‘Hacktivists’ randomly exposing millions of dollars worth of personal and corporate information may grab media headlines, but more common — and equally disturbing — forms of data breaches relate to everyday carelessness with non-encrypted work data, according to a panel of experts discussing the topic on Apr. 11.
The Chartis-sponsored event, Data Breaches, Coming to a Network Near You, was held in Toronto on Apr. 11. Panelists at the event said companies need to do a better job of creating a “climate of security” regarding the everyday handling of sensitive work information that includes employee and client records.
This means more than making sure IT people plug any holes in the company’s software, observed Jason Straight, managing director of risk consulting company Kroll Inc. “There’s a patch for software, but there’s no patch for stupid.”
In his presentation, Straight observed that companies are still too casual about dealing with their sensitive information, unnecessarily exposing them to potential data breaches.
“I cannot tell you the sheer volume of the cases that we have of laptops that have been left at a supermarket parking lot,” he said. “We had one guy, he worked for the IT department of a major company, he left a laptop in his car when he went into the supermarket. It was stolen. And of course the data was not encrypted.
“You’d be amazed how many times that situation plays out.”
In addition, company employees and IT people can often be lax about passwords at work, caught in that grey area between securing information and simply trying to get their work done quickly.
“People make mistakes,” said Straight. “Sometimes it’s out of frustration of having to remember several passwords, so they just use the word ‘Password.’ Or they don’t change default passwords. I could speak for an hour about password data, but it is a huge issue and we see it again and again and again.”
Also, a weak economy has led to disgruntled employees. This may lead the employees to loot company data for the purposes of vengeance, sabotage or extortion.
Andrea Laing, partner at Osler Hoskin and Harcourt LLP, said encrypting data is crucial.
She noted the federal government introduced amendments to the Personal Information Protection and Electronic Documents Act (PIPEDA) in 2011 that would require companies to disclose a "material breach of security safeguards.”
Part of the notification test is whether “it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to the individual.”
If data stolen from the company is encrypted, it will be a lot more difficult to prove that it might “harm” someone if stolen, said Laing. “Sometimes it might be unclear as to whether the information could be used in a harmful way, but I would say that whether or not the data has been encrypted is a very, very important consideration.”
Several panelists suggested the urgent need for companies to establish policies about the proper and improper use of data. These policies can be used in court to establish that an employee stealing company information acted as a “rogue,” and clearly contrary to company policy. This can help to mitigate a company’s exposure to liability in the event of a data breach.
Friday, April 13, 2012
Customer retention is key for North American insurers: Gartner
The top priority for information technology leaders at insurance companies is keeping the clients they have, Gartner Inc. said in a recent report.
In a survey of IT professionals from five Canadian and 57 U.S. property and casualty insurers, 81% of respondents cited client retention as their Number 1 priority for technology investments.
“Insurers have increasingly been looking to customer retention as a means to preserve revenue and avoid customer churn,” said Kimberly Harris-Ferrante, vice president and distinguished analyst at Gartner. “Protecting the customer base through improved customer service is key for P&C insurers, as well as helping to avoid negative brand images as consumers continue to use social media channels to share complaints and opinions about insurance companies in a public forum.”
The next top-rated priority is to promote relationships with brokers and agents, followed closely by the need to move from legacy assets to more modern claims and policy management solutions, according to Gartner.
In a survey of IT professionals from five Canadian and 57 U.S. property and casualty insurers, 81% of respondents cited client retention as their Number 1 priority for technology investments.
“Insurers have increasingly been looking to customer retention as a means to preserve revenue and avoid customer churn,” said Kimberly Harris-Ferrante, vice president and distinguished analyst at Gartner. “Protecting the customer base through improved customer service is key for P&C insurers, as well as helping to avoid negative brand images as consumers continue to use social media channels to share complaints and opinions about insurance companies in a public forum.”
The next top-rated priority is to promote relationships with brokers and agents, followed closely by the need to move from legacy assets to more modern claims and policy management solutions, according to Gartner.
Denial-of-service attacks surge in 2012
A wave of distributed denial-of-service attacks plagued financial services companies during the first quarter of this year, according to a report from Prolexic Technologies Inc.
A distributed denial-of-service attack is one in which several compromised systems attack a single target, causing denial of service for legitimate users. The flood of incoming messages to the target system essentially forces it to shut down, thereby denying service.
The Florida-based company said its client data showed a 25% increase in the number of attacks in the first three months of 2012 compared to the same period last year. The largest number of attacks originated from China, followed by the United States and Russia.
“The considerable increase in attack intensity indicates that attackers are evolving their strategies, increasing their firepower and focusing on specific targets such as financial services,” the report noted.
It also stated shorter average duration of attacks showed hackers are using “shorter, stronger bursts of traffic to conduct” denial-of-service campaigns.
A distributed denial-of-service attack is one in which several compromised systems attack a single target, causing denial of service for legitimate users. The flood of incoming messages to the target system essentially forces it to shut down, thereby denying service.
The Florida-based company said its client data showed a 25% increase in the number of attacks in the first three months of 2012 compared to the same period last year. The largest number of attacks originated from China, followed by the United States and Russia.
“The considerable increase in attack intensity indicates that attackers are evolving their strategies, increasing their firepower and focusing on specific targets such as financial services,” the report noted.
It also stated shorter average duration of attacks showed hackers are using “shorter, stronger bursts of traffic to conduct” denial-of-service campaigns.
Ontario court ruling that establishes a civil action for privacy breaches is a "game-changer" for defence counsel: lawyer
The Ontario Court of Appeal’s decision in Jones v. Tsige, which found a right to a civil action for breach of privacy, may be a “game-changer” for insurance defence counsel.
“We have this [data breach] case out there, and it may well change the landscape,” Andrea Laing, a partner of Osler Hoskin and Harcourt LLP, told a Chartis-sponsored event in Toronto on Apr. 11. “We should pay attention to it.”
In Jones, Sandra Jones, a customer and employee of the Bank of Montreal, became aware that another bank employee, Winnie Tsige, had snooped in Jones’ personal financial records at the bank 174 times over a period of four years. Jones was the former spouse of an individual with whom Tsige was involved in a relationship.
Jones and Tsige apparently did not know each other but Tsige took advantage of her employment at the bank to snoop in Jones’ banking records.
In its ruling on the matter, the Ontario Court of Appeal found there is a cause of action in tort for invasion of privacy. The court says an element of the civil action would include, among others things: “a reasonable person would regard the invasion as highly offensive causing distress, humiliation or anguish. However, proof of harm to a recognized economic interest is not an element of the cause of action.”
Laing said these boundaries of the new tort remain somewhat vague. They may be better defined in the future through more civil actions related to data breaches. But defence counsel are particularly worried about the suggestion that the absence of a proven economic harm, the reason why many actions have failed before, may no longer be an avenue for dismissing an action.
“One of the problems we have with a test that doesn’t really create a bright line [is that] it is going to be very difficult to get future cases to be struck at a preliminary stage,” Laing said. “Indeed, in some cases, it may be necessary to take it all the way to trial just to demonstrate [the case doesn’t meet the test]. Obviously, this raises the costs of settlement. It raises defence costs.”
“We have this [data breach] case out there, and it may well change the landscape,” Andrea Laing, a partner of Osler Hoskin and Harcourt LLP, told a Chartis-sponsored event in Toronto on Apr. 11. “We should pay attention to it.”
In Jones, Sandra Jones, a customer and employee of the Bank of Montreal, became aware that another bank employee, Winnie Tsige, had snooped in Jones’ personal financial records at the bank 174 times over a period of four years. Jones was the former spouse of an individual with whom Tsige was involved in a relationship.
Jones and Tsige apparently did not know each other but Tsige took advantage of her employment at the bank to snoop in Jones’ banking records.
In its ruling on the matter, the Ontario Court of Appeal found there is a cause of action in tort for invasion of privacy. The court says an element of the civil action would include, among others things: “a reasonable person would regard the invasion as highly offensive causing distress, humiliation or anguish. However, proof of harm to a recognized economic interest is not an element of the cause of action.”
Laing said these boundaries of the new tort remain somewhat vague. They may be better defined in the future through more civil actions related to data breaches. But defence counsel are particularly worried about the suggestion that the absence of a proven economic harm, the reason why many actions have failed before, may no longer be an avenue for dismissing an action.
“One of the problems we have with a test that doesn’t really create a bright line [is that] it is going to be very difficult to get future cases to be struck at a preliminary stage,” Laing said. “Indeed, in some cases, it may be necessary to take it all the way to trial just to demonstrate [the case doesn’t meet the test]. Obviously, this raises the costs of settlement. It raises defence costs.”
Friday, March 16, 2012
Aviva Canada warns of season for wildlife crashes
Wildlife collisions are in the sights of Canadian insurers, particularly between March and June, when wildlife collisions are most frequent.
“The most costly result of these collisions is injury or even death of both the wildlife and the driver,” Aviva Canada notes on its website. “They’re more common than you’d think — a report from Transport Canada found that between four to eight large animal vehicle collisions take place every hour in Canada.”
The Wildlife Collision Prevention Program, an initiative led by the B.C. Conservation Foundation, has a website dedicated to education and prevention of wildlife collisions. It cites statistics showing that about one out of every 25 crashes in 2007 were wildlife crashes, costing B.C.’s public insurer more than $30 million.
Five B.C. drivers were killed in wildlife crashes in 2007 and another 449 were injured.
In addition to paying attention to the road and wildlife signs, Aviva Canada offers the following tips to reduce change of being involved in a wildlife collision:
• Stay in control of the vehicle: Never swerve abruptly, because hitting a tree or moving into oncoming traffic can result in significantly more harm than hitting the animal. Brake firmly if an animal is standing on, or crossing, the road.
• React: If you can’t avoid striking the large animal, be ready to duck inside your car. Big animals weighing well in access of 100 kilograms can come through your windshield and cause severe injuries.
“The most costly result of these collisions is injury or even death of both the wildlife and the driver,” Aviva Canada notes on its website. “They’re more common than you’d think — a report from Transport Canada found that between four to eight large animal vehicle collisions take place every hour in Canada.”
The Wildlife Collision Prevention Program, an initiative led by the B.C. Conservation Foundation, has a website dedicated to education and prevention of wildlife collisions. It cites statistics showing that about one out of every 25 crashes in 2007 were wildlife crashes, costing B.C.’s public insurer more than $30 million.
Five B.C. drivers were killed in wildlife crashes in 2007 and another 449 were injured.
In addition to paying attention to the road and wildlife signs, Aviva Canada offers the following tips to reduce change of being involved in a wildlife collision:
• Stay in control of the vehicle: Never swerve abruptly, because hitting a tree or moving into oncoming traffic can result in significantly more harm than hitting the animal. Brake firmly if an animal is standing on, or crossing, the road.
• React: If you can’t avoid striking the large animal, be ready to duck inside your car. Big animals weighing well in access of 100 kilograms can come through your windshield and cause severe injuries.
Corporate board directors need to be aware of risk of data breaches in light of regulatory guidance on disclosing cyber threats
U.S. board directors need to be acutely aware of the risk of data breaches at their companies in light of recent regulatory guidance on disclosing cyber threats, according to speakers at a Willis-hosted cyber liability conference in London.
The U.S. Securities Exchange Commission (SEC) issued guidance on disclosing cyberthreats in October 2011.
“The SEC guidance is a useful wake-up call to the risks of data breaches for boards everywhere but [boards] now have a delicate balancing act,” Francis Kean of Willis Group Holdings told the audience on Mar. 13. “The problem with exposing cyber breaches is you don’t want to provide a route map to hackers or potential plaintiffs down the road, but you also don’t want to expose yourself to a shareholder class action.”
Kean stressed the need for boards to better understand emerging cyber threats.
“There is a whole universe of potential cyber risk not understood at a board level,” he said. “Their fiduciary duties require them to gain some understanding of the cyber threat faced by their companies and to ensure adequate and proportionate procedures are adopted to mitigate the consequences of a serious data breach.”
The SEC guidance was issued to address concerns that investors could not assess security risks properly if companies failed to disclose data breaches in their public findings.
Some of the SEC’s expectations about disclosure call for specifics: “A registrant may need to disclose known or threatened cyber incidents to place the discussion of cybersecurity risks in context,” the SEC guidance says.
“For example, if a registrant experienced a material cyber attack in which malware was embedded in its systems and customer data was compromised, it likely would not be sufficient for the registrant to disclose that there is a risk that such an attack may occur.
“Instead, as part of a broader discussion of malware or other similar attacks that pose a particular risk, the registrant may need to discuss the occurrence of the specific attack and its known and potential costs and other consequences.”
At another panel at the event, Jeremy Smith, Willis’ cyber liabilities practice leader, discussed the development of cyber liability insurance.
“The convergence of cyber coverage in recent years was largely due to a lack of sophisticated claims data and significant increases in cyber crime,” Smith said.
Now, however, Smith observed that brokers are now pushing for further innovation from the market and have managed to secure additional coverage for PCI fines, third party vendors and terrorism.
Also, advanced persistent threats (APTs), such as the Aurora virus and Nightdragon, are the next challenge for the insurance industry according to Smith. “APTs are sustained attacks designed to steal intellectual property over a number of years. The insurance industry hasn’t fully tackled this threat yet, but I hope that brokers and insurers will find a solution together in the future.” he said.
The U.S. Securities Exchange Commission (SEC) issued guidance on disclosing cyberthreats in October 2011.
“The SEC guidance is a useful wake-up call to the risks of data breaches for boards everywhere but [boards] now have a delicate balancing act,” Francis Kean of Willis Group Holdings told the audience on Mar. 13. “The problem with exposing cyber breaches is you don’t want to provide a route map to hackers or potential plaintiffs down the road, but you also don’t want to expose yourself to a shareholder class action.”
Kean stressed the need for boards to better understand emerging cyber threats.
“There is a whole universe of potential cyber risk not understood at a board level,” he said. “Their fiduciary duties require them to gain some understanding of the cyber threat faced by their companies and to ensure adequate and proportionate procedures are adopted to mitigate the consequences of a serious data breach.”
The SEC guidance was issued to address concerns that investors could not assess security risks properly if companies failed to disclose data breaches in their public findings.
Some of the SEC’s expectations about disclosure call for specifics: “A registrant may need to disclose known or threatened cyber incidents to place the discussion of cybersecurity risks in context,” the SEC guidance says.
“For example, if a registrant experienced a material cyber attack in which malware was embedded in its systems and customer data was compromised, it likely would not be sufficient for the registrant to disclose that there is a risk that such an attack may occur.
“Instead, as part of a broader discussion of malware or other similar attacks that pose a particular risk, the registrant may need to discuss the occurrence of the specific attack and its known and potential costs and other consequences.”
At another panel at the event, Jeremy Smith, Willis’ cyber liabilities practice leader, discussed the development of cyber liability insurance.
“The convergence of cyber coverage in recent years was largely due to a lack of sophisticated claims data and significant increases in cyber crime,” Smith said.
Now, however, Smith observed that brokers are now pushing for further innovation from the market and have managed to secure additional coverage for PCI fines, third party vendors and terrorism.
Also, advanced persistent threats (APTs), such as the Aurora virus and Nightdragon, are the next challenge for the insurance industry according to Smith. “APTs are sustained attacks designed to steal intellectual property over a number of years. The insurance industry hasn’t fully tackled this threat yet, but I hope that brokers and insurers will find a solution together in the future.” he said.
Friday, March 2, 2012
Drivers aged 56-60 pay less for auto insurance than 41-45 age group - unless they live in Ontario
Canadian drivers in the 56-60 age category can pay an average of up to $15 per month less for car insurance premiums than younger drivers in the 41-45 age bracket — unless you live in Ontario.
InsureEye Inc., a Canadian company providing independent online services to help consumers better understand and manage their insurance, found that Ontario drivers in the 56-60 age group pays roughly the same ($144 per month) as the 41-45 group ($146 per month).
“Interestingly, Ontario premiums are stuck in the past,” InsureEye Inc. said in its analysis. “The 56-60 group in Ontario hardly saves in comparison with the 41-45 crowd, and still pays around $144/month.”
Overall, Canadians’ average auto insurance premiums decrease by approximately 15% during a lifetime.
InsurEye’s study showed an average Canadian in the 25-30 age bracket pays $130 per month for auto insurance, with men paying $140 and women spending $123 monthly. Costs vary across provinces, and in Ontario the average premium for this youth segment was as high as $163 per month.
As might be expected, as drivers become more experienced, their premiums decrease. The study found drivers in the 41-45 age bracket paid an average of $115 per month for auto insurance, with the men paying $117 per month and the women paying $113 per month.
In the 56-60 age category, premiums across Canada averaged $108 monthly — $109 for men and $108 for women
InsureEye Inc., a Canadian company providing independent online services to help consumers better understand and manage their insurance, found that Ontario drivers in the 56-60 age group pays roughly the same ($144 per month) as the 41-45 group ($146 per month).
“Interestingly, Ontario premiums are stuck in the past,” InsureEye Inc. said in its analysis. “The 56-60 group in Ontario hardly saves in comparison with the 41-45 crowd, and still pays around $144/month.”
Overall, Canadians’ average auto insurance premiums decrease by approximately 15% during a lifetime.
InsurEye’s study showed an average Canadian in the 25-30 age bracket pays $130 per month for auto insurance, with men paying $140 and women spending $123 monthly. Costs vary across provinces, and in Ontario the average premium for this youth segment was as high as $163 per month.
As might be expected, as drivers become more experienced, their premiums decrease. The study found drivers in the 41-45 age bracket paid an average of $115 per month for auto insurance, with the men paying $117 per month and the women paying $113 per month.
In the 56-60 age category, premiums across Canada averaged $108 monthly — $109 for men and $108 for women
Subscribe to:
Posts (Atom)