In this digital age, businesses rely heavily on technology and the internet which makes them target for data breaches. Today, small or large all businesses face cyber security threats. Especially fintech industry and banks face highest risk in terms of losing funds and potentially the reputation.
Unique about this threat is that the attacker could be sitting in any part of the world and enter your system. Threats range from data breaches and ransomware attacks to phishing. If it is a direct cyber-attack then the consequences could be loss of data, loss of reputation, ransom from attacker or even vandalism on your digital assets. Often the ramson is demanded in bitcoins or other digital currency.
Cybersecurity insurance provides financial protection against the costs associated with cyber incidents, including data recovery, legal expenses, ransom and regulatory fines.
Areas of breaches: include Customer access points, payment infrastructure, core cloud service breaches, data center providers breaches, or other external hackers.
Causes of breaches: Lack of firewall, misconfiguration of partners software, open network access, insider malicious activity. Some research shows that the hacker will be in your system for 90 to 180 days before the attack is made. The stagnant cyber security policy or not updating the firewalls, means hackers get enough time to break down the firewall.
Key Aspects of Cyber Risks and Insurance:
E Vandalism: The hackers deface your website, to display the hackers’ power. The attacker may create some malware which damages some files. The cyber insurance in such case will cover the cost of defamation, restoration of the asset and any other cost incurred due to vandalism.
E Business Interruption: Attacker takes control of your server or main operational digital asset and brings down the business operations in such cases the business losses that company faces can be covered by cyber insurance. It provides coverage for financial losses due to downtime caused by cyberattacks. The cyber insurance provider would often expect the insured to have a business continuity plan in place.
Damage Due to Identity Theft: Attacker steals the identity of individual or company and enters fraudulent transaction. Identity theft is more prominent in the case of individuals rather than companies. Identity thefts could be stealing PAN. Credit card or Aadhar card numbers etc. The insurer will cover the cost of restoration and any financial loss caused due to identity theft.
Damage due to Phishing and mail spoofing: Email Phishing is an act of impersonating a business or entity it tricks the recipient of email into giving up sensitive personal information. The scamsters send e-mails or create web pages impersonating your Business and collect an individual's online bank, credit card, or other login information. Email spoofing means use of header that appears to have originated from your company. The email will appear to have come from a known contact or customer, requesting him to download the attachment in the mail. The insurer will make good the losses due to this.
Extortion and Ransomware: Insurer will give protection against ransomware attacks and extortion attempts, including ransom payments.
Cyber Liability: Liability coverage for lawsuits brought by affected parties due to data breaches or cyber incidents are covered by cyber insurance policy.
Vendor and Supply Chain Risks: Coverage can extend to risks posed by third-party vendors and supply chain partners, protecting your business from indirect threats.
Regulatory Compliance: Compliance with data protection regulations, such as the Personal Data Protection Bill (PDPB) in India, may require cybersecurity insurance as part of risk management strategies.
Cyber insurance provider makes good almost all the losses due to cyber incident but like any other insurance type, the insurance company will not give claims if the system was not as per the international standards in terms of cyber security. A caution here is that insurance companies do not pay claims if your system was highly vulnerable to attack.
As a basic cyber security hygiene, the insurer expects some of the following security and recovery measures in place before they even consider offering insurance coverage to a company.
BCP: business continuity plan
DR: Disaster recovery site, so in case of incidents the lost data can be recovered.
SoC: Security operations center that is capable of recovering, reporting and investigating security breaches.
NAC: Network access control which protects against advanced persistent threats.
Intrusion Detection and Prevention (IDS/IPS) solution for network
Data Leakage Prevention (DLP) tool
Next-Generation Firewall (NGFW) or Unified Threat Management (UTM) solution capable of in-line Deep Packet Inspection (DPI)
Conclusion:
By investing in cybersecurity insurance, businesses can minimize financial loss, and safeguard sensitive data. The cost of the cyber insurance varies based on business types, for example a B2C financial transaction related businesses premium would be higher than B2B business doing corporate transactions. Cyber risk is a business risk that needs to be acknowledged and mitigated, Cybersecurity insurance is not just an option; it's a strategic necessity to protect against cyberattacks and data breaches.
SimpliInsure.com is an online portal managed by Virtual Galaxy Insurance Brokers Pvt. Ltd., registered with IRDAI as a Direct Broker (Life & General). Registration No. 750, Registration Code IRDA/DB859/21, valid from 2024 to 2027.
Registered office: No. 91/1, 1st Floor, Above ICICI Bank, Infantry Road, Bengaluru 560001, Karnataka, India. Phone: +91 95133 55661.