CYBER LIABILITY BREAK OUT SESSION
Dakota Manufacturers' Day Summit October 5, 2016
Beth M. Watkins, CRM, CIC, CISR Director of Management Liability Marsh & McLennan Agency 763-746-8220 Beth.Watkins@MarshMMA.com
CYBER LIABILITY BREAK OUT SESSION Dakota Manufacturers' Day Summit - - PowerPoint PPT Presentation
CYBER LIABILITY BREAK OUT SESSION Dakota Manufacturers' Day Summit October 5, 2016 Beth M. Watkins, CRM, CIC, CISR Director of Management Liability Marsh & McLennan Agency 763-746-8220 Beth.Watkins@MarshMMA.com TODAYS DISCUSSION
Dakota Manufacturers' Day Summit October 5, 2016
Beth M. Watkins, CRM, CIC, CISR Director of Management Liability Marsh & McLennan Agency 763-746-8220 Beth.Watkins@MarshMMA.com
MARSH & McLENNAN AGENCY LLC
1
MARSH & McLENNAN AGENCY LLC
Discovery
Actual or alleged theft, loss, or unauthorized collection/disclosure of confidential information that is in the care, custody, or control of the Insured, or a 3rd for whom the Insured is legally liable. Discovery can come about in several ways:
First Response
Forensic Investigation and Legal Review
External Issues Public Relations Notification Remedial Service Offering Damage to Brand or Reputation Regulatory Fines, Penalties, and Consumer Redress Civil Litigation Income Loss Long-Term Consequences
2
MARSH & McLENNAN AGENCY LLC
3
BARNES & THORNBURG, LLP
“There are only two types of companies: those that have been hacked and those that will be. And even they are converging into one category: companies that have been hacked and will be hacked again.”
– Robert S. Mueller, III Director, FBI
MARSH & McLENNAN AGENCY LLC
4
numbers, birth dates, employee evaluations, customer lists, trade secrets)?
third parties? What about the cloud?
BARNES & THORNBURG, LLP
MARSH & McLENNAN AGENCY LLC
5
– Customer lists – Business/acquisition plans – Employee records (past, present and applicants) – Intellectual property
– Social Security and drivers license numbers – Credit card and financial account numbers – HIPAA
6
MARSH & McLENNAN AGENCY LLC
NetDiligence 2015 Claims Study
7
MARSH & McLENNAN AGENCY LLC
NetDiligence 2015 Claims Study
8
MARSH & McLENNAN AGENCY LLC
9
What Commonalities Exist
Source: Verizon 2013 Data Breach Investigations Report
MARSH & McLENNAN AGENCY LLC
– Small sums demanded and paid – Forensics & investigation
– Inadvertent email to thousands of unintended recipients – Lost laptops with confidential files
– Accessing individual records – Self reported to payment card brands – Breach vendors engaged
– Access to confidential information and network – Social Engineering schemes
10
MARSH & McLENNAN AGENCY LLC
11
– Patchwork of laws (47 states, D.C., Puerto Rico, Virgin Islands) – No Federal Law, International Laws developing
– Jurisdiction in which affected party resides governs notification requirement
– Negligence, invasion of privacy, breach of fiduciary duty, intellectual property infringement, unfair/deceptive business practices – Class Actions – Active Attorney General
MARSH & McLENNAN AGENCY LLC
12
MARSH & McLENNAN AGENCY LLC
13
MARSH & McLENNAN AGENCY LLC
14
business interruption
MARSH & McLENNAN AGENCY LLC
15
MARSH & McLENNAN AGENCY LLC
16
MARSH & McLENNAN AGENCY LLC
17
store/send/receive?
event of a breach?
MARSH & McLENNAN AGENCY LLC
18
reduce the likelihood and severity of a data security breach?
security in your type of business?
risks and consequences of data security breaches, and to enforce their compliance with data security measures?
third parties?
and business continuity plan?
MARSH & McLENNAN AGENCY LLC
19
– Limitations of Liability? – Proof of Insurance? – Availability of Insurance?
– Errors and Omissions (E&O) – tech & and sometimes mfg are excepted here; – Commercial General Liability (CGL); – Property; – Crime; – Kidnap and Ransom (K&R); – Directors and Officers (D&O)
MARSH & McLENNAN AGENCY LLC
20
product all in one
MARSH & McLENNAN AGENCY LLC
21
– Failure to update software? – Unecrypted portable devices?
MARSH & McLENNAN AGENCY LLC
22
In 2014: average claim payout was $733,109 average cost for legal defense was $698,797 average cost for legal settlement was $558,5201 Small businesses can expect forensic costs alone to run $10,000 to $100,0003
Does Insurance Really Pay?
A single call connects you to a team of experts who provide all the services you need to manage a breach and mitigate
Forensics Legal services Breach notification services Call center services Credit monitoring and restoration services
When It Happens To You, Who Do You Call?
In 2013, businesses with revenues less than $300M accounted for over 62% of cyber claims.1 1 out of 5 small businesses falls victim to cyber crime each year. Of those, about 60% go out of business within 6 months.2
It’s Not Just The Big Guys. . .
1. Net Diligence Cyber Claims Study 2014 2. “The Case for Cyber” National Underwriter, May 2015 citing National Cyber Security Alliance 1. Beazley PE Data Breach Report
MARSH & McLENNAN AGENCY LLC
23
MARSH & McLENNAN AGENCY LLC
24
www.datalossdb.org
404.com
MARSH & McLENNAN AGENCY LLC
Beth Watkins Beth.Watkins@MarshMMA.com (763) 746-8220
25
Legal/regional regulatory statement to be added here if required.
26