Date
January 23, 2018
Topic
Cyber Insurance
Got
Cyber
Insurance?
Can
You
Afford
the
Deductible?
Buy a cyber policy and you are set, right? Not so fast. Your coverage is contingent on following security best practices, and the deductible may surprise you.
Got Cyber Insurance? Can You Afford the Deductible?

If you are like many business owners nowadays, you are probably considering options when it comes to cyber insurance, which will likely protect you from a variety of liabilities you will incur if a cyberattack successfully penetrates your business network. But buy a policy and you are set, right? Not so fast. Read the fine print.

What a policy typically covers

  • Legal expenses. If your company is breached, you will want legal advice on the specific obligations you have under state, federal and local laws. A company needs to move swiftly through a breach to survive, and having counsel experienced in cyber incidents makes a big difference.
  • Forensic work. When you discover a breach, you are obliged to determine what happened and what information was exposed. Expert forensic examination determines the source and, more importantly, identifies the files that were touched.
  • Notifications and press releases. Your company will be required to release a statement and notification of a data breach, especially under regulatory pressure such as NCUA, PCI or HIPAA.
  • Credit and identity monitoring. You will likely be responsible for ensuring the identities of your users and clients are safe as a breach requirement.

Now read the fine print

Your cyber insurance coverage will be contingent on your business following cybersecurity best practices. At minimum, your insurer will likely expect a basic IT security regimen. Keep your network up to date, because applying security patches is your first bet at keeping your business secure. Train your users, because understanding how to recognize phishing scams is critical to reducing your risk. Back up your network, because as long as your team is down you get no cash flow. Monitor your traffic daily for suspicious activity. And test, test, test. If you do not test what you do, you cannot guarantee anything is working.

If you are not showing persistent effort in protecting your network, you might be at risk of not being covered under your policy, and will have to foot hefty bills yourself.

The deductible is not small

Even if you think you are taking proper precautions, many cyber insurance policies require a hefty deductible before they even kick in. While the policy will prevent you from having to foot the brunt of the cost of an attack, you will still have a big hole in your pocket after all is said and done.

So before signing your policy, get an IT security risk assessment completed. The first step to securing your network is to set up a risk assessment and impact analysis. You need to understand your risks before you can understand what your insurance policy will require, and a thorough assessment will also help you understand what kind of coverage you actually need.

You will need to prove the event

Know specifically what your insurance provider requires for you to make a claim. You may be required to perform a forensic investigation to determine how the breach occurred, and in some cases, if you were negligent in patching or keeping your network updated, the policy may not cover you at all.

You can think of cyber insurance the same way you think of auto insurance. Auto insurance does not give you a green light to drive drunk, just as cyber insurance does not give you the ability to overlook cyber security. Having cyber insurance may be helpful in recovering from a breach, but it is no silver bullet. Your first line of defense is solid IT security.