Cybersecurity: Balancing Risk and Cost
Chuck McGann | October 27, 2015
It seems not a week goes by without an unplanned data access, unapproved data exfiltration or unauthorized system access hitting the headlines. Most recently, the U.S. Government’s Office of Personnel Management (OPM) made the news, disclosing the unauthorized access to the personally identifiable information of over 21 million government employees, applicants, and non-applicant individuals including over 5.6 million employees’ fingerprints.
Insurance companies are familiar with risk management and the cost of a known risk being exercised. When that exposure occurs, the financial payouts can be staggering. Equal risks come from the possibility of information systems’ breach and data exposure.
However, many companies struggle with limited budgets and resources. It inevitably becomes an exercise in balancing risk and cost. I like to use the following analogy: You don’t put a $1,000 fence around a $100 horse. You take reasonable care to make sure the horse stays within the appropriate boundaries, but if that horse gets loose and causes damage in significant excess of the $1,000 fence, you might rethink that decision.
It’s a risk-based decision that can come back and haunt you. So, with solutions ranging from free to millions of dollars, how do you prepare a cyber risk management plan without breaking the bank?
The first step is to understand your risk and your vulnerabilities. What assets do we have in our infrastructure? What personally identifiable and/or sensitive data do we have to protect? What vulnerabilities do we have that need to be mitigated?
In order to understand your information technology assets, an assessment of the infrastructure should be undertaken. Asset management discovery via a network scan will highlight the connected and active assets and what those devices are connecting to. The output of this assessment gives a baseline of the infrastructure to upon which to base your vulnerability analyses.
Infrastructure-specific risk areas can be identified by conducting independent vulnerability assessments and penetration tests. These tests typically are performed by ethical hackers simulating how someone would attack your network and systems. They give you concrete data on where your immediate infrastructure vulnerabilities are.
As this first step is critical in crafting your program, it is a good place to invest budget dollars. Many companies offer the assessment services listed above for reasonable costs. If you must choose only one, it is crucial to have independent vulnerability assessment/penetration testing.
Next, you have to decide what your risk tolerance is. What happens when the horse gets out? How much risk do we want to retain? What is our budget? How much do we want to spend on technical prevention versus mitigation and response?
When answering these questions, you should keep in mind that it’s not a question of ‘if’ you will have an incident; it is a question of ‘when and how bad.’ While you can certainly seek the advice of a cyber professional, ultimately these are questions only you can answer and the answers will be different for every company.
You are now equipped with the information you need to build a balanced, comprehensive program that is unique to your organization. While your needs and their related costs will vary, here are some effective and inexpensive ways to help strengthen the overall security posture of your organization.
- Create a culture of security awareness. The number one security threat to an organization is its people. It is important to educate and enlist all members of your team in protecting your company’s assets. Securing the organization begins at the executive level—lead by example. Help manage your security awareness by walking around, look for unsecured systems or passwords on Post-It notes. See something, say something. An educated employee/user is a valuable security warrior in the fight against cyber threats. The SANS publication Securing the Human is a good resource to review and validate your security awareness program.
- Hit the low hanging fruit. The SANS Top 20 Controls is a list of critical items the security community has identified as having significant value in reducing an organization’s security gaps and controls. Adopting these controls can reduce an organizations exposure and potential liability by showing due diligence to addressing security issues.
Whether we are prepared for it or not, cyber intrusions are now a fact of life for businesses of all sizes. We need to recognize that fact and take the appropriate steps to protect our data and our customers’ data to the best extent possible within the reasonable limits of our financial and technical resources.
The basic cyber protections outlined herein are a quick and inexpensive place to begin your efforts. We can’t build a Berlin Wall to keep the horse in the field, but we can build and maintain a strong, wood-rail fence that contains and protects our data appropriately for our industry’s well-being.
Chuck McGann is chief cyber strategist for Salient Commercial Solutions.
- Electronic Chat with Sanjeev Kumar Chaudhry, Founder and CEO, Gigaforce
- Electronic Chat with Sylvester Mathis, Chief Insurance Officer, Insurity
- Inside the ITA: Meet the Board
- Digital Drip: New Lease on Life
- Transformation Corner: Core System Transformation
- Big Fix: Closing the Data Divide
- Tech, Processes, and a Plan
- Core Systems: Out with the Old?
- 5 Things to Consider When Modernizing a Surety System
- Four Benefits of Integrating Mobile Crash Detection and Accident Management
- Everybody Loves Gelato
- Electronic Chat with Jennifer Smith, VP of L&A Product Strategy, Sapiens North America
- Now Accepting Nominations for "Pick of the Litter" Issue
- “New Normal” Requires an Insurance Analytics Evolution
- Accuracy: Are Data Providers Pulling the Wool Over Your Eyes?
- Agents Send More Business to Insurers with Better Tech, Celent Finds
- Electronic Chat with B2Z Insurance
- Still Standing, Still Learning, and Still at Home
- ITA Pro Magazine, May/June 2021
- Electronic Chat with Chris Ewing, Founder and CEO, One Inc
- Electronic Chat with Sharmila Ray, Head of Carrier Strategy, Solutions and Go-To-Market, Vertafore
- Electronic Chat with Alex Devoto, Founder, LVLFi
- Prince Charles, Lloyd's Launch Sustainability Insurance Task Force
- UFCIC Becomes First U.S. Insurer to Accept Cryptocurrency for Premium Payments
- Electronic Chat with Ty Harris, Co-Founder, Openly Insurance
- The Insurance Industry’s Reliance on Friction: A Good Strategy?
- Loss Control, Premium Audit Systems Critical to Customer Experience, Celent Finds
- What's AI-Right and AI-Wrong?
- The Drive for Digital
- Electronic Chat with Candice Smith, Founder and CEO, Caregiven
- Electronic Chat with Nestor Hugo Solari, Founder/CEO, Sigo
- The Giant Hole in Actuarial Models
- Electronic Chat with Trent Cooksley, COO and Co-Founder, Cowbell Cyber
- The ITA Pro March/April 2021 issue is here!
- Purchasing and Innovation: Friends or Enemies?
- COVID Drives More Reliance on Risk Management Systems, New Study Finds
- Electronic Chat with Robert Clark, CEO, Cloverleaf Analytics
- Solving Customer Communications Challenges with Hybrid Mail
- Six Trends Shaping Digital Insurance Tech Strategies in 2021
- Billing a Key Component of Customer Service, Celent Finds
- Why Data Science Fails
- Electronic Chat with Andrew Jernigan, CEO, and Allen Koski, President and Chief Innovation Officer, Insured Nomads
- Electronic Chat with Allison Martin, CEO and Founder, UDoTest
- Are Carriers Ready for the Coming Crash?
- Electronic Chat with Christopher Moore, Director for North American Sales Engineering and Solutions, Trifacta
- Next Insurance Partners with Amazon Business Prime to Provide Small Businesses with Affordable Digital Insurance Options
- An AI Walks Into an Electronics Store...
- InsurTech NY Announces Global Early-Stage Competition Winners
- World’s Worst County/Western Insurtech Song
- Electronic Chat with Anne-Laure Klein, COO, Akur8
- COVID-19 One Year Later: The Digital Transformation of Insurance
- Electronic Chat with Michael Kassing, CEO/CVO, insured.io
- BrokerTech Ventures Announces 2021 Cohort Class for Accelerator
- An Entirely Preventable Disaster
- Flipping the Fraud Triangle
- The January/February ITA Pro Magazine is here!
- Credit Risk, ESG, Cybersecurity Top Risk Concerns for Financial Institutions, Deloitte Finds
- Electronic Chat with Ellen Moser, Senior Client Executive, Origami Risk LLC
- The Answer to “So What?”
- Leaders Rise from a Year Like No Other!
- Electronic Chat with Jonathan Roomer, Co-Founder, YuLife
- Getting Creative to Hit COVID Curveballs Out of the Park
- Electronic Chat with Eugenio Gonzalez, Plug and Play
- New Report Projects Global Insurtech to Grow by $21 Billion During 2020-2024
- The 2020 Virtual Event Wasteland
- Insurtechs, Investors Optimistic About Post-COVID Future, New DIA/McKinsey Study Finds
- Finding Grandmas
- No Code / Low Code: The New “Shortest Route” In Insurance Delivery
- Are You Addicted to Copy-and-Paste?
- Electronic Chat with Nino Tarantino, CEO- Americas, Insurance and Mobility Solutions (IMS)
- Driving Life Insurance:Tech Alone Won’t Solve Business Problems
- Electronic Chat with Robin Roberson, Managing Director, North America, Claim Central Consolidated
- How Do You Make It Happen?
- Electronic Chat with Jason Liu, CEO, Zywave
- New Partnership Models Take Program Business to the Next Level
- New Study Finds Less than Half of Consumers Trust Insurers to Respond to Their Needs
- Electronic Chat with Andrew Mauritzen, CFO and Head of Insurance Industry, Exactuals
- You Want Us To Do WHAT For Free?
- Electronic Chat with Evgeny Aleksandrov, Co-founder and CEO, Pilotbird
- Electronic Chat with Chris Cheatham, CEO, RiskGenius
- New MIT Sloan Study Finds Few Companies Gain Big Benefits from AI
- The September/October ITA Pro magazine is here!
- “Being Right” is Just the Start of the Battle
- Electronic Chat with Amit Ranjan, Executive VP and CAO, Xceedance
- Planning for Your Business and Tech Future: Strategies, Plans and Budgets for Rapid Transformation
- Electronic Chat with Jimmy Padia, Founder and CEO, Floatbot
- Gelato with Dots and Sprinkles
- COVID-19 and the Insurtech “Junk Drawer”
- Even “Change” is Different Now. Your Strategic Planning Needs to Be Too.
- The Road Ahead for P&C Insurers: How to Understand Customers Better and Navigate the Post-COVID Insurance Market
- Electronic Chat with Jake Tamarkin, Co-founder and CEO, Everyday Life
- Strategic Planning in the “New Normal” Digital Era of Insurance – Your Next Move
- Insurer Tech Investment Priorities See Major Shift in a Post-COVID World
- Plug and Play Selects 25 Insurtech Startups for Winter Batches
- Digital Transformation – A Top Strategic Priority and New Reality
- Four Steps to Successful Migration of Insurance CCM Applications
- COVID-19 Accelerates Insurance Digitalization to Meet Customer Demand: World InsurTech Report 2020
- Electronic Chat with Greg Williams, Co-Founder, President & CEO, Acrisure
- Electronic Chat with Matt Perlman, Partner, IA Capital Group
- Insurer Digitalization: Are you a Competitor or a Laggard?
- Leaders are Leading and Creating the Future of Insurance Distribution
- 3 Things You Need to Know About No-Code
- Electronic Chat with Adam Kiefer, CEO, Talage
- Underwriting in 3D: Using Data to Adapt and Improve Life Insurance Sales
- Getting Past the "Gelato Syndrome"
- Insurers Know CX/UX is Important, but Don't Agree on Execution, Study Finds
- Electronic Chat with Steve Lekas, Branch Insurance
- How AI Can Attract Millennial Talent to the Insurance Industry
- Preventing Data Breaches
- A New Boom for Life Insurance: Shifting Away from the 250-Year-Old Policy Transaction
- Electronic Chat with Ty Harris, Founder and CEO, Openly
- A Digital Wildfire Creates a Burning Platform for Digital Insurance Business Transformation
- Digitalization, COVID-19 Spurring More IT Investment in Cybersecurity
- Electronic Chat with Michael DeGusta, CEO, ClarionDoor
- U.S. Consumers Significantly Underestimate Flood Risk, New Survey Finds
- The Future of Insurance: Opportunities in Ecosystems
- Electronic Chat with Todd Greenbaum, CEO, Input 1
- Majesco to be Acquired by Thoma Bravo
- The Evolving Role of Managing General Agencies
- Electronic Chat with Char Hu
- Electronic Chat with Allan L. Egbert, Jr.
- Electronic Chat with Christopher Tramontano and Zbigniew Gawienczuk
- Data Science is Gelato
- Insurance Innovation: Alive and Kicking
- Independent Agents Divided on Digital Experience, New Survey Finds
- Electronic Chat with Michael Jones
- Electronic Chat with Paul VanderMarck
- As Auto Insurance Premiums Shrink, Insurers Need Mobility Ecosystem, New Study Finds
- Property & Casualty Insurers Raise Digital Games as COVID-19 Elevates Customer Expectations, J.D. Power Finds
- Electronic Chat with Bobbie Shrivastav
- Meet the Board: Marissa Buckley
- Big Data and Insurtech: A Carrier Perspective
- Traditional Insurers Need Open Ecosystems, Partnerships to Remain Competitive, CapGemini Report Finds
- Electronic Chat with John C. Siegman
- 4 Ways AI is Empowering Insurers During COVID-19
- 6 Big Changes to Insurance from the COVID-19 Crisis
- Electronic Chat with Christopher Ewing
- Independent Agency Staff Morale High During COVID-19, New Survey Finds
- Electronic Chat with Brad Epker
- Tapping AI to Improve Policyholder Experience
- Electronic Chat with Manisha Bhargava
- ITA Pro Magazine, March/April 2020
- COVID-19 a Game Changer for Workers’ Comp
- Electronic Chat with Steve Comer
- COVID-19 Pandemic Forces Cancellation of ITA LIVE 2020
- Leveraging Digital Resources in the Time of COVID-19
- Electronic Chat with Robert Hartwig on COVID-19 and Insurance
- Celent Study: Most Small Businesses Still Unclear on Importance of Cyber Insurance
- The January/February 2020 ITA Pro is here!
- Deloitte: New C-Suite Roles Mean More Opportunities for Women
- Electronic Chat with Pankaj Parashar
- Electronic Chat with Tara Kelly
- Electronic Chat with Chuck Wilson
- ITA, InsNerds Collaborate to Enhance ITA LIVE 2020 Content and Coverage
- How SMBs Can Compete in Digital Ecosystems in the 2020s
- 4 Ways Insurance Can Prepare for New Data Privacy Laws
- Brewer Lane Ventures Launches and Hires Insurtech Vet Martha Notaras as Managing Partner
- 2020 GIA Cohort Launches on January 14
- The November/December 2019 ITA Pro is here!
- Electronic Chat with Joshua Snead
- Electronic Chat with Wendy Aarons-Corman
- Simplifying the Move to a Third-party Print Provider
- Take a Business-Driven Approach to Continuous Improvement for Core Systems and Processes
- Electronic Chat with Ron Glozman
- Guidewire’s Data Guru Mike Byam on How Insurers are Using Internal and Third-Party Data
- Electronic Chat with Russ Bostick
- Electronic Chat with Rock Schindler
- Electronic Chat with John Siegman
- Electronic Chat with Martin Burlingame
- Insurtech Landscape 2019: Top 5 Takeaways
- Grinnell Mutual Tackles Massive Transformation -- in Stride
- A Candid Conversation with Paul Mang
- SageSure Insurance Managers Improved Competitiveness by Consolidating Payments to a Single Digital Platform
- Digital Does Matter in Insurance-- And Insurers are Missing the Mark
- The 22nd-Century Insurer: Taking a Cloud-First IT Approach
- The September/October 2019 issue of ITA PRO magazine is now available in digital format here:
- ITA Pro Magazine May/June 2019
- Spotlight on the 2019 IASA Conference
- ValueMomentum Selects Erie as Site of Regional Development Center
- Capgemini and Majesco Become Alliance Partners
- Electronic Chat with Dr. Dan Shoham
- Electronic Chat with Todd Greenbaum
- Martha Notaras: The “Outsider” with an Amazing Inside View
- Electronic Chat with Larissa Tosch
- Martha Notaras Will Join ITA LIVE 2019 as a Keynote Speaker
- Five Things to Consider When Evaluating Your Cyber Risk
- ITA Pro Magazine, January/February 2019
- Synergy Between Insurers' IT and Analytics Teams Key to Operationalizing Insights, Says Novarica
- Major Ransomware Attack Could Hit U.S. with $89B In Economic Damages
- ITA Announces 1st of Three Keynote Speakers at ITA LIVE 2019
- Electronic Chat with Jeroen Morrenhof
- Legacy Systems Are Dead. Really? Don't Count On It.
- Now Accepting Nominations for the 2019 ITA Bridge Awards
- It's time to register for ITA LIVE!
- Registration is Now Open for ITA LIVE 2019!
- What to Expect from a Digital Experience Platform Implementation
- ITA Pro Magazine September Edition is Now Available
- It's National IT Professionals Day
- Save the Date for ITA-LIVE 2019
- OneShield Software and UrbanStat Work Together to Improve Real-Time Analytics and Risk Decision-Making
- ITA LIVE 2019 - SAVE THE DATE!
- Insurance Technology Association Announces New Editor-in-Chief
- August 2018 Edition ITA Pro Magazine is Now Available
- Enterprise Architecture in an Agile World
- Top 10 Tips for Securing Your Mobile Devices and Sensitive Client Data
- Industry Insight: 4 Global Insurance Trends in Digital, Data, Content Services and Security
- Diving Deeper into Prioritizing Your Strategic Digital investments
- Why Content Rules
- How Mass Personalization Will Open the Small Business Benefits Market
- At Year End 2017, Will Your Organization Be Protected from Cyber Risks?
- Do Insurance Bots Dream of Mitigating Risk?
- Conditioned to Respond
- Managing & Mobilizing Insurance Data in a Connected World
- Race to the Finish Line
- New Tools, New Opportunities in Claims
- ITA LIVE: Reaching Insurance Industry Crossroads
- Advice to Insurance IT Leaders: Keep Your Eye on the Ball
- New Date, Venue for ITA LIVE 2017
- Guidewire Makes Major Push to Small and Midtier Market by Acquiring ISCS
- Insurance Disruption is Happening Right Now
- Insurity Adds Strategic Investment Partner, General Atlantic
- Beyond Transformation: The Convergence of Finance, Risk, and Actuarial Functions
- The Rapid Evolution of Consumer Protection Regulation
- Talent Hunt: Finding, Attracting, Retaining Top People
- Insurers Flexing Their Distribution Models
- Technology Driving Disruption in Insurance
- Fear of ‘Next Bubble’ Challenges Life, Annuity Carriers
- Technology Allows Commercial Lines Insurers to Stand Out
- Single Sign-on Viewed as Biggest Tech Challenge for Agencies
- ISCS Observes 20th Anniversary; Scurto Predicts Major Changes Ahead
- Policyholders and Their First Impressions
- Progressive Making Progress on the UBI Front
- High and Dry: Insurers Search for Disaster Recovery Plans
- Insurers Sign The (Un)Dotted Line
- Reflections of a Retired Insurance CIO
- Mobile Device Management Just One Answer to BYOD Issue
- Lessons from GEICO and Progressive on Winning the Critical Buying Stage
- You Are a Target for a Cyber Attack
- Web-based Systems are the Next Evolution in Claims Technology
- Gaining a “Wow” Experience from Web Users
- Time to Shift from Business/IT Alignment to Business/IT Alliance
- Healthcare Insurers Changing to Consumer Model
- Organization is the Key for Selecting Software Vendors
- Analysts Expound on the Needs of the Mid-tier Insurance Market
- Finding the Cure for Obamacare’s Website
- New Software Solutions Benefit Insurers on the Inside and Outside
- Products, Market Impede Investment in Systems for Life Insurers
- Combatting Cyber Threats: Predict, Prevent, Persist
- The Future of Telematics Heads Beyond Insurance
- The Shame in Cyber Security Lapses
- Building Policy Administration Systems for the Future
- Insurers Look Into The Eyes of Their Policyholders
- It’s a New Dawn for the ITA
INSURANCE IT NEWS
- IICF Celebrates Year-round Volunteerism with 2021 Week of Giving
- Vantage Selects Majesco Billing for P&C, Policy for P&C and Digital1st
- insured.io Launches insured.io Insights
- Concierge Cyber Bolsters Expert Cyber Team
- Plug and Play's Winter 2021 Batches Feature 153 Startups To Participate in Innovation Program
- New IICF White Paper Details the Future of Inclusive Work for Insurance
- Foxquilt Announces $8M Series A Round to Provide Customized Insurance for SMBs
- bolttech Extends Series A to $210 million
The Email Chat is a regular feature of the ITA Pro magazine and website. We send a series of questions to an insurance IT leader in search of thought-provoking responses on important issues facing the insurance industry.
ITA LIVE 2020
ITA LIVE 2020 –SAVE THE DATE!
April 5th – 7th, 2020
The Diplomat Resort
Become a member today to receive updates – www.itapro.org/MR
You have surely heard it said that small businesses are the growth engine for America. Today, the phrase has a special ring to it for benefits... READ MORE
With stagnant growth and lingering low interest rates, the life insurance industry faces a challenging future... READ MORE
Finding insurance carriers willing to write commercial lines risks has always been a challenge for producers... READ MORE
As Guidewire Software prepares for the start of Connections, its 11th annual user conference that begins on Nov. 2, Brian Desmond, chief marketing... READ MORE
Successful implementation requires balancing operational and emotional issues... READ MORE
- Vendor Views