Google Tanslate

Select Language

Sign up and be the first to know

About Hugh Terry & The Digital Insurer

Hugh Terry & The Digital Insurer Video

Contact Us

1 Scotts Road
#24-10 Shaw Centre
Singapore 228208

Write an article

Get in touch with the editor Martin Kornacki

email your ideas at [email protected]

Pre Registration Popup

itcasia2020 Registration Popup

Share Popup

Prime Member: Find out more

Access a unique programme!
  • 56 pre recorded lesson of online content from industry experts over 7 courses
  • The best in digital insurance for practitioners and by practtioners
  • Online MCQ after each lesson
  • Join the discussion forum and make new friends
  • Certificate upon completion to show your expertise and comitment
  • 3 months to complete
  • Normal price US$1,400 Your Prime member price is US$999
  • Access to future versions included in your Prime membership!
Become a member

Prime Member: Contact Us

Reach out to us. Please fill up the form below
Let us know how we can help. You can expect a response within 24 hours
Services of interest
Untitled

Arthur D. Little

Arthur D. Little has been at the forefront of innovation since 1886. We are an acknowledged thought leader in linking strategy, innovation and transformation in technology-intensive and converging industries. We enable our clients to build innovation capabilities and transform their organizations. ADL is present in the most important business centers around the world. We are proud to serve most of the Fortune 1000 companies, in addition to other leading firms and public sector organizations. For further information, please visit www.adlittle.com

Insurers are being targeted by cyber criminals, just as their customers are

View Newsletter

Insurance companies are double-sided with respect to cyber security. As they retain valuable personal information, they themselves are a prime target of cyber criminals and must therefore have effective protection. On the other hand, they can design and sell insurance that protects their customers from cyber risks, as well as helping them to cope with an eventual attack. Vincent Van de Winckel asks Mauro Almeida, from everis Portugal, who is responsible for information security and cyber-security, his perspective on the issue.

Vincent Van de Winckel (VVdW): With regard to safeguarding their own activity, how should insurers proceed in order to be immune to cyber risks? What are the key processes to implement and monitor?

Mauro Almeida (Pictured below): Insurance companies generate millions of personal and sensitive data from their customers, information that is critical to their business. Today, more than ever, all the management, control and custody of this information is on systems. Business is being completely digitized as well as all client interaction. The responsibility for information security, and cybersecurity, on the part of insurers gains added weight due to the quantity and criticality of the data that is processed and stored.

Undue access to confidential organizations’ data, or its tampering, can lead to loss of confidence on the part of customers, reputational damage, loss of intellectual property or the imposition of fines for non-compliance with regulations, or standards, with the consequent financial losses.  It is therefore essential that insurers preventively implement, for example, technological solutions such as network segmentation, device monitoring, the implementation of multi-factor authentication (MFA) mechanisms, data loss prevention and classification and information protection mechanisms.

However, in cybersecurity, there is no one – size – fit – all. The approach I advocate is to acquire solutions in the perspective of cyber – risk, and risk assessment as the cornerstone of a robust and holistic security strategy. This approach enables organizations to the proper selection of solutions to acquire, or implement, and ensures efficient application of available and correct budget prioritization of investment with the consequent reduction of the cyber – risk.

VVdW: What is the level of awareness of organizations in Portugal regarding cyber risk? Is there a need for awareness campaigns? By whom?

Mauro Almeida: Cyber – risk is already a key theme in top management agendas of organizations that effectively consider it as an operational risk. That is, a risk with the potential to generate a negative and profound impact on the organization, be it reputational, financial, regulatory, or capable of generating a break in production.

However, although we are seeing an increased awareness of organizations to cyber – risk, we also witness a considerable reduction in the level of confidence of these in their ability to manage it. This loss of confidence is often associated with the difficulty that companies have in understanding the likelihood, and priority, of the occurrence of these risks and how to act on them.

Another risk factor for organizations, which should not be neglected, is the fact that a large part of company employees is not aware of the issue and, therefore, do not take the necessary precautions. This risk is increased with a higher level of remote work, since employees are no longer on the perimeter of the organization and begin to use their home networks, to access confidential and sensitive information, or the assets of the organization. These personal networks do not have the same security controls as corporate networks and are yet another attack surface, uncontrolled by organizations.

Along with the adoption of some technological measures, it is essential to work on safety from the perspective of training and raising awareness among employees. It is not enough to invest in the best services, acquire the best hardware and software and define internal processes, if there is no investment in employees, who are really going to be at the forefront of the battle against cyber threats. It is wrong to think that users are the weakest link in organizations’ information security, when in fact they have the potential to be a company’s strongest element in protecting against security threats.

Content Home

Livefest 2019 Register Popup Event

Livefest 2019 Already Registered Popup Event

Livefest 2019 Join Live Logged-in Not Registered

Livefest 2019 Join Live Not Logged-in