Editor’s Note:  The comparison of a potential massive cyber-failure with Huricane Katrina has been used before, albeit with respect to the importance of preparation and planning.

From: Reactions

Feature: New laws coming into force in the EU are set to intensify the pressure on corporations to tighten their cyber security or face harsh financial penalties, increasing their insurers’ potential exposures.

New European regulations are forcing large corporations to closely examine cyber security and what measures they are taking to mitigate against potential cyber breaches. European legislators are putting into place complex new data protection laws that will force all companies to make customers aware of data breaches.

The new laws are designed to bring cohesiveness to pan-European regulations and to bring uniformity to cyber security across the European Union’s member states.Tanguy Le Gouëllec de Schwarz, partner at law firm Goldberg Segalla, suggests that the law is similar to previous EU regulations.

“The large majority of the regulation is not very different at all from the original regulation, the centrepiece of which was the directive 95/46ED. That was the directive that was established from which local laws, such as the data protection 1998 in the UK for instance, were derived.”

He adds that the laws are there to bring all EU member states in line with one another and to ensure that they all behave in a similar fashion.

“Unfortunately some of the member states enacted this directive in slightly different ways,” he says.

“The primary object of creating these regulations is to streamline everything across all member states. It’s not necessarily because a lot of things have happened and there was a need for legislation. It’s just to make sure that everybody behaves the same way. This is especially true with respect to protection of individual’s personal data and the free movement of that personal data, so the object of the regulation is still to protect the individual.”

However, the new laws are unique in the fact that they bring to the table new penalties for non compliance.

This is going hand in hand with the requirement that almost all industries are soon to be required to notify their customers in the case of data breaches, says Tom Scourfield, partner and the UK head of intellectual property at CMS Cameron McKenna.

Le Gouëllec de Schwarz comments that data breach notification makes up the vast majority of the new regulations. “Now the regulation will make everybody responsible for data breach notifications and that is across the board regardless of how much personal data you handle,” he says.

“There is a threshold of 500 individuals personal data where you don’t have to follow some of the regulations but regarding data breach notifications that is something everybody needs to abide by. The other big change is the level of accountability and transparency that the company will have to have.”

Another fine mess

Another important change is the potential severity of the fine that companies are likely to face if they are found to not be compliant with the data protection regulations.   “There have always been data protection laws, for example in the UK if you seriously contravene the data protection legislation you can be fined to up to £500,000 [$775,550],” explains Scourfield.

“It’s a not an insubstantial amount but at that value it’s not worthy of board level attention. However, when the new European data protection regulation comes into force that number is likely to change from £500,000 to 2% of global turnover.

“So if you’re a large multinational and you get it wrong and suddenly you’re looking at up to 2% of global turnover it immediately gets everybody’s attention. Obviously this would be only in the worst case scenario.”

Worryingly, the fine in itself is not the only economic consequence that insureds could face if they suffer a large data breach, however.

“If you had a massive 2% turnover fine the effect on the company’s value could be considerably more than 2%,” says Stephen Tester, partner in the insurance and reinsurance group at CMS Cameron McKenna.  “This raises the spectre of stockholder derivative claims against the company’s directors if it can be shown that relevant officers failed to have proper procedures in place to stop this kind of thing from happening (or failed to ensure that the procedures were followed).”

Tester reports that there is a debate about whether a fine itself is insurable.

“There is a big question about the extent to which you can insure the fine itself,” he says. “The answer tends to vary depending on who has imposed the fine and the applicable law and jurisdiction. In the UK, for example, the FCA [the new Financial Conduct Authority] has made it clear that its fines cannot be insured but there is more uncertainty with regards to the types of fines you can get from data protection agencies.”

Insurers may, however, be able to cover the costs that companies will have to pay in dealing with data breach investigations.

“There is less controversy about cover for the costs of dealing with investigations that might lead up to fines,” says Tester.“The best view is probably that you can normally cover your costs in dealing with investigations. There may have to be some provision for clawing back those costs if it was found that there was some kind of morally reprehensible behavior but in general terms it should be possible to cover them.”

The final and most difficult area of potential costs associated with data breaches is a firm’s reputational damage. Tester concedes this is difficult to quantify, especially if there is a substantial claim associated with it.

“Quite apart from the fines and so on there is the reputational damage that is caused by all this,” he says. “It is very difficult to cover reputational damage per se and a number of insurers have given thought to how they might cover it but none have really come up with any good ideas other than to meet the costs of PR consultants who are engaged to try and contain the reputational fall-out.”

An untested market

One of the problems that is currently associated with cyber as a specialist line of business is that there are very few models that exist to quantify how expensive it is to write and how it should be underwritten.

Dan Gerber, partner at Goldberg Segalla, says that the insurance industry is still waiting to feel the full brunt of potential cyber security breaches and how costly they can be.

He comments: “The industry may be waiting for its Hurricane Katrina moment with respect to cyber.” This lack of a market-changing cyber incident means some in the industry have historically taken a more relaxed approach to cyber security risk. This approach could be harmful to the industry if it was to see a greater frequency in expensive cyber incidents.

Read Complete Article