{"id":9647,"date":"2022-07-14T09:23:39","date_gmt":"2022-07-13T21:23:39","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=9647"},"modified":"2022-07-14T09:23:39","modified_gmt":"2022-07-13T21:23:39","slug":"are-you-meeting-the-requirements-of-your-cyber-insurer-and-are-you-minimising-your-risk-anyway","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=9647","title":{"rendered":"Are you meeting the requirements of your Cyber Insurer?\u00a0 (And are you minimising your risk anyway?)"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;||9px|||&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;||7px|||&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;||2px|||&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>Given the scale of cyber-attacks, we aren\u2019t surprised to be hearing reports of insurers applying a &#8220;duty of care&#8221; test before agreeing to pay out.<\/p>\n<p>Despite sending chills up your spine, when you consider this, it makes sense as Insurers do the same thing to vehicles, buildings and people. How would your organisation fare in such an evaluation? Are you as covered as you think?<\/p>\n<p>We\u2019re now all used to systems like multi-factor authentication, and multiple complex passwords.\u00a0 Hopefully we all have password vaults in use, and complex passwords that drive us slightly mad.\u00a0 Likewise, hopefully we are all experiencing regular phishing tests and other awareness tools.<\/p>\n<h3>Does that mean you can relax?\u00a0 NO!<\/h3>\n<p>&nbsp;<\/p>\n<h2>The risks of cyber-attack are increasing<\/h2>\n<p>Cyber-crime is a big business now, and the hackers have become very efficient.\u00a0 While some of the hack attempts are pretty obvious, others are very sophisticated scams.<\/p>\n<p>To avoid being scammed, we have to be at the top of our game every hour of every day.\u00a0 The hacker only has to get lucky once.\u00a0 Unfortunately, busy people, with all sorts of pressure and distraction, will be vulnerable to making a mistake, and that\u2019s when your insurance will be vital.<\/p>\n<p>However, the insurer wants you to minimise their risk and you do that with layers that align to a recognised standard like NIST. (<a href=\"https:\/\/www.nist.gov\/cyberframework\">Cybersecurity Framework | NIST<\/a>)<\/p>\n<p>That talks to a number of steps organisations should do, to reduce their risk.\u00a0 The question for the organisations you work with must be to check that you ARE doing these things.<\/p>\n<p><strong>For example:<\/strong><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_2,1_2&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; custom_padding=&#8221;9px||4px|||&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;0px|||113px||&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<ul>\n<li>Do you have all the devices that are used to access your systems and data inventorised? In these days of work-from-home, that is increasingly hard to do.<\/li>\n<li>Do you know all the software tools used within your organisation? What do you need to monitor to know the protections they need are in place?<\/li>\n<li>When assets, either hardware or software (e.g. web based systems) are retired, how do you know your data has been removed?<\/li>\n<li>Have you prioritised which ones are most important \u2013 most mission critical or have the most sensitive data? What is the appropriate level of response and investment for each of these?<\/li>\n<li>Who is responsible for cyber-risk and data privacy in your organisation, and if it is multiple people, are the responsibilities clear and are the resources they need available to them?<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;|92px||25px||&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<ul>\n<li><span style=\"font-size: 14px;\">How do you manage access credentials to these key information assets so that only the right people have access, and how do you log, verify and audit that? Are access privileges kept to a minimum?<\/span><\/li>\n<li>Who are your key stakeholders and who needs to know if you do come under attack?<\/li>\n<li>Who are you a stakeholder for? Who do you rely on and how confident are you of the steps they are taking to protect their organisation?<\/li>\n<li>While you might be under a cyber-attack, for example a denial-of-service attack, how can you continue to serve your customers?<\/li>\n<li>Are you monitoring the environment for signs of events and hacker activity?<\/li>\n<li>Do you know how data moves within your organisation? How is it protected in transit from system to system, or at rest in a system, including the web browser used to access it?<\/li>\n<li>Have you got, and have you tested, your recovery plan<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;|95px||101px||&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; custom_margin=&#8221;-28px|||||&#8221;]<\/p>\n<p><span style=\"font-size: 14px;\">This list could go on, and the NIST framework is comprehensive, breaking each of these steps down.\u00a0 It might seem like a lot of work, and it is, but what happens if you don\u2019t keep up.\u00a0<\/span><\/p>\n<p>For most NZ organisations, this boils down to :<\/p>\n<ul>\n<li>protecting your tools &#8211; knowing what you have and where it is, and what needs to be done to maintain it<\/li>\n<li>protecting your people, ensuring they are aware of the cyber-risks around them and practice good hygiene, and protecting the credentials they use to access the tools they need<\/li>\n<li>systems and policies to help govern these items, refreshing the steps and protections as circumstances evolve, and having a plan for when things do happen.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;|25px||7px||&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; custom_margin=&#8221;-28px|||||&#8221; sticky_enabled=&#8221;0&#8243; width=&#8221;100%&#8221; header_4_font_size=&#8221;19px&#8221;]<\/p>\n<p>&nbsp;<\/p>\n<h4 style=\"text-align: center;\">Are you ready?\u00a0 \u00a0The reality is that your systems have already been under attack, and they will under attack again with more sophisticated approaches.\u00a0 All it takes is one mistake or to overlook one protection and the hackers will get in.<\/h4>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>We can help you assess your protections, \u00a0and ensure they are at the right level for your business.<\/strong><\/p>\n<p style=\"text-align: center;\"><strong><\/strong><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h2 style=\"text-align: center;\"><a href=\"http:\/\/kinetics.co.nz\/contactus\/\">WANT A CYBER-RISK ASSESSMENT?\u00a0 GET IN TOUCH NOW.<\/a><\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_2,1_2&#8243; _builder_version=&#8221;4.14.2&#8243; _module_preset=&#8221;default&#8221; global_module=&#8221;8587&#8243; saved_tabs=&#8221;all&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;||0px|||&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>A <strong><a href=\"http:\/\/kinetics.co.nz\/flightplan\">Kinetics FlightPlan<\/a><\/strong> is the structured process to easily help you find the answers to these questions, and more.\u00a0<\/p>\n<p>For more information, contact us today.<\/p>\n<p>[\/et_pb_text][et_pb_image src=&#8221;http:\/\/kinetics.co.nz\/wp-content\/uploads\/2021\/02\/FP-brochure-1119-212&#215;300-1.png&#8221; title_text=&#8221;FP-brochure-1119-212&#215;300&#8243; align=&#8221;center&#8221; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_image][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_code _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<style type=\"text\/css\"><!-- [et_pb_line_break_holder] -->.label{font-family:Montserrat; font-size:14px; font-weight:bold; line-height:24px; color:#474747;}.ampfield{ width:100%; height:45px; border:solid 1px #dddddd; border-radius:3px; color:#999; font-size:12px; font-family:Montserrat; font-weight:bold; line-height:24px; padding:10px; cursor:text; outline:none; margin-bottom:14px;}.ampmsg{ width:100%; height:252px; border:solid 1px #dddddd; border-radius:3px; color:#999; font-size:12px; font-family:Montserrat; font-weight:bold; line-height:24px; padding:10px; cursor:text; outline:none; margin-bottom:16px;}.ampsubmit{ width:80px; height:43px; background-color:#3ec940; border-radius:3px; color:#ffffff; font-family:Montserrat; font-size:14px; font-weight:400px; padding-left:20px; padding-right:20px; padding-top:10px; padding-bottom:10px; text-align:center; outline:none; cursor:pointer; border:none;}<\/style>\n<p><!-- [et_pb_line_break_holder] --><script language=\"javascript\" type=\"text\/javascript\"> function validateform(){<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->var firstname = document.getElementById('FirstName').value.replace(\/\\s\/g,'');<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               var lastname = document.getElementById('LastName').value.replace(\/\\s\/g,'');<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               var email = document.getElementById('Email').value;<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               var worknumber = document.getElementById('WorkNumber').value;<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               if(firstname == \"\"){document.getElementById('FirstName').focus();alert('Please Enter Your First Name!');return false;}<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               if(lastname == \"\"){document.getElementById('LastName').focus();alert('Please Enter Your Last Name!');return false;}<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               if (!\/^\\w+([\\.-]?\\w+)*@\\w+([\\.-]?\\w+)*(\\.\\w{2,5})+$\/.test(email)){document.getElementById('Email').focus();alert(\"Please Enter a Valid Email Address!\")<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->return false}<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               if(worknumber == \"\"){document.getElementById('WorkNumber').focus();alert('Please Enter Your Telephone Number!');return false;}<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->               return true;<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] -->   }<!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/script><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --> <!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<form id=\"form_7e60be7dbf4346fe996bae072ee9c070\" action=\"https:\/\/msp.amp.vg\/public\/externalform2.ashx\" method=\"post\"><script language=\"javascript\" type=\"text\/javascript\" src=\"https:\/\/cmap.amp.vg\/track\/gloahbt8azdk\/webpl.js\"><\/script> <script language=\"javascript\" type=\"text\/javascript\"> function submitForm(){document.getElementById(\"form_7e60be7dbf4346fe996bae072ee9c070\").submit();} <\/script><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"token_7e60be7dbf4346fe996bae072ee9c070\" name=\"tokenkey\" type=\"hidden\" value=\"\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"templateid\" name=\"templateid\" type=\"hidden\" value=\"918939\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"formid\" name=\"formid\" type=\"hidden\" value=\"906033\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"doubleopt\" name=\"doubleopt\" type=\"hidden\" value=\"0\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"successurl\" name=\"successurl\" type=\"hidden\" value=\"https:\/\/cmap.amp.vg\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><input id=\"failureurl\" name=\"failureurl\" type=\"hidden\" value=\"https:\/\/cmap.amp.vg\" \/><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div id=\"captcha_7e60be7dbf4346fe996bae072ee9c070\" style=\"display: none;\"><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div id=\"divReCaptcha7e60be7dbf4346fe996bae072ee9c070\" class=\"g-recaptcha\" data-sitekey=\"6LeQHR4UAAAAALnbi_6DE8IEoKMjYnZk3IawV-5t\"><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div id=\"divInvisibleCaptcha7e60be7dbf4346fe996bae072ee9c070\" class=\"g-recaptcha\" data-sitekey=\"6LdTHh4UAAAAAHXtAKkvkcSmd-Zm_qdKgPUjMVsU\" data-callback=\"submitForm\" data-size=\"invisible\" data-bind=\"submit_7e60be7dbf4346fe996bae072ee9c070\"><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Your First Name (required)<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"FirstName\" class=\"ampfield\" name=\"FirstName\" type=\"text\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Your Last Name (required)<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"LastName\" class=\"ampfield\" name=\"LastName\" type=\"text\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Your Email (required)<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"Email\" class=\"ampfield\" name=\"Email\" type=\"text\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Telephone (required)<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"WorkNumber\" class=\"ampfield\" name=\"WorkNumber\" type=\"text\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Mobile<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"MobileNumber\" class=\"ampfield\" name=\"MobileNumber\" type=\"text\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div class=\"label\">Your Message<\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><textarea id=\"Comments\" class=\"ampmsg\" name=\"Comments\"><\/textarea><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/p>\n<div><input id=\"submit_7e60be7dbf4346fe996bae072ee9c070\" class=\"g-recaptcha ampsubmit\" type=\"button\" value=\"SEND\" data-sitekey=\"6LdTHh4UAAAAAHXtAKkvkcSmd-Zm_qdKgPUjMVsU\" \/><\/div>\n<p><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><script src=\"https:\/\/msp.amp.vg\/public\/externalform2.ashx?formKey=7e60be7dbf4346fe996bae072ee9c070\" async defer><\/script><!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --> <!-- [et_pb_line_break_holder] --><!-- [et_pb_line_break_holder] --><\/form>\n<p>[\/et_pb_code][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Given the scale of cyber-attacks, we aren\u2019t surprised to be hearing reports of insurers applying a &#8220;duty of care&#8221; test before agreeing to pay out. Despite sending chills up your spine, when you consider this, it makes sense as Insurers do the same thing to vehicles, buildings and people. How would your organisation fare in [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":9653,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-9647","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/9647","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9647"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/9647\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9647"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9647"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9647"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}