x
In simple terms, cyber insurance is insurance that covers the liability of a business under a data breach where sensitive personal data of the customer(s) are involved. This sensitive personal data includes credit card numbers, driver’s licenses, social security numbers, account numbers or health records. It not only covers businesses but also individuals that provide services under such businesses. Risks that are internet-based such as information privacy, information technology infrastructure, information governance liability, etc are generally excluded from traditional insurances that cover commercial liabilities.
Cyber insurances provide certain coverage like first-party coverage and liability coverage. First-party coverage includes losses caused by extortion, theft, data destruction, DoS attacks and hacking whereas liability coverage indemnifies companies against losses caused to others which includes failure to safeguard data, error and omissions or defamation. There are other benefits under cyber insurance like public relations post-incident and investigation expenses, criminal reward funds, and regular security audits.
Is cyber liability covered under general liability policies?
As explained above, cyber insurances are usually excluded from such general policies. This is because general liability policies only cover businesses from damage to property or bodily injuries that have been caused by their products.
What is covered under cyber insurance?
The process of sending notifications to customers whose Personal Identifiable Information {PII} have been compromised in a data breach can be very expensive. But most states in India requires companies to do so. When we even talk about free credit monitoring offered by companies, it is not required in most states but proves to be beneficial to go along with public relations. Due to this, cyber insurances include the costs related to the following:
Data breach notifications to customers
Legal fees and expenses
Recovery of data compromised by hiring computer forensics
Replacing or repairing computer systems that have been damaged
Restoring the affected customer’s personal identities or data that has been altered or stolen
Meeting demands of extortion under a ransomware attack.
What is not covered under cyber insurance?
Cyber events that have been caused by a company’s employees or insiders
The cost incurred in technological improvements like hardening security in the application or system
Cyber events that occurred in the past, before purchasing the policy
Failures in infrastructure that was not caused by any cyber event
Failure by the company to fix a vulnerability that was known
Who is required to get cyber insurance?
Cyber insurance should usually be taken by businesses that manage, create or store data electronically including customer sales, contacts, credit card numbers, health records, etc. The best examples are e-commerce platforms such as amazon, flipkart, myntra, etc who can undergo a huge loss in customers and sales due to cyber incidents. Even businesses who simply store information of their customers on their websites can benefit under cyber insurance.
To stay connected, please check: https://www.worldcybersecurities.com/
By: Aarushi Chopra
{BA LLB, Amity Law School}
Insightful! Thanks for sharing.
ReplyDeleteGreat work! Cyber insurance is indeed need of the hour. We need to build more infrastructure and create awareness about it.
ReplyDeleteIt is very important to understand and become aware about this topic - cyber insurance. Many cyber frauds take place and people face great financial losses due to same. Insurance companies can revamp such losses by giving aid to the cyber victims. There must be a legislation for the same where every person required would understand and can avail the insurance facilities.
ReplyDeleteCyber insurence developed faith towards the data sefty and Cyber security among the people. As it also cover financial loss as well as data loss both, it will help to people get atleast some amount of security.
ReplyDeleteThis blog is resources, yes we all organization need cyber insurance to cover from breaches.
ReplyDelete