Michelle Reed on Cybersecurity and Cyberinsurance with Metro Corp Counsel

Jul 24, 2015

Reading Time : 1 min

Among Reed’s observations:

  • On cyber risks facing corporations: “The biggest risk in my view is the head-in-the-sand mentality of too many companies, wherein companies acknowledge the issue, hand it off to the IT department, and then check it off the list.”
  • On the shifting threat landscape: “While advances in vulnerability assessment and security governance have greatly mitigated risks, no company is immune to zero-day attacks, which exploit holes in software unknown to vendor and user. The company is literally blindsided.”
  • On planning an adequate defense: “[E]veryone should look at certain controls, such as password protection, access limitations, proprietary encryption and effective policies on data retention and disposal. You also want to perform risk assessments on all software products and conduct top-notch employee training that includes exercises to ensure full awareness of necessary protocols.”
  • On shopping for cyberinsurance: “[D]etermine whether you need first- or third-party insurance. Ask yourself, ‘What am I worried about? Someone suing me because of a data breach? Or the cost of notification and mitigation in the event of a security breach?’… First-person insurance covers direct loss and out-of-pocket expenses incurred by the insured. Third-person covers liability incurred from harm actually caused by the insured. So if you’re the target of a consumer class action for failing to properly secure your systems, you would need third-party coverage. You also want to look at the liability limits, a tricky area because the market is changing….Retailers will need a greater amount of coverage and will pay higher premiums because of the types of data they hold. If payment card data is breached, the notification cost will be significant.”

To read the full interview, please click here.

Share This Insight

Previous Entries

Deal Diary

April 12, 2023

Read More

Deal Diary

2022-12-15

On December 14, 2022, the Securities and Exchange Commission (SEC) adopted amendments regarding Rule 10b5-1 insider trading plans and related disclosures. The amendments aim to strengthen investor protections concerning insider trading and to help shareholders understand when and how insiders are trading in securities for which they may at times have material nonpublic information (MNPI). In light of these amendments, issuers should review and revise, if needed, their insider trading policies and equity grant policies.

Read more.

...

Read More

© 2024 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.