/ BLOG

โ€œGONE PHISHING!โ€ โ€“ The Real Liability of the Virtual World

May 31, 2017 · 5 minutes to read

Phishing is a criminal practice that exploits individuals via fraudulent electronic communication and interaction. Together with spear phishing, clone phishing and whaling, the Internet can be a scamming minefield.ย  If you donโ€™t already, it might be a good time to pay attention to the security breaches you hear about in the news, like Gawker.com in 2010, Sony, Epsilon and others in 2011, and most recently Zappos in early 2012.

Generally speaking, social engineering is putting bait on a virtual fishing pole, casting it out into the vast ocean of the Internet, and waiting to see who might naively take a bite. After being hooked by the apparently trustworthy communication, the unknowing target then proceeds to give up confidential information (social security number, credit card number,ย etc.) โ€“ anything that can help perpetrate identity (ID)ย ย theft or credit card fraud.ย  In other cases, the scammer can even get cash from his hooked โ€˜phishโ€™ by sending emails from a hijacked email account posing as a friend in need.ย  Itโ€™s been estimated that scammers can make $500 a day from their victims, if not more.

Businesses of all sizes are subject to security breaches. It can be because their networks were compromised, an employee lost a laptop or perhaps there was an accidental disclosure of confidential information (like posting a spreadsheet of client data to a public website). When this type of breach happens, and it does often, the business can be liable for a host of breach-related costs. To mitigate the consequences, the negligent company must bear the responsibility to:

  • Notify customers their data has been disclosed,
  • Incur information technology (IT) forensics costs to investigate what caused the breach,
  • Be subject to privacy regulatory activity, and/or
  • Third-party liability from those who were caused financial harm from the breach.

The liability does not stop at the business that lost customer data; it extends to that companyโ€™s subcontractors, independent contractors and vendors who may be the linchpin in the breach.ย  When contracting with business clients, a subcontractor may take on its clientโ€™s highly sensitive customer information and therefore is alsoย responsibile forย maintaining its security.

Letโ€™s consider what happened to Epsilon in April 2011.ย  Epsilon is one of the largest email and online marketing firms, whose customers includes seven of the Fortune 10 amongst its 2,500 clients.ย  Their breach exposed the names and email addresses of massive customers like Best Buy, Citibank, and Walgreens.ย  While it may not seem like highly prized data in and of itself, names and email addresses are quality bait and useful in constructing a successful scam.ย  Receiving a personalized message from a company that you already have an account with can be convincing and leaves many people susceptible to ID theft.

Whether youโ€™re a big vendor like Epsilon, who performs email marketing services for huge Fortune 500 clients or an independent contractor working on your personal laptop with your clientโ€™s confidential data, you can become liable for a security breach of your customerโ€™s (or your customerโ€™s customersโ€™) data if you or your equipment is somehow the weak link.ย  The general consensus from the privacy/security community is not whether someone will be hacked, but when.ย  After that happens, itโ€™s about what was done to mitigate the loss.ย  In a recent study entitled โ€œEmpirical Analysis of Data Breach Litigation,โ€[1] law researchers at Carnegie Mellon and Temple University found that a company that offered credit monitoring after a breach was six times less likely to get sued.ย  If itโ€™s not preventable, then why not at least transfer and minimize the risk and cost.ย  Having a strong service contract that protects your position in the event of a security breach is one way to start, along with maintaining industry standard privacy and security controls.ย  One cost-effective way toย transfer the risk of this liability is through Cyber Insurance.

Cyber Insurance combines Technology Professional Liability (a.k.a. Errors & Omissions), Miscellaneous Professional Liability, Privacy Liability and Network Security Liability into one omnibus coverage that protects a company against todayโ€™s ever growing need to safeguard electronic information.ย  The coverage can help cover costs like Information Technology forensics, third-party liability, and credit monitoring.ย  The nuance of whether youโ€™re subject to a third-party liability claim or first-party privacy cost claim can be avoided, when you have a policy that covers you from all angles.

One obvious lesson is to be very careful with all communications and actively protect your own confidential information and passwords.ย  If youโ€™re not careful on a personal level, you may have your account hijacked and have to deal with your emailโ€™s support team who may, or may not, be able to retrieve your emails from the last five years.ย  Not to mention the scorn of your friends and family who may have given up money or other confidential data to someone perpetrating a scam from Nigeria.ย  For a business, however, itโ€™s critical to not be known as the company that let down its guard and made its customerโ€™s data vulnerable to the scores of hackers, scammers, and organized e-crime syndicates that are on the prowl.

As you explore and utilize the wonderful World Wide Web, enjoy surfing, but donโ€™t get hooked!

BizInsure Guest Blogger: Natalie Chin


[1] Romanosky, Sasha, Hoffman, David A. and Acquisti, Alessandro, โ€œEmpirical Analysis of Data Breach Litigationโ€ (February 19, 2012). Available at SSRN: http://ssrn.com/abstract=1986461ย or http://dx.doi.org/10.2139/ssrn.1986461

Talk to us

Todayโ€™s BizInsure offerings are just the beginning. Please take the time to tell us what you think, offer advice, ask questions, give compliments, or make a requestโ€ฆcustomer feedback defines us. Weโ€™re listening. Click hereย to contact us.

Let's find

The coverage you need for your business

Professional Liability Insurance

Professional Liability Insurance

Get a quote

General Liability Insurance

General Liability Insurance

Get a quote

Business Ownerโ€™s Policy (BOP)

Business Ownerโ€™s Policy (BOP)

Get a quote

Workers Compensation Insurance

Workers Compensation Insurance

Get a quote

Let's find

The coverage you need for your business

Professional Liability Insurance

Professional Liability Insurance

Get a quote

General Liability Insurance

General Liability Insurance

Get a quote

Business Ownerโ€™s Policy (BOP)

Business Ownerโ€™s Policy (BOP)

Get a quote

Workers Compensation Insurance

Workers Compensation Insurance

Get a quote

Very helpful and professional!
Wasn't that easy. Lot's of little hoops to jump through and added fees for my trouble.
It was an extremely simple process.
Easy to renew. No sales pitch.
The team is always quick with our requests for insurance documents and they were a great help finding us a policy that fits our needs. We'd highly recommend them for any small business insurance needs!
The most reasonably priced insurance that we can find for our business. Highly recommended!
Excellent, efficient! Would definitely use again!!
Very easy transaction renewing my insurance. They also have exceptional customer service!
Great company with ease of customer service.
Thank you, very efficient and fast
I never had to file a claim, but I want to take a moment to say the team is professional yet personable. I have had a pleasure having them in my corner. Highly recommended for E&O.
Jasmine helped me out took her time and made me comfortable. What a great experience
wonderful experience, customer service was excellent!!!
Great experience buying insurance
Help is fast and accurate
The Quotes With Biz Is Great! Try Them!!
The app is easy to work on thank you so much
Their website is easy to use and their fees are transparent and reasonable.
Alessandro Cardenas was very professional and incredibly helpful. I will definitely refer this company.
Great experience with jazzmine. She answered every question I had on spot. And made me feel safe moving forward.
The quickest, cheapest quote Iโ€™ve ever received for my business. I love them
"Getting business insurance through BizInsure was a smooth and straightforward process. Jazzmine was very knowledgeable about the product and explained everything clearly, which made it easy for me to understand. I'm very happy with my decision. โ€“ Susie G ๐Ÿ™‚"
Process of renewal is online, which is simple and strait forward.
I need and insurance policy for mu business right away the process online was easy I would recommend the any time





    This will close in 0 seconds





      This will close in 0 seconds