Think carefully about cyber insurance, says NCSC. But don't worry about buying off ransomware crooks
- Reference: 1596722405
- News link: https://www.theregister.co.uk/2020/08/06/ncsc_cyber_insurance_guidance/
- Source link:
Taking the form of seven questions for businesses [1]published on the NCSC website, the latest guidance urges companies to ponder security-specific things when deciding what insurance policy to take out.
“Most cover responds to the immediate effects on the organisation by working to quickly restore network systems and data, while seeking to minimise losses from business interruption,” said the GCHQ-sponsored agency. “For data breaches, there may be legal action from customers or other affected parties.”
Yet NCSC was rather coy when The Register asked what its position was on cyber insurance products that pay ransom demands made by criminals. Such insurance appears to have been a feature of a number of notable ransomware payoffs in recent weeks, where criminals profited handsomely from their crimes.
The agency would only say it was a matter for individual companies whether or not they pay a ransom to regain control of forcibly encrypted files.
Such advice fuels the insouciance of firms such as cloud CRM provider Blackbaud, which [2]got its insurer to buy off ransomware crooks who compromised customer data . Those crooks "promised" not to misuse the data they had taken and Blackbaud took them at their word. Similarly, Carlson Wagonlit Travel (aka CWT) [3]paid a $4.5m ransom at the end of July to get its corporate networks decrypted.
NCSC advice on cyber insurance in general is aimed at non-techies and managers. It advises higher-ups that they should consult with the people who “manage and run your IT and security systems” before signing a contract. Techies are, unsurprisingly, the best people to decipher the “cyber security jargon” that Reg readers know and love.
The guidance also warns that insurance policies bundled with the IASME Consortium’s Cyber Essentials certification “won’t be suitable for all organisations”. The consortium is the [4]sole issuer of the NCSC-approved award.
Earlier this year EU insurance companies [5]lamented that industry found their cyber products too complex to understand and opaque because there was little certainty about whether insurers would pay out on a genuine claim or pull the age-old trick of trying to squeeze out of their obligations. As Christophe Madec, client director at French insurance broker Besse told France’s FIC conference in February: “In liability insurance damages, we know the price of a liability [for] car insurance. For cyber, it's a little bit more vague.”
Last year Zurich made headlines after refusing a claim over a Notpetya infection, [6]claiming a “war exclusion” clause applied to ransomware cases . ®
Get our [7]Tech Resources
[1] https://www.ncsc.gov.uk/guidance/cyber-insurance-guidance#section_8
[2] https://www.theregister.com/2020/08/03/blackbaud_glosses_over_ransomware_payoff/
[3] https://www.theregister.com/2020/07/31/carlson_wagonlit_travel_ragnarlocker_ransom_paid/
[4] https://www.theregister.com/2020/04/20/mod_relaxes_cyber_essentials_plus_suppliers/
[5] https://www.theregister.com/2020/02/03/cyber_insurance_fic2020/
[6] https://www.theregister.com/2019/07/26/do_insurance_war_exclusion_clauses_apply_to_cyberattacks/
[7] https://whitepapers.theregister.com/
Just waiting to see how long before...
they try to claim "act of god".
Re: Just waiting to see how long before...
Surely keeping backups which would defeat a ransomware demand is a no-brainer ?
And for those who still don't do it, negligence.
Do insurers claim to protect from negligence (not just the legal liability of it, but the direct costs) ?
There are whole groups of schools, state and private, at the moment that are suing a bunch of insurers because their "pandemic" insurance (literally has the word in it) doesn't cover COVID-19.
The insurance company's defence is basically "It doesn't explicitly say COVID-19". Why would it? It wasn't known about when it was drafted. But it says things like pandemics, medical incidents, etc.
Hundreds of schools thought they were covered, went to cash it in, were told no, and now have to fight it in court. And they're questioning what they actually paid for, and whether it was worth paying for it at all.
Pretty much like every insurance I've ever heard of. There's a reason why, unless it's legally necessary, I don't bother with insurance. Just put the premium in the bank. On average you'll win just by doing that, and unless you're particularly unlucky you can stand to save a fortune that you'll never use.
Basket cases
Insurers, accountants and lawyer mostly all belong in the same basket.
Prefably hanging on a long rope and hanging over a hell mouth.
Come on. It a certainty insurers will try to squeeze out of their obligations if they can, as they always do.