Please ensure Javascript is enabled for purposes of website accessibility

Cyber insurance is an important tool – Does your institution know how to use it?

Cyber insurance is an important tool – Does your institution know how to use it?

Listen to this article

Higher education is a risky business. The interplay of education, housing, finance, maintaining a campus and fulfilling an institutional mission creates a unique fabric of risk found in few other industries, all against seemingly conflicting needs to maintain the security of sensitive data on the one hand, while not prohibiting information sharing on the other. And when it comes to cyber security risk, higher education is a perennial target. Whether it is theft of intellectual property, hijacking an institution’s network for illegal activity, or good old-fashioned fraud, there are few cyber risks that higher education institutions do not face.

Altieri

Cyber risk insurance is an important tool in managing these risks. Yet, like any tool, it can be misused or can even cause harm in untrained hands. With a small amount of forethought and preparation, an institution can increase the efficacy of its cyber risk policy and build internal competencies that will aid the institution if — and when — it faces a cyber security incident.

First, the language that an institution uses when faced with an incident is key. An incident is always an “incident,” and never a “breach,” absent a legal determination that a defined “breach” has occurred. This is because “breach” is a legal term of art, bringing with it reporting duties that, if missed, can be more harmful to an institution than the incident itself.  In relation to Title IV financial aid information, for example, the Department of Education has required notice within 24 hours of a defined breach.  And the N.Y. SHIELD Act — N.Y. Gen. Bus. Law § 899-aa — requires notice of a defined “breach of the security of the system” to affected individuals “in the most expedient time possible and without unreasonable delay.”  If, however, your institution’s IT department sends an email to senior leadership stating that a “breach” has occurred, the proverbial clock on these deadlines has likely started to run, even if the specific definitions of “breach” have not been met.

Close interaction with your cyber risk carrier when a “breach” is suspected is key, but early and inaccurate use of the “breach” term can muddy the waters and often spur reactive behavior, rather than reasoned response activities. What every institution should have in place is a detailed incident response plan that defines a material security incident as one that potentially gives rise to a reporting or other regulatory duty on the part of the institution. Once that threshold is met, notice to the carrier is likely appropriate, depending on the language of the policy.  Random and undisciplined use of the “breach” term is anathema to such a plan.

Second, every institution should assess what service providers the institution may use in relation to an incident under the policy. Higher education institutions can spend years or even decades developing close relationships with trusted advisors, be they in the cyber security or legal fields. But when it comes to cyber incident response, many leave it up to chance, taking whatever provider happens to answer the carrier’s toll-free incident response line. Few service providers can be as mission critical to an institution, however, than those that will aid in response to a security incident, for example ransomware. And many institutions may be in violation of their own procurement and security review policies if they engage a carrier-approved incident response provider without appropriate vetting or contract review. The worst time, of course, to vet or negotiate with a potential incident response vendor is when facing an existential cyber threat.

Having a cyber risk policy is no good unless an institution fully understands it, limitations and all. Exclusions to and conditions for coverage change often and an institution should not be left scrambling in the wake of an incident to develop an appreciation for what is and what is not covered.

For example, it is important for an institution to understand whether it has a right to choose incident response vendors under its cyber risk policy. Institutions often accept a carrier’s limitation of choice in relation to such vendors without asking why, or whether, such restricted choice is good for the institution. It is no secret that carriers limit choice of vendors in order to control their costs. Carrier-approved vendors can be good, but the real question is whether the vendor is a good fit for the institution.

Greene

The answer to that question may be yes if, for example, the vendor has dealt with a similar issue for a similar institution. It may also be no, depending on the needs and culture of an institution. It is true that in some cases, choice of vendor can lead to higher premiums, but the time to ask for choice is when the policy is being negotiated, not after it has been issued.

Having multiple options is key:  if an institution’s biggest service provider suffers an incident, chances are that the service provider may have engaged the institution’s preferred vendor before the institution even knew of the incident.  Such risk speaks volumes toward negotiating engagement with trusted incident response vendors before an incident occurs, so the same vendor cannot be engaged by a service provider in an incident affecting your institution.

Lastly, practice makes perfect, when it comes to how to best utilize your cyber risk policy. Drilling the institution’s incident response plan helps build muscle memory concerning incident escalation, when to involve the carrier and how to work with carrier-approved third parties. For example, is the list of approved vendors provided by the carrier up to date? Only by drilling the plan — involving trusted advisors, such as incident response counsel and potentially a forensic vendor — can an institution ensure that it knows how to use this crucial tool in mitigating cyber risk.

In the end, having cyber risk insurance is better than not having it, but an institution loses a valuable opportunity if it does not give appropriate forethought to how its policy can best be used.

Paul Greene and Daniel Altieri are partners in the Privacy and Data Security practice at Harter Secrest & Emery, LLP. They can be reached at [email protected] and [email protected].

l