Privacy Liability & Data Breach Management Nikos Georgopoulos 1 st Athens Privacy & Data Breach Management Conference



Similar documents
Privacy Liability & Data Breach Management Nikos Georgopoulos Cyber Risks Advisor cyrm October 2014

Privacy Liability & Data Breach Management Cyber Insurance as a Customer Privacy Protection Tool

Cyber Risks Management. Nikos Georgopoulos, MBA, cyrm Cyber Risks Advisor

Managing Cyber & Privacy Risks

Mitigating and managing cyber risk: ten issues to consider

Cyber Insurance: How to Investigate the Right Coverage for Your Company

Data Breach and Senior Living Communities May 29, 2015

Cyber Liability & Data Breach Insurance Claims

Cyber Liability. What School Districts Need to Know

Ten Questions Your Board Should be asking about Cyber Security. Eric M. Wright, Shareholder

Privacy / Network Security Liability Insurance Discussion. January 30, Kevin Violette RT ProExec

Cyber Insurance Presentation

GALLAGHER CYBER LIABILITY PRACTICE. Tailored Solutions for Cyber Liability and Professional Liability

NZI LIABILITY CYBER. Are you protected?

Understanding the Business Risk

Cybersecurity: A Growing Concern for All Businesses. RLI Design Professionals Design Professionals Learning Event DPLE 160 October 7, 2015

Cyber Security and Privacy Services. Working in partnership with you to protect your organisation from cyber security threats and data theft

PROFESSIONAL RISK PRIVACY CLAIMS SCENARIOS

Discussion on Network Security & Privacy Liability Exposures and Insurance

Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance

cyber invasions cyber risk insurance AFP Exchange

Cyber Risks in Italian market

Insurance Considerations Related to Data Security and Breach in Outsourcing Agreements

Cyber Liability Insurance

Data breach! cyber and privacy risks. Brian Wright Michael Guidry Lloyd Guidry LLC

How-To Guide: Cyber Security. Content Provided by

Cyber Risk: Global Warning? by Cinzia Altomare, Gen Re

Data breach, cyber and privacy risks. Brian Wright Lloyd Wright Consultants Ltd

WHITE PAPER KEEPING CLIENT AND EMPLOYEE DATA SECURE DRIVES REVENUE AND BUILDS TRUST PROTECTING THE PROTECTOR

Aftermath of a Data Breach Study

Logging In: Auditing Cybersecurity in an Unsecure World

Data Breach Cost. Risks, costs and mitigation strategies for data breaches

Cyber-Crime Protection

Law Firm Cyber Security & Compliance Risks

DATA BREACH COVERAGE

Network Security & Privacy Landscape

Cyber Liability. Michael Cavanaugh, RPLU Vice President, Director of Production Apogee Insurance Group Ext. 7029

DATA BREACH BREAK DOWN LESSONS LEARNED FROM TARGET

SafeBiz. Identity Theft and Data Breach Program For Small & Medium Size Businesses (SMB)

Cyber/ Network Security. FINEX Global

2015 PIAA Corporate Counsel Workshop October 22 23, 2015 Considerations in Cyber Liability Coverage

CYBER SECURITY SPECIALREPORT

Hit ratios are still very low for Security & Privacy coverage: What are companies waiting for?

How to Respond When Sensitive Customer and Employee Data is Breached, Stolen or Compromised

Cybersecurity Workshop

CYBER RISK SECURITY, NETWORK & PRIVACY

Cyber Threats: Exposures and Breach Costs

Managing Cyber Risk through Insurance

Demystifying Cyber Insurance. Jamie Monck-Mason & Andrew Hill. Introduction. What is cyber? Nomenclature

Cyber Risks in the Boardroom

How To Cover A Data Breach In The European Market

THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS

Managing Cyber Threats Risk Management & Insurance Solutions. Presented by: Douglas R. Jones, CPCU, ARM Senior Vice President & Principal

Beazley presentation master

Cybercrime: risks, penalties and prevention

Cybersecurity. Are you prepared?

The Growing Problem of Data Breaches in America

Is Your Company Ready for a Big Data Breach? Sponsored by Experian Data Breach Resolution

Proactive Credential Monitoring as a Method of Fraud Prevention and Risk Mitigation. By Marc Ostryniec, vice president, CSID

Updates within Network Security and Privacy Risk Management

Internet Gaming: The New Face of Cyber Liability. Presented by John M. Link, CPCU Cottingham & Butler

ACE European Risk Briefing 2012

Cyber Warfare. Global Economic Crime Survey. Causes of Cyber Attacks. David Childers, CEO Compli Vivek Krishnamurthy, Foley Hoag LLP. Why Cybercrime?

Cyber Risk Insurance for Agents. Frequently Asked Questions

Jefferson Glassie, FASAE Whiteford, Taylor & Preston

RLI PROFESSIONAL SERVICES GROUP PROFESSIONAL LEARNING EVENT PSGLE 123. Cybersecurity: A Growing Concern for Small Businesses

DATA BREACH, NETWORK SECURITY, CYBER LIABILITY, PRIVACY PROTECTION: ARE YOU INSURED?

Cyber-Security Risk- IP Theft and Data Breaches Protecting your Crown Jewels Internally and with Your Key Third Parties

CYBER LIABILITY INSURANCE

ISO? ISO? ISO? LTD ISO?

APIP - Cyber Liability Insurance Coverages, Limits, and FAQ

Vulnerability Assessment & Compliance

Cyber Insurance as one element of the Cyber risk management strategy

Transcription:

Privacy Liability & Data Breach Management Nikos Georgopoulos 1 st Athens Privacy & Data Breach Management Conference N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 1

Contents Information Age The Personal Data Stolen Market Data Breach Causes Data Breach Costs per record and country Greek Market Vs Global Market Security Incidents Directive On Network and Information Security Data Breach Reactive Management Risk Management Issues Privacy Liability and Data Breach Insurance Claims Target Case Study Top 5 List of Businesses Misconceptions The Data Breach Toolkit More Information N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 2

Information Age N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 3

The Market of Stolen Personal Information Large and sophisticated black market with shockingly low prices for personal information (supply > demand): Credit card information (name, billing address, card-number, CVV2 code, and expiration date) = $1.50 $3.00 per file. Social security numbers = $1 $6 per number, depending on availability of corresponding date of birth and/or mother's maiden name. Online banking log-in details = $50 $1,000. See, RSA Anti-Fraud Command Center, RSA Online Fraud Report, August 20010: ww.rsa.com/solutions/consumer_authentication/intelreport/11068_online_fraud_report_0810.pdf N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 4

Data Breach Causes N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 5

The Average per Capita Cost of Data Breach 2013 Cost of Data Breach Study global Ponemon Institute Research Report N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 6

The Average per Capita Cost of Data Breach per Industry 2013 Cost of Data Breach Study global Ponemon Institute Research Report N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 7

Greek Market Vs Global Market Security Incidents PWC Information Security Survey 2013 70% 60% 50% 40% 30% 20% 10% 0% Eurozone China Germany Greece Italy Spain UK None 1or 2 over 3 N/A Greek companies do not report Security Incidents N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 8

Directive On Network and Information Security The Commission extends the obligation to report significant cyber incidents except Internet and Telecommunications providers to: Key Internet companies (e.g. large cloud providers, social networks, e-commerce platforms, search engines). Banking sector and stock exchange Energy (e.g. electricity and gas) Transport (operators of air, rail and maritime transport and logistics) Health Obligation to notify Customers Breach notification within 24 to 72 hours to the local regulator Data protection officers for 250+ employee firms Fine: up to 100m or 5% of global annual turnover N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 9

Data Breach Reactive Management N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 10

Data Breach Consequences -21% 11.8months The average Diminishing Value of the Brand as a direct result of such an incident would be 21% according to the survey. is the average time it will take to restore an Organizations Reputation s following such an incident N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 11

Risk Management Issues Privacy (Cyber) Risks N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 12

Risk Management Issues Privacy (Cyber) Insurance Insure Intangible Assets http://www.youtube.com/watch?v=4cn5dwpkyla N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 13

Cyber Liability and Data Breach Insurance Claims 2012 Percentage of Breaches by Cause of Loss Other 17% Paper Records 3% Malware / Virus 5% Staff Mistake 7% Third Party Contractors 7% Hacker 23% Theft 9% Rogue Employees 10% NetDiligence Report 2012 Cyber Liability and Data Breach Insurance Claims Lost Laptop / Devices 19% N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 14

Cyber Liability and Data Breach Insurance Claims 2013 NetDiligence Report 2013 Cyber Liability and Data Breach Insurance Claims N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 15

Target Privacy (Cyber) Liability Insurance 100 Million Customers Had Info Stolen 17-year-old created malware used in Target breach Target has $100M of Cyber Insurance 6 insurance companies $10 million deductible $61 million data breach costs $17 million data breach costs reported due to data breach insurance Target Contractor is responsible for Data breach http://www.privacyrisksadvisors.com/case-studies/ N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 16

Target Data Breach Insurance Data Breach Insurance Covers hire a computer forensics investigator to determine how the breach occurred and what data was exposed, hire a data privacy attorney to help navigate the various U.S. State (and international) data privacy laws, send notification letters to the affected customers, offer a one-year credit monitoring service to the customers affected as well as a dedicated call center to answer any customer questions, hire a public relations firm to help with the media, pay for customer damages due to identity theft as well as defense costs in the event there s a lawsuit due to their data breach and pay for privacy regulatory defense and where insurable by state law, regulatory fines and penalties. http://www.privacyrisksadvisors.com/case-studies/ N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 17

Top 5 List of Businesses Misconceptions Every Data Breach is covered by General Liability Policy Our Employees would never act maliciously and know how to protect our data Our Information is well-protected by our IT consultants The Cost to respond to a data breach is very low. Most Data Breaches happen to Big Companies N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 18

The Data Breach Toolkit www.privacyrisksadvisors.com Cyber Risks Advisors N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 19

Nikos Georgopoulos www.privacyrisksadvisors.com Cyber Risks Advisors Linkedin Group Mob. 6948 365033 Email: georgopoulosn@ath.forthnet.gr Diversified Experience in Insurance, Asset Management and Banking 19 years experience in Financial Sector 8 years in Insurance: Alternative Channels Sales Manager Generali Hellas 5 years in Asset Management: Marketing Director ALPHA TRUST Asset Management Company 5 years in Banking: XIOSBANK Εducation ALBA Professional MBA BS Physics University of Patras N.G. Privacy Liability Insurance Presentation to Athens 1 st Privacy & Data Breach Management Conference March 2014 20