News: Spotlights

Real estate and cyber liability - by Spencer Macalaster and Robert Rosenzweig

Spencer Macalaster

 

Robert Rosenzweig

 

The past 24 months have been unprecedented with respect to society, work environments and political dictates. Entire companies pivoted to remote work environments in a matter of days. The consequential strain on the IT infrastructure was also unprecedented. One consequence of this new paradigm is system vulnerabilities were exposed. Every day a new company is added to the list of systems affected by a massive data breach. Hackers responsible for these types of security breaches can hold a company ransom or worse destroy their reputational credit. Real estate owners, developers, and asset managers are in the cross hairs of those bad actors looking to monetize on cyber vulnerabilities. Massachusetts requires companies to provide comprehensive data security to all personal information stored on a server. In addition, regulators in 47 states, the District of Columbia, Puerto Rico, and the Virgin Islands require that individuals (customers, employees, citizens, students, etc.) be notified in the event their data has been lost, stolen or compromised. The most recent data breaches introduce a new twist to a company’s cyber liability exposure and potential for exposure to extortion and ransom.

Computer hacking, stolen laptops and fraud scams are the primary culprits leading to cyber liability events. Settlements can include monetary damages, credit monitoring services, hardware and software restoration, business interruption, reputational damages and ransomware payments. Companies can incur millions of dollars in expenses to secure compromised networks, assess damages, and notify customers.

Protection on any corporate database will never be 100% secure. As soon as security measures, such as firewalls, are developed the cyber thieves are creating ways to breach those security measures. With the shift to remote work, contactless services, and increased health/safety precautions, corporate exposures expanded dramatically. Internet security protection is a continual process that cannot be solved entirely by technical means. There are many steps you can take to enhance your protection. Implement multi-factor authentication, don’t respond to emails or phone calls requesting your personal information. Use unique usernames and strong passwords for any online account. Make sure you have the most up to date security software installed on your computers. Cyber threats are now recognized as one of the biggest threats to business and individuals and are a matter of national security.

Cyber-crime is highly lucrative and provides huge financial incentives to the criminals who can derive large payouts from the data stolen. According to IBM the average cost of a cyber event is $3.8 million. Every company should evaluate the exposure and look into cyber insurance as a financial backstop to their data security risk management. Traditional insurance products, including property, general liability and professional liability, do not address cyber risks. As with most special types of risks, it takes a specialty insurance product to address the exposure. Cyber liability policies have been expanding in coverage to include privacy notification expenses, hardware restoration, business interruption expenses and ransom costs.

The bottom line is all companies are exposed to data security breaches. The financial consequences can be enormous, historically most companies relied almost exclusively on technological solutions to manage the risk. There is a growing awareness at many companies that data security should not be exclusively an IT issue, making cyber insurance coverage a standard part of a company’s risk management strategies.

In addition to evaluating the cost and coverage available through your insurance broker, we recommend conducting your own “cyber hygiene” analysis to protect against threats of loss. Cyber hygiene is a set of practices for managing the most common and pervasive cybersecurity risks faced by companies today:

• Identify and prioritize key organizational services, products and assets;

• Evaluate and respond to a company’s key services and products;

• Establish an incident response plan;

• Maintain a proactive and continuous educational and training program;

• Maintain continuous and updated security and monitoring;

• Implement controls to protect and recover data;

• Monitor and manage supplier and supply chain dependencies;

• Implement “MFA” (multi-factor authorization) throughout the organization;

• Perform continuous cyber threat and vulnerability monitoring.

Cyber exposures require an all hands on deck approach. Hardware, software, training, and insurance must work in a coordinated way to fully protect your company from significant financial loss and reputational harm.

Spencer Macalaster is an executive VP and Robert Rosenzweig is a VP/national cyber risk practice leader at Risk Strategies Co., Boston, MA.

READ ON THE GO
DIGITAL EDITIONS
Subscribe
READ ON THE GO
DIGITAL EDITIONS
Subscribe
Quick Hits
STAY INFORMED FOR $9.99/Mo.
NEREJ PRINT EDITION
Stay Informed
STAY CONNECTED
SIGN-UP FOR NEREJ EMAILS
Newsletter
Columns and Thought Leadership
Shawmut Design and Construction breaks ground on the 195 District Park Pavilion in Providence, RI

Shawmut Design and Construction breaks ground on the 195 District Park Pavilion in Providence, RI

Providence, RI Shawmut Design and Construction celebrated the ceremonial groundbreaking for the 195 District Park Pavilion, marking the start of construction on a facility that will feature year-round dining and support space for park operations. In addition to the 3,500 s/f building, the project will include infrastructure upgrades
The New England Real Estate Journal presents<br> the First Annual Project of the Year Award! Vote today!

The New England Real Estate Journal presents
the First Annual Project of the Year Award! Vote today!

The New England Real Estate proud to showcase the remarkable projects that have graced the cover and center spread of NEREJ this year, all made possible by the collaboration of outstanding project teams. Now, it's time to recognize the top project of 2024, and we need your vote!
Investing in a falling rate environment - by Harrison Klein

Investing in a falling rate environment - by Harrison Klein

Long-term interest rates have fallen by 100 basis points, and the market is normalizing. In December of 2022 I wrote an article about investing in a high interest rate, high inflation market. Since then, inflation has cooled off, and the Fed has begun lowering their funds rate.
The 2024 CRE markets: “The Ups” (industrial) and “The Downs” (Boston class B/C office) - by Webster Collins

The 2024 CRE markets: “The Ups” (industrial) and “The Downs” (Boston class B/C office) - by Webster Collins

The industrial markets have never been stronger. What has happened is that the build out of Devens with new high-tech biotech manufacturing with housing to service these buildings serves as the connector required to really make the I-495 West market sizzle. Worcester has been the beneficiary