/ BLOG

“GONE PHISHING!” – The Real Liability of the Virtual World

May 31, 2017 · 5 minutes to read

Phishing is a criminal practice that exploits individuals via fraudulent electronic communication and interaction. Together with spear phishing, clone phishing and whaling, the Internet can be a scamming minefield.  If you don’t already, it might be a good time to pay attention to the security breaches you hear about in the news, like Gawker.com in 2010, Sony, Epsilon and others in 2011, and most recently Zappos in early 2012.

Generally speaking, social engineering is putting bait on a virtual fishing pole, casting it out into the vast ocean of the Internet, and waiting to see who might naively take a bite. After being hooked by the apparently trustworthy communication, the unknowing target then proceeds to give up confidential information (social security number, credit card number, etc.) – anything that can help perpetrate identity (ID)  theft or credit card fraud.  In other cases, the scammer can even get cash from his hooked ‘phish’ by sending emails from a hijacked email account posing as a friend in need.  It’s been estimated that scammers can make $500 a day from their victims, if not more.

Businesses of all sizes are subject to security breaches. It can be because their networks were compromised, an employee lost a laptop or perhaps there was an accidental disclosure of confidential information (like posting a spreadsheet of client data to a public website). When this type of breach happens, and it does often, the business can be liable for a host of breach-related costs. To mitigate the consequences, the negligent company must bear the responsibility to:

  • Notify customers their data has been disclosed,
  • Incur information technology (IT) forensics costs to investigate what caused the breach,
  • Be subject to privacy regulatory activity, and/or
  • Third-party liability from those who were caused financial harm from the breach.

The liability does not stop at the business that lost customer data; it extends to that company’s subcontractors, independent contractors and vendors who may be the linchpin in the breach.  When contracting with business clients, a subcontractor may take on its client’s highly sensitive customer information and therefore is also responsibile for maintaining its security.

Let’s consider what happened to Epsilon in April 2011.  Epsilon is one of the largest email and online marketing firms, whose customers includes seven of the Fortune 10 amongst its 2,500 clients.  Their breach exposed the names and email addresses of massive customers like Best Buy, Citibank, and Walgreens.  While it may not seem like highly prized data in and of itself, names and email addresses are quality bait and useful in constructing a successful scam.  Receiving a personalized message from a company that you already have an account with can be convincing and leaves many people susceptible to ID theft.

Whether you’re a big vendor like Epsilon, who performs email marketing services for huge Fortune 500 clients or an independent contractor working on your personal laptop with your client’s confidential data, you can become liable for a security breach of your customer’s (or your customer’s customers’) data if you or your equipment is somehow the weak link.  The general consensus from the privacy/security community is not whether someone will be hacked, but when.  After that happens, it’s about what was done to mitigate the loss.  In a recent study entitled “Empirical Analysis of Data Breach Litigation,”[1] law researchers at Carnegie Mellon and Temple University found that a company that offered credit monitoring after a breach was six times less likely to get sued.  If it’s not preventable, then why not at least transfer and minimize the risk and cost.  Having a strong service contract that protects your position in the event of a security breach is one way to start, along with maintaining industry standard privacy and security controls.  One cost-effective way to transfer the risk of this liability is through Cyber Insurance.

Cyber Insurance combines Technology Professional Liability (a.k.a. Errors & Omissions), Miscellaneous Professional Liability, Privacy Liability and Network Security Liability into one omnibus coverage that protects a company against today’s ever growing need to safeguard electronic information.  The coverage can help cover costs like Information Technology forensics, third-party liability, and credit monitoring.  The nuance of whether you’re subject to a third-party liability claim or first-party privacy cost claim can be avoided, when you have a policy that covers you from all angles.

One obvious lesson is to be very careful with all communications and actively protect your own confidential information and passwords.  If you’re not careful on a personal level, you may have your account hijacked and have to deal with your email’s support team who may, or may not, be able to retrieve your emails from the last five years.  Not to mention the scorn of your friends and family who may have given up money or other confidential data to someone perpetrating a scam from Nigeria.  For a business, however, it’s critical to not be known as the company that let down its guard and made its customer’s data vulnerable to the scores of hackers, scammers, and organized e-crime syndicates that are on the prowl.

As you explore and utilize the wonderful World Wide Web, enjoy surfing, but don’t get hooked!

BizInsure Guest Blogger: Natalie Chin


[1] Romanosky, Sasha, Hoffman, David A. and Acquisti, Alessandro, “Empirical Analysis of Data Breach Litigation” (February 19, 2012). Available at SSRN: http://ssrn.com/abstract=1986461 or http://dx.doi.org/10.2139/ssrn.1986461

Talk to us

Today’s BizInsure offerings are just the beginning. Please take the time to tell us what you think, offer advice, ask questions, give compliments, or make a request…customer feedback defines us. We’re listening. Click here to contact us.

Let's find

The coverage you need for your business

Professional Liability Insurance

Professional Liability Insurance

Get a quote

General Liability Insurance

General Liability Insurance

Get a quote

Business Owner’s Policy (BOP)

Business Owner’s Policy (BOP)

Get a quote

Workers Compensation Insurance

Workers Compensation Insurance

Get a quote

Let's find

The coverage you need for your business

Professional Liability Insurance

Professional Liability Insurance

Get a quote

General Liability Insurance

General Liability Insurance

Get a quote

Business Owner’s Policy (BOP)

Business Owner’s Policy (BOP)

Get a quote

Workers Compensation Insurance

Workers Compensation Insurance

Get a quote

Great customer service. Quick and efficient. Amy rocked! I highly recommend using BizInsure for your insurance needs.
Prompt and efficient with the delivery of information. Excellent customer service. Easy online navigation.
Great Customer Service and easy renewal process
Extremely polite, very information and able to answer all questions, quick with issuing the policy and half the price of most insurers. Thank you for making it pain-free.
This system is short and sweet, thanks
Patrice was very professional and prompt. I definitely recommend this company.
Process was quit and easy.
Just getting started... excited!
Thank you Jen for assisting me with my insurance needs. Very professional! It was a pleasure chatting with you too!
So very easy. What a great service.
Cherice Williams is the best and very easy to talk to 😊
The process was easy to maneuver.
Good service
Jennifer was amazing, informative and guided me to exactly what was needed to cover my business. Highly recommend.
First of all the agent I spoke with was very kind and helpful. Her name is Andrea. I appreciate the easy and quick online application to purchase my insurance.
I worked with Amy on getting professional insurance and she was fantastic! Some of the best customer service I’ve experienced in a long time. She was diligent and supportive, but never pushy.
The process was smooth and everyone answered questions along the way as needed. Andrea’s follow-up was excellent. Thank you!
Jen was awesome
I have been with Bizinsure for many years and they are always up to date with the latest policy information and the most competitive rates!
My interaction with the agent was very pleasant and she answered my questions. She also responded very quickly when I had questions.
BizInsure understood exactly what I needed and provided an affordable quote. The process was easy and I'm glad I used their services!
Our company has been with BizInsure since 2020. we are very happy with the service they provide.
Just started but the process was easy. Agent was kind and the price was great.I will see how the service is going forward, but starting was very easy and inexpensive.
Customer service was great! I got the help I needed!
Super A rated and affordable coverage.
Dina and Ashleih were so helpful! They made our package work for us. Grateful for the quick service.
I want to thank you for making my insurance search so simple and efficient. I also appreciated the easy communication options, which helped me make the right purchase decision. I'm really grateful for your company's support!.
Jenifer S. was the agent that I worked withi to secure general liability insurance. She was very knowledgeable, helpful and worked diligently to ensure that.my coverage needs were met and for a great price. I would definitely recommend her to others as she was a pleasure to work with.
The agent was very knowledgeable and was very quick in handling my request.
Good customer service
js_loader
Google Rating
4.7
Based on 385 reviews
×
js_loader





    This will close in 0 seconds