Cybersecurity insurance, data, breach

What does Cybersecurity Insurance NOT Cover Which May Harm Businesses : 3 Case Studies

Introduction:

Cybersecurity with cybersecurity insurance = risk management that is balanced. It’s not a choice between the two. No cybersecurity programme can completely remove a company’s cyber risk. That is why you need cyber insurance to step up where the security programme leaves off by covering risks that cannot be controlled. When integrated, cybersecurity and cyber insurance enable balanced risk management, lowering expenses and improving your company’s overall risk posture.

While you may understand the fundamentals of insurance policies, it is more challenging to manage the specifics of each one. Which expenditures will be covered and which will not be in the event of a data breach or cyberattack? It’s the type of information you don’t want to find out after an incident has occurred. While cyber insurance protects organisations financially in relation to their digital assets, it does not cover every possible risk and cost. Some of the things that a standard cyber insurance policy may not cover are explored in this article.

What is not covered by cybersecurity insurance policies?

Individual insurers build each policy uniquely, despite the fact that there is a range of policies available. Without sufficient due diligence, the insured may receive a policy that excludes the majority of real-world hazards, imposes excessive limits on others, and over-covers less likely scenarios. A simple failure to notify the insurer on time, for instance, is a common basis for coverage denial.

For example, a policy may mandate that a breach be reported prior to or within 60 days of the policy’s expiration. However, according to a 2015 Ponemon Institute research, hacks go unnoticed for an average of eight months, which is more than enough time for data purveyors to obliterate audit logs, obstruct forensic analysis, and destroy legal evidence. As a result, a company that is ignorant of a breach until months later or until contacted by a third party, such as its credit card processor or police enforcement, will have missed the deadline for filing a claim.

Similarly, even if a corporation is determined to be eligible for reimbursement, some policies may exclude upgrades and improvements. Compensation for recovery objectives that do not include bringing the system(s) to a more resilient condition than before the attack will simply put the network in the same position of being vulnerable to comparable attack types, depending on the nature of the attack. The case studies that follow show the real-world, complex nature of cyberattacks and their influence on cyber liability insurance reimbursement that many businesses face.

1. Cottage Health System:

Cottage Health System, a nonprofit corporation based in Santa Barbara, California that administers a network of hospitals in Southern California, experienced a data breach involving around 32,500 personal medical records in 2013. According to the insurer’s complaint, the breach occurred because Cottage and/or its third-party vendor kept medical records on a system that was fully accessible to the Internet but failed to install encryption or take other security precautions to secure patient information.

Because the hospital system failed to follow the “minimum needed processes,” a CNA Financial Corp. affiliate is seeking a judicial declaration that it is not liable to pay a $4.1 million compensation under an exception in the hospital system’s cyber policy. According to the complaint, the Columbia policy covered privacy harm claims and privacy regulatory proceedings with limits of $10 million per claim and in the aggregate, subject to a $100,000 deductible. Columbia is not bound to finance the compensation, according to the complaint, because the policy excludes coverage for “failure to follow minimum needed practices.”

According to the complaint, Cottage’s Internet servers “allowed anonymous user access, causing electronic personal information to become exposed to the public via Google’s Internet search engine.”

The hospital system failed to “continuously apply the procedures and risk controls indicated” in its insurance application. The data breach was caused by the company’s “failure to regularly check and maintain security patches on its system, to regularly reassess its information security exposure and enhance risk controls, to have a system in place to detect unauthorised access or attempts to access sensitive information stored on its servers, and to control and track all changes to its network to ensure it remains secure, among other things.”

2. Ubiquiti Networks:

Ubiquiti Networks is one of the few corporations to admit it was duped out of millions of dollars. In its fourth-quarter financial statement, the San Jose, Calif.-based networking equipment manufacturer disclosed a loss of $46.7 million due to a hoax.

In 2015, the Company discovered that it had been the victim of criminal fraud. “An outside entity impersonated an employee and made false demands to the Company’s finance department during the event. This crime resulted in the transfer of funds totalling $46.7 million from a Hong Kong-based Company subsidiary to other foreign accounts controlled by third persons.”

3. BitPay:

In December of 2014, BitPay, Inc. was hacked for 5,000 bitcoins. BitPay is an easy target for hackers because it is a prominent financial services provider in the Bitcoin ecosystem. For incidents of hacking, it relies on an insurer, Massachusetts Bay Insurance Company, and this court case concerns the insurer’s refusal to pay on a policy involving hacking and fraudulent activities.

Using a tactic known as spear phishing, the hacker gained access to Bryan Krohn, BitPay’s chief financial officer’s e-mail account. The hacker obtains the targeted individual’s login information when they enter their credentials into that page. The hacker gained access to Krohn’s credentials by hacking into the e-mail account of David Bailey, the founder of bitcoin (a property of BTC Media Inc.). The hacker created a Google document that appeared to be from Bailey to Krohn, which allowed the hacker to obtain Krohn’s corporate account credentials and get access to his account.

The hacker obtains the targeted individual’s login information when they enter their credentials into that page.  The hacker gained access to Krohn’s credentials by hacking into the e-mail account of David Bailey, the founder of Bitcoin (a property of BTC Media Inc.)In terms of the phishing web page, the hacker created a Google document that appeared to be from Bailey to Krohn, which allowed the hacker to obtain Krohn’s corporate account credentials and get access to his account.

Because there was no hacking or unauthorised entrance into Bitpay’s computer system fraudulently triggering a money transfer, the facts do not justify a direct loss. Instead, Bitpay’s business partner David Bailey’s computer system was hacked, resulting in bogus emails being sent to Bitpay. Indirect losses generated by hacking into the computer system of someone other than the insured are not covered by the policy.”

This is a peculiar insurance coverage because it only covers what would be deemed a hack by technical compromise, not the main amount of modern hacking, which is “social engineering.”

Conclusion:

Strong cyber insurance is a must-have for almost any modern organisation, but you should be aware of these typical cybersecurity insurance coverage difficulties. We at Security Pilgrim are here to guide you through the process of making your business cyber secure, as a result, reducing vulnerabilities within your business to ensure it remains robust.

Please follow and like us:

Leave a Comment

Your email address will not be published. Required fields are marked *

RSS
Follow by Email
Facebook
Facebook
fb-share-icon
Twitter
Visit Us
Follow Me
Tweet
YouTube
YouTube
LinkedIn
LinkedIn
Share
WhatsApp