Insurers, organizations, and corporations without proper cybersecurity face significant risk.

Many of us have read about the Solar Winds Orion enterprise network attack. It may well be months, if not years, before the full damage to the Department of Homeland Security, State Department, Office of the President, and Fortune 500 companies can be fully assessed.

Accordingly, New York State’s Department of Financial Services (DFS) warns that the failure of any business or organization to develop a “rigorous and data driven approach to cyber risk” could result in both serious and unforeseen consequences. This is true both for insurers as well as corporations and organizations.

As to insurers, DFS warns that they must take great care in underwriting these risks, as many insureds use insurance as a cost-effective substitute for improving cybersecurity. As such, the insurer runs the risk of actually increasing cyber risk, as the insured will not upgrade their defenses, but simply seek to pass any losses on to the insurer. Unnecessary coverage disputes can also arise from policies that do not specifically rule cyber risk coverage in—or out. Specifically, Errors and Omissions, General Liability, and even Product Liability policies have been drawn into the dispute as to whether an insured has cyber risk protection.

Yet the concerns do not end there. According to the 2019 FBI Internet Crime Report, there was a 37% annual increase in ransomware attacks, which directly caused a 147% increase in associated losses. This raises the question as to who should be responsible for paying the ransom, insurer or insured. Surprisingly, the answer may be neither, because the payment may be prohibited by the U.S. Treasury’s Office of Foreign Assets Control (OFAC). 

The Treasury Department has taken the position that ransom payments on behalf of any victim, including financial institutions, cyber insurance firms, and companies performing digital forensics and incident responses, not only encourage future attacks, but also may violate OFAC regulations, resulting in significant sanctions. 

Because a victimized entity may never know if the attack was precipitated by anyone on the Specially Designated Nationals and Blocked Persons (SDN) List, the best course of action is to make no payments without consultation with, and clearance from, OFAC and the Financial Crimes Enforcement Network (FinCEN). Applications for license to make payments are reviewed on a case-by-case basis, “with a presumption of denial.”

Essentially, protection of an organization can be distilled to three basic elements. 

  • First, make sure that your data has all available cyber protection software. It would be prudent to engage professional cyber risk experts to perform testing, to ensure the adequacy of your defenses.
  • As to insurers, make sure that your underwriting department fully understands the anticipated risks associated with insuring an entity, with specific policy language and recommendations, to both minimize risks and clarify exposure. 
  • Finally, should an attack occur, make sure that all involved decision makers take no action until the proper authorities are contacted. 

While your organization may regard the risk of attack as slight, given the increased incidence of attacks, the rise in associated losses, and the order of magnitude of damage, it is long past time to address this existential risk to your organization. 

—————————————————————————————————————

James Denlea, Esq., is a founding partner of Denlea & Carton LLP. For more than forty years, he has represented the interests of individuals and corporations, both as plaintiffs and defendants. He began his legal career as a Westchester County Assistant District Attorney. Throughout his career, he has maintained an interest in protecting clients from both known and unforeseeable risks, especially as those risks have multiplied in the digital age. James has been a lecturer on risk management topics in the field of law, medicine, and accounting.

Written by:

Leave a Reply

Your email address will not be published. Required fields are marked *

Our Reviews

Richard Abrams
Richard Abrams
23:11 14 Sep 22
I was so impressed with the service and work I got from integras.It was a personal issue handled professionally and discreetly. And I love the podcasts!
adrian rosario
adrian rosario
15:51 17 Jul 22
Professional, honest and effective; I have had the privilege of working with Forhad and the Integras executive team since 2007. Having 35+ years experience in law enforcement and an investigative background, we have worked together to achieve successful outcomes investigative matters both domestically and internationally . Their staff is versatile, provides a broad range of security related and investigative know how, and consistently maintains a client-centric culture with unwavering communication and discretion. I highly recommend Integras for your investigative needs.
Brayant Sierra
Brayant Sierra
16:05 08 Apr 22
Elisa Sheftic, Right Executive Search, LLC
Elisa Sheftic, Right Executive Search, LLC
19:50 23 Mar 22
As an executive search firm, having a vendor that is able to execute a background check search, quickly and efficiently is paramount. Integras has been an exceptional partner and understand and communicate the ever changing laws that relate to each state. I would highly recommend them for any companies or recruiting firms that needs a professional background check service. Have used them for years and will continue to do so!
Yftah Kaluski
Yftah Kaluski
18:36 23 Mar 22
Great service and great team behind the product!
Jay McKillop
Jay McKillop
22:58 11 Mar 22
This is a first rate operation, and many of the people that work there are former colleagues. I have dealt with Forhad professionally for over twenty years and he has never let me down. The firm I was at used his team for a "red team" exercise which went extremely well. I have also had several instances where people have come to me with some very complicated investigative problems. I referred them to Intergras and they were extremely pleased with the results. Integras has a very deep bench, with international connectivity and the capacity to get things done.
Gonzalo S.
Gonzalo S.
14:59 26 Jan 22
Sets a standard of excellence in all areas of service it provides. The podcasts provide a wealth of information delivered by a panel professionals with extensive backgrounds. I know the podcast host to be a man of integrity. This has to be the best in the business. Great job!
Joel George
Joel George
22:42 25 Jan 22
We have partnered with Integras Intelligence on a number of occasions. I find their team to be knowledgeable, communicative and easy to work with. It is clear that they are focused on their clients and want to deliver world-class service with an impeccable attention to detail.
Jim Denlea
Jim Denlea
16:05 25 Jan 22
We have used Integras exclusively for all of our Investigative needs, both domestically and internationally. They have always exhibited an unparalleled level of expertise, sensitivity to our client's needs, and cost efficiency. We would highly recommend them without hesitation.
Edmund Hartnett
Edmund Hartnett
15:38 25 Jan 22
Integras Intelligence is the gold standard of investigations. Their cost effective investigations are conducted quickly and accurately; the two most important factors for most clients. I’ve often referred friends and colleagues to Integras. Without exception, they gave the service they received very high marks. I highly recommend Integras.
Aman Singh
Aman Singh
23:31 24 Jan 22
I have had the privilege of working with Integras Intelligence while being at two different companies. Not only is Forhad best in the industry but his team is superb.If you are seeking a company that is professional, responsive and provides thought leadership you should choose Integras Intelligence.Thank You!
Shawn Hale
Shawn Hale
22:06 24 Jan 22
I have known the Integras Intelligence leadership team for over 20 years and am a better person and professional because of it. Never cutting corners, always taking the high road, continually seeking to stay ahead of the industry and setting the standards by which others can measure. Great team. Highly recommend!
Christine Ippolito
Christine Ippolito
00:39 21 Jan 22
We have used Integras as our strategic partner for background checks and physical security advice for over 5 years. The Integras team is highly responsive knowledgeable and always willing to help. We highly recommend them to others and our clients.
Brandon Hunt
Brandon Hunt
13:52 20 Jan 22
I have worked with the team at Integras for over five years and have continually impressed with the professional and thoughtful approach they take to everything they do. They've assembled a terrific team of experts that you can feel confident in and enjoy working with. I strongly recommend Integras Intelligence for anyone who is in need of their services.
Patrick Kane
Patrick Kane
21:51 19 Jan 22
Integras Intelligence is a global leader in the investigative, business intelligence and security consulting space. Their team led by Forhad Razzaque, has a deep level of experience gained in both the public and private sectors.They augment this impressive team with an extensive network of investigators and other specialists that are dedicated to positive client outcomes. If you are looking for a professional, responsive, and skilled partner to help tackle a thorny issue, look no further than Integras.
USMC 0311
USMC 0311
19:36 19 Jan 22
Integras is a leading international provider of investigative and screening services that has been such a great support for our operations in Latin America. Integras is staffed by seasoned professionals who bring decades of experience in all investigative areas and who always go above and beyond the expected service.. Thank you to the Integras team for always striving for excellence!
See All Reviews
js_loader