The Dirty Loophole That Lets Insurance Companies Refuse to Cover a Cybercrime Theft in Your Business
As hacking hit the headlines in the last few years - most recently the global hack in May that targeted companies both large and small - insurance policies to protect businesses against damage and lawsuits have become a very lucrative business indeed. Your company may already have cyber insurance, and that's a good thing. But that doesn't mean that you don't have a job to do - or that the insurance will cover you no matter what.
When you buy a car, you get the warranty. But in order to keep that warranty valid, you have to perform regular maintenance at regularly scheduled times. If you neglect the car, and something foils, the warranty won't cover it. You didn't do your job, and the warranty only covers cars that have been taken care of.
Cyber insurance works the same way. If your company's IT team isn't keeping systems patched and up to date, taking active measures to prevent other cybercrime attacks, and backing everything up in duplicate, it's a lot like neglecting to maintain that car. And when something bad happens, like a cyber-attack, the cyber insurance policy won't be able to help you, just as a warranty policy won't cover a neglected car.
Check out this real-life policy exclusion we recently uncovered, which doesn't cover damages "arising out of or resulting from the failure to, within a reasonable period of time, install customary software product updates and releases, or apply customary security-related software patches, to computers and other components of computer systems." If your cyber insurance policy has a clause like that - and we guarantee that it does - then you're only going to be able to collect if you take reasonable steps to prevent the crime in the first place.
That doesn't just mean you will have to pay a ransom out of pocket, by the way. If your security breach leaves client and partner data vulnerable, you could be sued for failing to protect that data. When your cyber insurance policy is voided because of IT security negligence, you won't be covered against legal damages, either. This is not the kind of position you want to be in.
All of this is not to say that you shouldn't have cyber insurance, or that it's not going to pay out in the case of an unfortunate cyber event. It's just a reminder that your job doesn't end when you sign that insurance policy. You still have to make a reasonable effort to keep your systems secure - an effort you should be making anyway.
The weakest link in Cyber Security is not technology but employees and employee behavior. Organizations are failing to properly educate their employees on even the most basic of security education - how to spot phishing email. A Wombat Security Technologies study found that 30 percent of workers don't even know what a phishing email is and two-thirds are unfamiliar with ransomware. This is why one of the most important steps to securing your business is with employee training and education about cyber-security. We encourage you to give us a call at 203-504-8204 and ask about our extensive cyber-security training, that will not only educate your employees but also test them.



Thinking about driving for Uber? Tax planning for your new business
After fessing up to failings, travel-insurance firm remakes itself
Advisor News
- Global economy ‘resilient’ in the wake of massive disruption
- Cryptocurrency legislation takes one step forward with bipartisan support
- IRS CEO FRANK J. BISIGNANO VISITS OHIO TO TOUT WORKING FAMILIES TAX CUTS PROVISIONS ON NO TAX ON CAR LOAN INTEREST, NO TAX ON OVERTIME, ENHANCED DEDUCTION FOR SENIOR CITIZENS
- The hidden flaw in insurance AI adoption for advisors and carriers
- Rising healthcare costs impact 401(k) accounts
More Advisor NewsAnnuity News
- MetLife Expands Guaranteed Retirement Income Offering with Innovative Flexible Annuity Option
- How annuities can help protect retirees from financial scams
- MetLife Inc. (NYSE: MET) Climbs to New 52-Week High
- The Standard and Pacific Guardian Life Announce Entry into Agreement to Transition Individual Annuities Business
- AuguStar Retirement launches StarStream Variable Annuity
More Annuity NewsHealth/Employee Benefits News
- National Association for Veterans Rights Raises Questions About Federal Court Ruling Impacting Veteran Claims Assistance
- From Network Automation to Agentic NetOps: NetBrain Sets the Standard for Deploying AI in Network Operations
- Hecklers disrupt Hinson rally as Iowa U.S. Senate candidate touts stock trading ban
- The California governor’s race you hate is the one you helped create | Opinion
- Enrolling in Medicare
More Health/Employee Benefits NewsLife Insurance News
- AM Best Affirms Credit Ratings of Halyk-Life, JSC
- AM Best Affirms Credit Ratings of Symetra Financial Corporation and Its Subsidiaries
- AM Best Assigns Credit Ratings to Park Avenue Life Insurance Company
- Nationwide reaches reinsurance agreement with MassMutual on UL policy block
- Best’s Market Segment Report: AM Best Maintains Outlook on Philippines’ Non-Life Insurance Segment at Stable
More Life Insurance News