{"id":12625,"date":"2017-06-06T09:50:05","date_gmt":"2017-06-06T07:50:05","guid":{"rendered":"http:\/\/www.intelligentcio.com\/africa\/?p=12625"},"modified":"2017-06-06T09:50:05","modified_gmt":"2017-06-06T07:50:05","slug":"wannacry-highlights-need-for-businesses-to-protect-themselves-against-losses","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2017\/06\/06\/wannacry-highlights-need-for-businesses-to-protect-themselves-against-losses\/","title":{"rendered":"WannaCry highlights need for businesses to protect themselves against losses"},"content":{"rendered":"<p>The recent WannaCry ransomware attack made a lot of companies wanna cry. As such attacks become more frequent and gain scale, cyber insurance promises to be the next big blockbuster in the insurance industry&#8230;<\/p>\n<p><strong>Safety net<br \/>\n<\/strong><br \/>\nRecently, WannaCry, a ransomware program, infected more than 230,000 computers in 150 countries. Hackers demanded payments in bitcoins to allow users to access their data.<\/p>\n<p>The attack hit several large companies, including a major American parcel delivery company, a European car manufacturer and a Spanish telecom company. It disrupted the operations of Britain\u2019s National Health Service and affected some operations of German rail network Deutsche Bahn, among others. <\/p>\n<p>South Africa is leading among the countries affected in Africa, with approximately 83 websites infected followed by Ivory Coast and Nigeria. Egypt, Algeria and Morocco complete the top six countries, while only a small number of attacks have been located in the rest of the continent. The most attacked sector in the region was healthcare, similar to what was seen in the UK, and large companies were also the most targeted, according to data compiled by Fortinet, a security company. <\/p>\n<p>\u201cThe stoppage of the outbreak was rather fortuitous. While this \u2018flaw\u2019 in the malware has been \u2018fixed&#8217;, we can expect a new and improved attack. \u2018Smart\u2019 malware such as this will become the norm and organisations must do all they can to protect themselves,\u201d says Danny Myburgh MD of Cyanre, Allianz Global Corporate &amp; Specialty (AGCS) Africa IT partner for Cyber Insurance.   <\/p>\n<p>The incident again highlighted how vulnerable companies are to cyber risks \u2013 be it a technical glitch, a human error or a cyberattack \u2013 and the business interruption that usually follows. <\/p>\n<p>Reuters reported that the total cost of resuming operations could run into billions of dollars for companies. <\/p>\n<p>As such attacks become more frequent; companies are becoming aware of the need to protect themselves \u2013 not just from such attacks but also from the losses that they could bring. <\/p>\n<p>This is why the cyber insurance market promises to be the next blockbuster in the insurance space, says Hartmut Mai, Chief Underwriting Officer for corporate lines at AGCS.<\/p>\n<p>While cyber insurance is already a mature market in the United States with an estimated premiums volume of $3 billion, it is still an emerging segment in Africa.<\/p>\n<p>\u201cCyber incidents ranked as a top risk in South Africa for the second year in a row and fifth in Africa in this year\u2019s Allianz Risk Barometer. Clearly businesses are concerned about the proliferation and impact of cyber incidents. Legislative developments in African countries and the African Union on cybersecurity and personal data protection and increasing levels of liability will see growth accelerate on the continent,\u201d says Nobuhle Nkosi AGCS Africa Head of Financial Lines.<\/p>\n<p><strong>The need for cyber coverage <\/strong><\/p>\n<p>Technology is a double-edged sword. On the one hand, it makes processes easier and less time-consuming; on the other, it opens companies up to new risks. Industrial companies are increasingly interlinking their equipment and processes \u2013 the so-called Internet of things (IoT) \u2013 to improve their operations but this exposes them to the greater risk of business interruption in case of an attack or a glitch.<\/p>\n<p>\u201cThe more the industry integrates supply chains and processes, and digitalises production into \u2018smart factories\u2019, the more vulnerable the long-established industrial companies become as well. For them, the risk of business interruption tends to be paramount,\u201d says Mai.<\/p>\n<p>The threat doesn\u2019t always come from hackers. Many a times, it\u2019s just a technical failure or an employee deliberately or accidentally introducing viruses or paralysing computer systems. <\/p>\n<p>When a crisis unfolds, compensation for financial loss is important, but the support services that often accompany cyber insurance are invaluable. Computer forensics, data and systems recovery as well as professional crisis communication can help a policyholder get back on its feet quickly. \u201cAssistance services, which we provide ourselves or through our partners, are therefore becoming increasingly important,\u201d says Mai. <\/p>\n<p><strong>The challenges <\/strong><\/p>\n<p>Of course, developing solutions for new risks come with challenges. Given that cybercrime is a relatively new threat, the insurance industry needs to tread with caution in developing such products. <\/p>\n<p>\u201cWe lack historical claims data because it involves an insurance product that is still relatively new in our portfolio. Also, companies shun publicity when they have been victims of a hacking attack because they are worried about their reputation,\u201d Mai explains. <\/p>\n<p>The portfolio management of cyber risks is also challenging and the accumulation risks are enormous. Through the digital networking of companies and supply chains, an incident at an individual company can quickly spread like wildfire, immobilising entire industries. <\/p>\n<p>Imagine the operations of an energy provider or a cloud services provider are disrupted due to a cyberattack, it will trigger numerous policies \u2013 not just cyber policies, but also other coverage, if property damage and business interruption occur. <\/p>\n<p>\u201cAt the moment, the accumulation risk is still manageable because not many companies in Europe, Asia and Africa have cyber insurance yet,\u201d Mai points out. However, just like director and officer (D&amp;O) liability coverage, cyber insurance is expected to become the standard for companies over the medium term. \u201cCyber insurance will be a blockbuster \u2013 and we must prepare ourselves for it. When the much stricter data protection regulations take effect in Europe in 2018, not just big corporations but also mid-market and smaller companies will want to buy cyber coverage,\u201d Mai says. <\/p>\n<p><strong>Data as a tool<\/strong> <\/p>\n<p>According to Mai, insurers have to consider evaluating the technical standards and the information technology maturity of a company differently. \u201cIndividual risk dialogues and detailed IT and process audits that we usually do for large companies would be too complex for smaller and mid-sized companies,\u201d he says. <\/p>\n<p>\u201cGoing forward, we aim to increase our automated cyber risk analytic capability by cooperating with data analytics companies. They use IP address-based screening, linguistic algorithms and other comparable methods to evaluate the level of IT security of a company. Such cyber resilience ratings could especially help us in offering cyber coverage to small and medium-sized businesses and retail clients through digital distribution platforms,\u201d Mai adds. <\/p>\n<p><strong>C for cyber strategy<br \/>\n<\/strong><br \/>\nGiven the frequency of cyber events in the recent past, there\u2019s no denying that cybersecurity and related insurance will soon become an important part of corporate risk management strategies. <\/p>\n<p>\u201cIn 2016, AGCS generated premiums in the mid-range double-digit millions with our cyber policies. Demand and policy transactions continued to increase significantly in the first quarter. No management board member or chief information officer has any doubts about the danger anymore even if their IT security is state-of-the-art.\u201d <\/p>\n<p>The market is gathering steam and we will likely see more modular cyber solutions that can be adapted individually to a particular company. <\/p>\n<p>At the moment, AGCS limits its share of cyber coverage to 100 million euros per client as the market is still new and the risks are harder to assess. For individual companies, up to 500 million euros capacity is available in the cyber insurance market. <\/p>\n<p>As a new \u2018normal\u2019 emerges, companies may not be able to completely avoid the bite of bytes. What they can do is ensure that the pain is minimal.    \t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The recent WannaCry ransomware attack made a lot of companies wanna cry. As such attacks become more frequent and gain scale, cyber insurance promises to be the next big blockbuster in the insurance industry&#8230; Safety net Recently, WannaCry, a ransomware program, infected more than 230,000 computers in 150 countries. Hackers demanded payments in bitcoins to [&hellip;]<\/p>\n","protected":false},"author":23,"featured_media":12627,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,399,19],"tags":[385,1694,1450,387,388,610],"class_list":["post-12625","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-more-news","category-regional-news","tag-africa","tag-allianz","tag-cyber-insurance","tag-cyberattack","tag-cybersecurity","tag-wannacry"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/12625","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=12625"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/12625\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/12627"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=12625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=12625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=12625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}