YOUR BUSINESS AUTHORITY

Springfield, MO

Log in Subscribe

Opinion: Cyberpolicies can help mitigate digital security breaches

Posted online
This year has been a breakout period for cyberattacks. Target Corp., Microsoft Inc. and eBay all have recently been hacked. Although these are all large, household name companies that get the press, surprisingly 75 percent of all security breaches occur in companies with fewer than 100 employees.

This risk is growing exponentially and even the FBI is, “struggling to combat cyber-attacks by hackers. We are not winning,” Executive Assistant Director Shawn Henry acknowledged in an Associated Press report.

The loss, misuse and unauthorized release of client, employee, health and financial data can not only be expensive, but also it can devastate a company’s reputation. Including Missouri, 48 states have “red flag laws” requiring companies to adequately protect data and notify affected parties if their information is compromised. Privacy and security must now be a priority for businesses – large and small.

The first line of defense should be a company’s computer network security. Firewalls and content management systems need to be in place to protect both the system from attacks and the innocent user from accessing dangerous sites. Updating programs with the latest version is extremely important too, but always access the website for the update rather than clicking on links embedded in unknown source emails, which could be ploys from cybercriminals or hackers.

Antivirus software is important, but not enough on its own. Antivirus software is reactionary in nature and requires constant management.

Another level of protection is white listing. This software determines what programs your staff regularly uses, and when a new unauthorized program is detected, it shuts down the network to protect it. If the program is valid, it then can be added or if it’s not valid, it protects the network from access.

Managing your computer-use policies and training your staff also is critical. The loss of data through stolen or misplaced mobile devices such as laptops and phones is the most prevalent risk. Encryption programs should be considered for sensitive data. Good password policies and use, coupled with systems that shut down and erase lost devices, also can be prudent.

Train your staff to recognize potential threats and to “raise their hand” when they are concerned regardless of whether they are on a questionable site. Security should be emphasized over fear of punishment. Understanding that clicking on links in emails is risky, especially from unfamiliar sources, social networking and the risks associated with it should be emphasized. Every company should have policies and training around its use.

Even after a robust effort regarding network security training and implementation, your businesses will want to consider cyber insurance coverage. Quite simply, even the best security and training can’t eliminate the risk.

Cyber-insurance policies are relatively new to the marketplace and vary in both protection – coverage – and retentions – deductibles. The liability limit protects a business from third-party legal actions, normally suits from adversely impacted parties. These third parties include customers, employees, shareholders and vendors who have been harmed by the unauthorized release of private information.

The most common information includes financial, health and personal data. Every business has some of this data, some more than others. Financial services, health care and retail organizations are the most vulnerable.

Cyberpolicies also have first-party coverages that usually have sublimits or separate coverage provisions. Notification and expenses associated with a breech to protect these parties with credit monitoring can be expensive, often in excess of $200 per record. This coverage limit is normally one quarter to one half of the primary liability limit.

Another sublimit to be aware of is regulatory defense and penalties. Fines and penalties from governmental agencies for Health Insurance Portability and Accountability Act violations and the payment card industry are becoming more prevalent. On April 22, Concentra Health Services was fined $1.7 million for failing to prevent information from being stolen right here in Springfield.

Consultation services and crisis management is another coverage that may be separated into a sublimit. Making sure you respond effectively and communicate timely are priorities after an event occurs. Enlisting and paying for the right advice is paramount.

Our world is changing and technology is driving significant portions of that change. Focusing resources on computer security, training and computer use policies and procedures is critical. Coupling that with cyber insurance coverage is fast becoming the new best practice.

Richard Ollis is president and CEO of Springfield-based Ollis and Co., specializing in risk, employee benefits and insurance. He serves on the national board of the Wellness Council of America and can be reached at richard.ollis@ollisco.com.

Comments

No comments on this story |
Please log in to add your comment
Editors' Pick
Fall 2026 Architects & Engineers Project Report

This installment of Springfield Business Journal’s Architects & Engineers Project Report showcases 26 endeavors by area design and engineering professionals.

Most Read
Update cookies preferences