Just released: How to raise venture capital in 2023

Download

3 Cyber Insurance Lessons From the HBO Data Breach

TL:DR

Key Takeaways

Matt McKenna Scale Underwriting
Matt McKenna

Underwriting Manager

Copyright 2017 Home Box Office, Inc.


Winter is com…wait, nope, those are lawyers.

Lawyers are coming.

Fresh off the heels of the personally identifiable information (PII) of every registered voter in the United States being stolen, another American institution is on the defense.

OK so maybe it’s not an “institution” per se. HBO was the target of a hacking attack in July which resulted in a 1.5 terabyte data breach. Much of this data was highly sensitive or valuable information.

We can learn countless lessons from this but there are three in particular that stand out:

  1. Data breaches can happen to anyone.
  2. Data breaches against smaller companies consume less time and resources.
  3. Cyber insurance is designed to cover the costs that HBO is dealing with right now.

Data Breaches Can Happen to Anyone

HBO announced on July 31st that it was the victim of a hacking attack. A week later, new details began to emerge. We now know that the breach was 7 times the size of the Sony breach. It included the PII of employees and even famous actors. Adding fuel to the fire, internal and confidential communications were released which could have serious PR implications.

We also know that Time Warner (HBO’s parent company) is no stranger to data breaches. Just last year, the passwords of 320,000 cable users were compromised in what was believed to be a social engineering scheme. (More on social engineering here).

They’ve navigated the intricate terrain of lawyers and regulators, demonstrating a thorough commitment to the auditing process within their insurance company, ensuring meticulous scrutiny and enhancement of their cybersecurity practices.

And still they got attacked. The thing is, it took six months to get the job done.

GUIDE

Cyber Risk Management Guide

Data Breaches Against Smaller Companies Consume Less Time and Resources

Let’s use another big budget franchise to help us out here:

So I’m Jaws, right? Big shark, sharp teeth…the whole deal. For six years I try to eat those delicious little 1970’s Amity Island beachgoers, and for six years that meddling Police Chief Brody and his little “shark expert” buddy get in the way.

A few foolhardy fisherman and promiscuous college kids here and there are not enough for the modern shark to make ends meet…do you have any idea what overhead is like on the ocean?

So I’ve had enough. No more cold winters. I’m heading down to Florida, I’m getting a relaxing spot by the beach and I’m going to eat Dennis Quaid. I’m taking the path of least resistance — avoiding any liability — because I’ve been burned in the past. And shot. And blown up!

Hackers are predators. It took this hacker (or hackers) six months to breach HBO’s systems. This level of persistence is the exception, not the rule. The vast majority of black hats will instead choose the path of least resistance and attack the target that doesn’t see it coming. This is the target that hasn’t had an attack in the past. They haven’t brought in their “expert” to review their situation. They honestly don’t think it can happen to them.

For this reason, 85% of “targets of opportunity” are small businesses, and 55% of small businesses have experienced some sort of data breach. Considering the average total cost of a data breach is $3,500,000, you can see why it’s vital to prepare. Cyber insurance in the USA is crucial for mitigating these risks, ensuring businesses can recover from attacks without bearing the full financial burden themselves.

Cyber Insurance Is Designed to Cover the Costs That HBO Is Dealing With Right Now

Here are some data breach expenses that HBO may have on its horizon:

  • Credit monitoring for all of its employees (they’ve already confirmed they’re doing this).
  • Cyber security contractor to investigate the source of the breach (this, too, is in progress).
  • Notifying people that they’ve been affected by the breach.
  • Defending any civil suits that are filed.
  • Responding to investigations, fines and penalties from state or federal regulators.
  • Public relations expenses.
  • Data restoration services for anything that could not be recovered.

These are all standard costs that could contribute to a multi-million dollar price tag at the end of the day. The good news is they can all be covered by the right cyber insurance policy!

Related Articles

startup lawsuits 2024
December 19 • Thought Leadership

Legal Battles: The Biggest Startup Lawsuits of 2024

The startup landscape in 2024 was marked by increased regulatory scrutiny, AI-related legal battles, and challenges in navigating complex legal and financial landscapes. Through a risk management lens, let’s look at the biggest startups lawsuits of 2024!

cleantech companies
October 8 • Thought Leadership

Learn From the Best: Top 25 Cleantech Companies Raising Funds

Discover the top 25 cleantech companies making waves. This comprehensive list highlights innovative projects, unique business models, and pioneering technologies driving the cleantech industry forward.

data breach 2024
October 1 • Cyber Liability

Top 10 Cyber Security Data Breaches of 2024

Cybersecurity under attack in 2024! Discover the top 10 data breaches that rocked the world. Learn how major companies fell victim to cybercriminals. Understand the risks and take action to protect your business from cyber threats.

tech ipos 2024
September 24 • Thought Leadership

Tech IPOs 2024: Back from the Brink?

Discover the latest trends and insights shaping the IPO market in 2024. Explore the rise of AI-powered companies, the impact of economic uncertainty, and key success factors for a successful IPO. Get ready to navigate the dynamic world of tech IPOs and seize opportunities for growth and innovation.

supply chain disruptions
August 27 • Cyber Liability

Cyber Attacks & Supply Chain Disruptions: Startup’s Worst Enemy?

Explore the evolving threat landscape for supply chain disruptions, mitigation strategies, and the importance of risk management in today’s volatile business environment.

August 21 • Thought Leadership

Webinar – Continuity Strategies for Business Operations & Insurance

Our goal is to highlight ways to position your company for success during this difficult time; or at least provide guidance on bizops offense and defense to get you through economic downturns.