Insurance for Online Attacks Has Yet to Catch On

By Preston Gralla

Sat, December 01, 2001CIO When Ted Visner’s Visnet ISP was attacked 44 times by a hacker in early 1999, he assumed that the vandalism clause in his insurance policy would cover the damage?costs he estimated at nearly $350,000. To his chagrin, he discovered that his traditional insurance didn’t recognize the true costs of cyberattacks. The insurer said it would pay only $19,000, forcing Visner to battle the company in court. He lost?and now Visnet is out of business.

If Visner had taken out a cyberinsurance policy, he might have been able to collect more appropriately on his losses.

Cyberinsurance covers a number of areas not normally spelled out in traditional policies. These areas include denial-of-service attacks that bring down e-commerce sites, electronic theft of sensitive information, virus-related damage, losses associated with internal networks crippled by hackers or rogue employees, privacy-related suits, and legal issues associated with websites, such as copyright and trademark violations.

The cost of such policies can be high, running to hundreds of thousands of dollars per year, depending on the size of the business and coverage specifics. But that figure might look reasonable compared with closing the company doors forever. As hacker break-ins, server shutdowns and internal sabotage become the normal costs of doing business, CIOs have to make basic decisions about cyberinsurance. Does the company need cyberinsurance at all, or will existing policies suffice? Would it be more beneficial to spend the money on additional security technology instead of insurance? If the company does decide to buy cyberinsurance, what should the policy cover? Some insurance providers offer discounted premiums for companies that use certain software or security services. This can make cyberinsurance a technology issue as well as a financial and legal question, and it can even take some security decisions out of IT’s control and place them in the hands of insurance adjusters and actuarial tables.

Still Waiting

Given these questions, it’s understandable that cyberinsurance has yet to catch on in a big way, especially when you consider that many CIOs don’t even know such policies exist.

And even those executives who are aware of the offerings don’t always bite. Ken Anderson, CIO for Provo, Utah-based Novell, acknowledges that his company looked into purchasing cyberinsurance but has yet to buy any. Company lawyers, he says, determined that Novell’s existing liability insurance offers adequate coverage, making cyberinsurance redundant.

Like Anderson, John Voeller, chief knowledge officer and CTO of Kansas City, Mo., engineering construction company Black & Veatch, investigated cyberinsurance but decided not to purchase it. "We’ve talked to a lot of insurance companies about it," he says, "but we haven’t seen something we can use broadly here and overseas. We operate globally, and some of the protections we can buy in some places we can’t buy in others."

Loading...
Network MarketSpace
White Papers
The Challenge of a Demanding Network Infrastructure
Today's data centers are expanding as demand for data and storage continues to grow exponentially. Learn more »
Reduce Infrastructure and Administrative Costs
The Brocade® FastIron® CX Series of switches provides new levels of performance. Learn more »
A New Generation of Application Delivery Controllers (ADCs)
Learn more about Brocade® ServerIron® intelligent application delivery and traffic management solutions. Learn more »
Want to Offer a Superior User Experience?
Control a "boundary-less" enterprise with scalable solutions. Learn more »
Realize Potential Without Increasing Your Risk
Combining Brocade's high-performance infrastructure and McAfee's Web gateway solution ensures trusted environments. Learn more »
Brocade and Imperva: Providing Best-of-Breed Products
Web applications have become the backbone of business in nearly every segment of the economy. Learn more »
 
SPONSORED LINKS
 

Maximizing the Business Value of the PC Infrastructure

Enterprise PBX Comparison Guide

Getting Value from Outdated Networking Equipment

Seven Ways ITIL Can Help You in an Economic Downturn

Data Loss Prevention: A Better Way to Approach Security

Learn how to managing client systems in the enterprise.

Cloud Computing: Read about VMware's compelling vision & set of products

Top-line Performance that's Bottom-line Efficient

Accenture: Outsourcing for uncertain times. Click to learn more.

White Paper: 8 Key Ingredients to Building an Internal Cloud

Read about virtualization and consolidation effort best practices

Building the Virtualized Enterprise with VMware Infrastructure

Top 10 Business and IT Drivers for the Wealth Management Sector

Bottom-Line Benefits of Virtualization

White Paper: The Building Blocks for Cloud Computing

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Learn about The Information Technology Infrastructure Library.

Achieving Pervasive Performance Management

Automating the Generation and Secure Distribution of Excel Reports

64-page prescriptive guide to security, compliance, and IT operations.

Get Google Enterprise Search for your business information.

Accenture IT Consulting: Enabling high performance. More...

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

Taking the Service Desk to the Next Level

Why Data Loss is Increasing--and What You Can Do About It

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Mid-Sized Company CIO Community: infoBOOM!

Accenture IT Consulting: Logical meets technological. More . . .

Stop Application Fraud at the Source with Device Reputation

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

8 Key Ingredients to Building an Internal Cloud

Data Center Optimization: Three Key Strategies

A CIO Executive Guide: Cloud Computing Looms Big on the Horizon

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Tips for successful virtualization management.

Smart Decisions: The Role of Key Performance Indicators

Gartner Shares Predictions for 2009

Improve ROI, lower TCO and reduce energy consumption.

Introducing the new HP ProLiant G6 server family

Accenture: Outsourcing for Competitive Advantage. More...

 
 
RESOURCE CENTER