{"id":10348,"date":"2023-04-14T16:30:44","date_gmt":"2023-04-14T04:30:44","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=10348"},"modified":"2023-04-14T16:30:44","modified_gmt":"2023-04-14T04:30:44","slug":"is-cyber-insurance-worth-it","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=10348","title":{"rendered":"Is Cyber-insurance worth it?"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;||5px|||&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>Every day we see stories in the newspaper about cyber-attacks. Years agio they seemed a bit remote, but lately they&#8217;ve been getting closer to home.<\/p>\n<p>&nbsp;<\/p>\n<h2>Many businesses are responding by taking on cyber-insurance.\u00a0 But is it worth it?<\/h2>\n<blockquote>\n<p><strong>When you sign up, you are asked to fill in a form, much like any other form of insurance.\u00a0 We&#8217;ve seen these forms get increasingly more demanding and complex.\u00a0 It makes sense that many of our clients ask us to help them compete them, <a href=\"http:\/\/kinetics.co.nz\/helping-you-with-cyber-insurance-audit-forms\">and we do so as a service.<\/a><\/strong><\/p>\n<\/blockquote>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_2,1_2&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h3><span style=\"color: #000000;\">Unfortunately, unless you complete these application forms accurately, you may find your insurance company doesn&#8217;t pay out on any eveNtual claim.\u00a0 \u00a0<\/span><\/h3>\n<p><span style=\"color: #000000;\"><strong>Even worse, unless you meet these insurer requirements, they may decline to offer you cover, or do so at a much higher premium.\u00a0 After all, they are looking to minimise their risk, and just as they don&#8217;t want to insure houses that subject to flooding, or young drivers in expensive cars or any other obvious risks, they won&#8217;t want to cover you unless you are taking reasonable precautions.<\/strong><\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_image src=&#8221;http:\/\/kinetics.co.nz\/wp-content\/uploads\/2021\/09\/CyberInsurance.jpg&#8221; title_text=&#8221;CyberInsurance&#8221; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;#4CB84A&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h3><span style=\"color: #ffffff;\"><strong>Our first conclusion then is that cyber-insurance doesn&#8217;t make sense unless you are prepared to take reasonable steps to protect your organisation first, and to keep those steps in place.<\/strong><\/span><\/h3>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h2>So what are the reasonable steps required?<\/h2>\n<p>Here lies the challenge.\u00a0 What is &#8220;reasonable&#8221; keeps changing and becoming more intense, and more costly.<\/p>\n<p>It used to be that patching systems and keeping them up to date, good daily backups,\u00a0 and up-to-date antivirus was enough.<\/p>\n<p>But that is no longer the case.<\/p>\n<p>It is now well understood that most hacks either occur through unpatched systems, so that remains important.\u00a0 However people breaching a user&#8217;s credentials is increasingly common.\u00a0 THis might be through poor behaviours,simple passwords, common passwords\u00a0 and the like, or it might be through trickery (&#8216;<a href=\"http:\/\/kinetics.co.nz\/beware-social-engineering-the-number-one-security-threat-to-business-is-your-people\/\">social engineering<\/a>&#8216;)<\/p>\n<h2>How can we stop credential-theft?<\/h2>\n<p>Firstly,\u00a0 two-factor, or multi-factor authentication (MFA) is the number one defence. So your insurance company will be looking to make sure this is rolled out for all users, on all devices, in your business.\u00a0 But<a href=\"http:\/\/kinetics.co.nz\/mfa-is-important-but-it-is-no-silver-bullet\/\"> it is not infalliable<\/a> so we need additional layers.\u00a0<\/p>\n<p>Password complexity means the need for password vaults.\u00a0 It is impossible to have unique and unguessable passwords for every site you use without them.\u00a0 You can assume your email address and at least one or two of your passwords will be leaked into the darkweb somewhere.\u00a0 \u00a0Even worse when your data is exposd through a cyber-event on someone else&#8217;s site and your <a href=\"http:\/\/kinetics.co.nz\/is-ignorance-bliss\">private data might be in the hands of bad actors<\/a>.\u00a0 \u00a0That&#8217;s why dark-web monitoring can help.<\/p>\n<p>Education is another vital step.\u00a0 The insurer will probably want to see regualr awareness training, and <a href=\"http:\/\/kinetics.co.nz\/every-day-we-see-smarter-phishing-emails\/\">phishing testing<\/a> in place.<\/p>\n<h2>What about straightout system breaches?<\/h2>\n<p>It is easy to click on a link that takes you to an infected website.\u00a0 Once there, malware loads on your device, and spreads through any network that you are attached to.<\/p>\n<p>An insurer will be looking for a range of tools to defend against this.These include:<\/p>\n<ul>\n<li>EDR (Endpoint detection and response) is the new standard, in place of old anti-virus tools.\u00a0 More proactive, using AI and machine learning, EDR works to detect abnormal activity and shut it down.<\/li>\n<li>Web browser protection are tools that check websites before you connect to them, looking against a database of known &#8216;bad&#8217; sites and looking for signs of danger.<\/li>\n<li>Deepscan of incoming emails makes sure they only have links that are &#8216;safe&#8217; to click on, and the attachments are fully tested before being passed on to you.<\/li>\n<\/ul>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;#4CB84A&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h3><span style=\"color: #ffffff;\">These are just a few of the requirements your insurer will be looking for.\u00a0 \u00a0But they will want a little more than that.<\/span><\/h3>\n<p><span style=\"color: #ffffff;\"><strong>They will want to know they were not only in place, but they have been maintained and kept current.\u00a0 You will need to be able to demonstrate a process of keeping these protections active.<\/strong><\/span><\/p>\n<p><span style=\"color: #ffffff;\"><strong>The easiest way to do that is to have a regular reporting process that demonstrates cyber-compliance.<\/strong><\/span><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h3><span style=\"color: #000000;\">Make sure your IT team or partner can show this to you.<\/span><\/h3>\n<blockquote>\n<p><span style=\"color: #000000;\">We&#8217;re confident our latest KARE reports are industry-leading to prove compliance,and our new <a href=\"http:\/\/kinetics.co.nz\/proactive-it-service-and-support\/\">KARE Foundation and KARE Securty Plus<\/a> packages offer best-in-clase cyber protetion so you can be confident of your cyber-insurance protection.<\/span><\/p>\n<\/blockquote>\n<p><span style=\"color: #000000;\"><i><\/i><\/span><\/p>\n<h3><span style=\"color: #000000;\">IT is important, because hackers ARE trying to steal your data, and while no one can guarantee security, we can make it harder for the hackers and easier for your cyber-insurer.<\/span><\/h3>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Every day we see stories in the newspaper about cyber-attacks. Years agio they seemed a bit remote, but lately they&#8217;ve been getting closer to home. &nbsp; Many businesses are responding by taking on cyber-insurance.\u00a0 But is it worth it? When you sign up, you are asked to fill in a form, much like any other [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":7974,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-10348","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/10348","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10348"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/10348\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10348"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10348"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10348"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}