Cyber security insurance
Cyber Controls/Cyber Legal & Regulatory Landscape
Session 3
September 15, 2022
Agenda
| 1 | Schedule Updates |
| 2 | Cyber Insurability Controls Review |
| 3 | Cybersecurity Laws & Regulations |
| 4 | Cybersecurity Contractual Requirements |
| 6 | Assignment 2 Discussion |
2
Cyber Insurability Controls
Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.
3
Use Cybersecurity Frameworks as Your Guide
4
4
Why does this matter?
Cyber insurance requirements are becoming increasingly technical. Organizations that are not prepared may not be able to obtain or maintain cyber insurance coverage.
5
Source: Marsh 12 key controls to strengthen your security - https://www.marsh.com/es/en/services/cyber-risk/insights/cyber-resilience-twelve-key-controls-to-strengthen-your-security.html#sizetracker
5
Asset and Data Inventory
6
IT Assets
Servers
Endpoints
Mobile Devices
Employee Devices
Wireless Access Points
Networked Devices
IoT Devices
Software Assets
Local Databases
Software Programs
Cloud Applications
Software you use to run the organization (CRM, ERP, AMS, etc.)
Websites and Web Apps
Accounting & Payroll
Communication & collaboration
Unapproved software/SaaS
Data Assets
Customer Data
Intellectual Property
Financial Account Info
Confidential Employee Data
Protected Healthcare Information (PHI)
Personally Identifiable Information (PII)
Marketing Communication Lists
Donor Information
Payment Card Information (PCI)
Passwords
Biometric Data
6
Attack Surface & Vulnerability Management
7
Defenders need to succeed 100% of the time
Attackers only need to succeed once
Effective threat management programs identify and remediate vulnerabilities and exposures before malicious actors get a chance. Some common techniques include:
External attack surface scanning – what is visible from the outside
Vulnerability & patch management – quickly (within 30 days) identifying and patching known vulnerabilities
Penetration testing – Internal/external testing to simulate tools, tactics and techniques used by cyber criminals and malicious actors
7
Backup and Recovery
Cyber resilience requires the ability to recover quickly and effectively when something goes wrong. Secure, tested and immutable backups are critical in today's environment.
8
https://docs.microsoft.com/en-us/azure/backup/backup-overview
8
Encryption
9
Public Internet
Enterprise Resource Planning System
Email Server
File Server
Shared Resources
Virtual Data Center
Next Gen Firewall
Encrypt Data on Mobil Devices
Virtual Private Network to securely connect to on premises assets. Must also include MFA
Encrypt data in the cloud & web applications
Encrypt Data in Transit
Encrypt data at rest
9
10
Identity & Access Management
Protect Identities & Access to Systems
Multi-Factor Authentication (MFA) is the concept of requiring more than one simultaneous means of authentication to provide access. This usually comprises something you have and something you know, or something you know and something you are.
Single sign-on (SSO) is the concept of having a single location or portal for sign on, allowing user access to multiple applications (websites, applications and so forth). Without SSO, each site or application requires individual login sessions.
Password management – or credential management to be more accurate – is the secure storage and management of usernames and passwords. The method can be as simple as a stored data file with linear encrypted data or an advanced policy-enabled system with complex attributes and algorithms.
Privileged access credentials are those that provide elevated access and permissions across systems, applications and accounts. After an account is accessed, an intruder can move laterally, often undetected, to exfiltrate data. This is common in many of today’s ransomware attacks.
One of today’s most important security tools - that is increasingly important for cyber insurability - is privileged access management (PAM).
PAM It’s based on the concept of least privilege, which means users and accounts are provided only with the privileges needed for the task at hand and for the time required to complete the task.
Privilege Access Management
11
Session Management
Password Vault
Endpoint Management
11
Email Security
12
Phishing
Malicious Domains
Downloads
Malicious Links & Sites
Attachments
Unencrypted Data
Data Leakage
User Behavior
Email Spoofing
Email is # 2 action vector in breaches in 2022 Verizon DBIR
12
Cybersecurity Awareness Training
Technology can’t defend against our blind spots and mistakes. Humans are especially good at being tricked
13
Training will never be 100% effective (or even close) but we need to know what to watch out for
Awareness is important but training should model and shape behavior
Controls and process should reinforce training
13
Endpoint Protections
14
The number of tablets, laptops, mobile phones and IoT devices has exploded as more organizations than ever before have moved to a virtual workforce. This expands the attack surface cyber criminals can attack, and makes it difficult to defend. Examples of endpoint security include:
Antivirus (AV) – Essential baseline signature-based endpoint protection that protects devices (that can support this type of software) from known vulnerabilities and malware. Is not effective for unknown vulnerabilities or attacks that do not involve malware or hacking.
Endpoint Detection Response (EDR) – Supplements traditional signature-based protections by monitoring and detecting malicious activities and behaviors that indicate a possible compromise. This technology also allows for automated intervention to prevent lateral movement and proliferation to other devices.
Managed Detection Response (MDR) – Enhanced version of EDR that is delivered as a service to organizations that do not have in house expertise to act on alerts and remediate malicious activity or compromises.
14
Incident Response Planning
15
Cyber Insurance Alignment (More to come on this)
Insurance provides access pre-approved & vetted legal & forensics specialists experienced with cyber incident response.
Many policies will provide access to cyber incident handlers to help contain the spread of malware or an active event. This step may come earlier or in parallel with others.
Cyber insurance is essential to response and recovery. Some key elements include recovering data, restoring systems, reimbursement for lost income during disruption, minimizing reputation damage after an event as well as others.
15
Cyber Incident Response
Core Elements
(Simplified for PowerPoint)
1. Detect & Assess
2. Engage IRT/IRP & Broker
4. Contain & Eradicate
5. Recover & Lessons Learned
3. Engage legal & Forensics
Cybersecurity & Data Privacy Laws/Regulations
Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.
16
Case Study
17
https://www.insurancejournal.com/magazines/mag-features/2016/09/06/424905.htm
Group 1: Did P.F. Chang’s policy cover any part of the cyber insurance claim? If yes, why was only part of the claim covered?
Group 2: Assuming P.F. Chang’s policy included coverage for Regulatory Fines & Penalties, why was the PCI Assessment not covered?
Group 3: Based on the information in the article, are there cyber insurance policies that cover PCI Fines Assessments?
Group 4: Despite the fact that part of the claim was not covered, do you believe organizations like P.F. Chang’s should still use cyber insurance? Briefly explain your answer.
17
Cybersecurity Laws, Regulations & Contract Requirements
The current legal and regulatory environment is best described as a “patchwork.”
Organizations must be aware of multiple different requirements based on the type of data they handle, where they operate, their industry and who they do business with.
This adds cybersecurity complexities to many decisions organizations make and is a key driver for adding cyber insurance coverage.
18
18
Sarbanes-Oxley (SOX)
What is it? A 2002 United States federal law that established or expanded requirements designed to protect shareholders and the public from accounting errors and fraud as well as guide public disclosures. It addresses issues such as: Management of Electronic Records, Security Controls, Data Protection and Compliance.
Applies to: All Public Companies
19
Penalties for non-compliance: There are penalties for non-compliance and violations. These are monitored by the Securities and Exchange Commission (SEC)
More Information: https://www.law.cornell.edu/wex/sarbanes-oxley_act
19
Gramm-Leach-Bliley (GLBA)
What is it? United States law that went into effect in 1999 that was designed to protect personal financial information of consumers that is held by financial institutions.
Applies to: Financial institutions must comply and requires the protection of sensitive customer information that could be accessible online. In 2003 GLBA adopted the “Safeguards Rule” requiring proactive steps to secure customer information.
20
Penalties for non-compliance: Yes, and this is under the jurisdiction of the Federal Trade Commission (FTC)
More information: https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act
20
State Data Privacy & Cybersecurity Laws
21
What is it? The United States does not currently have a federally mandated data privacy and cybersecurity law. Instead, data privacy and cybersecurity is under the jurisdiction of each state. The result is a complex web of laws and regulations that apply based on where the individual resides, not necessarily where a data breach or cybersecurity incident occurs.
Applies to: All 50 states have Data Breach Notification Statutes; 27 have Information Security Standards
Penalties and Non-Compliance: Enforcement is handled by each State Attorney General
More Information: https://lewisbrisbois.com/privacy
21
Health Insurance Portability & Accountability Act (HIPAA)
22
What is it? A United States Law that went into effect in 1996 that was revised in: 2000 to add a ”Privacy Rule,” 2003 to add a “Security Rule,” and in 2003 (and subsequent years) to add Enforcement provisions.
Applies to: Any organization that is considered a “Covered Entity” or “Business Associate.” The law was initially designed to develop national standards for electronic healthcare transactions but was quickly revised to include privacy and security provisions. It applies to the transmission and security of “Protected Health Information.”
Penalties and Non-Compliance: Yes, this law is enforceable by the Office of Civil Rights (OCR). Fines and penalties are assessed based circumstances, but can be significant.
More Information: https://www.hhs.gov/hipaa/index.html
22
California Consumer Privacy Act (CCPA)
23
What is it? The California Consumer Privacy Act (CCPA) went into effect in 2018 and was the first law of its kind that significantly expanded the scope and scale of data privacy protections for individuals, requirements for organizations and types of data and information that is protected.
Applies to: For-profit businesses that do business in California that “1) have gross revenues over $25M, 2) Buy, receive or sell personal information of more than 50,000 California residents, or 3) derive 50% or more of their annual revenue from selling California resident’s personal information.”
Penalties and Non-Compliance: Yes, this is enforced by the Office of the Attorney General of California. Non-compliance and violations carry fines and penalties.
More Information: https://oag.ca.gov/privacy/ccpa
23
European Union General Data Protection Act (GDPR)
24
What is it? The European Union (EU) General Data Protection Act (GDPR) is a regulation that went info effect in 2016 and changed the way that governments regulate and manage data protection and privacy. Many of the provisions in GDPR were used by California as a model for CCPA. This includes provisions like “the right to be forgotten” and expanded protected information to include data such as IP address and cookie data (that’s why you have to accept cookies on websites now.)
Applies to: Any company that processes or stores personal information (as defined by GDPR) of EU Citizens, even if they do not have a presence in the EU.
Penalties and Non-Compliance: Yes, this is enforced by the Office of the Attorney General of California. Non-compliance and violations carry fines and penalties.
More Information: https://lewisbrisbois.com/privacy/EU
24
Insurance Data Security Standards
25
What is it? New state data privacy laws that specifically apply to Insurance Carriers, Agents, Brokers and other insurance support organizations. As of 2022, a total of 17 states have insurance data security laws in place.
Applies to: Licensed insurance entities like Insurance Carriers, Agents, Brokers as well as other insurance support organizations. Some of the more comprehensive versions of these laws (like Virginia) have strict standards for protecting data and systems (encryption, MFA, audit trail requirements, etc.) as well as compliance and assessment requirements.
Penalties and Non-Compliance: Yes, but varies state by state. This type of law is typically enforced by the state Insurance Commissioner
More Information: https://lewisbrisbois.com/privacy/US
25
Cybersecurity & Data Privacy Laws/Regulations
Take 10 Minutes
Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.
26
Contract Requirements & Contractually Assumed Liability
27
Data Privacy and Cybersecurity Laws are important, but they are not the only driver of data privacy and cybersecurity liability for organizations. Over and above any applicable data privacy and cybersecurity law that may apply to an organization, they also routinely agree to additional requirements for protecting systems and data via contract.
27
Payment Card Industry (PCI) Data Security Standard (DSS)
28
What is it? PCI DSS Compliance is an industry standard organizations agree to via a contract. PCI DSS is not a law or regulation. Requirements are based on the number and type of transactions per year.
Applies to: The best way to determine requirements for PCI DSS Compliance is to ask your bank, the major payment brand you use (Visa, MasterCard, AMEX, Discover, JCB) or the vendor that processes your payments.
Penalties and Non-Compliance: Yes, there are fines and penalties that can be significant depending on the volume and circumstances.
28
System and Organization Controls Type 2 (SOC 2)
29
What is it? SOC 2 is a report produced by an audit of an organizations controls related to security, integrity, availability and confidentially of data. The reports and guidelines are defined by the American Institute of Certified Public Accountants (AICPA). These types of assessments are often conducted by Accounting firms that conduct other types of financial audits.
Applies to: This type of audit is typically conducted by organizations that manage, store or process large amounts of data for their clients. It is an excellent way to show a potential
client or prospect that appropriate controls, processes and procedures are in place. In many instances, customers or clients will request this type of audit or results to vet potential service providers.
Penalties and Non-Compliance: No, this is voluntary and driven by business need
29
Cybersecurity Maturity Model Certification (CMMC)
30
What is it? CMMC was developed and implemented by the U.S. Department of Defense that went into effect in 2020. It is essentially the DoD’s method of implementing cybersecurity 3rd Party Risk Management.
Applies to: Organizations in the Defense Industrial Base doing business with the Department of Defense. Requirements for CMMC requirements are typically outlined in government contracts and passed down from prime to sub contractors. The drive behind this is the DoD’s desire to protect “Controlled Unclassified Information” in non-federal systems. Organizations must meet different levels of compliance based on contract requirements and some require a 3rd party assessor is required to validate compliance.
More Information: https://cyberab.org/
30
Assignment 2 Q&A
Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.
31
32
Assignment 2 Walkthrough
Company Groupings – Healthcare, Legal, Manufacturing & Non-Profit
Why are we spending time going over this? – This assignment is CRITICAL to your success in this course. All subsequent assignments will build off of this exercise. It is essential that everyone completes this assignment.
What am I looking for – See guidance document
Organization Profile Walkthrough
Cyber Insurance Application Walkthrough
Questions & Discussion
33
image1.png
image2.png
image5.png
image7.png
image8.png
image9.png
image10.png
image11.png
image12.png
image13.png
image14.jpeg
image15.png
image16.svg
.MsftOfcResponsive_Fill_ff0000 { fill:#FF0000; }
image17.png
image18.svg
.MsftOfcResponsive_Fill_7030a0 { fill:#7030A0; }
image19.png
image20.svg
.MsftOfcThm_Text2_Fill_v2 { fill:#0057B8; }
image21.png
image29.png
image30.svg
image31.png
image32.svg
image33.png
image34.svg
image35.png
image36.svg
image37.png
image38.svg
.MsftOfcThm_Accent1_lumMod_75_Fill { fill:#003C6D; }
image39.png
image40.svg
.MsftOfcThm_Background1_lumMod_50_Fill { fill:#7F7F7F; }
image41.png
image42.svg
image22.png
image23.png
image24.png
image25.png
image26.png
image27.png
image28.svg
image46.svg
.MsftOfcThm_Accent2_Fill { fill:#92D050; }
image47.png
image43.png
image44.svg
image45.png
image48.png
image49.png
image50.svg
image51.png
image52.svg
.MsftOfcResponsive_Fill_414042 { fill:#414042; }
image53.png
image61.svg
.MsftOfcResponsive_Fill_7030a0 { fill:#7030A0; }
image54.png
image55.svg
.MsftOfcResponsive_Fill_7030a0 { fill:#7030A0; }
image56.png
image57.svg
.MsftOfcResponsive_Fill_7030a0 { fill:#7030A0; }
image58.png
image59.svg
.MsftOfcResponsive_Fill_7030a0 { fill:#7030A0; }