Cyber Risk

31
® Northbridge Insurance and The power of together are trademarks of Northbridge Financial Corporation (“Northbridge”). Used under licence from Northbridge. Cyber Risk Patrick Cruikshank Northbridge Insurance

Transcript of Cyber Risk

Page 1: Cyber Risk

® Northbridge Insurance and The power of together are trademarks of Northbridge Financial Corporation (“Northbridge”). Used under licence from Northbridge.

Cyber RiskPatrick CruikshankNorthbridge Insurance

Page 2: Cyber Risk

A growing concern in Canada

69% of companies reported a cyber attack

51%of companies had sabotaged data with a moderate to major impact on business

30% of attacks where on businesses with less than 250 employees

Source: Symantec Internet Security Report (2013 & 2014)

Page 3: Cyber Risk

What are Cyber Exposures?

Page 4: Cyber Risk

Common causes of harmHacking

Human error

Denial of service

Malware

Extortion

InfringementOnline

defamation

Privacy incidents

Theft

Phishing

Spear-phishing

Waterholes

Page 5: Cyber Risk

ResultsBusiness

Income Loss

Data Recovery Expenses

Incident Response Expenses

Reputational Damage

Opportunity Costs

Class Action Lawsuits

D&O Claims

Investigative Costs

Fines & Penalties

Page 6: Cyber Risk

Is there not already coverage?

Page 7: Cyber Risk

Property:• Data Problem

CGL:• Financial loss• Loss or corruption

of electronic data

Property & CGL coverage gaps

Page 8: Cyber Risk

What’s the coverage?

Page 9: Cyber Risk

Cyber Risk exposures

Privacy Breach Network Security

Breach

Internet Media Liability

Page 10: Cyber Risk

• Viruses that corrupt data or deny system access

• Transmitting a virus that corrupts someone else’s data or denies system access

Network security breach

Page 11: Cyber Risk

• Personal injury from information posted on your website

• False advertisement posted on your website

• Plagiarized information on your website

Internet media liability

Page 12: Cyber Risk

• Non-public information

• Information belonging to employees, clients or customers

• Digital or hard copy data

Privacy breach

Page 13: Cyber Risk

Introducing IDT911, Privacy Breach Experts

Page 14: Cyber Risk

Why IDT911?

Double-Click to Insert Picture Double-Click to Insert Picture

Double-Click to Insert Picture

600,000Businesses rely on

IDT911 for data risk management

services

45%P&C insurance

marketplace use IDT911

17.5MHouseholds turn to IDT911 for fraud resolution services

Page 15: Cyber Risk

Breach response services

Breach counseling

Crisis management

Remediation planning

Notification assistance

Evidentiary support

Page 16: Cyber Risk

Canadian Marketplace

Page 17: Cyber Risk

Real cases

Lost USB

Hacking

Stolen Laptop

Lost USB

Breach caused by a Vendor

Home Depot Canada ‘assessing’ possible Customer data breach

Privacy breach accessed 20

patient records: Eastern Health

$412-million lawsuit launched against Toronto hospital over privacy breach

Laval transit card disposal

breaches privacy

Privacy watchdog to probe UVic in security breach

Toronto woman sues Rogers after her affair is exposed

Page 18: Cyber Risk

Hard drive disposal

Document disposal

Employee Error

Unauthorized Access

NRC writes companies

potentially affected by data

breach

Student loan data on half a million people was left unsecured: watchdog

Privacy office finds Medicentres failed to protect patient data on stolen laptop

Canadian Online Retailer suffers Data

Breach - Waits entire month before

telling customers

Privacy breach at Rouge Valley

hospital involves thousands of new

mothers

Real cases

Staples investigating potential

security breach

Page 19: Cyber Risk

• BundleSmall business (<$10MM)No websalesMinimal US salesLow hazard risksBasic protection

• CustomLarger risks (<$50MM)Global exposuresHigher hazard risksWebsales

Sectors by Appetite Weight

M&RHESSCBSC&C

Target Customers

SME Business

Page 20: Cyber Risk

Are these industries at risk?

Construction• Basic Info• Payment info• Business

model

Retail• Basic Info• Application

info• Credit reports

Trucking• Basic Info• Location

Tracking / Telematics

• Background Check

• Credit Check

Manufacturing• Basic Info• Intellectual

Property• Access to

Suppliers and Vendors

Page 21: Cyber Risk

Northbridge Insurance’s Cyber Risk

Page 22: Cyber Risk

Incident Response Expense

Digital Asset Expense

Business Interruption

E-Commerce Extortion Expense

First Party coverage

Page 23: Cyber Risk

Network Security & Privacy Liability

Internet Media Liability

Regulatory Proceeding Expense

Third Party coverage

Page 24: Cyber Risk

Two Solutions

BUNDLE

CUSTOM

Page 25: Cyber Risk

Cyber Risk bundle qualifications

Receipts up to $10,000,000

US receipts up to 50%

Current Firewall and anti-virus

Monthly data back-up

No web based receipts

No previous breach claims

Page 26: Cyber Risk

Policy Aggregate $100,000 DeductibleFirst Party

a Breach Incident Response Expenses Coverage 100,000 2,500

b Digital Asset Expense Coverage 50,000 2,500

c Business Income Loss 50,000 48 hours

Third Party

a Network Security and Privacy Liability Coverage 100,000 2,500

b Internet Media Liability Coverage 100,000 2,500

Cyber Risk bundle $100,000

Page 27: Cyber Risk

Insuring Agreement Maximum limitGeneral Aggregate $2,000,000

a Breach Incident Response Expenses Coverage 1,000,000

b Digital Asset Expense Coverage 500,000

c Business Income Loss 500,000

d E-Commerce Extortion Coverage 100,000

Third Party

a Network Security and Privacy Liability Coverage 2,000,000

b Internet Media Liability Coverage 2,000,000

c Regulatory Proceeding Coverage 100,000

Custom Cyber Risk coverages

Page 28: Cyber Risk

LOCATION SIZE INDUSTRY ETHICS

Top MisconceptionsSmall and medium sized risks are relatively safe from cyber risk.Truth: They are not; hackers do not discriminate;

human error does not discriminate.

Page 29: Cyber Risk

Our Cyber Risk Solution

A full first and third party solution

Easy to sell & affordable bundles

Value add of IDT911

Quoted by sector underwriters

Page 30: Cyber Risk

Questions?

Page 31: Cyber Risk