It seems like every week we are alerted to another data breach or other cyber incident. These events occurred beyond our expectations. It’s not just a retailer or online store. We see hospitals, cities, etc. fall victim to cyber incidents. The latest news to pop up on my screen comes from a place you might think is unlikely—the National Association of Insurance Commissioners (NAIC).
I get it. Your first thought is what exactly does a hacker want with the NAIC data? If insurance is inherently boring (it isn’t, but some people think so), then insurance data must be even more boring and of much less value than the personally identifiable information someone might obtain elsewhere. This is where we have to change our first assumption. Sometimes cyber incidents have nothing to do with how much someone can profit from the data they receive. Sometimes the question is how far we can disrupt the operations of a business, a business sector or the larger economy.
Cyber risk is operational risk
We tend to think about cyber issues in terms of how much information is being accessed, what it will be used for, and how it will really affect me. But when a cyber incident occurs, there’s more going on. Immediately after any cyber incident, victims shut down their systems, making it difficult or even impossible for them to conduct business. Think about this in the context of NAIC. What is their business?
The NAIC is an organization composed of all insurance commissioners in all jurisdictions in the United States, regardless of their actual title and regardless of whether they were elected or appointed to that position. Their operations are no different than the overall regulatory environment in the United States. They proposed model laws for states to consider addressing new and changing risks. They compile some data across the insurance industry. They help other organizations rate insurance companies and provide data to credit rating agencies.
All this work stopped when their systems were breached. Organizations like AM Best cannot rely on NAIC data to update any ratings they may be working on. Kroll Bond Rating Agency (KBRA), which is responsible for rating bonds on certain investments purchased by insurance companies, has suspended providing data to the NAIC until everything about the breach is known and mitigated. Investment rating is part of regulating the financial solvency of insurance companies and is an important part of the work of the insurance department.
Not all “sensitive data” is PII
We’ve heard from the NAIC that they do not believe payment data or other non-public ratings data was compromised. They believe the breach was limited to publicly available financial reporting information and possibly outdated logs and its system configuration information. In this case, the criminals don’t appear to be looking for personally identifiable information. They were looking for sensitive business data, and the NAIC had a lot of it.
That’s the problem with cyberattacks. They’re not just looking for Social Security numbers, payment information or other types of data related to these breaches. They pursue more diverse information, and this risk will continue to evolve as more systems become more interconnected. Criminals look for vulnerabilities not just because they can make quick money right away.
Sometimes, the breakthrough is the point. The data they’re after is understanding and letting others know they can break that particular system. Sometimes, disruption is done to practice and build a resume of the system they disrupt. Like it or not, the entire economy is built on cybercrime.
Then there is the long tail
Operational disruptions are also part of the problem. By now, you’ve probably heard of ransomware attacks, where criminals lock down a system or data until they receive a ransom for an unlocking key. After several years of this risk growing, responses have shifted from paying ransoms quickly to resetting and restoring old backups. In the case of a NAIC breach, the criminals did not lock down the system, but the NAIC had to lock down the system so that they could assess what happened, figure out how to harden their system, and convince their partners that the system was secure enough to continue interacting with it.
Let’s talk a little bit about coverage here. A cyber incident that may (or may not) initially be covered by a cyber policy can quickly turn into a commercial revenue event, and even less likely to be covered by any insurance policy. This is certainly not covered by their business income and additional expenses policy. This is where the troubles for businesses become more complicated.
Without proper coverage, businesses end up shutting down because their systems have to be shut down due to a cyber incident, and they never recover because they have multiple financial impacts when someone gets into their system and doesn’t even touch the kind of data we normally think about.
theme
network
interested in network?
Get automated alerts on this topic.
