Printer Friendly
The Free Library
14,503,364 articles and books
Member login
User name  
Password 
 
Join us Forgot password?

IT experts: tighten cyber-security. (Property/Casualty: Loss/Risk Management Notes).


A cyber-loss control expert at Chubb Group of Insurance Cos. is advising U.S. companies to increase their cyber-security.

"Cyber-warfare is a real possibility, given the skill sets and resources of today's terrorists and cyber-criminals," said James Tucker, assistant vice president, Chubb & Son, and loss control computer security specialist, Chubb Commercial Insurance. "The threat of cyber-terrorism, push-button (electronics) push-button - A roughly fingertip-sized plastic cover attached to a spring-loaded, normally-open switch, which, when pressed, closes the switch. Typical examples are the keys on a computer or calculator keyboard and mouse buttons.  warfare and launching online bombs at corporate targets thousands of miles away is very real."

Tucker noted that a successful cyber-security breach could translate into significant financial loss, loss of market share, loss of reputation and a falling stock price, significantly impacting shareholder value.

The Business Software Alliance has released a survey that mirrors this concern. The U.S. Business Cyber Security Study, which was conducted by Ipsos Public Affairs Those public information, command information, and community relations activities directed toward both the external and internal publics with interest in the Department of Defense. Also called PA. See also command information; community relations; public information. , questioned 602 information technology professionals and more than 1,000 Internet users Internet user ninternauta m/f

Internet user Internet ninternaute m/f 
. The study found that this industry segment thinks the risk of a major cyber-attack on U.S. businesses has increased since Sept. 11. While about 62% of respondents In the context of marketing research, a representative sample drawn from a larger population of people from whom information is collected and used to develop or confirm marketing strategy.  said the risk has grown, 47% think U.S. businesses are likely to face a major cyber-attack within the year.

To help companies respond to cyber-terrorist threats, Tucker recommends 10 steps for companies to take in designing an information and networking security program:

1. Don't downplay down·play  
tr.v. down·played, down·play·ing, down·plays
To minimize the significance of; play down: downplayed the bad news.

Verb 1.
 the risk. Acknowledge that the cyber-terrorist threat exists and prepare for cyber-warfare.

2. Emphasize prevention over repair and invest in an enterprisewide cyber-security plan.

3. Institute a corporate cyber-risk management, information and network security assessment with input from representatives of all disciplines within the company, not just the information technologists.

4. Appoint a senior executive who will be responsible and accountable for the assessment and the security plan.

5. Establish trust within and outside the organization. Include supply chain, Internet service providers Internet service provider (ISP)

Company that provides Internet connections and services to individuals and organizations. For a monthly fee, ISPs provide computer users with a connection to their site (see data transmission), as well as a log-in name and password.
, business partners and vendors in the assessment plan and demand confirmation of the sturdiness stur·dy  
adj. stur·di·er, stur·di·est
1. Having or showing rugged physical strength.

2. Substantially made or built; stout: sturdy canvas.

3.
 of security systems.

6. Establish internal information security education, training and awareness.

7. Initiate security auditing, validation See validate.

validation - The stage in the software life-cycle at the end of the development process where software is evaluated to ensure that it complies with the requirements.
 and measurement processes. Report all security violations, not just the major ones.

8. Use independent cyber-security expertise to test and validate To prove something to be sound or logical. Also to certify conformance to a standard. Contrast with "verify," which means to prove something to be correct.

For example, data entry validity checking determines whether the data make sense (numbers fall within a range, numeric data
 security systems.

9. Protect critical servers. The Internet may provide easy and unwelcome access from outsiders.

10. Conduct a risk assessment and evaluate the cost effectiveness of implementing protection. For example, evaluate the trade-off between how well and how fast a Web site functions, and the security issues.
Risk of Major Cyber-Attack On U.S. Businesses

Do you think that the risk of a major cyber-attack on U.S. businesses
has strongly increased, somewhat increased, remained the same, somewhat
decreased, or strongly decreased since 9/11?


Strongly Increased  14%
Somewhat Increased  48%
Remained the Same   30%
Somewhat Decreased   5%
Strongly Decreased   2%
Not Sure             1%

Source: Ipsos Public Affairs

Note: Table made from pie chart
COPYRIGHT 2002 A.M. Best Company, Inc.
No portion of this article can be reproduced without the express written permission from the copyright holder.
Copyright 2002, Gale Group. All rights reserved. Gale Group is a Thomson Corporation Company.

 Reader Opinion

Title:

Comment:



 

Article Details
Printer friendly Cite/link Email Feedback
Comment:IT experts: tighten cyber-security. (Property/Casualty: Loss/Risk Management Notes).
Publication:Best's Review
Article Type:Brief Article
Geographic Code:1USA
Date:Oct 1, 2002
Words:462
Previous Article:Maximizing the market: if this hard market doesn't last long, it's more critical than ever to seize the opportunities. (Property/Casualty:...
Next Article:AIR clarifies data. (Property/Casualty: Loss/Risk Management Notes).(Brief Article)
Topics:



Related Articles
Looking Ahead.(Brief Article)
High-Tech Fidelity.(cyber crimes)
Deleting the risk: Hackers invading corporate Web sites by using more sophisticated techniques fuel the market for cyber-risk insurance. (Cyber-Risk:...
Securing D&O in a hard market. (Insurance).(directors and officers liability insurance industry)
A megabyte of prevention. (Up front: news, trends & analysis).(against computer crimes)(Industry Legal Issue)(Industry Trend or Event)(Brief Article)
Chubb's cybersecurity targets financial institutions. (Property/Casualty: Marketplace).(Brief Article)
The unlikely heroes of cyber security: viruses, privacy breaches, and other malicious cyber activity regularly threaten organizations' vital...
D&O [directors and officers insurance] recovery linked to realistic rate base: Reeling from the effects of corporate scandals, D&O insurers are tying...
Under separate cover: Internet risks have become so great that some insurers have taken them out of general liability policies and given them...
New test for Loss Controllers.(Loss/risk management notes: property/casualty)(Brief Article)

Terms of use | Copyright © 2009 Farlex, Inc. | Feedback | For webmasters | Submit articles