Financial Services Industry
Industry: Email Alert RSS FeedThe 'cyber' risks of outsourcing: outsourcing does not mean out of mind when it comes to cyberliabilities. Instead, companies with databases full of client and employee information should be even more wary
Risk & Insurance, Sept 1, 2007 by Brian Branner, Emily Freeman
Further, the customer should negotiate with vendors on indemnification, limitation of liability provisions, and warranties and representation not just on performance risk, but on security and confidentiality risk as well.
Finally, customers should require their vendors have the appropriate insurance to respond to performance failures and security/privacy breaches. Simply asking for "technology errors and omissions" or "professional liability" will not guarantee that the vendor has strong and affirmative coverage for data protection.
Most PopularCBS MoneyWatch.com Articles
Instead, specify the types of risks, including identity theft, unauthorized access and use, transmission of malicious code and insiders as perpetrators, for example. The reason is that there is no standardized coverage for data-protection risks within professional liability policies. It can vary from none, poor, adequate to superior. Limits requirements should start at $1 million, but be increased based upon the aggregate exposure and operations of the vendor. Waiving of requirements for insurance should be escalated to senior levels and done with thorough consideration, given the risks mentioned above.
As customers cannot rely on the insurance and indemnification provided by their vendors, they should also have their own insurance in place to address their own direct risks and vicarious liability, including the possibility that the vendor becomes insolvent. Traditional commercial general liability or crime insurance will not cover the consequential financial loss associated with data crimes.
In fact, over the last five years, the general liability policy has restricted coverage with respect to Internet activities. Crime coverage was really designed to cover theft of tangible property, money and securities where the perpetrator and the intent of the perpetrator was manifest and known.
PRODUCT EVOLUTIONS
Traditional insurance is not addressing growing data-protection risks in the age of network-based technology. Fortunately, insurance products have evolved to address data protection risks, commonly called cyberinsurance. The term "cyber" is really a bit of a misnomer as these policies need to address not only a breach in a computer system, but also a lost laptop/personal digital assistant or theft of hard-copy data.
The better policies provide broad coverage for security and privacy liability, including a sublimit for regulatory defense and notification costs. There are a number of insurers that offer policy forms with widely varying scope, claims management approach and exclusions. Clients should consider underwriters who provide strong, affirmative coverage that provides a balanced approach to management of claims and defense.
Coverage should include areas such as breach in confidential employee information, data theft following a theft of a mobile device, insiders as perpetrators and vicarious liability for breach of security by a vendor. The policies should also address privacy violations associated with collection, notice, use, disclosure and correction of personal information about individuals. For global companies, privacy risk is considerably greater in some countries and regions, such as Canada and the European Union.
Brought to you by CBS MoneyWatch.com
- Best- and Worst-Paid College Degrees
- 6 Things You Should Never Do on Twitter or Facebook
- How Much Sleep Do You Really Need?
- 6 Big Myths about Gas Mileage
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Business Articles
- "Do not rely on a single economy" ; Larsen and Toubro (L and T) was affected due to the slowdown particularly the products businesses, which include switchgears, construction equipment and industrial bars.
- "The first deliberate call we took was not to lay off anybody" ; The diversified group decided to reskill all surplus workers.
- "Government had to step up its demand" ; The downturn affected the government as much as India Inc. The outgoing advisor to the Government of India details its impact and its lessons.
- "Help your customers even in difficult times" ; Oil was at an all-time high at over $135 per barrel just before the financial meltdown. Then oil crashed to a low of $35 per barrel in January this year, bringing down any fresh demand for pipes fr
- "You have to be visible as a leader" ; Transparency is a standard operating procedure for communications during a downturn.
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- Using object-oriented analysis and design over traditional structured analysis and design
- FAS 109: a primer for non-accountants - Financial Accounting Standards Board's "Statement 109: Accounting for Income Taxes"
- Design a commission plan that drives sales - Sales Commissions
- The best time to buy a car: December is not the only time to get a new set of wheels. We'll show you when to make your move to the dealer's showroom



