- 10/03/2017
- Category: Commentaries
In late 2016, banking industry had been mapping several challenges for its clients. One of the significant challenges is synthetic identities on the personal level. Forget about identity theft. With the growing sophistication of digital innovations, hackers and cybercriminals are not just stealing people’s personal information but they alter that information and reassemble it to create entirely new identities to allow them to obtain mortgages and conduct other fraudulent transactions. Sonya Andreassen-Henderson, vice president of the mortgage investigative services group at PNC Bank, said fraudsters and cyber criminals are capable of intercepting customer personal email or other means of communication and then responding back to banks with new wire transfer instructions.[i] Currently, it is indicated that banks are struggling to determine who is a legitimate customer because it can’t rely on technology to flag false transactions. It requires a combination of employees with a right mix of human intelligence and technological aptitude. For now, banks still face difficulties.
As banks struggle to combat fraudulent transactions from synthetic identity, security providers are pitching new business-style protection and insurances policies to customers. Some security providers are offering beyond identity-theft coverage. They offer home security audits and checking whether computer systems are hack-proof. [ii] This personal cyber insurance provides protection for individuals with investments and sensitive data they access on home and mobile systems. One of the insurance and security company, Pure Insurance, began offering a “CyberSafe Solutions” program back in 2015. The program provides a full-day home networks audits at $1,500, depends on the size of the customer network. With additional $500 to $3,000 monthly, the insurer will monitor a client’s home computer systems for intrusions. Customers also can buy a $2,500 “social engineering assessment,” which analyzes how criminals could exploit publicly available information on a client. If there is any breach after the audit and monthly safety program, the insurer will compensate for certain important data loss.
At a glance, the price might be sensitive to several customers. Thus, the burning question for this insurance is, is it worth it? Before customers decide whether they need extra dollars to secure their network or not, it is advisable to firstly review your bank policies, especially the ones related to fraudulent transactions. Banks typically offer protection against liability for fraud. Even if banks have not yet adopted every element of fraudulent transactions policy, the trends in the next following years show that there will be a high increase in the number of insurance companies which will start to offer cyber security insurance for organizations and financial institutions, especially on banking transactions.[iii] There will be a race for the best cyber security talent to assess the risks and provide pre and post-breach services as monitoring, incident response, forensics, etc. These insurance firms will offer a cyber insurance coverage of up to $1M per organization and financial institutions[iv]. The increase competitions among insurer that willing to cover bank transaction will enhance the security system on this basis. However, what is needed to be underlined is the fact that the trend seems to be coming in the – near – future. While we wait until these security companies fully penetrate to bank institutions, it is advisable for personal bank customers to consider investing in and adopting personal security insurance providers, for the security of their personal data.
Different with the bank and credit-card transactions, investor and intellectual property owner might want to consider personal cyber security. In the case of investment, there are only 15% of broker-dealers and 9% of advisers who have written policies that guarantee the client lose should a breach take place.[v] Thus, people with several million dollars’ worth of liquid and investable assets might want to extra layer of risk management to safeguard their wealth. In the case of intellectual property rights, an owner of specific prototype or an executive from the prominent company who accesses financial or other sensitive information on a personal device or home computer may be a target. Since the nature of intellectual property is entirely different with the financial products, private cyber insurance becomes important particularly in the level of research and prototype because there are almost no formal institutions that will insure this particular product.
Even though in the digital age, where hackers and cybercriminals are more sophisticated than ever, not everyone has to pay extra dollars to insure their networks and personal devices. Private cyber insurance is only necessary if there are no institutional policies on specific issues. As mentioned before, customers of day to day bank and credit-card transactions may consider using the personal security insurance, while waiting for the advancement in banking technology in protecting customers’ data from identity thefts and synthetic identities. Personal cyber insurance may also be proven useful for investment and intellectual property rights customers because there is less to none safety layer from institutions, both in the present and in the near future. Private cyber insurance is indeed useful whether you are a cancer researcher, successful investor with million-dollar worth of liquid, or even ordinary bank customers with three-zeros balance. Because losing personal data and privacy is painful either way.
picture: pixabay
[i] Reed, K., (2015). Three Big Risk Issues for Banks in 2016. [online] Linkedin. Available at: https://www.linkedin.com/pulse/three-big-risk-issues-banks-2016-kristin-reed
[ii] Anand, P., (2015). Do Individuals Need Cybersecurity Insurance? [online] Wall Street Journal. Availabe at: https://www.wsj.com/articles/do-individuals-need-cybersecurity-insurance-1442800951
[iii] Romanosky, S., (2016). Examining the Costs and Causes of Cyber Incidents. [online] Oxford Academic. Available at: https://academic.oup.com/cybersecurity/article/2/2/121/2525524/Examining-the-costs-and-causes-of-cyber-incidents
[iv] Golan Y., (2017). Cyber Insurance: Coming of Age in 2017. [online] Info Security. Available at: https://www.infosecurity-magazine.com/opinions/cyber-insurance/
[v] Anand, P., (2015). Do Individuals Need Cybersecurity Insurance? [online] Wall Street Journal. Availabe at: https://www.wsj.com/articles/do-individuals-need-cybersecurity-insurance-1442800951