Cyber Risk Insurance: Digital Identity Protection

04/03/2016
|

This week, Selva Orejón took part in the Silicon article on the cyber risk insurance available on the market. Here is her contribution:

Cyber risks are already one of the biggest concerns for companies worldwide. More and more organisations are taking out insurance to protect themselves against potential attacks.

Cyber risks entered Aon’s global ‘top 10’ risks list for the first time last year. And for good reason. According to Radware’s ‘Global Application & Network Security Report 2015-2016’, 90% of companies suffered cyberattacks in 2015.

But what types of attacks do companies typically face? “They can be domestic or corporate in nature, and either random or targeted. When an attack is targeted, it generally has four types of motivations: personal—love, hate…—financial, professional, or psychological.There are also cases where several motivations are combined. And the consequences can be classified from four perspectives: legal—for victims and attacker—reputation and/or digital identity, security and/or privacy, and psychological. As a result, we see attacks on honour, unlawful access to communications or devices, disclosure of secrets and data leaks, industrial espionage, intimidation, coercion, insults, slander, etc. And cases of harassment and bullying are on the rise,” explains Selva Orejón, lecturer at EAE Business School and Director of onBRANDING.

Pablo Fernández Burgueño, a lawyer specialising in IT security, partner at Abanlex and lecturer in Law at ICEMD, notes that the most frequent cyberattacks “tend to be those caused by computer attacks and security breaches that destroy files or compromise personal and confidential information”, leading to repair costs and damage to the company’s image due to defamation.

Meanwhile, Elena Alhambra, international underwriter for Space Lines at Beazley—Lloyd’s syndicate—specifies that the main cyber risks are DDoS attacks (denial-of-service attacks); human error, especially sending documents by email to the wrong recipient or the loss or theft of computers—laptop, phone…—; malware; and cyber extortion, hackers who demand a cash payment in exchange for not disclosing non-public personal information contained in the victim’s files.

Severe repercussions

The threat of a cyberattack is very real, and experiencing one can have significant consequences for a company’s operations. “Any cyber event or attack could cause damage to a company’s information systems, resulting in material, financial or other losses, as well as reputational damage that could have a decisive impact on its bottom line,” says Andrés Martínez, Director of the Legal and Compliance Area at Dual Ibérica.

But what impact can a cyberattack have? “It is difficult to quantify the average claim amount because it depends on many circumstances. The fine that may be imposed by the Spanish Data Protection Agency (AEPD) alone can involve a major outlay,” notes Alhambra. It is worth remembering that a breach of the Data Protection Law can result in a fine of up to €60,000, €300,000 or €600,000, depending on whether the infringement is classified as minor, serious or very serious, respectively. In other words, it could seriously jeopardise the company’s continuity. And committing these infringements is not difficult at all. For example, the AEPD fined a website for including the ‘send to a friend’ option, as reported by El Economista.

In addition, the EAE lecturer states that every day there are more cases “that cost more time, human resources, money and reputational capital. Here the cost is incalculable and, in some cases, hardly repairable if measures are not taken. We cannot have our business on the internet without digital protection insurance. The cost of repairing the damage, in cases where there is a solution, is high. Sometimes it involves legal fees, a psychological forensic report or criminal profiling, digital identity work, post-incident device security forensic analysis, etc.” Digital protection training is essential in these situations, along with crisis management protocols.

Having cyber risk insurance has become a necessity, given the exposure any internet-connected company faces to data loss due to human error or hacking of IT systems. “Business owners try to prevent data loss, but the reality is that companies are increasingly dependent on technology and therefore more vulnerable. It is vital to be able to respond to a data loss in such a way that, at the lowest possible cost, we can avoid reputational damage and act within the framework of the law. Managing the incident is even more important than being able to respond to third-party claims. Good management will mitigate the damage to customers,” comments the Beazley expert.

She adds that “cyber risk insurance helps business owners with those incident management costs, which may be difficult to cover in the short term if an unauthorised disclosure of customers’ private data occurs”. For example, in the event of a DDoS attack, “coverage would likely be triggered to manage the incidents and, in addition, the potential loss of profits”.

A safety net

More and more companies are choosing to protect themselves with cyber risk insurance. “The size of the global market has grown from $850 million in premiums in 2012 to an estimated $2.5 billion in 2015. Forecasts estimate that the global market will continue to grow to $3 billion in 2016 and $7.5 billion by 2020,” Alhambra explains.

According to the ICEMD lecturer, these policies are particularly necessary for medium-sized and large companies, especially in sectors such as banking, e-commerce and travel agencies, but also for “anyone with a significant online presence or who is connected to the network”. Martínez assures that large companies already tend to take out this insurance, although he highlights theincrease in uptake among SMEs, “especially those linked to the technology sector, but also companies that, by their nature, store a large amount of data or hold particularly sensitive information, such as health data, banking details, etc.”.

The representative from Dual Ibérica explains that the premium “is calculated based on factors such as turnover, company size, its activity, its IT architecture, the security measures implemented, etc.”. He adds that “the average premium is around €10,000, but the range is very wide. There are policies for €350 and for €100,000, depending on the risk and the cover taken out”. Fernández Burgueño, for his part, notes that “in Spain, it is common to find insurance between €80,000 and €600,000, although there are limited policies of up to €2,000, and much higher amounts for multinationals or especially high-risk companies. The average sum insured can be set at around €200,000”. It should be borne in mind that most companies that take out this insurance in our country are medium and large corporations.

Coverage and exclusions

The Beazley expert clarifies that “like all liability insurance, cyber risk policiescover claims brought against the insured for damage caused to third parties. They also cover legal costs incurred and administrative fines from the AEPD”. Martínez emphasises that they cover “liability as a result of security breaches and/or non-compliance with privacy legislation, multimedia liability, administrative fines, legal defence and bonds, communication costs, third-party notification, crisis management and customer support, data extortion, data restoration and loss of business income”.

Alhambra adds that “the element that differentiates this insurance from others is that the insured will have access to a team of data privacy experts who will help manage the incident, even before it reaches the attention of customers or the regulator”. In this way, it typically covers legal advisory costs in relation to the AEPD or the customers whose data has been disclosed; costs to hire an IT security expert to determine the nature of the incident—what happened—and prevent further damage; consultancy costs in public relations, marketing and advertising to manage potential reputational harm; or identity monitoring solutions, ‘data patrol’—a company that checks whether compromised data is being used illegally online.

Another interesting aspect is that these policies include the costs incurred for the repair, renewal or reconstruction of files, certificates, receipts, invoices or any stored data that the insured holds for carrying out the assigned management, as Fernández Burgueño notes.

As for exclusions, they are usually the generic ones applicable to all types of insurance, although the Dual Ibérica expert highlights some specific ones, such as “failure, outage or interruption of electricity supply, public utilities, satellites or external telecommunications services that are not under the insured’s direct operational control; the use of programs, applications and software that have not been successfully tested in a real environment; or the insured’s knowledge of the use of illegal or unlicensed programs, or in violation of provisions or laws relating to the protection of programs or software. In addition, Alhambra notes that cyber risk insurance excludes property damage and bodily injury.

Digital Identity

Methods for analyzing and
assessing online
reputation damage