
When most business owners think about a cyber claim, they picture a sophisticated hacker sitting somewhere halfway around the world trying to break into their computer system.
The reality is often quite different.
A cyber loss can begin with something as simple as an employee opening an email, clicking on a link, using a compromised password, or following what appears to be legitimate instructions from a customer or company executive.
From an insurance standpoint, I believe there are three cyber exposures that virtually every business owner should understand: ransomware, data theft, and email compromise.
Ransomware — When Your Business Is Held Hostage
Ransomware is probably the cyber threat most people recognize. A criminal gains access to a company’s computer system, encrypts its files or disables its network, and then demands money to restore access.
But the ransom itself may be only part of the loss.
The business may have to hire computer forensic specialists to determine what happened and how the criminals entered the system. Data may have to be restored. Attorneys and other specialists may need to become involved. The company may be unable to operate normally for days or even weeks.
There is also an increasingly important question: Did the criminal simply encrypt the information, or did they steal it as well?
If information was taken, what started as a ransomware attack can quickly become a data-breach claim.
A properly designed cyber insurance policy may respond to many of these expenses, including forensic investigation, data restoration, business interruption, crisis management and, subject to the policy and applicable law, ransomware-related expenses.
Data Theft — The Cost Goes Far Beyond the Stolen Information
Almost every business possesses information somebody else would like to have.
It might be customers’ names, addresses, Social Security numbers, credit card information or financial records. It could also be employee payroll and personnel information.
When that information is stolen, the financial consequences can extend well beyond the value of the data itself.
The company may have to determine exactly what information was compromised and whose information was involved. Customers or employees may have to be notified. Credit monitoring may need to be provided. Attorneys, forensic specialists and public-relations professionals may become involved.
There can also be regulatory investigations and lawsuits from customers or others who claim they were damaged because the company failed to adequately protect their information.
This illustrates an important distinction in cyber insurance. There are first-party losses—the expenses your own company incurs responding to the event—and third-party liability, where someone else makes a claim against your company.
A good cyber policy should be evaluated from both perspectives.
Email Compromise — The Email Looks Real, the Money Is Gone
This may be the cyber exposure that concerns me the most because it doesn’t necessarily require a criminal to defeat an elaborate computer-security system.
Sometimes they simply have to fool one person.
An employee receives what appears to be an email from the owner, a senior executive, a customer or a trusted vendor. The email may request a wire transfer, change banking instructions or provide a new account number for payment.
Everything looks legitimate.
The employee follows the instructions. The money is transferred. Only later does the company discover that the email was fraudulent and the money is gone.
This is commonly associated with business email compromise and social engineering, and it raises an important insurance question.
Business owners should not automatically assume that because a loss involved a computer or an email, their cyber insurance policy will cover it.
Depending upon the circumstances and the policy language, coverage for the stolen money may involve cyber insurance, crime insurance, funds-transfer fraud or specific social-engineering coverage. Limits and conditions can also vary considerably.
This is one of those situations where the details of the insurance contract matter before the claim occurs—not afterward.
Cyber Isn’t Just a Big-Business Problem
There was a time when cyber insurance might have seemed like specialized coverage primarily for technology companies, financial institutions and large corporations.
That is no longer the case.
If your business uses email, maintains customer or employee information, conducts electronic banking, accepts electronic payments or simply depends upon its computer system to operate, you have a cyber exposure.
In fact, a serious cyber loss can be particularly difficult for a smaller business. A large corporation may have an IT department, cybersecurity specialists, attorneys and substantial financial resources available immediately. A smaller company may have none of those resources readily available.
That is one of the important benefits of cyber insurance that is sometimes overlooked. You aren’t simply purchasing an insurance limit. You may also be purchasing access to the people and resources needed to respond when something goes wrong.
Cyber risk will continue to change, and criminals will continue to find new ways to exploit both technology and human behavior.
The question for a business owner should no longer be simply, “Do I need cyber insurance?”
The better questions are: “What cyber losses could put my business at risk, and does my insurance program actually cover them?”
