← Articles
RIPOSTE research · 2022

Cyber Insurance. It Doesn’t Cover Reputation

In February 2019 a sequence of events that would see LandMark White - one of Australia’s largest property valuation companies - lose many of its major clients, its CEO, an estimated initial financial loss of $7,000,000 and more than 74% of its share value; from which it, and its successor company, Acumentis, following a re-brand and significant investment in attaining an ISO27001 certification, has still not recovered. This tragic chain of events was set in motion by two data breaches; the first in February 2019, which saw approximately 137,000 unique records being posted on the dark web, and a second in May of the same year, when a further 250,000 individual records (some duplicated) were posted onto SCRIBD (a US file sharing site).

The LandMark White/Acumentis story should serve as a cautionary tale. The decision to invest in security after the company had suffered two (near enough to) fatal data breaches is a classic example of “shutting the gate after the horse had bolted”… twice! However there is another note of caution concealed within; that is: Cyber Insurance would not have changed the outcome for LandMark White, but why not?

The below is an excerpt of what Chubb’s (one of the world’s largest providers of cyber insurance) cyber insurance policy covers:

Business interruption loss due to a network security failure or attack, human errors, or programming errors

Data loss and restoration including decontamination and recovery

Incident response and investigation costs, supported by a 24/7 multilingual incident reporting hotline and on-demand vendors

Delay, disruption, and acceleration costs from a business interruption event

Crisis communications and reputational mitigation expenses

Liability arising from failure to maintain confidentiality of data

Liability arising from unauthorised use of your network

Network or data extortion / blackmail (where insurable)

Online media liability

Regulatory investigations expenses

If we turn our attention specifically to the “Crisis communications and repetitional mitigation expenses” point, the policy covers “reasonable expenses: to retain the services of a public relations firm, law firm or crisis management firm for advertising or related communications solely for the purpose of protecting or restoring Your reputation as a result of a Cyber Incident or business Interruption Incident.”

This sounds – and in many ways is – reasonable. However calculating the real financial cost of reputational damage is difficult, and over what timeframe do these calculations apply? For reputational damage – as was the case for Landmark White – the effects can be long term. Factors such as: value of lost clients, value of new clients, relative cost of attracting new clients and relative cost in retaining existing clients all contribute to the algorithm. However; defining the period post incident for which this data is illustrative of the effects of reputational damage as opposed to the dynamics of prevailing market conditions is a near impossibility. This combines to create a situation where, even with the availability of data in the wake of an incident, putting a true dollar figure on the cost of reputational damage is all but impossible.

Before an incident, such a calculation is impossible! Thus, a simple set of assumptions must be used. The core assumptions can be summarised as: costs will go up, and value will go down. The question is, what net change in percentage terms can your business absorb before damaged reputation becomes fatal?

Insurance policies may assist you with the costs associated with incident response, including loss of revenue during the period where services are disrupted and crisis communications are activated in an attempt to limit the reputational damage, however, once the services are restored and the incident is closed, reputational damage remains; and insurance cannot cover the financial implications of this.

So what is the solution? In the case of LandMark White, had they invested in a security and assurance framework prior to the incidents that triggered their series of unfortunate events, there is a good chance they could have been avoided all together. The moral of this tragic story is; an investment in assurance can save a business from the sort of pain that insurance can’t. Adopt the assurance before insurance mind-set.

Sources

  1. Massive data breach costs valuer LandMark White $7m — iTnews
  2. LandMark White returns to trading after data breach devastation — The Daily Swig (PortSwigger)
  3. OAIC Notifiable Data Breaches publications (breach statistics)
About the author

Cameron McCollum — Director & Founder, RIPOSTE. He spent two decades in Australian Army intelligence — serving as Head of Intelligence on operations across the Asia-Pacific and Afghanistan — before building and leading the cyber-risk program at Lexon Insurance. He holds Master's degrees in Cyber Security Operations and Business (UNSW) and is an ISO/IEC 27001 Lead Implementer.

RIPOSTE helps organisations turn analysis like this into action.

Talk to us