Politics

When Cyber insurance is not enough: Hamilton’s lesson

The column – Cybersecurity Week

The following is a brief “educational” story for those who think (unfortunately they are more than you think) that an insurance against the risk of cyber attacks is the solution of the problem. He ran the month of February 2024 and the Canadian city of Hamilton was suddenly on his knees. A ransomware attack, sophisticated and targeted, had compromised about 80% of the city network, blocking for weeks critical services such as the issue of commercial licenses, transport planning, tax management. Some systems, including the registers of the firefighters and those for the management of road signs will be discovered later that they will be unrecoverable. The criminals asked for a ransom of $ 18.5 million. The city did not pay, judging the recovery through tools provided by criminals risky and unreliable. On the other hand, the expenditure for the response to the attack, the restoration of the systems and the support of external experts today reached 18.3 million, of which 14 million only for technical consultancy. And for the future the Municipality expects further costs. Of course, the emergency was managed in record time of two days, but above all there was the “great hope” because the city had entered into a specific policy for the cyber risk. Too bad that after a year and a half the insurance company has definitively rejected the request for compensation. The reason? At the time of the attack, the authentication to multiple factors (MFA) had not been completely implemented, a condition explicitly provided by the coverage policy. The city did not even think of bringing the company to court given the evidence of the facts; Hence, he has invested other millions of dollars to improve the safety of his systems and then renewed insurance coverage. Cyber policies are quite complex, also because the same insurances make a huge effort to evaluate the risk, but, and this is a gigantic banality, as always when it comes to digital, it seems that people escape the most elementary logics. If you leave the door open and give you the reimburse insurance? Obviously not. If you leave the keys in the car and steal it, will you be compensated? Clearly not. If someone takes money with your card from a counter using the pin, will the bank return you the money? Obviously not. So, for what arcane mystery, many think that, if they enter into a cyber policy without securing the systems, will the insurance pay? Clearly they are devoid of any abstraction capacity.