Cyber security insurance

profileBfh
3.CyberControls-CyberLegal_RegulatoryLandscape-Fall22.pptx

Cyber Controls/Cyber Legal & Regulatory Landscape

Session 3

September 15, 2022

Agenda

1 Schedule Updates
2 Cyber Insurability Controls Review
3 Cybersecurity Laws & Regulations
4 Cybersecurity Contractual Requirements
6 Assignment 2 Discussion

2

Cyber Insurability Controls

Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.

3

Use Cybersecurity Frameworks as Your Guide

4

4

Why does this matter?

Cyber insurance requirements are becoming increasingly technical. Organizations that are not prepared may not be able to obtain or maintain cyber insurance coverage.

5

Asset and Data Inventory

6

IT Assets

Servers

Endpoints

Mobile Devices

Employee Devices

Wireless Access Points

Networked Devices

IoT Devices

Software Assets

Local Databases

Software Programs

Cloud Applications

Software you use to run the organization (CRM, ERP, AMS, etc.)

Email

Websites and Web Apps

Accounting & Payroll

Communication & collaboration

Unapproved software/SaaS

Data Assets

Customer Data

Intellectual Property

Financial Account Info

Confidential Employee Data

Protected Healthcare Information (PHI)

Personally Identifiable Information (PII)

Marketing Communication Lists

Donor Information

Payment Card Information (PCI)

Email

Passwords

Biometric Data

6

Attack Surface & Vulnerability Management

7

Defenders need to succeed 100% of the time

Attackers only need to succeed once

Effective threat management programs identify and remediate vulnerabilities and exposures before malicious actors get a chance. Some common techniques include:

External attack surface scanning – what is visible from the outside

Vulnerability & patch management – quickly (within 30 days) identifying and patching known vulnerabilities

Penetration testing – Internal/external testing to simulate tools, tactics and techniques used by cyber criminals and malicious actors

7

Backup and Recovery

Cyber resilience requires the ability to recover quickly and effectively when something goes wrong. Secure, tested and immutable backups are critical in today's environment.

8

https://docs.microsoft.com/en-us/azure/backup/backup-overview

8

Encryption

9

Public Internet

Enterprise Resource Planning System

Email Server

File Server

Shared Resources

Virtual Data Center

Next Gen Firewall

Encrypt Data on Mobil Devices

Virtual Private Network to securely connect to on premises assets. Must also include MFA

Encrypt data in the cloud & web applications

Encrypt Data in Transit

Encrypt data at rest

9

10

Identity & Access Management

Protect Identities & Access to Systems

Multi-Factor Authentication (MFA) is the concept of requiring more than one simultaneous means of authentication to provide access. This usually comprises something you have and something you know, or something you know and something you are.

Single sign-on (SSO) is the concept of having a single location or portal for sign on, allowing user access to multiple applications (websites, applications and so forth). Without SSO, each site or application requires individual login sessions.

Password management – or credential management to be more accurate – is the secure storage and management of usernames and passwords. The method can be as simple as a stored data file with linear encrypted data or an advanced policy-enabled system with complex attributes and algorithms.

Privileged access credentials are those that provide elevated access and permissions across systems, applications and accounts. After an account is accessed, an intruder can move laterally, often undetected, to exfiltrate data. This is common in many of today’s ransomware attacks.

One of today’s most important security tools - that is increasingly important for cyber insurability - is privileged access management (PAM).

PAM It’s based on the concept of least privilege, which means users and accounts are provided only with the privileges needed for the task at hand and for the time required to complete the task.

Privilege Access Management

11

Session Management

Password Vault

Endpoint Management

11

Email Security

12

Phishing

Malicious Domains

Downloads

Malicious Links & Sites

Attachments

Unencrypted Data

Data Leakage

User Behavior

Email Spoofing

Email is # 2 action vector in breaches in 2022 Verizon DBIR

12

Cybersecurity Awareness Training

Technology can’t defend against our blind spots and mistakes. Humans are especially good at being tricked

13

Training will never be 100% effective (or even close) but we need to know what to watch out for

Awareness is important but training should model and shape behavior

Controls and process should reinforce training

13

Endpoint Protections

14

The number of tablets, laptops, mobile phones and IoT devices has exploded as more organizations than ever before have moved to a virtual workforce. This expands the attack surface cyber criminals can attack, and makes it difficult to defend. Examples of endpoint security include:

Antivirus (AV) – Essential baseline signature-based endpoint protection that protects devices (that can support this type of software) from known vulnerabilities and malware. Is not effective for unknown vulnerabilities or attacks that do not involve malware or hacking.

Endpoint Detection Response (EDR) – Supplements traditional signature-based protections by monitoring and detecting malicious activities and behaviors that indicate a possible compromise. This technology also allows for automated intervention to prevent lateral movement and proliferation to other devices.

Managed Detection Response (MDR) – Enhanced version of EDR that is delivered as a service to organizations that do not have in house expertise to act on alerts and remediate malicious activity or compromises.

14

Incident Response Planning

15

Cyber Insurance Alignment (More to come on this)

Insurance provides access pre-approved & vetted legal & forensics specialists experienced with cyber incident response.

Many policies will provide access to cyber incident handlers to help contain the spread of malware or an active event. This step may come earlier or in parallel with others.

Cyber insurance is essential to response and recovery. Some key elements include recovering data, restoring systems, reimbursement for lost income during disruption, minimizing reputation damage after an event as well as others.

15

Cyber Incident Response

Core Elements

(Simplified for PowerPoint)

1. Detect & Assess

2. Engage IRT/IRP & Broker

4. Contain & Eradicate

5. Recover & Lessons Learned

3. Engage legal & Forensics

Cybersecurity & Data Privacy Laws/Regulations

Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.

16

Case Study

17

https://www.insurancejournal.com/magazines/mag-features/2016/09/06/424905.htm

Group 1: Did P.F. Chang’s policy cover any part of the cyber insurance claim? If yes, why was only part of the claim covered?

Group 2: Assuming P.F. Chang’s policy included coverage for Regulatory Fines & Penalties, why was the PCI Assessment not covered?

Group 3: Based on the information in the article, are there cyber insurance policies that cover PCI Fines Assessments?

Group 4: Despite the fact that part of the claim was not covered, do you believe organizations like P.F. Chang’s should still use cyber insurance? Briefly explain your answer.

17

Cybersecurity Laws, Regulations & Contract Requirements

The current legal and regulatory environment is best described as a “patchwork.”

Organizations must be aware of multiple different requirements based on the type of data they handle, where they operate, their industry and who they do business with.

This adds cybersecurity complexities to many decisions organizations make and is a key driver for adding cyber insurance coverage.

18

18

Sarbanes-Oxley (SOX)

What is it? A 2002 United States federal law that established or expanded requirements designed to protect shareholders and the public from accounting errors and fraud as well as guide public disclosures. It addresses issues such as: Management of Electronic Records, Security Controls, Data Protection and Compliance.

Applies to: All Public Companies

19

Penalties for non-compliance: There are penalties for non-compliance and violations. These are monitored by the Securities and Exchange Commission (SEC)

More Information: https://www.law.cornell.edu/wex/sarbanes-oxley_act

19

Gramm-Leach-Bliley (GLBA)

What is it? United States law that went into effect in 1999 that was designed to protect personal financial information of consumers that is held by financial institutions.

Applies to: Financial institutions must comply and requires the protection of sensitive customer information that could be accessible online. In 2003 GLBA adopted the “Safeguards Rule” requiring proactive steps to secure customer information.

20

Penalties for non-compliance: Yes, and this is under the jurisdiction of the Federal Trade Commission (FTC)

More information: https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act

20

State Data Privacy & Cybersecurity Laws

21

What is it? The United States does not currently have a federally mandated data privacy and cybersecurity law. Instead, data privacy and cybersecurity is under the jurisdiction of each state. The result is a complex web of laws and regulations that apply based on where the individual resides, not necessarily where a data breach or cybersecurity incident occurs.

Applies to: All 50 states have Data Breach Notification Statutes; 27 have Information Security Standards

Penalties and Non-Compliance: Enforcement is handled by each State Attorney General

More Information: https://lewisbrisbois.com/privacy

21

Health Insurance Portability & Accountability Act (HIPAA)

22

What is it? A United States Law that went into effect in 1996 that was revised in: 2000 to add a ”Privacy Rule,” 2003 to add a “Security Rule,” and in 2003 (and subsequent years) to add Enforcement provisions.

Applies to: Any organization that is considered a “Covered Entity” or “Business Associate.” The law was initially designed to develop national standards for electronic healthcare transactions but was quickly revised to include privacy and security provisions. It applies to the transmission and security of “Protected Health Information.”

Penalties and Non-Compliance: Yes, this law is enforceable by the Office of Civil Rights (OCR). Fines and penalties are assessed based circumstances, but can be significant.

More Information: https://www.hhs.gov/hipaa/index.html

22

California Consumer Privacy Act (CCPA)

23

What is it? The California Consumer Privacy Act (CCPA) went into effect in 2018 and was the first law of its kind that significantly expanded the scope and scale of data privacy protections for individuals, requirements for organizations and types of data and information that is protected.

Applies to: For-profit businesses that do business in California that “1) have gross revenues over $25M, 2) Buy, receive or sell personal information of more than 50,000 California residents, or 3) derive 50% or more of their annual revenue from selling California resident’s personal information.”

Penalties and Non-Compliance: Yes, this is enforced by the Office of the Attorney General of California. Non-compliance and violations carry fines and penalties.

More Information: https://oag.ca.gov/privacy/ccpa

23

European Union General Data Protection Act (GDPR)

24

What is it? The European Union (EU) General Data Protection Act (GDPR) is a regulation that went info effect in 2016 and changed the way that governments regulate and manage data protection and privacy. Many of the provisions in GDPR were used by California as a model for CCPA. This includes provisions like “the right to be forgotten” and expanded protected information to include data such as IP address and cookie data (that’s why you have to accept cookies on websites now.)

Applies to: Any company that processes or stores personal information (as defined by GDPR) of EU Citizens, even if they do not have a presence in the EU.

Penalties and Non-Compliance: Yes, this is enforced by the Office of the Attorney General of California. Non-compliance and violations carry fines and penalties.

More Information: https://lewisbrisbois.com/privacy/EU

24

Insurance Data Security Standards

25

What is it? New state data privacy laws that specifically apply to Insurance Carriers, Agents, Brokers and other insurance support organizations. As of 2022, a total of 17 states have insurance data security laws in place.

Applies to: Licensed insurance entities like Insurance Carriers, Agents, Brokers as well as other insurance support organizations. Some of the more comprehensive versions of these laws (like Virginia) have strict standards for protecting data and systems (encryption, MFA, audit trail requirements, etc.) as well as compliance and assessment requirements.

Penalties and Non-Compliance: Yes, but varies state by state. This type of law is typically enforced by the state Insurance Commissioner

More Information: https://lewisbrisbois.com/privacy/US

25

Cybersecurity & Data Privacy Laws/Regulations

Take 10 Minutes

Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.

26

Contract Requirements & Contractually Assumed Liability

27

Data Privacy and Cybersecurity Laws are important, but they are not the only driver of data privacy and cybersecurity liability for organizations. Over and above any applicable data privacy and cybersecurity law that may apply to an organization, they also routinely agree to additional requirements for protecting systems and data via contract.

27

Payment Card Industry (PCI) Data Security Standard (DSS)

28

What is it? PCI DSS Compliance is an industry standard organizations agree to via a contract. PCI DSS is not a law or regulation. Requirements are based on the number and type of transactions per year.

 

Applies to: The best way to determine requirements for PCI DSS Compliance is to ask your bank, the major payment brand you use (Visa, MasterCard, AMEX, Discover, JCB) or the vendor that processes your payments.

  Penalties and Non-Compliance: Yes, there are fines and penalties that can be significant depending on the volume and circumstances.

28

System and Organization Controls Type 2 (SOC 2)

29

What is it? SOC 2 is a report produced by an audit of an organizations controls related to security, integrity, availability and confidentially of data. The reports and guidelines are defined by the American Institute of Certified Public Accountants (AICPA). These types of assessments are often conducted by Accounting firms that conduct other types of financial audits.

Applies to: This type of audit is typically conducted by organizations that manage, store or process large amounts of data for their clients. It is an excellent way to show a potential

client or prospect that appropriate controls, processes and procedures are in place. In many instances, customers or clients will request this type of audit or results to vet potential service providers.

  Penalties and Non-Compliance: No, this is voluntary and driven by business need

29

Cybersecurity Maturity Model Certification (CMMC)

30

What is it? CMMC was developed and implemented by the U.S. Department of Defense that went into effect in 2020. It is essentially the DoD’s method of implementing cybersecurity 3rd Party Risk Management.

Applies to: Organizations in the Defense Industrial Base doing business with the Department of Defense. Requirements for CMMC requirements are typically outlined in government contracts and passed down from prime to sub contractors. The drive behind this is the DoD’s desire to protect “Controlled Unclassified Information” in non-federal systems. Organizations must meet different levels of compliance based on contract requirements and some require a 3rd party assessor is required to validate compliance.

More Information: https://cyberab.org/

30

Assignment 2 Q&A

Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.

31

32

Assignment 2 Walkthrough

Company Groupings – Healthcare, Legal, Manufacturing & Non-Profit

Why are we spending time going over this? – This assignment is CRITICAL to your success in this course. All subsequent assignments will build off of this exercise. It is essential that everyone completes this assignment.

What am I looking for – See guidance document

Organization Profile Walkthrough

Cyber Insurance Application Walkthrough

Questions & Discussion

33

image1.png

image2.png

image5.png

image7.png

image8.png

image9.png

image10.png

image11.png

image12.png

image13.png

image14.jpeg

image15.png

image16.svg

.MsftOfcResponsive_Fill_ff0000 { fill:#FF0000; }

image17.png

image18.svg

.MsftOfcResponsive_Fill_7030a0 { fill:#7030A0; }

image19.png

image20.svg

.MsftOfcThm_Text2_Fill_v2 { fill:#0057B8; }

image21.png

image29.png

image30.svg

image31.png

image32.svg

image33.png

image34.svg

image35.png

image36.svg

image37.png

image38.svg

.MsftOfcThm_Accent1_lumMod_75_Fill { fill:#003C6D; }

image39.png

image40.svg

.MsftOfcThm_Background1_lumMod_50_Fill { fill:#7F7F7F; }

image41.png

image42.svg

image22.png

image23.png

image24.png

image25.png

image26.png

image27.png

image28.svg

image46.svg

.MsftOfcThm_Accent2_Fill { fill:#92D050; }

image47.png

image43.png

image44.svg

image45.png

image48.png

image49.png

image50.svg

image51.png

image52.svg

.MsftOfcResponsive_Fill_414042 { fill:#414042; }

image53.png

image61.svg

.MsftOfcResponsive_Fill_7030a0 { fill:#7030A0; }

image54.png

image55.svg

.MsftOfcResponsive_Fill_7030a0 { fill:#7030A0; }

image56.png

image57.svg

.MsftOfcResponsive_Fill_7030a0 { fill:#7030A0; }

image58.png

image59.svg

.MsftOfcResponsive_Fill_7030a0 { fill:#7030A0; }

image60.png

image62.png

image63.png

image64.jpg

image65.jpg

image66.png

image67.png

image68.png

image69.png

image70.png

image4.png

image71.jpg

image72.png

image73.png

image74.png

image75.png