Cybersecurity threats faced by insurance companies are growing and evolving at an alarming rate. This has been spurred by many factors, including the internet of things (IoT). While the IoT presents opportunities for insurers, it also exposes security gaps. The severity and frequency of cyber-attacks are likely to increase.
Insurers must commit to protecting sensitive customer information in a compliant and reliable way. The cybersecurity threat is huge. It is time for insurance companies to reboot their approaches to cybersecurity.
Common cybersecurity threats facing the insurance industry
1. Cyberextortion
Cyberextortion is increasingly becoming a common problem. Some types of ransomware attacks are so effective that victims may be forced to meet the attacker’s demands and pay a hefty bribe to get their system running again.
2. Automated threats
Credential cracking, vulnerability scanning, bad bots, credential stuffing, and denial of service can potentially shut down a company’s systems quickly.
3. Identity theft and loss of confidential data
Identity theft may result from system vulnerabilities to data breaches. For instance, files stored on a firm’s local servers may not be protected adequately. Insurers collect and store sensitive personal client information. This information can be particularly valuable for attackers to sell in black markets. They can use it as a tool for fraud, extortion, unauthorized borrowing, and many other financial crimes.
4. Business disruption and reputational damage
Cyber-attacks can seriously disrupt business. For instance, a cyber-attack on Sony Pictures erased its computer infrastructure, including telephone directories, emails, voicemails, and business records like contract templates. A malicious attack like this on an insurer could disrupt operations for months.
The foundation of any insurance business is policyholder trust. If an insurance company were to suffer a data breach exposing policyholder information or a cyber-attack that renders it unable to conduct normal operations, that trust would be shaken. This, in turn, can lead to reputational damage that may negatively affect the confidence of investors, consumers, policyholders, and rating agencies.
Four tips for boosting security
1. Assess your defense capabilities realistically
Pressure-testing the company’s defenses can determine whether they can repel targeted, high-impact attacks, whether external or internal. It includes vulnerability assessment, testing programs, penetration tests, and scenario-based testing. Consider hiring a cyber-security firm to test your defenses.
2. Invest in early detection
Insurers need to continually invest and innovate to thwart potential attackers. Early detection is crucial. Otherwise, a cyber-attack can sit undetected for weeks.
Efficient and quick detection and response will help determine the source of the attack, the systems targeted, extent, and cause. Then, the threat can be neutralized before damage is done. Insurers need to invest in technology. There is a wide range of software solutions that provide near real-time threat detection.
3. Making cybersecurity everyone’s job
While implementing sophisticated systems will reduce external threats, insurers tend to neglect internal threats such as human error, which could include revealing customer data in response to a convincing phishing email. Cybersecurity awareness among employees can significantly decrease the risk of cyber-attacks resulting from human error.
Alert employees can provide early detection. An Accenture survey found that up to 98% of security breaches that are not detected by a firm’s security team are discovered by employees.
4. Learn from the past and evolve
Effective cybersecurity requires insurers to learn from previous cyber incidents and use this to improve planning and technology investments. Solutions include:
- Upgrading systems: using last-generation or unpatched security software provides easy fodder for cyber attackers. Speak to your IT consultant about upgrading your systems.
- Migrating systems to the cloud: the cloud provides users a wide range of compliant and secure storage solutions. Choose a cloud provider that offers the highest possible security.
- Implementing appropriate security software, protocols, and appliances: this will effectively shield data and systems from automated threats.
- Establishing a disaster recovery plan: despite all efforts, systems can be breached. Have a detailed up-to-date plan so that you can respond effectively to any problem, major or minor.
Cyber-crooks are relentless and determined. Security is an ongoing battle. You can’t afford to let down your guard a second. Staying one step ahead of hackers takes constant effort.
Related: 7 reasons 2019 is the year of privacy
Mike de Waal is president and founder of Ottawa-based Global IQX, a software provider of web-based sales and service solutions to employee benefits insurers. He can be reached at mike@globaliqx.com.