- +
Doing Your Sums on . . . Build, Buy or Rent 05/11/2007 13:32:30
You’re trying to build a world-class IT team, but everyone’s going after the same talent pool. What mix works best? Should you grow your own, draft your players or barter your way to the line-up you want to field?CIOs should never forget that while new technologies have a maturity cycle, the maturity cycle for human beings in IT is even longer
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Email Archiving Technical Overview
Email Archiving 101—Customer Case Study
CRM your salespeople will love
Delivering the Power of Choice with Microsoft Dynamics CRM
Why Security SaaS Makes Sense Today
Solve Exchange Storage Problems Once and For All: A New Approach without Stubs or Links
How to Beef Up Your Sales Pipeline
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Cyber insurance will become as commonplace as car or home or any form of business cover within a decade as a way to mitigate financial losses should a "cyber attack" occur and sensitive data be lost or stolen.
But that's a decade away. Today, very few IT managers are aware of cyber insurance. Even underwriters and insurance agencies have shown little interest in the market despite hundreds of serious breaches in the past two years.
Sydney-based security services provider Sift has released a white paper entitled, The Economic Viability of Cyber Insurance: Seeking Financial Certainty in IT Security. According to Sift associate Bosco Tan, the government needs to educate both the insurance industry and vendors on this issue.
"Both academics and insurance industry professionals forecast that cyber insurance will become as common as traditional brick-and-mortar insurance products within the next decade," Tan said.
"In order for the accelerated development of cyber insurance to occur there is a role for the information security industry, the insurance and reinsurance industry as well as the government to work together."
Tan said the government should be supporting market education as it should be part of an overall risk management strategy.
While cyber liability does exist, Hydrasight research analyst John Brand said enterprises have refused to buy it.
He said there are existing policies relating to disaster recovery, but when it comes to hacking or malicious attacks, few policies exist.
"Insuring data as a result of a malicious penetration is often included in disaster recovery policies, [because] it is something that is easy to protect against. A base level of security technology is shared among most organizations anyway; but information leakage and the damage it can cause to a company is unquantifiable and undetectable," Brand said.
"From a senior IT perspective, it would be difficult to assure the rest of the business is doing the right things, and be able to defend your position in the event of forensic investigation as a result of the claim.
"Once an issue is raised that would result in a claim, most people are worried about fixing the public image and then considering the financial losses; from an audit perspective, breaches are difficult to trace anyway and there is an enormous amount of work to discover what really happened."
Despite the obvious need, most IT managers have not heard of cyber liability insurance.
IT manager for Rigby Cooke Lawyers, Anthony Strangis, said he would rather spend the time that it took to fill in such a policy in better securing his company.
"There is just no point vying for insurance against data breaches when security systems are inadequate and, conversely, if the systems were up to date, why would you want to get insurance?" Cooke queried.
Micheal Axelsen, IT manager for chartered accountancy firm BDO Kendalls, said the problem with such insurance is insurance firms would apply and enforce security standards for clients through a very costly and thorough third-party audit, which may not be feasible.
"The lag between software vendors becoming aware of security vulnerabilities and a patch becoming available is wider than it used to be, and hackers and malicious coders are becoming smarter and exploiting this," Axelsen said.
"Business needs to take a holistic approach to security and a company could invest greatly in electronic data security, yet sensitive data could be left in the back of a taxi."
Cyber insurance: where do you get it?
Zurich Insurance does not offer any policy relating to liability of data breaches.
QBE - professional liability - ICT proposal for hardware and software faults - no mention of data protection or liability.
Allianz Insurance - does not offer any form of cyber insurance relating to households or businesses.
IAG - offers a business liability package but nothing relating directly to hacking, loss of data or cyber liability.
Insurance house Lloyds of London currently offers a "Cyber Insurance" policy through various underwriters in Australia, but according to analysts and IT managers, uptake in Australia has stalled.
The actual policy document, provided by Australian Insurance underwriters Epsilon, is called Esurance and contains nine elements relating strictly to IT that extends as far as liability cover in terms of viruses interrupting business, extortion, intellectual property rights, brand protection cover and even paying the costs of a public relations agency to "minimize the damage to your reputation".
The document also covers system damage in restoring computer records in the event of a hacking incident or virus, lost revenue as a result of network downtime and covers "ransom demands or threats to introduce a virus or hack into computer systems, or to disseminate to third parties the data held on computer systems."
An element of the insurance also covers forensic consultants to repair systems and restore data in the event of an incident.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
F-Secure achieves excellent results in Internet security suite comparison 2008-10-10 14:37:00+10
M2M Connectivity announces the new Sierra Wireless MC8792V embedded module for 900 MHz 3G/HSPA networks 2008-10-10 08:51:00+10
Pitney Bowes MapInfo Launches New Version of AnySite 2008-10-10 05:58:00+10
IOGEAR Gears Up in Australia 2008-10-09 20:18:00+10
Internet Service Providers offer new unlimited Online Backup from F-Secure 2008-10-09 19:42:00+10
Enterprise Wireless WLAN Security
Learn more about the security challenges to be faced when defining and implementing security mechanisms within diverse wired and wireless network environments. Download this must-read guide to plan your wireless data protection strategy now.










