On April 20, 2011, someone hacked the Sony Playstation Network. They found an opening in the online video gaming network’s password-reset system and penetrated the security protecting its customer database. Days later, the company admitted that the hackers had obtained personal information on 70 million or more subscribers. The hackers got names, physical and e-mail addresses, birth-dates, and other identifying information, and it’s possible that they got credit card numbers. Sony took the network offline to reinforce it, but within days of it coming back online, hackers broke in again.
Playstation Network is a high-profile target with tens of millions of subscribers, making it attractive to criminals. However, even small businesses that do business over the Internet are vulnerable to the same kinds of intrusions. The federal Internet Crime Complaint Center referred more than 146,000 complaints to local, state and federal law enforcement agencies in 2009, 22 percent more than the year before. One out of every three of those complaints was for identity theft, credit card fraud and computer fraud. The Ponemon Institute has reported that the average data breach costs businesses $7.2 million.
What could happen to a business’s data?
Over a seven-year period, a Georgia man stole 675,000 credit card numbers and associated information. He racked up thousands of fraudulent transactions and bills exceeding $36 million. A Texas man received a 110month prison sentence for hacking into 14 computers in the hospital where he worked as a security guard. He disabled network security systems, installed malicious software, infiltrated a nursing station computer containing patient medical records, and gained remote access to temperature-control systems. The FBI caught a North Carolina man in the act of attempting to access an ATM in 2010. The man had planned to hack into 35 ATM’s located around Houston, Texas in the hope of pocketing more than $200,000.
When consumers and business owners give their credit card numbers and other personal information to a business or organization, they expect that this information will stay confidential. They will hold the organization responsible if they suffer financial harm because their information fell into the wrong hands.
Data breach notification laws are in effect in most states today that require notifcation of customers in the event of a data breach. The Red Flags Rule is being enforced by the Federal Trace Commission (FTC) that requires organizations to have Identity Theft Protection programs in place (or be subject to penalties or fines). The compliance costs to notify customers as well as the risk of incurring fines/penalties can cdrive business costs.
Organizations that lose private data face the potential for large jury awards or out-of-court settlements. To protect themselves, they should consider buying cyber liability insurance.
Insurance companies are advertising Cyber Liability policies that provide coverage for expenses such as:
- Damages to third parties caused by a network security breach
- Loss resulting from administrative or operational mistakes made by the business’s own employees or by outside vendors
- Expenses resulting from a breach of consumer protection laws, such as HIPAA or the Fair Credit Reporting Act
- Costs of notifying customers of a breach (the average per record cost of data breach is $214.00 per customer record)
- Public relations expenses necessary to repair the business’s reputation.
- Extorsion Threat expense
Nearly 30 insurance companies currently offer Cyber Liability policies. If an organization’s insurance broker does not have direct access to a company that offers the coverage, they might be able to obtain it through a specialty broker.
To prevent or reduce losses and to make themselves more attractive to insurance companies, businesses should implement strong network security systems, and continually monitor and update them as needed. Develop plans for responding to any network intrusion events that do occur. A sound plan identifies who should be involved in the response, has procedures for notifying affected customers and authorities, and has a public relations strategy for keeping the public informed.
The majority of businesses and organizations operating today are vulnerable to unauthorized intrusions into their computer networks. The potential costs are more than most organizations can fund on their own. Cyber Liability insurance is a smart investment that can literally save a company.
Fitts Insurance can provide a Cyber Liability quote for your business. For more information, please contact us today!
You can contact our commercial lines department by phone: 888-697-6542 or e-mail our commercial lines department.Tags: cyber crime, cyber liability, cyber theft, id, id theft, identity theft, personal data