Car, health, and home are assets we usually protect. But threats like data leaks and hacking into corporate networks have increased the demand for another type of insurance: cyber insurance. According to the Superintendence of Private Insurance (Susep), Brazilian insurers have already paid out almost R$12.9 million in claims (occurrences) up to June of this year for this type of service. To give an idea of how much is being claimed, the same amount for the entire previous year was R$145,000.
Demand has also grown in recent months. According to Susep, cyber insurance companies collected R$3.5 million in premiums (amount paid by clients) in January; in April, there was a decrease, reaching R$1.3 million; in June there was a new increase, to R$4.1 million. One of the reasons for this is the General Data Protection Law (LGPD).
Enacted in July, it established the creation of the National Data Protection Agency (ANPD), responsible for overseeing and applying sanctions. Companies must comply with the law by the date it comes into effect, which could be this month or next year. The sanctions, however, have been postponed until August 2021 due to a provisional measure from the government.
The perception of risk by companies is also another factor driving the new demand. "Not to mention the cases of companies that have faced cyber crises," says Flávio Sá, manager of financial lines at AIG, a multinational in the sector. That is, when the risk ceases to be a possibility and becomes a reality.
Sá recounts a case of an AIG policyholder whose network was hacked. The hackers gained access to 2,000 files containing personal and corporate data. "AIG helped the company investigate what happened and comply with legal requirements, in addition to the forensic investigation. The client received compensation in the amount of R$ 1.2 million," he says.
Ana Albuquerque, financial lines manager at the insurance brokerage Willis Tower Watson, says that growth has been ongoing since last year. The company saw a 200% increase in demand for cyber insurance compared to the same period in 2018. "In December alone, I had 20 requests for presentations from clients," she says.
In addition to the enactment of the LGPD (Brazilian General Data Protection Law), she points to the "corporate governance aspect" as a reason, which is a set of practices guided by transparency, accountability, fairness, and corporate responsibility. With insurance, the company builds credibility with clients and shareholders.
How do you purchase this type of insurance?
- When contacted, the brokerage firm assesses the risks and potential losses of the company seeking cyberattack insurance.;
- She sends out a questionnaire with questions about how data is handled, actions taken in case of business interruption, and the company's priorities in terms of digital security.;
- Next, the brokerage firm searches the market for the best coverage for the company's profile;
- The risks and value of the policies are calculated based on the companies' profiles.
“If you don’t have a minimum level of control, you won’t have an insurance policy,” says Gustavo Galrão, coordinator of financial lines at FenSeg (National Federation of General Insurance). The minimum varies according to the size and nature of the company.
With hospitals and financial institutions, the requirement is more stringent. The company must have a committee to discuss and manage risks, and create two positions: the DPO (Data Protection Officer), responsible for the legal aspects; and another for the information technology security aspects.
Costs
The insurance company takes into account the size of the company and its area of operation, the data and transactions that pass through its networks, and what security protection tools the company already has in operation.
“For small and medium-sized enterprises, it costs between R$10,000 and R$30,000 per year, but it can exceed R$100,000, depending on the sector of activity, or even several hundred thousand reais, depending on the size of the company,” says Sá.
Which companies are most vulnerable?
It is possible to separate them into two groups: industrial companies and service providers. The former, although lacking a rich database, is a target for attacks that disrupt business.
Insurance companies call this type of loss "lost profits." That is, when production stops. The most common example is ransomware, in which the criminal invades the network and blocks it, releasing it only after a ransom is paid. "It is recommended never to pay the ransom, but often people pay and the hacker still doesn't release access," says Galrão.
The second group includes financial institutions, hospitals, online sales platforms, and even the insurance companies themselves. Albuquerque says that financial institutions are the ones that most frequently seek out the brokerage firm.
They are targeted by hackers because they have a rich database with information about credit cards or patient health. If they are compromised, the effects are loss of credibility and financial damage. It costs approximately US$100 to notify each user, not including legal expenses.
Is it just a matter of hiring and that's it?
Having insurance does not exempt companies from legal responsibilities. What the policy covers are fines and compensation, as well as costs related to investigating the attack (such as hiring technical experts), notifying those whose privacy was violated, and, in some cases, managing the company's image through a public relations professional.
According to Renato Opice Blum, coordinator of the Data Protection and Digital Law courses at Insper, "every possible effort should be made to protect and, consequently, repair any damages that may have been caused to data subjects.".
In 2018, the Public Prosecutor's Office found that Netshoes suffered a security incident that compromised the personal data of two million customers. In February 2019, it reached an agreement to pay R$ 500,000 in compensation for moral damages. There was no leak of customers' credit card numbers and passwords, but the criminals had access to their names, email addresses, CPF numbers (Brazilian tax identification numbers), dates of birth, and purchase history. Netshoes also had to contact all two million consumers whose data was leaked by phone.
Galrão says that compliance begins with awareness, as many companies are barely aware of the law's existence. Another problem is the corporate culture regarding insurance contracting. For Blum, complying with the LGPD (Brazilian General Data Protection Law) is a "demonstration of good faith and diligence.".
Although hiring insurance or using a broker is not mandatory to comply with the law, doing so provides the company with an overview of how it manages information and its level of security. "The insurer's role is not to correct, but to assume the risk according to the policy limits," says Galrão.
SOURCE:
UOL





