Major Cyber Incidents Cut Shareholder Value by 9%: AON 

Along with additional (and alarming) detail on its findings about hacks and shareholder value, AON provides some good news. Based on data from its risk assessment platform, security of common IT domains is improving. As is the security of some industry sectors: “Healthcare: The overall cyber risk score for healthcare clients improved from 2.6 to … Read more

Lawyers — Better Consider Cyber In Addition to Malpractice Insurance to Protect Against Losses from “Spoofing” 

Interesting report about whether legal malpractice insurance covers lawyers when scammers trick them into sending their clients’ payments for real estate into phony accounts. “Of course, not all legal malpractice policies contain misappropriation exclusions, and in the absence thereof, the outcome of the coverage analysis could be different. However, where such an exclusion is present, … Read more

Widespread MOVEit Attacks Highlight Difference in Coverage Between Encryption and Extortion 

“While an insurance company may pay a ransom to get file decryption keys, ‘they won’t pay an extortion fee,’ Wisniewski said. ‘The conventional wisdom of insurers has been, ‘I’m buying encryption keys that are going to let me get this customer online faster, and that reduces my cost of the incident.’ They think they’re getting … Read more

How to Avoid Being on the Hook for Your Vendors’ Inadequate Cybersecurity 

The report includes a description of the nightmare Laboratory Corporation of America endured after one of its vendors was hacked. You’ve likely heard some of these tips on how to start mitigating such risk, but the compilation here is useful. Source: Insure Against Data Breaches Suffered By Vendors and Service Providers

China Releases Plan for Cyber Insurance Development

Xinhua, a state media outlet, reports the “guideline” comes from the Ministry of Industry and Information Technology and the National Financial Regulatory Administration. “The country will further improve the supporting policies and regulations, promote the application of cybersecurity insurance among enterprises, and cultivate more high-quality cybersecurity insurers, said the guideline.” Some might say the PRC … Read more

×