<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Insurance for Techs &#187; security</title>
	<atom:link href="http://www.insurancefortechs.com/blog/index.php/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.insurancefortechs.com/blog</link>
	<description>Commentary And Advice On Technology Insurance And Risk Management.</description>
	<lastBuildDate>Fri, 06 Jan 2012 18:46:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Small Companies Prime Target For ACH Fraud</title>
		<link>http://www.insurancefortechs.com/blog/index.php/2010/12/small-companies-prime-target-for-ach-fraud/</link>
		<comments>http://www.insurancefortechs.com/blog/index.php/2010/12/small-companies-prime-target-for-ach-fraud/#comments</comments>
		<pubDate>Mon, 20 Dec 2010 13:23:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Breach Of Security]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[cyber liability]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[loss]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[theft]]></category>

		<guid isPermaLink="false">http://www.insurancefortechs.com/blog/?p=235</guid>
		<description><![CDATA[Online criminals are targeting small to midsized businesses according to the US Federal Bureau of Investigation.  Hackers are getting away with over $100 million in bank fraud through malicious programs know as Trojans.  Trojans are planted into networks of target companies, stealing passwords to various online services such as fund management and online banking.  This [...]]]></description>
			<content:encoded><![CDATA[<p>Online criminals are targeting small to midsized businesses according to the US Federal Bureau of Investigation.  Hackers are getting away with over $100 million in bank fraud through malicious programs know as Trojans. </p>
<p>Trojans are planted into networks of target companies, stealing passwords to various online services such as fund management and online banking.  This opens up ACH or Automatic Clearing House Network Fraud where hackers wire money from the victim’s accounts and into the accounts of money “mules” that launder the money for a profit.  Criminal masterminds positioned in other countries such as China and Russia receive the funds since they are out of the reach of US law enforcement.    </p>
<p>The small and midsized businesses are favored because hackers know they often lack the time and money to put stringent security controls in place.  Even though this may be true there are ways to protect your business and yourself.  Educate your employee’s about the risk and instruct them in basic security awareness.  Also, use network security procedures such as web and mail filtering solutions, network firewalls, and antivirus software.</p>
<p>Source: US Federal Bureau of Investigation</p>
]]></content:encoded>
			<wfw:commentRss>http://www.insurancefortechs.com/blog/index.php/2010/12/small-companies-prime-target-for-ach-fraud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Funds Transfer And Computer Fraud Crime Insurance Coverages Needed</title>
		<link>http://www.insurancefortechs.com/blog/index.php/2010/12/funds-transfer-and-computer-fraud-crime-insurance-coverages-needed/</link>
		<comments>http://www.insurancefortechs.com/blog/index.php/2010/12/funds-transfer-and-computer-fraud-crime-insurance-coverages-needed/#comments</comments>
		<pubDate>Mon, 20 Dec 2010 13:16:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Breach Of Security]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[loss]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[theft]]></category>

		<guid isPermaLink="false">http://www.insurancefortechs.com/blog/?p=230</guid>
		<description><![CDATA[I found an excellent bulletin from Travelers Insurance that describes the financial threats posed by funds transfer fraud and computer fraud and the need for specialized Crime Insurance Coverage.  The Travelers coverage version, wrap +, includes both Electronic Funds Transfer and Computer Fraud coverages on a combined basis. Here are some eye opening facts: According [...]]]></description>
			<content:encoded><![CDATA[<p>I found an excellent bulletin from Travelers Insurance that describes the financial threats posed by funds transfer fraud and computer fraud and the need for specialized Crime Insurance Coverage.  The Travelers coverage version, wrap +, includes both Electronic Funds Transfer and Computer Fraud coverages on a combined basis.</p>
<p>Here are some eye opening facts:</p>
<ul>
<li>According to a 2008 survey by Computer Security Institute, the average financial loss due to computer fraud was $289,000.  The average loss due to funds transfer fraud was $500,000.</li>
<li>Pfishing scams, Trojan horses, key loggers and other techniques allow hackers to gain control of online banking transactions and to circumvent normal online authentication controls.</li>
<li>Internal controls such as antivirus, firewalls, and employee training are critical, but not enough for 100% protection. </li>
<li>Specialized Financial Insurance coverages should be purchased to protect against this risk.</li>
</ul>
<p>Electronic Funds Transfer Fraud Claim Examples:</p>
<ul>
<li>The bank of a victim company allegedly sent a letter explaining a new security program.  The company received the email that appeared to be from the bank and an employee opened the email.  Opening the email allowed a Trojan horse virus access, which read keystrokes from the company’s computer, thereby allowing the perpetrator to obtain banking and password information.  A fraudulent electronic wire transfer was initiated and the company lost $683,000.  </li>
<li>Finance director of a company opened an attached zip file in an email that contained a virus.  The user ID and password to the company’s account with its bank was obtained through code inserted by the virus.  A fraudulent electronic wire transfer totaling $147,000 was initiated by criminals from the company’s bank account to an unknown bank account in Arizona.   The immediate withdrawal was unrecoverable. </li>
<li>Payroll supervisor logged on to the payroll account for the company and noted that three payments totaling $704,632 had been wired from the account. The transactions were reported to the bank as unauthorized and the account was shut down.  Unfortunately, $238,781 was not recovered. </li>
</ul>
<p>Computer Fraud Claim Examples:</p>
<ul>
<li>An employee of a customer of a company hacked into the company’s website and changed the bank routing and account numbers to her own.  When the company paid her employer for services rendered, she fraudulently received the funds in her account. </li>
<li>A former employee used his supervisor’s password to enter the insured’s unlocked building and gained access to use the supervisor’s computer.  Using his bank routing number, he activated transactions to receive fake reimbursements allegedly made to the company’s customers.</li>
</ul>
<p> </p>
<p>Source: Travelers Bond &amp; Financial Products, Bulletin, 11-09</p>
]]></content:encoded>
			<wfw:commentRss>http://www.insurancefortechs.com/blog/index.php/2010/12/funds-transfer-and-computer-fraud-crime-insurance-coverages-needed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Electronic Fraud Overtakes Traditional Theft Losses</title>
		<link>http://www.insurancefortechs.com/blog/index.php/2010/10/electronic-fraud-overtakes-traditional-theft-losses/</link>
		<comments>http://www.insurancefortechs.com/blog/index.php/2010/10/electronic-fraud-overtakes-traditional-theft-losses/#comments</comments>
		<pubDate>Tue, 19 Oct 2010 14:20:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Breach Of Security]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[cyber liability]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[employees]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[loss]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[theft]]></category>

		<guid isPermaLink="false">http://www.insurancefortechs.com/blog/?p=218</guid>
		<description><![CDATA[For the first time, major international corporations are reporting higher fraud losses more from electronic theft of data than from physical stealing of assets, cash and inventory.  With 98 percent of businesses affected, China appears to have the highest level of fraud followed by Colombia with 94 percent and Brazil at 90 percent.   A recent study performed [...]]]></description>
			<content:encoded><![CDATA[<p>For the first time, major international corporations are reporting higher fraud losses more from electronic theft of data than from physical stealing of assets, cash and inventory.  With 98 percent of businesses affected, China appears to have the highest level of fraud followed by Colombia with 94 percent and Brazil at 90 percent.  </p>
<p>A recent study performed in 2010 showed that the amount lost by businesses to fraud rose from $1.4 billion to $1.7 billion over the previous year.  The majority of fraud losses have been from &#8220;inside jobs&#8221; carried out by company employees. </p>
<blockquote><p>&#8220;How much fraud there is depends more on opportunity than anything else,&#8221;  Tommy Helsby, Kroll chairman for Europe, Middle East and Africa, told Reuters.  &#8220;Much more work is done electronically, and that creates new opportunities for fraud. It takes time for companies to catch up with that.   There&#8217;s a real range of dangers,&#8221; said Helsby.    &#8220;&#8216;It can be simple theft or the risk of reputational damage if your firm loses customer data. That itself could be an existential threat to your business.&#8221;</p></blockquote>
<p>Many companies are discouraged from expanding in some crucial emerging markets, China, Africa, and Latin America due to their suspicions over fraud. </p>
<blockquote><p>&#8220;That means you miss out on some of the fastest growing markets,&#8221; said Helsby. &#8220;You can&#8217;t make the risk go away, but you can manage it through having the right systems in place.&#8221;</p></blockquote>
<p>With fraud losses at an all time high, Cyber Liability insurance is a critical part of the risk management plan of any major corportation.</p>
<p>Source: <a href="http://www.insurancejournal.com/news/national/2010/10/18/114098.htm" target="_blank">Insurance Journal</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.insurancefortechs.com/blog/index.php/2010/10/electronic-fraud-overtakes-traditional-theft-losses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Prevent Scammers From Figuring Out Your Social Security Number</title>
		<link>http://www.insurancefortechs.com/blog/index.php/2009/10/prevent-scammers-from-figuring-out-your-social-security-number/</link>
		<comments>http://www.insurancefortechs.com/blog/index.php/2009/10/prevent-scammers-from-figuring-out-your-social-security-number/#comments</comments>
		<pubDate>Mon, 19 Oct 2009 20:48:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[Identity infringement]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Social Security Number]]></category>

		<guid isPermaLink="false">http://www.insurancefortechs.com/blog/?p=148</guid>
		<description><![CDATA[I came across an excellent article that explains how easy it is for scammers to decode your Social Security number.  I always wondered how they did this. Carnegie Mellon University researchers only need two pieces of information to guess SSNs in a recent study published in the Proceedings of the National Academy of Sciences.  The [...]]]></description>
			<content:encoded><![CDATA[<p>I came across an excellent article that explains how easy it is for scammers to decode your Social Security number.  I always wondered how they did this.</p>
<p>Carnegie Mellon University researchers only need two pieces of information to guess SSNs in a recent study published in the <em><span style="text-decoration: underline;">Proceedings of the National Academy of Sciences.</span></em>  The study implies that knowledge of your hometown and your birth date allows scammers to discover most of, if not all, of the nine digits of your Social Security number.</p>
<p>$50 can buy your SSN from dozens of websites used by private investigators, businesses conducting credit checks, and savvy scammers who know your name, birth date, and current address.</p>
<p>And if the scammer doesn’t have the information, Alessandor Acquisti, the study’s lead researcher, says it is easy to find.  Acquistis states, “There are many websites and database where one can access the birth dates of thousands of people easily and cheaply.” </p>
<p>Public databases and voter registration lists include this information.  Over the years the first three digits of the SSN have been an “area number”.   The fourth and fifth has been a “group number” and the last four digits which are more difficult to guess are issued sequentially depending on how long the Social Security application took to process.</p>
<p>Today’s highest risk group for decoding are those born since 1988 because that is the year the Social Security Administration began to order SSNs for newborns and older children who did not already have a SSN.  The SSA plans to start a more arbitrarily process of assigning SSNs next year.</p>
<p>For those who use social networking websites such as Myspace, Facebook, Twitter, etc. or have online accounts, here are four easy ways to help prevent potential problems:</p>
<p>Do not use your birth date or any part of your SSN as a password.</p>
<p>Do not post any personal information such as your birth date, hometown and location of your high school.</p>
<p>If you post obituaries of loved ones, exclude hometowns and other personal information, as deceased are frequent targets.</p>
<p>Stay away from online security questions that ask for your hometown.</p>
<p>Source:  Sid Kirchheimer   <a href="http://bulletin.aarp.org/yourmoney/scamalert/articles/scam_alert_protecting_your_ssn.html?cmp=NLC-WBLTR-CTRL-101609-F7t" target="_blank">AARPBULLETINtoday</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.insurancefortechs.com/blog/index.php/2009/10/prevent-scammers-from-figuring-out-your-social-security-number/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Media Risks To Businesses</title>
		<link>http://www.insurancefortechs.com/blog/index.php/2009/10/social-media-risks-to-businesses/</link>
		<comments>http://www.insurancefortechs.com/blog/index.php/2009/10/social-media-risks-to-businesses/#comments</comments>
		<pubDate>Mon, 19 Oct 2009 14:13:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[cyber liability]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[employees]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://www.insurancefortechs.com/blog/?p=136</guid>
		<description><![CDATA[YouTube, Facebook, and Twitter have become prevalent and the risks involved for the workplace are often not taken into account. Here are a few threats that can be overlooked: 1.  Your Friends List “Social media” can be very helpful when making contact with customers, finding jobs, corresponding with potential clients, etc. But dangers lurk when [...]]]></description>
			<content:encoded><![CDATA[<p>YouTube, Facebook, and Twitter have become prevalent and the risks involved for the workplace are often not taken into account.</p>
<p>Here are a few threats that can be overlooked:</p>
<p>1.  Your Friends List<br />
“Social media” can be very helpful when making contact with customers, finding jobs, corresponding with potential clients, etc. But dangers lurk when all the people in your friends list have access to your comments. Ranting and raving about your boss and forgetting that he/she is listed as “your friend” can lead to obvious problems.</p>
<p>2.  Employers Fail To Set Internet Usage Policy<br />
Many companies are using blogs and social networking to their advantage; however, they can also become a liability risk. It is vital that policies are in place for how and when employees can use the Internet and that personal data is secured.</p>
<p>3.  Hackers Look For Any Open Door<br />
Any employee using these sites while on the job exposes the organization to phishing, being hit by spam, and malware attacks. One result shows that a quarter of all businesses have been affected by “social media” use in the workplace.</p>
<p>4.  Providers Fail to Take Appropriate Safety Measures<br />
Lawsuits are beginning to target the social media companies for privacy issues along with user-generated content. Several classmates set up a private group on Facebook. Now Facebook has been named in a lawsuit for over allegedly defamatory content contained in the private group’s comments.</p>
<p>5.  Ignorance Is Your Loss<br />
An even bigger danger is to ignore the social media frenzy. In doing so Companies lose the newest, most poplar opportunity to stay in touch with their markets, their clients, and build customer relationships. Just be wise in how your company uses social media.</p>
<p>Source: Patricia Vonwinkle   <a href="http://www.riskandinsurance.com/story.jsp?storyId=261687419" target="_blank">Risk and Insurance</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.insurancefortechs.com/blog/index.php/2009/10/social-media-risks-to-businesses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Floating In Cyberspace</title>
		<link>http://www.insurancefortechs.com/blog/index.php/2009/04/data-floating-in-cyberspace/</link>
		<comments>http://www.insurancefortechs.com/blog/index.php/2009/04/data-floating-in-cyberspace/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 14:25:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Breach Of Security]]></category>
		<category><![CDATA[cyber liability]]></category>
		<category><![CDATA[Errors & Ommissions]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[extrusion]]></category>
		<category><![CDATA[Identity infringement]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.insurancefortechs.com/blog/?p=103</guid>
		<description><![CDATA[Do you know how much of your organization’s data is getting into cyberspace?  Daily vital information about your company and your employees is seeping out and probably into the wrong hands.    There are laws in place in more that 40 states that are requiring companies to notify customers if their data may have been compromised.  Not [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: Arial;"><span style="font-size: small;">Do you know how much of your organization’s data is getting into cyberspace?<span style="mso-spacerun: yes;">  </span>Daily vital information about your company and your employees is seeping out and probably into the wrong hands.<span style="mso-spacerun: yes;">  </span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: Arial;"><span style="font-size: small;"> </span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: Arial;"><span style="font-size: small;">There are laws in place in more that 40 states that are requiring companies to notify customers if their data may have been compromised.<span style="mso-spacerun: yes;">  </span>Not only is damage done to the company’s reputation, but also in some states, if a company neglects to inform an individual of possible identity infringement, then they may face civil liability, regulatory and legal cost. </span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: Arial;"><span style="font-size: small;"> </span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: Arial;"><span style="font-size: small;">Founder and executive chairman of the board, Timothy Sullivan of Fidelis Security Systems has developed a risk management method that moves the focus from “intrusion” to “extrusion” prevention.<span style="mso-spacerun: yes;">  </span>Sullivan states that the way companies handle the personal data of their clients and employees are of utmost importance.<span style="mso-spacerun: yes;">  </span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: Arial;"><span style="font-size: small;"> </span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Arial;">Fidelis Security System’s XPS is the only one that runs at such high speeds to thwart unauthorized transfer of sensitive data on all network channels according to Sullivan.  The system provides content security to all e-mails, file transfers, and peer communications.<span style="mso-spacerun: yes;">  </span>Evidence of extrusions can be obtained to enforce laws that control privacy and financial data integrity, states Sullivan. </span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p>
<blockquote>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: Arial;"><span style="font-size: small;">“Ninety-eight percent of computer investment today involves trying to prevent people from getting into a system.<span style="mso-spacerun: yes;">  </span>We believe some of that money would be well spent in trying to keep information from getting out.”</span></span></p>
</blockquote>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: Arial;"><span style="font-size: small;">Source:<span style="mso-spacerun: yes;">  <span class="051060614-10042009">  Rough Notes Magazine, April 2009, Greg Davis </span></span></span><a title="http://www.roughnotes.com/" href="http://www.roughnotes.com/"><span style="font-size: small;">http://www.roughnotes.com</span></a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.insurancefortechs.com/blog/index.php/2009/04/data-floating-in-cyberspace/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

