Cyber Risks, An Impactful Reality – How to Deal with it?
CIOREVIEW >> Document Management >> NEWS

SAE Towers

Jaqueline Monteiro, Insurance and Risk Manager

Cyber Risks, An Impactful Reality – How to Deal with it?

Jaqueline Monteiro, Insurance and Risk Manager
Jaqueline Monteiro, Insurance and Risk Manager, SAE Towers

We live in a connected world, which brings many advantages for business. However, it also exposes companies to cyber invasions that can negatively impact corporate image and finances.

The agenda on cybersecurity is in the center of debates around the world, as cybercrime is currently one of the major global threats. In addition to exposures to private data and information, a cyber-attack can have a major financial impact. According to Cyber Security Ventures, in recent years, financial losses from hacker attacks have exceeded USD 6 trillion worldwide, surpassing losses from natural disasters on the same period (that was approximately USD 600 billion).  In 2022, cyber-attacks increased around 38%. The shocking numbers represent the largest transfer of economic wealth in history, directly impacting corporate finances. The most common incidences are fraudulent phishing schemes, that is, data leakage caused by viruses entering the system via email or links with malicious content and ransomware, which is data kidnapping. The targets were mainly educational institutions and companies in the health sector followed by banks.

Data related to a process, especially revolving around a company's product, is more important than its market value. Systemic data is the main value of the organization as it is the central core of information that comprises the formulas and components of the final product, making information security the focal point for the survival in the corporate world.

The financial impacts caused by a cyber-attack can be irreparable. Although the use of technology is a stimulus to increase productivity and efficiency in companies, most of the time when new technologies are implemented, there are no mechanisms for evaluating the increased exposure that these new technologies may cause. Organizations still do not see these potential new risks. Today the level of uncertainty regarding cyber-attacks is almost non-existent; fatally at some point the company will be the victim of an attack.

Faced with this scenario of potential risks, the necessity to adopt protective measures - both for data manipulated by human interface and for data interconnected between suppliers - customers and companies is paramount, it is necessary to evaluate its entire database.

  Implementing a complete, effective and efficient cyber risk management plan and contracting a cyber-risk insurance policy are actions that will guarantee the company greater control and security of stored data.   

Realizing the impactful reality, both public and private entities are in constant motion to create defense solutions to protect the data of companies and people. In May 2018, the General Data Protection Regulation (GDPR) law came into force to protect the European Union and its citizens from the violation of data privacy, bringing rules to the structural environment of information security, which inspired other countries around the world, such as Brazil, where the law 13.709/18 (General Data Protection Law) LGDP was created in 2018 and enforced in 2020 with the same purpose.

But if the risks of attacks are in evidence, what needs to be done to minimize them, mitigate them in order to protect the company's assets?

The answer is to deploy Effective Cyber Risk Management, integrating all points in the system to generate a picture of risks and security vulnerabilities in order to protect the company from future attacks. I mean, cyber risk management demonstrates all vulnerabilities exposed in technological processes, outlining a cyber-risk management plan together with a team integrated with all areas of the company. The risk management plan mitigates attack risks and operating costs, protects the company's assets and revenue, and maintains its reputation in the market.

To create a cyber-risk management plan, it is necessary to pay attention to some basic points. These include creating a management team, understanding the current scenario in which the company is inserted, identifying and classifying vulnerabilities, assessing the impacts and severities of these vulnerabilities, create transfer and control plans for these risks, monitoring exposures by creating response plans to these incidents, a crisis committee, and a business continuity plan.

And to help in mitigating and transferring these risks, there is cyber insurance today; cyber insurance policies cover both direct loss and liability for a cyber-event. Cyber risk insurance is civil liability insurance that guarantees financial losses arising from a cyber-attack, and may even cover errors and/or internal negligence that may result in the leakage of confidential information.

Products sold on the insurance market generally guarantee:

Data theft or hijacking;

Theft of Hardware carried out by a third party;

Violation of the Personal Data policy;

Complaint for exposing confidential data or content;

Misuse of confidential information

System Interruption

Modification, deletion, destruction, corruption of stored data;

Insurers also offer:

Technical Support for Risk Management;

Costs for Crisis Management;

Defense costs in legal proceedings;

Image restoration costs;

Extortion – Costs of losses suffered by the insured as a result of a security threat;

Fines – Costs that the insured pays arising from data liability that has been caused by the breach of data security regulations;

Network Interruption – Operating expenses arising from business interruption caused by data security failure;

However, it is necessary to pay close attention to the coverage exclusions for cybernetic exposures of some market products such as:

Extortion – Kidnapping and Rescue of data

Professional and Publicity Liability - Personal Injury to Employees

General Product Liability for Cyber Failure

Cyber Security Employee Fraud

Cyber threat in remote work

Media Content

Network Interruption

The insurance program should be tailored to your business to protect against the common and unusual impacts that a cyber crisis can cause. Insurers evaluate the information security plans that companies have to accept the risk, if a company does not have a cybersecurity structure, it will possibly have restricted acceptance of coverage or even denied.

Unfortunately, most companies are still not sure how to respond to cyber incidents, and it is of very important to create protection measures, with periodic reviews of compliance and data security policies, preventing information leakage and attacks on company systems.

Cyber criminals are always evolving, expanding the methods and level of sophistication of their attacks. There is an urgent need to invest in cybersecurity tools and services.

The cost of investing in cyber security and risk management programs is challenging, but will pay off in security, excellent reputation and long-term protection.

Implementing a complete, effective and efficient Cyber Risk Management plan, contracting a Cyber Risk insurance policy, are actions that will guarantee the company greater control and security of stored data.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.