Tuesday, March 10, 2009

Cyber Terrorism

I recently had the pleasure of speaking with Jonathan Bernstein, President of Bernstein Crisis Management. Bernstein Crisis Management, Inc. is a national consultancy providing 24/7 access to its president, Jonathan Bernstein, and a network of carefully screened and highly experienced crisis management experts who are on call nationwide and in many markets overseas. Bernstein Crisis Management engages in the full spectrum of crisis management services: crisis prevention, response, planning, training and simulations. The business was created and has been operated since January 1994 on the premise that its clients' executive leadership wants direct assistance from senior-level crisis management professionals.

On the Bernstein Crisis Management website, there are numerous great articles dealing with a variety of issues related to all the realms of identity theft. These articles include crisis management and public relations, dealing with the blogospheres, and most importantly crisis prevention. The article that I am reprinting specifically deals with Cyber Terrorism. I feel that this is an issue that at first only affected the large, financial institutions. But now, as the economy crumbles around our feet, more and more cyber thieves are going to try out cyber terrorism on the middle markets and maybe even the small business of America. To protect your company, you need to speak with someone like Jonathan Bernstein, and you need to get an Internet Liability Insurance policy that covers you for Cyber Terrorism. Cyber Terrorism insurance is found in many, but not all, internet liability insurance policies. But, most companies do not have internet liability insurance policies, and they are unprotected and face serious consequences to their company, their reputation, and their clients.

This article was originally title, "ISP Thwarts Cyber-Terrorists: LinkLINE Communications Turns Crisis Into PR Success":

Editor's Note: this is another of those rare occasions when a crisis has been very public and the client is justifiably proud of its response and willing to share the results with others. As I've told linkLINE's management, their willingness to take some direction on this challenging situation reflects great credit on them; I assured them that I've known other organizations not nearly so willing to "do the right thing."

The Crisis

"We think that someone calling himself 'Mr. Zilterio' may have accessed our customer records, to include credit card numbers. He's threatening to reveal that information to our customers and the press if we don't pay him a large amount of money."

That was the initial call I received from Marc Benzakein, one of the founders of linkLINE Communications (www.linkline.com), an expanding, relatively small (15,000 subscriber) but profitable Internet service provider based in Mira Loma, California (note: in their business, "profitable" is rare).

In that phone call, and a subsequent meeting with linkLINE's management/crisis response team, I learned that:

  • According to federal authorities and information available to anyone who does a search for "Zilterio" on the Internet, the same individual may have extorted as much as $4 billion from other organizations who wanted to sweep the situation under the rug for fear of losing business.
  • linkLINE, with law enforcement direction, had been stringing Zilterio along for a little while identifying how he got past their security. In the process, they traced the bank account to which Zilterio wanted money wired through Russia (where he said he was from) to Yemen, a known hotbed of terrorism.
  • The ISP felt strongly that it was ethically and morally wrong to give in to what could clearly be construed as "cyber-terrorism."
  • linkLINE had taken the steps necessary to ensure that the security hole which Zilterio may have exploited was plugged.
  • A significant loss of customers could be devastating to linkLINE because of its still-small size.

Crisis Response Team Meets

As a crisis response team, we agreed that:

  • linkLINE's customers needed to be notified of the threat before Zilterio communicated with them. This meant that the entire "response package" needed to be in place between our Thursday afternoon meeting and the following Monday evening. We all wanted to move even more quickly, but double-checking some security preparations precluded any more haste. The team member in touch with Zilterio felt he could stall him as long as necessary.
  • The best approach, very much in keeping with linkLINE's operating philosophy, was to express compassion for the concern this might cause customers, provide them with information they would need as a consequence of the situation, while also calling for them to unite with linkLINE in combating cyber-terrorism.
  • Close coordination would need to be made with the security offices for the four major credit card companies so that (a) linkLINE customers would have the least-possible work to do regarding the possible exposure of their credit card numbers and (b) that linkLINE's relationships with the credit card companies remained sound.

Pre-Announcement Activities

During three intense days of preparation:

  • linkLINE management contacted the four credit card companies, who were very appreciative of linkLINE's proactive response, agreed to put a special watch on linkLINE customer credit card numbers to see if they were fraudulently abused, and assured linkLINE that customers would not be held liable for any such fraud.
  • A Customer Alert letter was drafted for release late in the evening of Monday, March 18. That letter has been posted for "Crisis Manager" readers at:: http://www.piersystem.com/clients/bernstein/linkline1.txt
  • A press release was drafted for distribution in the early morning of March 19. That release, as an MS-Word doc, is temporarily archived at: http://www.piersystem.com/clients/bernstein/Linkline2.doc
  • A Customer Q&A was drafted in preparation for posting on linkLINE's website. That Q&A can still be found at: http://www.linkline.com/corp/securityfaq.asp
  • A special Customer Service Response Guide was created and customer service reps trained on its use.
  • linkLINE's crisis response team identified other key stakeholders, besides customers, who might need to be called or contacted when the news was released, and prepared to make those communications.
  • Marc Benzakein was trained to be the primary spokesperson on the situation, with another member of the team as backup spokesperson.

The Announcement and Results

Zilterio did not act during the preparation period, and linkLINE was able to launch its crisis communications campaign.

  • In the late evening of March 18 and early morning of March 19, respectively, the Customer Alert went out by email and the press release by PR Newswire (California circuit only, as 95% of their customers were in-state, and knowing that even the California circuit also goes to Internet news sites and certain other key media).
  • While customer call volume did go up, it was not overwhelming; linkLINE had contingency plans for what to do if it backed up, but the Customer Alert, combined with the Customer Q&A, apparently satisfied the vast majority of customers.
  • Most of the calls and emails that DID come in were highly complimentary of linkLINE's response. Some examples:
  • "In today's world of competition and LOVE of money very few companies are up front when they have a problem that could affect their business. YOU GUYS ARE THE EXCEPTION. Thanks for letting us all know the truth. Because of people like you I feel much safer on the NET. THANKS AGAIN."
  • "I would like to commend you on your handling of the Zilterio blackmail incident. Prompt and full disclosure through email and your website is the exact way to go. This kind of professionalism makes me happy to continue with linkLINE as my ISP. Nothing is 100% secure; what separates the pros from the rest is the response to a security breach. Your response measured up in every respect."
  • There were some people who were initially very disgruntled, but linkLINE execs did a great job of communicating in a caring and informative manner that made customers more comfortable.
  • A few credit cards were voluntarily (by customers) or involuntarily (by banks, when they were also ATM cards) suspended, but even those customers were understanding. And as part of their preparation, linkLINE had made it easy to switch to another credit card (securely) or use another method of payment.

Today, two weeks later, linkLINE had no net loss in customers and has continued to enjoy its usual level of growth.

Editor's Note: Unfortunately, Zilterio hasn't stopped doing his thing -- there's a Dow Jones story out today about his attack on another company. Any organization which maintains confidential information on its Internet-accessible servers is vulnerable and would do well to (a) assess its level of vulnerability and (b) be prepared to respond if and when a security breach occurs. Not merely operationally, but in terms of legally appropriate public relations.


 

 

Friday, February 27, 2009

Time to Let Citi and AIG go Down

I'm going to preface this article by telling you that I am not an economist, nor do I fully understand the economic reasons behind our government propping up Citi Group and AIG. However, I think the world and the American people are finally ready for the fall of Citi and AIG. When AIG was first bailed out, it followed weeks of generally surprising news of collapses of Bear Sterns and Lehman Brothers, and basically the collapses of Wachovia and Washington Mutual. At that time, if two of the largest financial institutions in the world collapsed, there would have probably been near Armageddon panic.

But I think that the American people are ready for these Baby Hueys to collapse. How many people really like using Citigroup or AIG? As an insurance agent, I can speak from personal experience that I didn't like working with Travelers Insurance when they were part of Citi, and for the most part, I avoid working with AIG, with a few exceptions. The big problem with AIG is that they insure things that no one else does, or seems to want to. However, the insurance business has been profitable for AIG, so I cannot imagine that someone like a Berkshire Hathaway Company wouldn't come in, and either buy the AIG book, or even better, offer an alternative in AIG's marketplaces.

A lot of people don't really understand this part of the AIG issue. AIG insures a lot of higher risk endeavors. I can mainly only speak to Florida insurance, but here they are one of the best carriers still writing high valued homes with hurricane insurance coverage all over the State. They are also my only option to write USL&H (United States Longshore and Harbor Workers Act), as well the only market I can get to write high risk workers compensation including 24-hour emergency restoration services and Aviation industry. They are also one of the main players in a not very competitive aviation insurance industry.

That all being the case, I still think it is finally time we said good riddance to AIG and CitiGroup. No more bailouts for bad companies, the American people are ready, we know things suck now and we expect them to get worse. Let's speed it up, the faster these invalid companies crash the faster we can recover. So next time they need money, we need to count to ten, and rip off the band-aid.

Wednesday, December 3, 2008

Insurance for Healthcare Regulations including HIPAA for Doctors, Healthcare Providers and other Medical Facilities

    Healthcare providers such as physicians face many risks and challenges practicing in the United States today. A recent CNN survey of primary care physicians said that nearly half would seriously consider getting out of the medical profession in the next three years. They constantly have to keep up to date on the changes in their profession. Physicians also need to constantly monitor their relationships with the Healthcare Insurance providers. They have to pay close attention to State and National legislatures to see what new regulations they have to comply with. For instance, Massachusetts recently passed a new statute regulating all companies that collect and store any private information of its citizens.

    The United States today is as litigious as ever, and lawyers and doctors are still not the best of friends. As new laws get passed by the legislatures, mostly lawyers, new risks are presented to physicians. Privacy is one of the biggest issues in the media. The healthcare industry is far from immune from this issue. In fact there has been numerous acts passed specifically regarding the medical and healthcare industry's regulation of private information.

Legislation such as HIPAA, EMTALA and STARK has caused many headaches for healthcare providers since their enactment. I am not going to be able to help alleviate those headaches, but I will be able to provide an insurance policy that will help those providers sleep a little easier at night. This new program provides defense cost coverage and coverage for civil fines and penalties in regards to healthcare regulations and other proceedings.

    These policies offer payment of defense costs and civil fines for billing errors, including fraud and abuse, voluntary reporting, Qui Tam and commercial payor claims. They also cover HIPAA, EMTALA and STARK. The policies have limits for solo physicians up to $1,000,000 and up to $5,000,000 aggregate limits for physician groups. These policies should name the employees, directors, trustees, officers and the entity as an insured in the definitions page of the policy.

    Network security and Privacy liability insurance is also a very important issue for physicians and other healthcare providing agencies. Network security and Privacy liability insurance is a policy which covers the company against suits due to invasion of privacy and computer hacking. We've all heard the horror stories of different corporations losing laptops, or having private information stolen including Sears, TJX, the Veterans Affairs Administration and the University of Miami.

All companies that collect and store non-public information of their clients should make certain that they have certain procedures in place. For one, everything needs to be reviewed by an expert in computer security. But secondly, even the best laid plans can go awry, that is why every one of these companies also needs to have a privacy liability insurance policy. Healthcare agencies have more personal and private information than anyone other entity including the government. That is why it makes the most sense for those agencies to have the insurance.

    Doctors have a bad view of insurance. They hate health insurance because they never get paid. They hate casualty insurance because it costs too much. And they are correct on both accounts. However, privacy liability insurance policies and the defense coverage for regulatory actions are reasonably priced. Underwriting for these policies is based on how many doctors are in the practice, gross revenue and what you have done to mitigate against these risks, among other things.

    For a free quote, and to speak with a privacy liability insurance expert, please contact Andrew Cohn by calling, 786-382-6833 or emailing, acohn@alcrisk.com. You can also visit the ALC Risk Solutions website at www.alcrisk.com.Andrew has had articles published by the Insurance Journal and Website Magazine regarding privacy liability insurance. Andrew will also be speaking about privacy policies and other insurance matters at the Social Network and Internet Dating Conference in Miami, January, 2009.

Insurance for Healthcare Regulations including HIPAA for Doctors, Healthcare Providers and other Medical Facilities

    Healthcare providers such as physicians face many risks in the United States today. They constantly have to keep up to date on the changes in their profession. Physicians also need to constantly monitor their relationships with the Healthcare Insurance providers. They have to pay close attention to State and National legislatures to see what new regulations they have to comply with. For instance, Massachusetts recently passed a new statute regulating all companies that collect and store any private information of its citizens.

    The United States today is as litigious as ever, and lawyers and doctors are still not the best of friends. As new laws get passed by the legislatures, mostly lawyers, new risks are presented to physicians. Privacy is one of the biggest issues in the media. The healthcare industry is far from immune from this issue. In fact there has been numerous acts passed specifically regarding the medical and healthcare industry's regulation of private information.

Legislation such as HIPAA, EMTALA and STARK has caused many headaches for healthcare providers since their enactment. I am not going to be able to help alleviate those headaches, but I will be able to provide an insurance policy that will help those providers sleep a little easier at night. This new program provides defense cost coverage and coverage for civil fines and penalties in regards to healthcare regulations and other proceedings.

    These policies offer payment of defense costs and civil fines for billing errors, including fraud and abuse, voluntary reporting, Qui Tam and commercial payor claims. They also cover HIPAA, EMTALA and STARK. The policies have limits for solo physicians up to $1,000,000 and up to $5,000,000 aggregate limits for physician groups. These policies should name the employees, directors, trustees, officers and the entity as an insured in the definitions page of the policy.

    Network security and Privacy liability insurance is also a very important issue for physicians and other healthcare providing agencies. Network Security and Privacy liability is a policy which covers the company against suits due to invasion of privacy and computer hacking. We've all heard the horror stories of different corporations losing laptops, or having private information stolen. All companies that collect and store non-public information of their clients should make certain that they have certain procedures in place. For one, everything needs to be reviewed by an expert in computer security. But secondly, even the best laid plans can go awry, that is why every one of these companies also needs to have a privacy liability insurance policy. Healthcare agencies have more personal and private information than anyone other entity including the government. That is why it makes the most sense for those agencies to have the insurance.

    Doctors have a bad view of insurance. They hate health insurance because they never get paid. They hate casualty insurance because it costs too much. And they are correct on both accounts. However, privacy liability insurance policies and the defense coverage for regulatory actions are reasonably priced. Underwriting for these policies is based on how many doctors are in the practice, gross revenue and what you have done to mitigate against these risks, among other things.

    For a free quote, and to speak with a privacy liability insurance expert, please contact Andrew Cohn from Internet Risk Specialist, the technology division of Wilson, Washburn & Forster Insurance. Andrew Cohn has been specializing in the unique risks of the technology and life sciences industries. Andrew has had articles published by the Insurance Journal and Website Magazine regarding privacy liability insurance. Andrew will also be speaking about privacy policies and other insurance matters at the Social Network and Internet Dating Conference in Miami, January, 2009.

Wednesday, November 26, 2008

Directors and Officers Liability Insurance for Start-Ups and other Private Companies

    Venture capitalists invest millions of dollars into start-ups and small businesses hoping that they will take off and be the next Google or Facebook. From my understanding they look over the business proposals and the presentations and financials and hopefully do a lot of due diligence in selecting their investment companies. But, why don't they take a better look at the insurance?

    Directors and Officers Insurance
(D&O Insurance) is insurance important for both public and private companies. Public companies all need and have Directors and Officer Liability Insurance, but many private companies do not. But private companies are exposed to securities litigation when they have investors, including venture capital investors. Directors and Officers Liability Insurance is necessary to protect the personal assets of the officers when these claims happen. D&O Insurance covers the defense costs, settlements and judgments associated with these claims.

    If you are a start up firm looking for insurance, and hopefully you are talking to Andrew Cohn at ALC Risk Solutions, your agent should be asking you if you have or are looking for investors. You are out there every day and night working on your business and trying to sell it. You sell it to potential investors, you sell it to potential clients, you sell it to the media, you sell it to whoever is in the elevator with you at that moment. Doing all this selling you might slip up, or you may have an investor that perceives something different from what you are doing.

    If you are a venture capitalist, requiring directors and officers liability insurance is a no-brainer. Some venture capitalists just give the money, and for you, if you have a problem with the management of the company, you have a wallet to sue in the insurance company. Think about it, if these start-ups had real money, they wouldn't be coming to you for a $100,000 investment. If they mismanage the company, and it goes under, you're out your capital. With the insurance you can try to file suit.

    Other venture capitalists invest money, and also make sure that they are named a director or officer of the corporation. Now this is the really tricky spot. You invest $100,000 in Company XYZ and are put on the board of directors. Company XYZ gets other investors and eventually they mismanage the venture into the ground and everyone is upset. XYZ never had money and now has less. But you, the venture capitalist, one of the directors of the XYZ Company does have money, has money to lose. Require the coverage.

    Here's the final reason to get Directors and Officers Insurance, it's relatively cheap. It really isn't very expensive for the coverage it is providing. As a small to midsized private company you really present a much lower risk in the insurance company's eyes compared to the publicly traded corporations they normally deal with. So if you're a venture capitalist giving hundreds of thousands and possibly millions of dollars to new ventures, require that they spend some of that money on their Directors and Officers Liability Insurance, and recommend that they speak to Andrew Cohn at ALC Risk Solutions.

    Lastly, not all D&O policies are created the same. You need an expert like Andrew Cohn atALC Risk Solutiont to read over the definition of "insured", does it include all past and future directors, officers, international functional equivalents, members of a board of manager, employees, and advisory committees. Make sure it has Spousal and Domestic Partner Liability. Why? A lot of new ventures are started with one spouse working a "real job" and the other playing with their new venture company. Make sure the "real worker" is protected financially as well. Make sure coverage is worldwide, if you're a local entity that has no plans to branch out, they maybe this isn't a factor, but in the age of globalization most companies are now global, and it doesn't cost more for your insurance to be. You should also review the "insured vs. insured" exclusion language. Is your policy a "duty to defend" or "defense reimbursement"? Can you afford to front the bill and be reimbursed? There are a whole lot of clauses, terms and conditions to be mindful of. You really need to deal with an expert like Andrew Cohn at ALC Risk Solutions

Three F’n Percent Follow Up

This morning I get into my office and I see that the number one headline on CNN behind, the picking of the head of the new economic recovery panel is "Durable Goods Orders Drop Sharply". Third place is "Consumer spending Drops 1%". This is crazy, the world must be ending. This must be the worst we've seen since the great depression, or maybe even the worse we've seen since the repealing of the Bank of The United States by Andrew Jackson. But here's the key to staying positive in this economy, Read the Articles. But wait, it's actually a two step process. Step one, read the article, step two, think about what it says.

Article one, "Durable Goods Orders Drop Sharply", the headline when you click on the scary link says, Biggest durable order drop in 2 years. My god, two years, I remember how badly off we were when we found out that durable goods orders were so low 2 years ago. I remember those harsh winters of 2006 after the October 2006 durable goods report. Come on media, stop with your scare tactics and report the news.

The second article "Consumer spending Drops 1%", has two key things it reported on. One, consumer spending dropped 1% in October, partially due to people saving up for their holiday spending. The second thing they reported, in the penultimate paragraph was "Personal income, however, rose 0.3% in October, following a 0.2% rise in the previous month. Economist had expected a 0.1% rise." (CNN) And finally the last paragraph talks about how prices are starting to come back down slightly.

My conclusion is simply read the media articles for the facts and come up with your own conclusions. The Weather Channel makes money during Hurricanes and Blizzards; CNN makes money during bad Economies, War and Elections. Sadly Americans have all but forgotten the wars in Iraq and especially Afghanistan, so CNN all but stopped covering them. The election is over, and they want to make us worry. So they need more than anything for this economy to keep sucking.