4 min. read • Email this page
Listen to this blog post:
Insurance is just a funding mechanism
–Murphy Insurance Agency’s president Michael Murphy
An organization’s foundational problems may lead to losses insurance money can never fix.
I had the opportunity to speak with Michael Murphy president of Murphy Insurance Agency on cyber liability insurance. I wanted to know things like about pricing and post-breach investigations. He replied by email that while my questions were great that all he’d be able to answer was, “it depends.”
But there was a lot Michael would tell me, like giving a peek into insurance mechanics, looking at the reasons to take a deeper view of security than post-breach financial reimbursement and how to get people to start thinking about their organization’s cyber vulnerabilities.
The complete discussion with Michael, is here.
So what can you tell me about cyber insurance?
When you buy insurance, you’re transferring an exposure from yourself to an insurance company – moving it off your personal balance sheet and onto theirs. But from a cyber liability standpoint, it goes much deeper than simply making that transfer. You need to understand where your cyber exposures actually are.
Gone are the days when people thought cyber risk only impacted what I’d call the service layer: the holy grail of personal information – name, date of birth, social security number – that criminals would co-opt and use for identity theft. That was the original threat model.
If people still believe, ‘well, I don’t have that kind of information, I’m a construction company’ – they need to realize: ‘wait, we can’t operate our business because so much of what we do today is automated.’ The risk is well beyond someone trying to steal identities. Which is still a problem – it’s a huge problem – but these cybercriminals have moved well beyond trying to co-opt people’s personal information, with ransomware and all kinds of additional strategies of attack.
We’re now in a world of artificial intelligence, where someone can look at how a business operates and then mimic that business – so what someone sees isn’t really that business at all.
For an example: suppose a client gets an email that seems like it came from you with your logo and your signature. It tells them your banking details have changed and directs them to a new account. They’ve worked with you for years, so they pay the next invoice. But the money is gone. AI made a version of you convincing enough to steal money.
What would be the role of cyber insurance in such a breach?
When I counsel customers, it’s not simply, ‘just buy a cyber liability policy and you’re all set.’ Cyber liability is just a funding mechanism. If an event happens, the coverage certainly plays a role – it can fund potential litigation against your organization, help rebuild your infrastructure. All of that is important. But my point is that people aren’t looking deep enough. You need to push further back and ask, ‘what are we doing to mitigate this? what is the potential risk? fundamentally, how are we looking at this from a risk management standpoint?’
There is no shortage of high-profile cyber events that make this point. Entire categories of business have been brought down simultaneously by a single upstream failure – a system they depended on stopped working. It was great to have a cyber liability policy to help pay for it. But did they have a plan to react to a situation like that? I’m in the insurance business, and yes, we sell insurance policies, but I think it requires a deeper view.
And part of what gets people thinking is understanding who’s on the other side of this. Our firewall was being pinged something like 10,000 times. That is a motivated actor. They weren’t manually sitting there doing it – they had set up automation, just hoping that one time they’d get lucky. The source traced back to somewhere overseas. It seemed almost absurd, but that’s what motivation looks like when the effort cost is near zero.
So it’s like plugging a dam. You’ve got to fill every crack. The hackers only have to be right once. You have to be right thousands of times. A cyber liability policy is not going to do that.
The clearest example of where an insurance policy falls short is reputation risk. Insurance can never pay to fix reputation.
Read the complete interview with Michael at Bryley’s Substack.
Bryley’s staff is here to help guide you in maintaining uptime as they have for many years for Murphy Insurance Agency. To speak to Bryley’s Roy Pacitto please complete the form, below. Or you can email Roy at RPacitto@Bryley.com or reach him by phone at 978.562.6077 x217.
Lawrence writes about networking and security. His consumer-scam writing has appeared on the Moneywise website. He’s written for Bryley since 2015.