LTN Law Technology News
  • Home
  • News
  • Reviews
  • Commentary
  • Surveys
  • Events
  • LegalTech® Directory
  • About LTN
  • Register
  • Topics:
  • E-Discovery & Compliance
  • Litigation Support
  • Practice Management
  • Office Tech
  • Mobile Lawyer
  • Research & Libraries
  • Tech Law

Home > Why Risk Data Breaches?

Font Size: increase font decrease font

Why Risk Data Breaches?

Insurance against data breaches in a new era of data insecurity.

By Judy Selby All Articles 

Law Technology News

November 20, 2012

  •    
  •    
  •    
  •      
 
Judy Selby, partner, Baker Hostetler

Judy Selby, partner, Baker Hostetler
Image: Baker Hostetler

Related Items

  • Jury Convicts U.S. Man in iPad Data Breach Case

What do Sony Corp.'s PlayStation Network, Zappos.com, Hannaford Brother Co.'s grocery stores, and South Carolina's Department of Revenue all have in common?

Each has been the victim of a serious data breach. Data breaches can occur in a variety of ways, some by accident, some motivated by profit or political belief, and some simply for the sport of it. A breach can result from a malicious attack designed to destroy or disable a network or to steal private, competitive or proprietary information; from a disgruntled employee out for revenge; from the negligence of a vendor handling data; or from a laptop or thumb drive being left accidentally in a cab or airport. Paper documents also are involved in a significant number of data breaches.

While some data breaches are caused by cyberattacks carried out by zealots (so-called "hacktivists") for political or other non-monetary reasons, a large black market exists where stolen personal and financial information is bought and sold. Stolen medical information can be particularly lucrative because of its use in Medicare fraud.

As all entities, particularly health care providers, law firms, financial institutions, and retailers, continue to gather and store more and more personal and protected information every year, the risk of a data breach grows in turn. Cyberassaults are continuously taking place, with ever increasing levels of sophistication. In fact, the Ponemon Institute's "Second Annual Cost of Cyber Crime Study" reports that the 50 organizations participating in its survey experienced 72 successful attacks per week.

Data breaches can have serious financial effects, including business interruption losses, regulatory and credit card company fines, legal defense costs, and civil damages. Further complicating the situation are federal and state laws imposing fines for and/or mandating public disclosure of data breaches to the affected parties and law enforcement. The Health Information Technology for Economic and Clinical Health Act (HITECH), the Health Insurance Portability and Accountability Act (HIPAA), and Gramm-Leach-Bliley, among other federal laws, can be implicated by a breach. Beginning with California in 2003, 46 states, the District of Columbia, Guam, Puerto Rico, and the Virgin Islands have enacted laws requiring notification of security breaches involving personal information. In addition, in October 2011, the SEC issued cybersecurity guidance, noting that cyber-risks should be disclosed "if these issues are among the most significant factors that make an investment in the company speculative or risky." International companies must be particularly attuned to breaches involving private information, because foreign privacy laws, especially in Europe, can be more inclusive and onerous than those in the United States.

Reputational damage resulting from a data breach can be devastating as well. Recent studies report that significant numbers of customers said they will terminate their relationships with companies after being notified of a data breach. "The Reputational Risk of a Data Breach," Advisen Insurance Intelligence, September 2012.

An astronomical number of people can be implicated by a single data breach. The Sony hackers allegedly gained access to personal identification and financial information of over 100 million users. Zappos' hacking incident affected 24 million customers. 2.4 million credit card numbers reportedly were stolen in the Hannaford cyberattack. The South Carolina breach implicated 3.6 million unencrypted Social Security numbers.

Not surprisingly, the costs associated with data breaches also are astronomical. Sony's costs related to the PlayStation breach are reportedly over $170 million. In a March 2012 report, the Ponemon Institute estimated the 2011 average per capita cost of a data breach to be $194 per compromised document.

Given this environment and the exponential growth of electronically stored information, the necessity of implementing, monitoring and updating systems and practices to safeguard sensitive data cannot be overstated. But what else can entities do to protect themselves from the fallout of a data breach? How can this risk be managed?

Traditional insurance policies may or may not provide coverage for data breach incidents. For example, although a court recently held that the shoe retailer DSW had coverage under a computer fraud rider to its corporate crime policy for the theft of customer credit card and checking account information from a hacking attack in Retail Ventures, Inc. v. National Union Fire Ins. Co. of Pittsburgh, PA, No. 10-4608 (6th Cir. Aug. 23, 2012), an insurer is denying any coverage obligation under a general liability policy for Sony's PlayStation data breach claim. Zurich American Insurance Company v. Sony Corporation of America, No. 651982/2011 (NY Sup. 2011).

A browser or device that allows javascript is required to view this content.

Continue reading

  • 1
  • 2

Next



Subscribe to Law Technology News

You must be signed in to comment on an article

Find similar content

Companies, agencies mentioned

    
  • PlayStation Network
  • Ponemon Institute
  • National Union Fire Ins
  • Retail Ventures
  • Hannaford Brother Co.
  • Hitech
  • Beazley Group
  • Department of Revenue
  • United States Securities & Exchange Commission
  • Sony Corporation
  • Lockton Companies

Key categories

    
  • Networking, Storage, Content
  • Information Security

Most viewed stories

    
  1. 10 Devices You Should Never Take Along on a Business Trip
    •      
  2. Is Stanford Law the New Vortex of Legal Technology?
    •      
  3. Using Computer Forensics to Investigate IP Theft
    •      
  4. Redacted Emails Ordered Released in Aaron Swartz Case
    •      
  5. Big Law Whipped for Poor Tech Training
    •      
  6. CEIC: the Destination for Digital Investigation
    •      
  7. FTC Warns Companies of Children's Privacy Violations
    •      
  8. Law Technology News Goin' Mobile With ALM
    •      
  9. Judge Opens Toyota's Secrets to Additional Attorneys
    •      
  10. Collaboration Is Key to Defending Cyberattacks
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

The General Counsel and the Compensation Committee

Your Company's Been Hacked -- What Comes Next?

Amid Spy Scandal, Russia Boots Baker & McKenzie Lawyer

Survey: Firm Leaders Admit Downturn's Permanent Impact

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

Cisco E-Book Delivers Ethics on the Go

Collaboration Is Key to Defending Cyberattacks

Prolific ADA Plaintiff Faces Nemesis in Harassment Suit

Ullyot Exit Closes Chapter for Facebook

Fla. Attorneys Lead Force-Placed Insurance Fight

Lawsuit Names Missing Fla. Attorney for Alleged Fraud
  •      
    • Subscription Required

$3M Judgment Voided Against 'Girls Gone Wild' Producer

Judge Says Boston Bombings Had No Effect on Terrorist Sentences
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Court System, Counties Agree on 3 Court Facility Upgrades

Guardian Who Delayed Final Account Must Pay Referee Fee
  •      
    • Subscription Required

Perelman's Case Against Arlin Adams Thrown Out

McVay Wins Superior Court Nod With Western Turnout
  •      
    • Subscription Required

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Advising Clients on Weather and the Workplace
  •      
    • Subscription Required

Texas Sues BP, Transocean, Halliburton, Anadarko Entities
  •      
    • Subscription Required

Insurer Beats Bid By Bilked Client
  •      
    • Subscription Required

Barnes Asks For Court-Appointed Lawyer To Help Defend Brooks

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • Contact LTN
  • Editorial Guidelines
  • Magazine
  • RSS Feeds
  • LTN Awards
  • Bookstore
  • Site Map
  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media