Email
Newsletters
R&I ONE®
(weekly)
The best articles from around the web and R&I, handpicked by R&I editors.
WORKERSCOMP FORUM
(weekly)
Workers' Comp news and insights as well as columns and features from R&I.
RISK SCENARIOS
(monthly)
Update on new scenarios as well as upcoming Risk Scenarios Live! events.

Cyber Threats

Heading Off ‘Cybergeddon’

Cyber experts say resistance is futile, but resilience is paramount.
By: | May 8, 2014 • 3 min read
Cyber dragon

In April’s R&I cover story, Cyber: The New CAT, experts called catastrophic cyber attacks “inevitable” and the prevailing attitude in the C-Suite “denial.”

Jason Healey, director, Atlantic Council’s Cyber Statecraft Initiative, says that in order for organizations to weather the inevitable attacks, the key will be resiliency. “The organizations that fare best,” he said, “will be those that have the size, agility and resilience to bounce back as quickly as possible.” Healey is also author of Beyond Data Breaches: Global Interconnections of Cyber Risk, commissioned by Zurich Insurance Company Ltd. and published in April 2014.

Advertisement




Developing resilience would include conducting exercises, developing response playbooks, increasing funding and grants for large-scale crisis management and developing redundant data storage in case one is compromised.

The tangle of Internet information that companies and countries depend on to function is now so complex, Healey said, that companies and governments can’t manage the risk from within their own four walls. Beyond Data Breaches notes that Internet failures could cascade directly to Internet-connected banks, water systems, cars, medical devices, hydroelectric dams, transformers and power stations.

Like superstorms such as Hurricane Sandy, cyber risks are inevitable and unstoppable, and like the financial crisis of 2008, they can’t be contained, because of organizations’ interconnection and interdependency. The worst-case scenario, stemming from the principle that everything is connected to the Internet and everything connected to the Internet can be hacked, is “Cybergeddon,” where attackers have an overwhelming, dominant and lasting advantage over defenders.

Even now, Healey said, attackers have the advantage. The Internet’s original weakness — that it was built for trust, not security — perpetuates defenders’ vulnerability. “Some ‘serious’ thinkers suggest we should start over” rather than try to retrofit an Internet so flawed by weak security as to threaten every user, he said, despite the impracticality of a do-over.

Second, Healey said, defenders have to be right every time, and attackers have to be right only once.

Third, technology evolves very quickly, and most people don’t understand it well enough to lock out intruders. “Every time we figure out what we’re supposed to be doing right, the technology has moved on and once again we don’t know how to properly secure our data,” Healey said.

Software is still poorly written and so insecure that “a couple of kids in a garage” can hack into corporate and government systems just for a naughty thrill. “Bad guys” with theft or sabotage on their minds can work their mischief behind a veil of anonymity. “The Internet almost encourages bad behavior because of the anonymity involved,” Healey said.

Companies, governments and risk managers should shift the drumbeat from resistance to resilience, and to expand cyber risk management from individual organizations to a resilient and responsive Internet system, Healey said. For systemic risk management, Beyond Data Breaches recommends:

  • Putting the private sector at the center, not the periphery, of cyber risk efforts, since they have the advantage in agility and subject matter expertise.
  • Advertisement




  • Using monetary or in-kind grants to fund effective but underfunded non-government groups already involved in minimizing the frequency and intensity of attacks. Governments and others with system-wide concerns (such as internet service providers and software and hardware vendors) should advocate for this research.
  • Borrowing ideas from the finance sector. This could include examination of “too big to fail” issues of governance and recognition of global significantly important internet organizations.
Susannah Levine writes about health care, education and technology. She can be reached at riskletters@lrp.com.
Share this article:

Infographic: The Risk List

6 Costly Causes of Data Breaches

Network exposures can add up to big losses for companies. Presented by Travelers.
By: | October 15, 2014 • 2 min read
RiskList_Oct15 RiskList_Oct15 RiskList_Oct15

The Risk List is presented by:

RiskList_Oct15

RiskList_Oct15 RiskList_Oct15 RiskList_Oct15

The R&I Editorial Team may be reached at riskletters@lrp.com.
Share this article:

Sponsored: Liberty International Underwriters

A Renaissance In U.S. Energy

Resurgence in the U.S. energy industry comes with unexpected risks and calls for a new approach.
By: | October 15, 2014 • 5 min read

SponsoredContent_LIU
America’s energy resurgence is one of the biggest economic game-changers in modern global history. Current technologies are extracting more oil and gas from shale, oil sands and beneath the ocean floor.

Domestic manufacturers once clamoring for more affordable fuels now have them. Breaking from its past role as a hungry energy importer, the U.S. is moving toward potentially becoming a major energy exporter.

“As the surge in domestic energy production becomes a game-changer, it’s time to change the game when it comes to both midstream and downstream energy risk management and risk transfer,” said Rob Rokicki, a New York-based senior vice president with Liberty International Underwriters (LIU) with 25 years of experience underwriting energy property risks around the globe.

Given the domino effect, whereby critical issues impact each other, today’s businesses and insurers can no longer look at challenges in isolation one issue at a time. A holistic, collaborative and integrated approach to minimizing risk and improving outcomes is called for instead.

Aging Infrastructure, Aging Personnel

SponsoredContent_LIU

Robert Rokicki, Senior Vice President, Liberty International Underwriters

The irony of the domestic energy surge is that just as the industry is poised to capitalize on the bonanza, its infrastructure is in serious need of improvement. Ten years ago, the domestic refining industry was declining, with much of the industry moving overseas. That decline was exacerbated by the Great Recession, meaning even less investment went into the domestic energy infrastructure, which is now facing a sudden upsurge in the volume of gas and oil it’s being called on to handle and process.

“We are in a renaissance for energy’s midstream and downstream business leading us to a critical point that no one predicted,” Rokicki said. “Plants that were once stranded assets have become diamonds based on their location. Plus, there was not a lot of new talent coming into the industry during that fallow period.”

In fact, according to a 2014 Manpower Inc. study, an aging workforce along with a lack of new talent and skills coming in is one of the largest threats facing the energy sector today. Other estimates show that during the next decade, approximately 50 percent of those working in the energy industry will be retiring. “So risk managers can now add concerns about an aging workforce to concerns about the aging infrastructure,” he said.

Increasing Frequency of Severity

SponsoredContent_LIUCurrent financial factors have also contributed to a marked increase in frequency of severity losses in both the midstream and downstream energy sector. The costs associated with upgrades, debottlenecking and replacement of equipment, have increased significantly,” Rokicki said. For example, a small loss 10 years ago in the $1 million to $5 million ranges, is now increasing rapidly and could readily develop into a $20 million to $30 million loss.

Man-made disasters, such as fires and explosions that are linked to aging infrastructure and the decrease in experienced staff due to the aging workforce, play a big part. The location of energy midstream and downstream facilities has added to the underwriting risk.

“When you look at energy plants, they tend to be located around rivers, near ports, or near a harbor. These assets are susceptible to flood and storm surge exposure from a natural catastrophe standpoint. We are seeing greater concentrations of assets located in areas that are highly exposed to natural catastrophe perils,” Rokicki explained.

“A hurricane thirty years ago would affect fewer installations then a storm does today. This increases aggregation and the magnitude for potential loss.”

Buyer Beware

On its own, the domestic energy bonanza presents complex risk management challenges.

However, gradual changes to insurance coverage for both midstream and downstream energy have complicated the situation further. Broadening coverage over the decades by downstream energy carriers has led to greater uncertainty in adjusting claims.

A combination of the downturn in domestic energy production, the recession and soft insurance market cycles meant greatly increased competition from carriers and resulted in the writing of untested policy language.

SponsoredContent_LIU

In effect, the industry went from an environment of tested policy language and structure to vague and ambiguous policy language.

Keep in mind that no one carrier has the capacity to underwrite a $3 billion oil refinery. Each insurance program has many carriers that subscribe and share the risk, with each carrier potentially participating on differential terms.

“Achieving clarity in the policy language is getting very complicated and potentially detrimental,” Rokicki said.

Back to Basics

SponsoredContent_LIUHas the time come for a reset?

Rokicki proposes getting back to basics with both midstream and downstream energy risk management and risk transfer.

He recommends that the insured, the broker, and the carrier’s underwriter, engineer and claims executive sit down and make sure they are all on the same page about coverage terms and conditions.

It’s something the industry used to do and got away from, but needs to get back to.

“Having a claims person involved with policy wording before a loss is of the utmost importance,” Rokicki said, “because that claims executive can best explain to the insured what they can expect from policy coverage prior to any loss, eliminating the frustration of interpreting today’s policy wording.”

As well, having an engineer and underwriter working on the team with dual accountability and responsibility can be invaluable, often leading to innovative coverage solutions for clients as a result of close collaboration.

According to Rokicki, the best time to have this collaborative discussion is at the mid-point in a policy year. For a property policy that runs from July 1 through June 30, for example, the meeting should happen in December or January. If underwriters try to discuss policy-wording concerns during the renewal period on their own, the process tends to get overshadowed by the negotiations centered around premiums.

After a loss occurs is not the best time to find out everyone was thinking differently about the coverage,” he said.

Changes in both the energy and insurance markets require a new approach to minimizing risk. A more holistic, less siloed approach is called for in today’s climate. Carriers need to conduct more complex analysis across multiple measures and have in-depth conversations with brokers and insureds to create a better understanding and collectively develop the best solutions. LIU’s integrated business approach utilizing underwriters, engineers and claims executives provides a solid platform for realizing success in this new and ever-changing energy environment.

SponsoredContent

BrandStudioLogo

This article was produced by the R&I Brand Studio, a unit of the advertising department of Risk & Insurance, in collaboration with Liberty International Underwriters. The editorial staff of Risk & Insurance had no role in its preparation.


LIU is part of the Global Specialty Division of Liberty Mutual Insurance.
Share this article: