by Tina Crivello
Brock & Scott, PLLC *
USFN Member (CT, NC, RI, AL, FL, GA, KY, MA, MD, ME, MI, NH, NJ, OH,
PA, SC, TN, VA, VT)
USFN kicked off the new year with a Briefing on one of the
industry’s most timely and critical topics for today and the foreseeable future
– Cyberattacks & How to Respond. On January 23, a panel of industry leaders,
including attorneys, fintech leaders, and insurance experts, provided attendees
key insight into the state of cyberattacks and what we can do now to prevent
and prepare.
Cyberattack prevention as the first line of defense should
be at the forefront of everyone’s efforts. Ronny Loew, ProCirrus Technologies,
Inc., and Jan Duke, a360inc, shared the top elements of a prevention plan which
includes a three-prong approach of user education, using application controls,
and increasing awareness throughout an organization. Loew reminded attendees,
“Eighty-two percent of the issues that are occurring are due to the human
element.” Security training and simple, yet effective, controls such as
multifactor authentication can help prevent many attacks. Just as important is
email security, patching and updating of anything connected to the network or
internet, and cybersecurity services such as endpoint monitoring. Duke
suggested to ensure that phishing training campaigns in organizations are
relevant to users, “so it’s something that really will try to appeal” to
employees. She encourages organizations to have town hall meetings to discuss
the dangers and “make it real” to employees, so they hear it from the top of
how important this is.
Wendy Lee, of Sagent, covered highlights of communication plans
once an incident has unfortunately occurred. She stressed the importance of
pre-planning a crisis communication plan and how the onslaught of communication
will be handled. Most critical is understanding federal law, state breach
notification laws, contractual obligations, as well as executive buy-in and
control. Lee shared a story about a recent settlement related to failure to
disclose timely to victims of a cyberattack and stressed how critical it is to meet
the notification requirements. Federal requirements, such as the Securities and
Exchange Commission’s (SEC) four-day time limit, may not directly impact your
business, but it could impact a company you do business with if they are a
publicly traded company. Customers may require reporting in one day due to the
SEC’s requirement for reporting events “that could have a material
impact.” Evaluating materiality in a 24-hour window may be almost impossible, which
means potentially reporting an incident whether it’s known yet if there is a
material impact. Big companies today are making the required filing regardless
of potential material impact to ensure adherence to the law.
Key points to include in a crisis communication plan
include:
· Understanding who to notify – victims, state Attorneys
General, or other government entities
·
Knowing when to notify the above
·
Adhering to specific requirements about the
notice contents
·
Following any state specific form of requirement
– in writing, electronic, or by phone
Perhaps even before, or at minimum at the same time, as sending
any other notices, Harrison Tropp of SGP Advisors, recommended immediately
notifying your cyber insurance carrier or broker. Carriers have designated
claims hotlines through which you are assigned an adjuster who will begin
assembling the claim team. This may include the insurance adjuster and broker,
a legal expert, a data security firm, and law enforcement. They will help a
company figure out next steps. In cases of ransomware, this will almost always
include immediately paying the ransom so companies can regain access to systems
as expeditiously as possible. Tropp notes it’s critical to have draft
communication ready to go should an event happen. It is also important to have an
action plan in place and test it regularly. He also highlighted how the
underwriting process, “especially in the default space has gotten increasingly
more difficult.” During the underwriting process, insurance companies may run
certain tests on a company’s systems and if they don’t meet the requirements they
will refuse to underwrite.
Brian Nicholas, Esq., McCalla Raymer Leibert, Pierce, LLC, stressed
the importance of running a test of a company’s action plan and key questions
to ask. First response type questions may include, “How do you know if the
attack is real?” and “Who should you contact first?,” among others. Second to
answering those questions is knowing what your cyber insurance policy covers,
how it helps, and how to activate coverage. In today’s online world, Nicholas
recommends having a hard copy of your policy and response plan available to key
members of your organization. Finally, Nicholas posed the question of how we
reduce the risk of Personally Identifiable Information (PII) exposure. “The
biggest risk is loss of that confidential information.” Understanding how
companies keep or expunge that data, especially when considering, for many,
adhering to state bar guidelines.
Nate Braun, of NetDirector, provided pointers on risk
reduction with data segregation and segmentation. Network segmentation, which
is the grouping and isolation of information systems by function and
classification through use of controls, virtual environments, and disk
encryption, are just a few steps an organization can take to protect data. Braun
cleverly compared network security to being akin to physical security and showed
how the multiple check points needed to access a physical file in a cabinet are
analogous to the multifactor authentication steps needed when accessing data on
a network.
The briefing was concluded by moderator Elizabeth DeSilva,
Esq., and Brian Nicholas discussing what it really means to run a “table-top”
drill. Nicholas explained it is just like your disaster recovery drills, where
you run through the steps as if it had been a real event. It’s important to
throw a few “curveballs” into the drill as well. What happens if your CIO is on
vacation? If your email is down, do you have a secondary system or plan in
place to communicate with employees and clients?
USFN is committed to helping the industry combat
cybersecurity issues and will continue to bring members together to learn and
share experiences and expertise surrounding this critical topic.
In the meantime, bookmark USFNevents.org and plan to join us for these upcoming virtual programs:
- March 12: USFN Briefing: Show Me the Judicial Foreclosure
- May 7: USFNgage: Artificial Intelligence
Copyright © 2024 USFN
USFNews - Feb. 21
* Denotes Member is a 2023 USFN Award of Excellence Recipient