Byย Tony Hopkins, CPCU, CIC, CRM
Lessons from Marriottโs Starwood Database Hackย
In late November, another major brand, Marriott, made headlines for a recent cyber-attack. According toย Business Insurance, the hackers accessed credit card data for some 327 million customerย records containing personal information which may have includedย passport details, birthdates, addresses, phone numbers, and email addresses.ย
Whileย Fortune 500ย companies likeย Marriott garner headlines, according toย Advisenย and theย Insurance Information Instituteโsย Cyber Risk Report, the reality is that cyber-related incidents have been increasing since 2010. Theย Ponemonย Institute estimated 55 percent of businesses with less than 250 employees will experience a cyberattack.ย The aftermath of a breach costsย an average $1.8 million in damage, theft,ย and disruption of normal operations.ย
There are always good lessonsย to learnย from these breaches:ย
-
Reputational risk is an ever-increasing exposure. The public relations andย restoration ofย consumer trust will be an upward battle.ย
-
Breaches translate into hard dollars,ย not just incurred costs. While mitigation will be costly for Marriott, likely hitting the hundreds of millions of dollars, the plunge in their stock and value will hurt and have aย long-lasting effect.ย
-
Sizeย doesnโtย matter.ย Whether you are aย large businessย with endless resourcesย orย aย small businessesย with limited resources, both areย at risk.ย
-
Never let your guard down.ย Hackers can lay dormant in the system undetected for a long time, sometimes years.ย
-
Be aware of major inflection points in your business such asย anย M&A.ย During these deals, a lot of data and informationย is passedย between businesses making them especially vulnerable to a cybercriminal that has been stalking your business.ย
-
The buck stops with you.ย Itย doesnโtย matter theย safeguardsย you put into place, you and your business are ultimately responsible for any data accessed from any of your systems โ social, website, databases, etc.ย
So what can you do to protect your business?ย
First, make sure review and ensureย correctย insuranceย coverage for aย cyber-incident. Often, organizations incorrectly believeย commercial property and commercial theft policies will provide coverage for loss of data, which is considered intangible. Intangible property values often far outweigh tangible property.ย
Cyber liability insuranceย is specifically designedย to cover cyber-related losses such as:ย
-
Breach costsย โ Costs incurred as a response to a breach.ย
-
Media liabilityย โ Publication ofย falsehoodsย or misuse of trademark or copyright inflicting damage connected to your business.ย
-
Cyber business interruptionย โ Interruption or degradation of one of your systemsย becauseย of a third-party blocking access.ย ย
-
Hacker damage eventย –ย Damaging, destroying, altering, corrupting,ย stealingย or misusingย one of your systems or data.ย
-
Cyber extortion eventย –ย Your receipt, directly or indirectly, of an illegal threat from a person or entity who is not an insured threatening to damage, destroy, or corruptย one of your systemsย for their own benefit as a condition of not carrying out this threat.ย
-
CyberCrimeย –ย money and/or securities transferred, paid or delivered from your transfer account directly resulting from a fraudulent instruction.ย
Cybersecurityย is achievableย ifย anย organizationโsย leadersย not onlyย recognize, but also acknowledge the risk, makingย it a priority, and implementingย the right approaches when the unexpected happens.
Material posted on this website is for informational purposes only and does not constitute a legal opinion or medical advice. Contact your legal representative or medical professional for information specific to your legal or medical needs.


