Companies Slow to Get CyberInsurance Coverage Even as CyberAttacks Increase

09 December 2014 Internet, IT & e-Discovery Blog Blog
Author(s): Peter Vogel

A recent report showed a slight increase from 10% to 26% of companies with cyber insurance coverage between 2013 and 2014, and stated that most US companies are deficient in “keeping the data breach response plan up-to-date, conducting risk assessments of areas vulnerable to a breach, continuous monitoring of information systems to detect unusual and anomalous traffic and investing in technologies that enable timely detections of a security breach.”  In September 2014 the Ponemon Institute LLC issued a report entitled “Is Your Company Ready for a Big Data Breach?” which was sponsored by Experian Data Breach Resolution and stated that cyber insurance policies and incident response (IR) awareness are becoming more important:

In 2013, only 10 percent of respondents said their company purchased a policy. This year, the percentage more than doubled to 26 percent. Further, the use of standard or model contract terms with third parties, vendors or business partners increased. In 2013, 65 percent of respondents said their organizations had these in place and this year it increased to 70 percent of respondents.

Here are topics reported by Ponemon about cyber problems and IR planning:

More companies have data breach response plans and teams in place. In 2013, 61 percent of companies had such a plan in place. This increased to 73 percent in this year’s study. More companies have teams to lead data breach response efforts. In the 2013 study, 67 percent of respondents said they had a data breach response team. This increased to 72 percent.

Data breaches have increased in frequency. In 2013, 33 percent of respondents said their company had a data breach. This year, the percentage has increased to 43 percent. Sixty percent say their company experienced more than one data breach in the past two years. This increased from 52 percent of respondents in 2013.

Most companies have privacy and data protection awareness programs. Ponemon Institute research has revealed that mistakes made by employees are a frequent cause of data breach. While we believe all companies should have such a program, it is a good sign that the existence of training programs increased. In this year’s study, 54 percent say they have privacy and data protection awareness training for employees and other stakeholders who have access to sensitive personal information. This increased from 44 percent in 2013.

There was very little change in the training of customer service personnel. When companies lose customer data, very often it is customer service that must field questions from concerned customers. In 2013, 30 percent of respondents said they provided training on how to respond to questions about a data breach incident. This increased slightly to 34 percent of respondents in 2014.

Informationworld Darkreading also reported:

Nearly three-fourths of US Fortune 500 companies now have set up incident response plans and teams in preparation for cyberattacks, but only one-third of them consider their IR operations actually effective in the face of a data breach, according to a new study.

Hopefully more companies will understand their risk and do a better job to protect with cyber insurance and IR

This blog is made available by Foley & Lardner LLP (“Foley” or “the Firm”) for informational purposes only. It is not meant to convey the Firm’s legal position on behalf of any client, nor is it intended to convey specific legal advice. Any opinions expressed in this article do not necessarily reflect the views of Foley & Lardner LLP, its partners, or its clients. Accordingly, do not act upon this information without seeking counsel from a licensed attorney. This blog is not intended to create, and receipt of it does not constitute, an attorney-client relationship. Communicating with Foley through this website by email, blog post, or otherwise, does not create an attorney-client relationship for any legal matter. Therefore, any communication or material you transmit to Foley through this blog, whether by email, blog post or any other manner, will not be treated as confidential or proprietary. The information on this blog is published “AS IS” and is not guaranteed to be complete, accurate, and or up-to-date. Foley makes no representations or warranties of any kind, express or implied, as to the operation or content of the site. Foley expressly disclaims all other guarantees, warranties, conditions and representations of any kind, either express or implied, whether arising under any statute, law, commercial use or otherwise, including implied warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall Foley or any of its partners, officers, employees, agents or affiliates be liable, directly or indirectly, under any theory of law (contract, tort, negligence or otherwise), to you or anyone else, for any claims, losses or damages, direct, indirect special, incidental, punitive or consequential, resulting from or occasioned by the creation, use of or reliance on this site (including information and other content) or any third party websites or the information, resources or material accessed through any such websites. In some jurisdictions, the contents of this blog may be considered Attorney Advertising. If applicable, please note that prior results do not guarantee a similar outcome. Photographs are for dramatization purposes only and may include models. Likenesses do not necessarily imply current client, partnership or employee status.


Related Services