McGowanPRO Professional Liability Blog / Resources / Articles

Cyber tip: How often to change passwords

Posted by Alison Simons on Thu, Aug 06, 2015 @ 03:10 PM

As an insurance agent we deal with applications every single day, yet, when I have to fill one out, I have the same reaction as my insured’s, “I hate applications”.

However there are times when an application is a good thing, like a cyber-application.

The cyber application is designed to ask risk management questions that hopefully provide some insight on cyber exposures.

For example: How often do you change passwords?

The majority of answers is anywhere from 90 days to once a year by most applicants.

So what is the best answer? Monthly

We all get careless with passwords and we are never sure if they have fallen into the wrongs hands.

Changing passwords monthly insures a better risk management landscape it also makes employees responsible for managing their passwords and not used as afterthought.

The main reason for not changing passwords is “I have so many” and “I can never remember them” however in reality this is more consistent with passwords that you may only use once in a while. To help safeguard your business network, passwords should be used every time you log on. One common error when choosing passwords is the employee uses the same login as their personal bank account or Amazon account.

This now puts the business at risk when any other of their personal accounts are hacked and the hacker goes phishing for other easy computer systems connected to that individual.

Let’s look at a recent case of password hacking. Employee Alice, Facebook account was taken over without her knowledge and they used this information to gain access to her Amazon account where her credit card information was stored. Alice’s G-mail account was the next hacking opportunity using personal information they were able guess her password using a combination of personal information and birth date.

Alice had several work e-mails in her personal account so they now went after her work e-mail, the first password used on her employer system was her Gmail account password and instantly they are now in the company’s server.

Hackers know that people re-use or use one password for many applications (log-ins). With Alice’s work e-mail account accessible a series of e-mails were sent pretending to be Alice to capture additional confidential information. Think about a co-worker sending e-mail requesting information that appears to be a legitimate e-mail, most of us would respond. In this case human resources was sent e-mail asking for her personal banking information, explaining that her direct deposit account was hacked and she need to change the account prior to the next pay period.

Fortunately there was no theft of funds and the HR person called Alice and the jig was up. However that was not the end of the story for Alice’s company. The company was concerned that their data may have been compromised and brought in an outside forensic IT company to ascertain any data breaches. Calls were also made to their attorney to review if this was a reportable event to state regulatory agencies.

All company passwords were changed and remote access from outside employees was shut off. It was several long days before the business was back to normal. Although the company escaped any real threat, there were still significant costs incurred not including lost employee time and production.

Alice was able to notify all her credit cards and banking relationships and re-establish her social media accounts. Hundreds of fake e-mails were sent posing as herself to friends and family and several months later she is still monitoring all of her accounts closely.

The moral of the story, employers need to carefully monitor passwords. Passwords should have all of the following attributes:*

  • At least 10 characters long

  • A mix of lower case, upper case, and non-alphabetic characters and numbers

  • No words found in the dictionary (English or a foreign language)

  • No more than two consecutive characters

  • No common names, terms

  • No simple pattern


In conclusion: changing passwords every 30 days helps mitigate potential access. Establishing rules against employees using work passwords for personal use is strictly prohibited. Training employees to protect and secure passwords is one way to try and avoid hacking incidents. So when the cyber applications asks the question how often do you change passwords, and the first answer is 30 days, consider reflecting on the answer from a risk prospective position.

 

*Taken form the Cyber and Data Security Handbook written by Eric Hess, July of 2015 for NAPLIA

Tags: Data Breach, NAPLIA, Information Security, identity theft, cyber, records

Active Response to Cyber Attacks Has High Risk

Posted by Alexandra Swan on Wed, Apr 10, 2013 @ 12:38 PM

With an increase in Cyber exposures and cyber claims against CPA firms, CPAs need to be aware of the strategies to minimize these risks and ensure that the strategies are legal. There are both national and international laws governing the ways in which firms combat cyber exposures. The article below explains the added exposures that may result from not knowing the laws. 

http://www.forbes.com/sites/jodywestby/2012/11/29/caution-active-response-to-cyber-attacks-has-high-risk 

Tags: Data Breach, employee dishonesty, fraud, Information Security, identity theft

Protecting your Client Data from Identity Theft

Posted by Tom Henell on Fri, Nov 16, 2012 @ 03:21 PM

Personal information can exist in either a physical or electronic form. Regardless of the form in which the information exists, the standard of protection remains, only the implementation of that protection changes.

Physical Information

Physical copies of personal information can be easily protected by simply storing the information in a locked storage area. This area can be anything from a filing cabinet to a safe to a third party storage facility. So long as access to the information is limited to properly trained employees, any of these forms of locked storage should be sufficient.

See more about File Retention Policy

Electronic Information

The storage and security of electronic personal information can be more complicated than the storage of physical personal information. The implementation of an electronic storage system can vary widely depending on the size of a company or firm, and the amount of information that must be secured. At a minimum, the WISP (Written Information Security Plan) must cover authentication protocols, including the use of user IDs and passwords and their security; secure and restricted access to the personal information records; the encryption of the electronic records; and the monitoring of the implemented systems.

Many electronic file systems and operating systems have a built-in function for the creation and maintenance of a user ID and password system. For larger firms and companies, a more robust system may be needed and can be found through third-party vendors.

Encrypted storage and transmission of personal electronic information can be implemented in many ways. Many manufacturers now sell USB drives and external hard drives with built-in encryption systems. For the encryption of current drives and file systems there are numerous programs available for purchase and comparable free programs as well.

State Security Breach Notification Laws

It is essential to be familiar with your particular State’s Security Breach Notification Law.  At this time, 46 States have unique Security Breach Laws in place.  NAPLIA provides you with a summary of each State Security Breach Law identifying:

  • Date law was enacted
  • Definition of Personal Information by State
  • Notification Requirements
  • Penalties
  • Links to full State Statutes, and Laws

Tags: Data Breach, state security breach law, identity theft

The incalculable cost of Identity Theft to your firm

Posted by Tom Henell on Tue, Jul 10, 2012 @ 01:50 PM

The Computer Crime and Security Institute has estimated that as many as 43% of US businesses experience some level of cyber security incident.  The cost of a cyber incident to your firm can be calculated in claims and lost wages.  In addition, with more than 46 states having State Security Breach Laws, client notification costs can be significant ($5 - $10 per client).

What can't be measured is the cost to your brand.  According to Ponemon Institute 2010 global costs of a data breach, the value of brand and reputation can decline 17% - 31% after a breach.  In addition, it can take over a year for an organization to recover it's corporate image.

Having a formal security breach plan in place can assist you in informing your clients the steps you have taken to protect their data in the event of a loss.

For more information download our White Paper on Information Security & Cyber Liability: Essential Steps to Protecting your Firm

Tags: accountants, Data Breach, Information Security

War Story: Why Coverage Matters (Client Identity Theft)

Posted by Tom Henell on Tue, Apr 24, 2012 @ 01:33 PM

One of NAPLIA’s long-term clients recently received a competitive quote from another agency for their accountant’s professional liability insurance. The quote was $170.00 lower than their existing premium. Despite a discussion with the client regarding policy differences and the benefits of their existing program, the insured elected to go for the minimal premium savings.

They stated they were comfortable with the new agent’s representation of the coverage “being equal”.

Two months into the policy, one of the accountant’s laptops, which contained confidential client information, was stolen from their office. The theft occurred over a weekend and was not discovered until Monday morning.

The accountant called his new agent and was informed that there was coverage in place, but to a limited extent. The agent provided the accountant with the carrier’s toll free hotline to get additional information and support. The additional information amounted to a single piece of advice; secure local legal representation, at the accountant’s expense, to determine the extent of the security breach.

At a loss, our former client remembered the discussion with our office regarding Identity Theft coverage and called our office.

Although no longer a client, NAPLIA was able to assist the accountant with the following:

  • NAPLIA provided the accountant with their specific state’s security breach laws.
  • Upon review of the relevant state security breach law, NAPLIA determined that under the relevant circumstances, they were only required to notify any client whose personal information was not encrypted in a reasonable manner. 
  • NAPLIA provided a sample security breach letter that the accountant could use to send to these clients.
  • NAPLIA provided the accountant free access to our Attorney / CPA to assist him with additional questions.
  • NAPLIA explained the difference between “first party” and “third party” liability relevant to a client data breach.
  • NAPLIA reviewed their current policy and determined their first party coverage was limited to $1,000.

In hindsight, the accountant requested that we review the difference in coverage between the policy they had with NAPLIA and their new policy.

The policy they left with NAPLIA provided $25,000 for first party Cyber Liability in comparison to the $1,000 with their new policy.

The accountant had moved their coverage to save $170, and within two months realized that NAPLIA’s resources and service alone negated the premium savings. In addition, the new policy was not “equal” to their previous coverage leaving them with significant exposures.

The moral of this real story is to understand that not all polices are the same and coverage does indeed matter more than premium savings.

Tags: accountants, Data Breach, cpas, identity theft

What is the cost of a Data Breach ?

Posted by Tom Henell on Thu, Oct 27, 2011 @ 09:02 AM

When evaluating the potential cost of a data breach we have previously referenced the direct first party costs incurred by a firm as $5 to $50 per client.

Further information provided by the Ponemon Institute estimate this cost to likely be closer to $214 per record.  The Ponemon Institute conducts independent research on privacy, data protection and information security policy. 

cost of data breach

Their research estimates direct costs of $73 per record.  Direct costs may include forensic, notification, call center, credit monitoring, victim assistance, legal defense costs, and breach consulting.

However, they further consider the indirect costs of diminished customer trust as approximately $141 per record.  This creates a total potential cost for a data breach of approximately $214 per record, not factoring any potential Errors & Omissions claims related to to the breach. 

Tags: accountants, Data Breach, Information Security

Emerging Cyber Threats; You can’t hide your head in the sand

Posted by Tom Henell on Thu, Oct 20, 2011 @ 11:08 AM

According to a recent report by the Georgia Tech Information Security Center, Emerging Cyber Threats Report 2012, Cyber threats against personal information [data] continues to evolve.  We will see advances in the sophistication and implementation of attacks in the near future.

As a professional who maintains personally identifiable information (PII) of your clients it is essential to be aware of these new and emerging threats, and take possible steps to safeguard your data.

Some of the areas cited in the report include:

  • Mobile Phones / browsers

There are currently four billion mobile phones in use around the world and mobile Internet is expected to outpace desktop Internet usage by 2014 (http://www.digitalbuzzblog.com/2011-mobile-statistics-stats-facts-marketing-infographic/ ).  Characteristics of mobile browsers create a new platform to introduce threats to data, as well as, potentially bypass existing firewalls and other security measures.

  •  Botnets

Botnets have been around for a long time but they continue to evolve.  PII is big business and this means increasingly sophisticated processes to access information.  Botnets have gone from targeting small pieces of data to creating complex demographic models that can potentially be sold into legitimate markets.

  • Online Information

We live in the digital world and more business and personal interaction is transacted online than ever before.  Marketers continue to expand the way our personal information is utilized to “control” our online experiences.  In addition, attackers are now capitalizing on search engine optimization (SEO) to increase rankings and, therefore, credibility.

  • Technology Advances

Advances in technology that enhance the way we conduct business also increase our potential exposure.  Cloud computing creates new exposures that were previously addressed through physical servers.  However, human error, education, and weak passwords continue to create the most vulnerability.

You can read the whole report here.  It is not necessarily possible to understand all of the exposures created through enhancements in technology.  However, broader education creates awareness to avoid potential disasters.

If you have not already, download NAPLIA’s recent White Paper on Information Security: Essential Steps to Protecting your Practice.

Tags: accountants, Data Breach, cpas, Information Security

NAPLIA named to the Inc. 5000 for 2011

Posted by Tom Henell on Thu, Aug 25, 2011 @ 09:02 AM

We hate to take space to blow our own horn, but we at NAPLIA are extremely proud to be recognized for the fourth consecutive year as one of the fastest growing private companies in America.

http://www.naplia.com/Naplia/inc500.html

What does this mean for you?

You can be confident that you are working with a nationally recognized company that has been successful through our dedication and service to our clients.  We like to think we are changing the way professionals buy insurance.

NAPLIA is committed to providing you with a better buying experience for your Professional Insurance by:

  • Providing Choice
  • Providing Education & Resources
  • Providing Experience & Expertise
  • Providing Quality Service

Backed by a track record of success and national recognition.  We can confidently say that "no national agent can match our personal service, and no local agent can match our national recognition".

Contact us today for more information about your professional liability insurance, errors & omissions, or other professional insurance needs!

Tags: accountants, Data Breach, cpas, employee dishonesty, errors & omissions, professional liability, Employment Practices Liability

Insurance claims for data theft worldwide jumped 56% last year

Posted by Tom Henell on Tue, Aug 16, 2011 @ 08:57 AM

According to a recent newsletter from Willis, data production is growing at an exponential rate (currently compound annual 60%) and that claims for data theft worldwide jumped 56% last year.  

In our experience, questions regarding insurance coverage for data security and identity theft are increasing daily.  Professional liability policies are intended to cover errors or omission in the delivery of professional services.  The question that often arises is, if data is lost or stolen outside the office (i.e. theft of a laptop computer) is there a connection to the delivery of professional services?

In addition, first-party expenses often triggered by state security breach laws are generally not covered under a professional liability policy.  This is the direct cost of client notification and credit monitoring that can run between $5 - $50 per client.

Download NAPLIA's White Paper on Information Security & Cyber Liability to learn more about essential steps to protecting your firm.

Tags: accountants, Data Breach, Information Security

Laptop Security – Important Steps to Mitigating Risk

Posted by Tom Henell on Wed, Jun 08, 2011 @ 03:00 PM

Modern technology allows us to enjoy a more mobile workforce.    With Laptops, Tablet Computers, Smart Phones, and other devices we are able to access work from virtually any location.  However, these devices also expose companies to new risks previously not experienced by a desk-bound workforce.

Here are several simple steps to consider to protect your mobile computers, and mitigate your personal, and professional exposure.

  1. Identify your potential exposures.  The first step is to simply acknowledge that you may have weaknesses in your network security and take the time to identify them.  This process will require some research on your part, but is well worth the time.  For more information, download our recent White Paper: Information Security & Cyber Liability: Essential Steps to Protecting your Firm
  2. Use visible locks on laptops in your office.  A number of cable style locks are available to secure laptops to a desk when in your office.  These will not prevent a determined burglar, but a high percentage of laptop thefts are snatch & grab and can be prevented with a simple lock.
  3. Treat your laptop like a wallet or purse.  You would not leave your wallet sitting on your desk when you leave for the night, nor would you leave it sitting in the backseat of your car.  Laptops are prime targets for theft and simply keeping them out of sight will remove the temptation.  Lock them in your desk, and put them in your trunk if necessary.
  4. Do not store client data, passwords, or other important information on your laptop.  Only use laptops to access a server never store personal or confidential information, instead use the laptop as a portal to see but not store information.
  5. Keep your anti-virus software and firewalls updated.  In addition, make sure that laptops are encrypted to prevent access, as well as, have encrypted hard drives.
  6. Consider laptop tracking & recovery software.  There are several programs now available that can track, locate, and remotely delete files from stolen or lost laptops.

Not convinced?, read an actual claim scenario by one of our clients.

Tags: accountants, Data Breach, Information Security