  Even if the victim pays, there is almost never a code provided that will unlock the files.  Any individual or organization can be a potential ransomware target.

Education and awareness are the best defense against a ransomware attack, but combining an awareness with the steps below can help mitigate the risk.

  1. All critical software, including computer and mobile operating systems, security software and other frequently used programs and apps, should be running the most current versions.
  2. Back up all files, photos, music and other digital information by making a copy and storing it in the cloud or on a removable device or both. 
  3. As a departure from traditional password schemes, use a sentence that is at least 12 characters long. Focus on positive sentences or phrases that you like to think about and are easy to remember.
  4. Links in email, are often how cybercriminals try to steal your personal information. Even if you know the source, if something looks suspicious, delete it.
  5. If you use USBs and other external devices to share files, or if you use email to attach and share files, these can all be infected by viruses and malware. Use your security software to scan them before downloading files onto your computer.


Resources

There are a number of great resources centers to get a better understanding of cybercrime and how to protect your business from any malicious attacks.  

Anti-Phishing Working Group, Inc. (APWG) - APWG is the international coalition unifying the global response to cybercrime across industry, government and law-enforcement sectors and NGO communities. 

STOP. THINK. CONNECT. - STOP. THINK. CONNECT.™ is the global online safety awareness campaign to help all digital citizens stay safer and more secure online. The message was created by an unprecedented coalition of private companies, non-profits and government organizations with leadership provided by the National Cyber Security Alliance (NCSA) and the APWG.

Associated with these organization are a number of private companies that can provide additional resources in the protection against cybercrime. Cybercrime is a rapidly changing and evolving risk to individuals and businesses.  The more we know, the better we can be vigilant and protect. 

Until next time, stay safe and be kind to one another.