YOUR BUSINESS AUTHORITY

Springfield, MO

Log in Subscribe

Opinion: Know your cyber liability

Posted online
Conducting business today is very different than it was 10 years ago.

A decade ago, money was handled differently, products were sold differently, and people communicated differently. Those of us who still don't really understand what Twitter is can relate. Technology is responsible for many of those changes and has, for the most part, made us more efficient and productive.

On the flip side, however, technology also has opened an entirely new era of liability, and businesses are now exposed to cyber liability.

In layman's terms, cyber liability is what you and your business can be held financially responsible for in terms of how you conduct your business electronically. The largest portion of cyber liability is the data stored on company computers and servers.

Aug. 28 marked a milestone for Missouri businesses and the mounting liabilities they face.

Perhaps sparked by the 2003-04 T.J. Maxx incident in which more than 45 million credit card numbers were electronically stolen, Missouri joined a list of 44 states that have now enacted their own data-breach notification laws. Missouri's requirements are broader in scope than most other states.

The Missouri Data Breach Notification Law will require businesses to inform individuals if their confidential personal information has been breached from company databases or records. Personal information is defined as first and last name combined with: Social Security numbers, driver's license numbers, financial account numbers, credit/debit card numbers, medical information or health insurance information. A breach is simply the unauthorized access or acquisition of this information, and the requirements apply to client and employee information.

What this really means to employers is that if they become aware of personal information breaches, notifying affected individuals will be required - at the company's expense.

Notification is more involved than simply sending out a letter with a 42-cent stamp. Liable parties also may be required to pay for the credit monitoring of breached individuals for a specific time period, and the state can issue fines for violations of privacy laws.

Some experts estimate the cost of notification at approximately $200 per record. If more than 1,000 records are breached, employers are required to notify the Missouri attorney general's office, and failure to do so can result in action from the attorney general's office for actual damages or a fine up to $150,000 per breach.

The answer to combating this growing area of liability is really threefold.

First, give increased attention to security measures and procedures. Studies show that businesses can significantly reduce the risk of cyber liability with additional technology and prevention.

Second, exploring a cyber-specific insurance policy might be warranted. If hackers can break into the U.S. Embassy Web site in China, they can probably get into your system if they really want to. Virtually all businesses have general liability policies, which respond to bodily injury and property damage. Cyber liability policies, like professional errors and omissions policies, respond to financial damages. These exposures are not protected on general liability policies or crime policies. They require a separate cyber policy. These policies are 100 percent underwritten and can vary greatly in coverage between carriers. They will respond to notification costs, regulatory fines, defense costs and other expenses.

Lastly, we may have to change our mindset on risk. Ten years ago, a company's building may very well have been its most valuable asset and largest liability, but today, it may be its data.

More personal records were breached in 2008 than in the four previous years combined. In a year where cash reserves seem to be dwindling for many area businesses, this is definitely a topic for discussion as you approach your insurance renewal. Cyber liability may be a risk that you would be better off transferring to your insurance company.Doug Stone is a business risk adviser with Springfield-based Ollis & Co., an employee-owned risk, benefits, and insurance agency. He can be reached at doug.stone@ollisco.com.

Comments

No comments on this story |
Please log in to add your comment
Editors' Pick
Fall 2026 Architects & Engineers Project Report

This installment of Springfield Business Journal’s Architects & Engineers Project Report showcases 26 endeavors by area design and engineering professionals.

Most Read
Update cookies preferences