About Emily Holbrook

Emily Holbrook is a former editor of the Risk Management Monitor and Risk Management magazine. You can read more of her writing at EmilyHolbrook.com.
Игроки всегда ценят удобный и стабильный доступ к играм. Для этого идеально подходит зеркало Вавады, которое позволяет обходить любые ограничения, обеспечивая доступ ко всем бонусам и слотам.

Proposal Would Increase Earthquake Coverage in CA

Surprisingly, only about 12% of insured households in California currently have earthquake insurance. For such an quake-prone area, 12% is just not enough and, luckily, a new initiative may provide a sharp increase in the number of households with coverage against such catastrophes.

According to a RAND Corporation study, a proposal for the federal government to support state-run catastrophe insurance programs would increase the number of people buying earthquake coverage in California. The plan would also lower both uninsured losses and government assistance following a major quake. The four main tenents of the Catastrophe Obligation Guarantee Act (COGA) are:

  • lower insurance costs
  • more households with earthquake insurance coverage
  • decrease in uninsured losses
  • decrease in demand for federal disaster assistance

The RAND Corporation’s study estimates that lower premiums will produce a 13.2% increase in the purchase of earthquake insurance from the California Earthquake Authority, the privately-funded organization that provides earthquake insurance to the state’s residents.

“While catastrophe obligation guarantees could substantially reduce earthquake insurance costs in California, they would ultimately have a modest effect on decreasing uninsured losses and reducing the amount of disaster assistance spending.” said Tom LaTourrette, lead author of the study and a senior physical scientist with RAND, a nonprofit research organization.

So, though the study predicts an increase in the purchase of earthquake insurance, a substantial portion of earthquake losses are expected to fall below policy deductibles. Thus, an increase in coverage would translate to “less than a 1% increase” in the amount of losses that would be reimbursed. So while COGA is expected to decrease the amount of uninsured losses after a California quake, it is not a total solution. The study suggests that officials consider other avenues for increasing earthquake insurance coverage, such as public education and marketing and new, more attractive earthquake insurance products.

Ernst & Young’s Global Information Security Survey

Last week, I attended the Ernst & Young media roundtable to hear the results of its 2010 Global Information Security Survey (GISS). The survey includes responses from participants in 1,598 organizations in 56 countries across all major industries.

With the increase in the use of external service providers and the adoption of new technologies such as cloud computing, social networking and Web 2.0, companies are increasingly exposed to data breach threats. In fact, 60% of respondents perceived an increase in the level of risk they face due to the use of social networking, cloud computing and personal devices in the enterprise. And according to the survey, companies are taking a proactive stance as 46% indicated that their annual investment in information security is increasing. Though IT professionals are trying, not all are succeeding in keeping up with new tech threats.

“I’ve never seen this kind of shift in IT before,” said Jose Granado, the America’s practice leader for information security services within Ernst & Young. “Security professionals are trying to keep up with the pace, but aren’t really doing a great job. The have limited resources and a limited budget.”

A concern for IT professionals is mobile computing. Demands of the mobile workforce are driving changes to the way organizations support and protect the flow of information. In fact, 53% of respondents indicated that increased workforce mobility is a significant or considerable challenge to effectively delivering their information security initiatives. Aside from investing more on data loss prevention technologies, 39% of respondents are making policy adjustments to address the potential new or increased risks.

“You have to implement realistic policies,” said Chip Tsantes, principal within the financial services division of Ernst & Young. “They need to be liveable and workable, or else people will go around them. You can’t simply ban things.”

Another major concern for IT pros is the gaining popularity of cloud computing. Both Granado and Tsantes were shocked to learn that 45% of respondents (primarily those on the non-financial services side) are currently using, evaluating or are planning to use cloud computing services within the next 12 months.

“From the standpoint of a traditional IT security professional, endorsing or supporting a cloud environment is counter-intuitive,” said Granado. “How do I know where my data is and how do I know it is protected?”

So how do companies increase their confidence in cloud computing? According to the survey, 85% say that external certification would increase their trust.

So I asked Granado and Tsantes if they could tell me when they believed there would be a universal set of standards for cloud computing providers. Granado feels there is a two-to-three year timeline in regards to having something solidified. He says businesses are going to drive it; If businesses continue to push, “cloud providers would have to follow.” With more and more sensitive data calling the cloud home, let’s hope Granada is being conservative with his estimate.

cloud computing2

November Issue of Risk Management Now Online

It’s that time again — a new issue of Risk Management magazine is now online. The cover story in our November issue celebrates the 100th anniversary of the modern U.S. workers compensation system and highlights the fact that even though workers comp is only 100 years old, its principles date back a millennium.

Additional features in the newest issue are a first-hand account by Michael Cawley of 25 lessons learned during his 25 years as a risk manager, the pros and cons of cloud computing and seven steps to building a successful workers comp program.

Our columns explore topics such as the rise in workplace suicides, the largest data breach in history, regulatory uncertainty within the insurance industry, the Red Flags Rule, and human clinical trial insurance in South Korea. Also included are monthly staples such as our articles highlighting recent industry reports (Findings) and our book reviews (Shelf Life).

If you enjoy what you seen online, you can subscribe to the print edition to enjoy even more content.

Please let us know what you think in the comments below. And stay tuned to the blog for even more coverage in the future. Lastly, you can follow the magazine on Twitter“like” us on Facebook and join our LinkedIn group.

October: A Busy Month for Data Breaches

Every company, no matter what industry it is aligned with or what country it is based in, is vulnerable to losing sensitive data, either accidentally or by malicious endeavors. The Ponemon Institute has found that the average cost of a data breach in 2009 was an incredible $3.4 million. And, unfortunately, the frequency with which these breaches occurs appears to be increasing. Let’s take a look at some of North America’s more notorious breaches for October 2010:

October 14: In Lake County, Florida, a credit union employee stole customer’s credit information to take out loans — money which was used to help finance the attorney fees of her son, who is on death row for murder. The employee, Nazreen Mohammed, was accused of attempting to take $430,000 from banks such as RBC and Fairwinds Credit Union.

October 14: An employee of Accomac, Virginia had his laptop computer stolen while on vacation in Las Vegas. The computer held the names and Social Security numbers of approximately 35,000 county residents. The employee took the laptop on a personal vacation without permission from his superiors.

October 14: Though the incident occurred in August, it wasn’t recognized until October when the Veterans Benefit Administration Office in Boston realized they sent 6,299 benefit letters to the wrong address. All nine digits of Social Security numbers were on 3,936 of the letters. A Veteran’s Affairs report blamed the incident on programming error.

October 15: On this date, the University of North Florida reported that more than 100,000 people could be affected by a security breach. UNF stated that a file containing personal information on prospective students was possibly accessed by someone outside the United States. The university is working with the FBI “to determine the cause and intent of the breach.”

October 20: The personal information of 280,000 Medicaid members in Pennsylvania was compromised when a portable hard drive belonging to Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan was lost. “The insurers said they have beefed up security practices and will provide free credit-monitoring assistance to the people whose Social Security numbers, either in whole or in part, were on the missing hard drive.”

October 21: The Thames Valley District School Board in Ontario, Canada shut down its online student portal after it realized that the internet passwords of more than 27,000 high school students were compromised. The culprit in this incident posted a link on Facebook that directed users to a site that listed the names and passwords of students.

This, however, is only a partial list. More incidents can be found at DataLossDB.org.

Does your company have a solid cybersecurity strategy? If not, check out the article, The 5 Steps of a Cybersecurity Risk Assessment, by Peyton Engel, a data security expert at CDW.

keyboard