The Enemy Without: Managing Third-Party Cyber Risk
CIOREVIEW >> Cyber Security >> NEWS

Alliant Insurance Services

David M. Finz, First Vice President

The Enemy Without: Managing Third-Party Cyber Risk

David M. Finz, First Vice President
David M. Finz, First Vice President, Alliant Insurance Services

David M. Finz is a First Vice President of Cyber Risk at Alliant Insurance Services, specializing in helping businesses manage the financial impact of cyber threats. With a strong background in risk management, he educates clients on the cyber insurance marketplace, negotiates best-in-class coverage and provides claims advocacy. A graduate of Brooklyn Law School, David is also an author and speaker on cybersecurity and privacy law topics, frequently sharing insights through articles, podcasts and industry events. His expertise extends to regulatory developments, incident response planning and evolving cyber risk landscapes.

Through this article, Finz highlights the increasing reliance on third-party IT and non-IT service providers and the associated cybersecurity risks, emphasizing the importance of due diligence and robust risk management strategies to minimize exposure to network interruptions and data breaches.

We live in an interconnected world. Hardly a business can survive without IT and nonIT service providers. Whether cloud storage, payment processing, HR or inventory management, companies need and demand instant access to information. They expect customer data to be held securely and for any network outages, planned or unplanned, to result in minimal downtime.

Unfortunately, reality often falls short of these expectations. High-profile network interruptions at critical vendors have disrupted operations at healthcare facilities, financial institutions, airlines, automotive dealerships, and many other organizations. In this article, we will look at risk management strategies that firms can employ to minimize their exposure to such incidents and to be better positioned to absorb the shock when it occurs.

Due Diligence: Know Your Vendor

If there is one takeaway from recent incidents, it’s that vigilance around an organization’s supply chain has become a critical component of cybersecurity. This is particularly true for software developers. Once malicious code is inserted into the software of one of these vendors and pushed out to their downstream clientele, it creates a vulnerability in a range of government and corporate networks. Thus, businesses must factor this exposure into the vendor selection and contract review.

Understanding a vendor’s level of cyber maturity is crucial to gauging third-party risk. There are several ways to incorporate this due diligence into a company’s procurement process.

• Security Questionnaire: Requesting the vendor’s Chief Information Security Officer or Managed Service Provider to complete a security questionnaire is relatively straightforward, although it relies on an honor system to some extent.

• Vulnerability Scan: Utilizing a subscription service to conduct a noninvasive vulnerability scan on the vendor’s network provides another perspective on security from the perspective of a potential threat actor.

 The Amount Of Limits A Vendor Should Carry Is An Inexact Science, But It Is Typically Driven By The Size Of The Contract, The Scope Of Work Involved And The Parties' Relative Bargaining Power

• External Audit: Asking the vendor to present evidence of an outside network security audit is more burdensome. It may not be practical for smaller service providers but should be considered for the company's most critical vendors.

• Cyber Insurance: Supplying evidence that the vendor carries cyber insurance indicates that they underwent the process of qualifying for coverage, which is no small task given the more stringent criteria employed by underwriters in recent years.

Contract Wording: Understanding Your Recourse As A Customer

Many service providers have standard engagement agreements that legal counsel prepares. These agreements are designed to minimize the vendor’s exposure to liability. However, the best contracts are the product of negotiation between the parties and reflect both interests. There are three key considerations for businesses looking to engage a technology vendor:

Limitations of Liability: It is not unusual for tech firms to insert a cap on their liability (for example, one year’s fees) in their standard client service agreements. However, the damage they can impose could far exceed the liability cap. Seek to have the cap increased or removed altogether in cases where a lapse in the vendor’s security results in financial loss to your business and liability to a third party. Intentional wrongful acts on the part of the vendor’s rogue employees or contractors should not be subject to a limitation of liability in any instance.

Indemnification Clause: The vendor should defend and indemnify your organization for claims by third parties resulting from negligence or privacy breaches.

Insurance: As noted above, vendors should be asked to provide evidence of cyber insurance coverage. This is a backstop so the vendor can follow through on its obligations to indemnify your business. The amount of limits a vendor should carry is an inexact science, but it is typically driven by the size of the contract, the scope of work involved and the parties' relative bargaining power.

Cyber Insurance: An Effective Tool For Transferring Third-Party Risk

Cyber insurance is an increasingly common form of coverage for businesses today. It is designed to reimburse a company for its out-of-pocket costs in responding to a cyber incident and the legal fees and damages associated with any resulting litigation and regulatory proceedings. While an exhaustive discussion of this critical coverage is beyond the scope of this article, there are a few policy terms that should be kept in mind when addressing vendor management:

Breach Response: While you may arrange with a vendor to determine whose data was compromised and notify the affected parties, the ultimate legal responsibility still rests with your company. Your customers don’t know who your vendors are, and they have no “privity of contract” with those firms. Cyber insurance covers the cost of engaging privacy counsel, sending out the required notices, setting up a call center, and offering consumer credit monitoring or identity theft protection to the extent that your vendor is unable or unwilling to bear these costs.

Dependent Business Interruption: A recent study by the cybersecurity firm Security Scorecard concluded that 59% of cyber claims are now attributable to vulnerabilities at a vendor. These so-called single points of failure (SPoF) can have ripple effects across an entire industry sector. Cyber insurance covers the extra expenses and income loss associated with an outage at a vendor that disrupts your company’s operations for an extended period.

Subrogation: Unless you have waived your insurer’s right to subrogate against the vendor as part of your contract, cyber insurance can assist policyholders in determining who is ultimately responsible for a loss and potentially recovering those losses by initiating legal action against the vendor. Insurers exercise This option selectively, but there is a shared interest in ensuring those responsible for the policyholder’s loss are held accountable.

Conclusion

Exposure to third-party cyber risk is a reality for businesses today. Through a combination of security assessments, thoughtful contract wording and insurance, companies can better manage this risk to ensure that they come through an incident with their balance sheet and reputation intact.

Alliant note and disclaimer: This information is designed to provide general information and guidance and is not intended as legal advice. Alliant Insurance Services disclaims any liability for any loss or damage from the information provided in this communication.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.