Cyber Coverage.
It's Good Policy.
According to cyber security expert Gary Chan, 58% of all cyber attacks are aimed at small or mid-size business owners because they are easy targets. The average cost of a breach to a business over $1,000,000. Establishing information security basics that don’t break the bank is the key to proper risk management of this exposure.
Headquartered in Missouri, POWERS Insurance and Risk Management thinks globally but act locally with personal services designed specifically for each individual client. Our relationship and leverage with carriers enable us to meet your pricing and coverage expectations while maintaining high quality risk management services.
Episode 263: Gary Chan shares 12 actions to enhance your information security
Quote Request Form
IT Security Basics
Back Up Data
Save at least 6 months' worth of history, not just the last version. That way, if you get hit by ransomware, you can restore your data to pre-crisis times.
Know Your Obligations
Understand your legal, regulatory, and contractual obligations. A business must follow all state and local regulations when their data is breached.
Provide Training
Bring security awareness to your team members and print compliance reports to see who watched training videos and passed quizzes.
Sign up for free security awareness training videos with our security partner Alfizo.
Save at least 6 months' worth of history, not just the last version. That way, if you get hit by ransomware, you can restore your data to pre-crisis times.
Be sure to know your legal, regulatory, and contractual obligations. Each state and local jurisdiction have their own rules and regulations on the procedure a business must follow when they are victims of a data breach.
Grant access rights only when needed for the job. Give your employees access only to applications that they need. Prevent employees from surfing the Internet from computers that accept credit card payments. If an employee leaves your company, be sure to turn off all access privileges immediately.
Bring security awareness to your team members and print compliance reports to see who watched training videos and passed quizzes.
Sign up for free security awareness training videos with our security partner Alfizo.
Multi-factor authentication requires two forms of authentication (typically the online login + a code texted to your phone). Requiring multi-factor authentication makes it substantially harder, though far from impossible, for a hacker to break into your account.
If you are on a budget, use the built-in Windows Defender for Windows PCs and XProtect for Macs. Otherwise, purchase business versions of commercial anti-virus software because they are typically of better quality and easier for IT personnel to manage on behalf of users.
Make sure to regularly update and patch your operating system and applications.
Use a commercial email security system to quarantine potentially malicious email.
Have a way to wipe mobile devices in case they are lost or stolen ... or in case one of your employees goes rogue.
If you use Wi-Fi, make sure you are using a strong password and WPA2 (a security protocol you can select when creating a Wi-Fi Network). Place all guests and customers on a separate network.
Release and document employee expectations for handling your data. Require your associates to sign-off on these procedures, thus establishing acceptable and unacceptable behavior.
Invest in an insurance plan to protect your business against unexpected events. Review your policy to ensure that it covers the right scope and dollar amount for your business.
Key Cyber Insurance Terms
These are the funds you are obligated to pay due to a breach event (you’ve had a breach, and these are the awarded sums). These can be the funds to your employees or third parties.
Also known as First Party costs with a cyber liability claim. This element of coverage will apply to direct expenses for your business like notification costs, credit monitoring, individual’s restoration costs / services, call center if needed.
This element of coverage will apply to the expenses others must incur as a result of your company's data breach. This typically includes elements like credit monitoring and restoration services, additional privacy breach notifications, and additional third-party expenses.
Costs associated with response team – basically your breach response coach.
These are the costs of: Legal advice, notifications, notifying attorney general (in all states where the individuals live), response to regulatory investigations, etc.
External IT firm (appointed by carrier), this is to get the malicious code (of hacker etc) out of the network and secure the network. IT firm to do the forensic investigation to understand what information was compromised.
This is basically your PR firm that can help remediate public damage.
Funds electronically transferred from your bank, theft of funds electronically from bank, or corporate credit cards, and this includes social engineering (deceived into sending funds).
A breach (malware, ransomware, intrusion etc) of the network that prevents access to the network (your network breached, and prevents your organization from getting to a third party system – such as your cloud, agency management system, critical network). Threat to release confidential information, or brand reputation harm due to false information. This can pay the costs for cryptocurrency or other funds paid.
Costs for fraudulent use/ misuse of your electronic identity (establishing credit, signing contracts, websites designed to impersonate the org, done by a third party).
This covers the telephone system being hacked and a third party making unauthorized calls, and also the use of bandwidth. The bandwidth is specifically of interest because a new trend is cyberjacking. Cyberjacking typically occurs when a third party breaches the network and uses some of the bandwidth to mine bitcoin. Normally you won’t even know this is occurring for some time because hackers don’t want to disrupt or substantially slow the network of the organization. A hacker just wants to quietly mine bitcoin.
Fraudulent electronic communications or a website impersonating your organization. So, this could be the cost of communications to your clients about the situation, a suit to reimburse your clients if they paid fraudulent invoices that were distributed to them by the impersonators. This also covers the external costs of a third party to remove the website.
The additional costs of using employees (overtime), or additional staff to rebuild data.
Reimburse your organization for lost income during the downtime of a breach event, after the waiting period.
Extra expense is throughout the insuring clauses, and these expenses incorporate: sourcing your product elsewhere to maintain your client base, contract staffing, overtime for employees, etc. These expenses are to mitigate the interruption of your business.
If a third party (supply chain partner) computer system has a continuous outage longer than the waiting period of the policy that is a result of a cyber event. This is the business income loss that your organization incurs if such supply chain partners as: file storage, infrastructure, a third-party platform, etc.
Income loss due to the reputational harm from having a breach. This is in the event that you have a loss of clients, and it provides an estimate for the year over year (and trends) for the income you lost. This is especially important to professional service providers because if a client is to move then it is harder to regain them.
Costs the senior executive officers are required to pay directly due to a cyber event (indemnity costs). This coverage is excess any other valid and collectible policy (if they purchase Directors and Officers insurance then that policy would respond first).
Your organization transmits a malicious code / malware etc to a third-party computer system (potentially a client or a partner company). Your organization transfers the malware, and your organization is sued due to the costs the third-party company incurs.
