Just released: How to raise venture capital in 2023

Download

Year in Review: 2014 Cyber Attacks (What Startups Should Know)

TL:DR

Key Takeaways

Carl Niedbala - Founder Shield
Carl Niedbala

Managing Partner; COO & Co-Founder

2014 Cyber Attacks Reviewed

For the last four years, cyber risk management firm Net Diligence has done a report on cyber insurance claims for the year…and 2014 has been a hell of a year for cyber attacks.  This year’s report has been published and has some very interesting findings pertaining to the startup community.  An excerpt from the introductory pages reads:

“For this study, we asked insurance underwriters about data breaches and the claim losses they sustained. We looked at the type of data exposed, the cause of loss, the business sector in which the incident occurred and the size of the affected organization. For the first time, this year we also looked at the two additional data points: was there insider involvement and was a third- party vendor responsible for the incident.”

While the general claims data is valuable, the 3rd party vendor data is particularly important for startups.  From AWS to Heroku to WordPress, almost all startups use a slew of these vendors to host and deploy their apps and content.

Here are the biggest takeaways from this year’s study:

  • Startups accounted for roughly 23% of claims reported.  The study considered 3 revenue ranges for “small revenue” companies.  Companies under $2B accounted for 75% of the claims studied and companies under $50M in revenues accounted for 23%.
  • 20% of claim situations arose due to an error of a 3rd party vendor.
  • Healthcare and financial services were the 2 most frequently breached areas, collectively accounting for 55% of the studied breach incidents.  The study notes that the healthcare space has seen a rise in claims due to a more aggressive approach taken by state attorney generals in recent years.
  • The average cost to defend a data breach claim was $698,797.  The average cost for legal settlement was $558,520.

The key takeaway here is that while Home Depot and Target have received most of the data breach press over the last year, it doesn’t mean that startups are any less of a target.  Furthermore, some of the areas most ripe for disruption – Healthcare and Fintech – are particularly exposed to cyber risks.  A base level cyber insurance policy with $1M limits can go a long way for a company that plans on making big waves in one of these areas.


You can download/view the full report here.  Check out our coverage page to learn more cyber insurance (and other important coverages).

GUIDE

Cyber Risk Management Guide

Related Articles

cyber security tips
March 20 • Cyber Liability

Cyber Security Tips for Founders: Hackers Are Coming — Are You Ready?

Cyber threats endanger startups. Learn key cyber security tips to protect your business from financial loss, reputational damage, and legal liabilities. Implement strong defenses now.

ecommerce live social shopping 1
February 26 • Risk Management

Level Up Your E-Commerce With Live Social Shopping: A Go-To Guide

Live social shopping is changing the face of e-commerce. Discover the benefits, risks, and best practices for success in this emerging trend.

February 19 • Risk Management

Protecting Decentralized Exchanges: A Comprehensive Guide to DeFi Risk Management

This post explores emerging risks DEX companies face along with actionable tips for smart DeFi risk management, from vital insurance policies to best industry practices.

privacy regulations
January 22 • Cyber Liability

Navigating the Complex Landscape of Privacy Regulation

Explore the crucial role of data privacy in today’s digital world. Learn about key regulations like GDPR and CCPA, understand the consequences of data breaches, and discover best practices for building trust and compliance within your organization.

cyber insurance 2025
January 15 • Cyber Liability

Cyber Insurance 2025: A Review & Outlook

Explore the evolving cyber threat landscape, including AI-powered attacks, supply chain disruptions, and nation-state threats. Learn how these trends are impacting cyber insurance pricing and discover essential strategies for mitigating cyber risks and protecting your business.

AI Compliance
December 30 • Cyber Liability

How to Conduct a Thorough DPIA for AI Compliance [with GDPR]

This article outlines the key steps involved in conducting a Data Protection Impact Assessment (DPIA) for AI systems, emphasizing the importance of identifying and mitigating risks to comply with GDPR and build trust with data subjects.