The Herald (South Africa)

Understand cybercrime and insure against it

- BERTUS VISSER

The recent hack at one of SA’s largest insurers has been a wake-up call for many businesses that have maintained a fairly relaxed approach to cyber security.

As the biggest South African breach to date, it dominated the headlines, but the reality is that cyber security issues have been creeping up on us for some time, with an increasing number of businesses having been victims of “ransomware” attacks.

It is crucial for advisers to understand cyber risks, and how to insure against them.

This is often easier said than done, however, as they are very different from traditiona­l business risks, and the nature of cybercrime is continuall­y evolving.

Cyber risks are often intangible and difficult to quantify, as the value of a loss depends on things like the nature and volume of the data compromise­d and the damages that have resulted. These could include: Loss of revenue

Loss of intellectu­al capital Loss of competitiv­e advantage Reputation­al damage Litigation from clients and third parties affected by the compromise­d systems/data

These risks can lead to a host of costs for a company, such as the costs of IT specialist­s to contain the problem, or a forensic investigat­ion to ascertain how the leak occurred.

There could also be legal costs and the cost of public relations specialist­s to limit reputation­al damage.

Then there are industry and regulatory fines and penalties to consider.

Under POPI, for example, if you send an e-mail with personal informatio­n to the wrong person, it can be seen as an informatio­n breach and could trigger a liability.

How an organisati­on responds to an incident is pivotal to reducing the damage of a breach to all concerned. How does a cyber-attack happen?

Phishing is a major risk for individual­s and businesses alike, with increasing­ly sophistica­ted tactics being used to obtain sensitive informatio­n like usernames, passwords and credit card details.

Breaches can also result from negligence, either by a company or its third parties, and from rogue employees looking to gain financiall­y or to damage a company and disrupt its operations.

Cyber insurance to cover these risks does not normally form part of convention­al commercial insurance, which only covers tangible assets.

Cyber insurance needs to be purchased as a standalone policy, and is available from a handful of specialist suppliers, who assist companies in identifyin­g and pricing their cyber risks.

The cost of a policy normally relates to a company’s turnover, and the state of its IT infrastruc­ture. Who needs insurance?

Any business that has an online presence and holds confidenti­al data is at risk.

Research suggests that there are as many as a million cyber-attacks worldwide every day, and South Africa is certainly not immune.

Every business today must ensure that it has the appropriat­e IT security measures in place – as well as the appropriat­e insurance cover.

A discussion with an insurance adviser who has experience in this space will help you better understand these risks and how they could affect your business – as well as how to mitigate them.

Bertus Visser is chief executive (distributi­on) at PSG Insure

 ??  ??

Newspapers in English

Newspapers from South Africa