Target as Target
After fumbling its initial response to a massive data breach, Target Corp. has rebounded, according to experts in crisis management.
However, they said, the retailer still faces challenges in regaining consumer confidence, especially among people directly harmed by the cyber attack, which struck at the height of the holiday shopping season.
In late November and early December, malware lodged in the retailer’s point-of-sale system siphoned off account and personal information for up to 110 million customers. But Minneapolis-based Target is not the only company that may have been struck. Luxury retailer Neiman Marcus suffered a smaller breach, and news reports suggest at least six other retailers have been hit. These other companies likely are keeping a close eye on Target’s handling of the crisis.
Critics have focused, in part, on the company’s early communications. Target appeared initially to underestimate the gravity of the situation, crisis consultants said. For example, Target’s first message to customers apologized for the inconvenience.
“You don’t call something like this an inconvenience,” said Rich Klein, a crisis management consultant in New York City.
Subsequent messages from Target used stronger language, acknowledging customers’ stress and anxiety, he said. Messages also switched from assuming customer confidence to promising to regain it, Klein added, praising the change.
“I would still say it’s so much better to get it right the first time,” he said.
Still, he added, the company made good use of its Twitter feed and Facebook page. Facebook, for example, was used only to communicate about the breach, not to advertise sales, though it also acted as something of a lightning rod for complaints.
Consultants also panned the company’s decision to extend a 10 percent discount to shoppers during the weekend of Dec. 21, a few days after news of the breach first surfaced. While the discount was a nice gesture, it did not adequately address customer concerns and seemed to suggest the crisis had passed, consultants said.
In addition, the company has occasionally appeared to be behind the news, with information trickling out in the media before being revealed by Target, said Jeff Jubelirer, vice president of Philadelphia-based Bellevue Communications Group. “We should expect more from a retailer of that size and that reputation and that level of success.”
A key turning point came on Jan.13 when the company’s CEO, Gregg Steinhafel, appeared on CNBC, apologizing for the breach, reassuring customers and defending the company’s reaction:
Steinhafel should have been giving interviews in December, said Jonathan Bernstein, an independent crisis management consultant in Los Angeles. “They would have suffered less loss of sales and less impact on their stock value if they had been more assertive from the get-go.”
Other observers gave Target high marks for making a relatively quick disclosure of the breach and offering a free year of credit monitoring to customers. The four-day gap between discovery of the breach on Dec. 15 and public disclosure on Dec. 19 was faster than it’s been in other cases, said Alysa Hutnik, an attorney in the Washington, D.C. office of Kelley Drye.
“I haven’t done the math, but I think that would rate somewhere at the very top,” said Hutnik, who specializes in cyber security issues.
Another high point is the prominent role of Target’s CEO, Hutnik said. “He knows there’s work to be done to earn back customer trust, and it looks like he is taking that obligation seriously,” she said, noting that top executives rarely serve as public faces after a data breach.
Other positive steps include Target’s $5 million investment in cyber security education said Michael Soza, a partner in accounting and consulting firm BDO.
“This latest move … is really going on the offensive to show that they really are trying to get out in front of this thing and really attack what is not just a Target problem,” Soza said.
As long as no other damaging details leak out, most customers will remain loyal to the chain, said Daniel Korschun, an assistant professor of marketing at Drexel University in Philadelphia.
But the company will have to work harder to win back customers who suffered directly. They will be hard to find and hard to soothe, especially if they’ve had to spend hours on the phone undoing damage to their credit or bank accounts.
“Those are the ones where the trust has really been lost,” Korschun said.
Cyber Trolls Menace Reputation and Revenue
Cyber attacks aren’t always the immediately quantifiable attacks of old when hackers steal customer data, sites are harried by denial of service attacks and computer networks are compromised and hijacked.
A new breed of orchestrated campaigns dubbed “troll attacks” are now in the mix.
These attacks, which feature organized disinformation campaigns augmented by social media posts, create an atmosphere of chaos and economic disruption, and can have ripple effects on a company’s reputation and a downstream impact on revenue.
A recent New York Times story by Adrian Chen details one source for such attacks. A pro-Kremlin company called the Internet Research Agency in St. Petersburg, Russia, faked a story on Sept. 11, 2014, about a chemical plant explosion in St. Mary Parish, La., which is a center for numerous chemical companies.
When word of the bogus disaster spread, there was extensive concern online, enflamed by fictional eyewitness accounts on Twitter about the plant explosion and fire.
“If the Russians want to convince the Western world that something dreadful has happened, they could pretty much hoodwink the world.” — Simon Milner, broker, Miller Insurance
According to a whitepaper published in May 2015 by Hays Cos., cyber attacks were once mostly about individuals stealing money or data but now some attacks are about “brand terrorism” that can create an environment of chaos and economic disruption.
“Our clients have seen various types of malicious or mischievous activity, although not to the extent described in the New York Times article,” said Dave Wasson, cyber liability practice leader for Hays Cos., based in Chicago.
“The Internet has provided incredible transparency for sharing information on an anonymous basis and that can often be viewed as one of the best attributes of the Internet. But that transparency cuts both ways in that the Internet provides an equal transparency for sharing misinformation.”
Simon Milner, a broker with Miller Insurance in London, began working in the cyber space nearly 20 years ago and says troll attacks have relatively low frequency but are potentially damaging “blunt instruments.”
Former Soviet Republics — Russia, Estonia, and Latvia — are behind many of these orchestrated efforts, as detailed in the New York Times investigation, he said.
“If the Russians want to convince the Western world that something dreadful has happened, they could pretty much hoodwink the world.”
“I don’t necessarily believe that reputation and revenue can be fully distinguished,” added Wasson.
“Consumers will choose companies they trust and part of that trust is the company’s security. The math underlying reputational harm is very difficult to measure.
“For public companies, we have stock prices, although that certainly doesn’t make valuation easy. It’s still more difficult to measure the financial impact of a diminished reputation for a privately held, nonprofit, or government entity.”
So what insurance solutions should risk managers look for? That depends on the potential exposure, according to James Murtaugh, managing director for BDO Consulting, based in New York City.
Coverage for any kind of cyber attack might fall under a wide variety of policies, including business interruption, GL, property, E&O, D&O and EPLI, depending on how the event affected the company’s revenue and reputation.
He noted that cyber-specific coverages have a shorter waiting period but the loss can be more substantial in a shorter period of time.
“With cyber attacks, the numbers could be too big, in the billions of exposure,” he said.
“Every cyber loss is a very complicated event.”
There are also challenges when trying to explain to the C-suite how troll attacks might impact a company financially, said Murtaugh, who specializes in calculating maximum foreseeable losses from business interruption claims, particularly related to supply chains.
“With cyber attacks, the numbers could be too big, in the billions of exposure.” — James Murtaugh, managing director, BDO Consulting
He advises risk managers to use enterprise risk management (ERM) language to treat reputation risk the same as any property peril, and to get away from the notion that this is all IT-related, because it is not.
“We’re seeing the turning point where people are still definitely uncomfortable about their exposure but understand they have to get more comfortable about it instead of keeping their heads in the sand,” said Michael Born, vice president of global technology and privacy practice for Lockton Cos., based in Kansas City, Mo.
“They need to get their arms around it, and have discussions about what are the exposures [and] what they can do about it. It’s becoming more of a discussion because of the [overall] discomfort about the topic of cyber risks.”
Whether such attacks could harm an individual company’s reputation enough to impact revenue is the open question.
For Born, naming the perils in a troll attack could consist of a media attack (either planted stories on real media or all-out fake media sites), bogus social media posts and fake websites.
“The [cyber] exposures that we’re talking about are changing so fast that it’s hard to keep up with them even when you’re in the business 24/7,” said Born, who advises companies to look for consulting firms that provide constant vigilance over online reputation and business intelligence.
“For a company not in the business of cyber security, it’s very, very difficult to keep up with all that stuff.”
“In event that there was an attack by a Russian-backed troll organization,” Milner said, “our products would pay for a PR consultancy to rehab the image of the policyholder and should there be a significant BI loss, that would also be covered.”
Finally, how can risk managers protect against such attacks, aside from insurance?
Wasson advises high-profile companies — those that are involved in critical infrastructure or have controversial political, religious or ideological stances or activities — to plan for malicious troll attacks as they would for any business continuity, disaster recovery or incident response.
“It doesn’t currently seem that an entity can materially change their exposure to this risk, so the two main things an entity can do are prepare their response plan and, onerous as it may be, treat all information assets as mission-critical,” he said.
“There are certain tools a company can use to check if they are being mentioned on the dark web, but it’s not a given that dark web chatter will precede such an event.”
Pathogens, Allergens and Globalization – Oh My!
In 2014, a particular brand of cumin was used by dozens of food manufacturers to produce everything from spice mixes, hummus and bread crumbs to seasoned beef, poultry and pork products.
Yet, unbeknownst to these manufacturers, a potentially deadly contaminant was lurking…
What followed was the largest allergy-related recall since the U.S. Food Allergen Labeling and Consumer Protection Act became law in 2006. Retailers pulled 600,000 pounds of meat off the market, as well as hundreds of other products. As of May 2015, reports of peanut contaminated cumin were still being posted by FDA.
Food manufacturing executives have long known that a product contamination event is a looming risk to their business. While pathogens remain a threat, the dramatic increase in food allergen recalls coupled with distant, global supply chains creates an even more unpredictable and perilous exposure.
Recently peanut, an allergen in cumin, has joined the increasing list of unlikely contaminants, taking its place among a growing list that includes melamine, mineral oil, Sudan red and others.
“I have seen bacterial contaminations that are more damaging to a company’s finances than if a fire burnt down the entire plant.”
— Nicky Alexandru, global head of Crisis Management at AIG
“An event such as the cumin contamination has a domino effect in the supply chain,” said Nicky Alexandru, global head of Crisis Management at AIG, which was the first company to provide contaminated product coverage almost 30 years ago. “With an ingredient like the cumin being used in hundreds of products, the third party damages add up quickly and may bankrupt the supplier. This leaves manufacturers with no ability to recoup their losses.”
“The result is that a single contaminated ingredient may cause damage on a global scale,” added Robert Nevin, vice president at Lexington Insurance Company, an AIG company.
Quality and food safety professionals are able to drive product safety in their own manufacturing operations utilizing processes like kill steps and foreign material detection. But such measures are ineffective against an unexpected contaminant. “Food and beverage manufacturers are constantly challenged to anticipate and foresee unlikely sources of potential contamination leading to product recall,” said Alexandru. “They understandably have more control over their own manufacturing environment but can’t always predict a distant supply chain failure.”
And while companies of various sizes are impacted by a contamination, small to medium size manufacturers are at particular risk. With less of a capital cushion, many of these companies could be forced out of business.
Historically, manufacturing executives were hindered in their risk mitigation efforts by a perceived inability to quantify the exposure. After all, one can’t manage what one can’t measure. But AIG has developed a new approach to calculate the monetary exposure for the individual analysis of the three major elements of a product contamination event: product recall and replacement, restoring a safe manufacturing environment and loss of market. With this more precise cost calculation in hand, risk managers and brokers can pursue more successful risk mitigation and management strategies.
Product Recall and Replacement
Whether the contamination is a microorganism or an allergen, the immediate steps are always the same. The affected products are identified, recalled and destroyed. New product has to be manufactured and shipped to fill the void created by the recall.
The recall and replacement element can be estimated using company data or models, such as NOVI. Most companies can estimate the maximum amount of product available in the stream of commerce at any point in time. NOVI, a free online tool provided by AIG, estimates the recall exposures associated with a contamination event.
Restore a Safe Manufacturing Environment
Once the recall is underway, concurrent resources are focused on removing the contamination from the manufacturing process, and restarting production.
“Unfortunately, this phase often results in shell-shocked managers,” said Nevin. “Most contingency planning focuses on the costs associated with the recall but fail to adequately plan for cleanup and downtime.”
“The losses associated with this phase can be similar to a fire or other property loss that causes the operation to shut down. The consequential financial loss is the same whether the plant is shut down due to a fire or a pathogen contamination.” added Alexandru. “And then you have to factor in the clean-up costs.”
Locating the source of pathogen contamination can make disinfecting a plant after a contamination event more difficult. A single microorganism living in a pipe or in a crevice can create an ongoing contamination.
“I have seen microbial contaminations that are more damaging to a company’s finances than if a fire burnt down the entire plant,” observed Alexandru.
Handling an allergen contamination can be more straightforward because it may be restricted to a single batch. That is, unless there is ingredient used across multiple batches and products that contains an unknown allergen, like peanut residual in cumin.
Supply chain investigation and testing associated with identifying a cross-contaminated ingredient is complicated, costly and time consuming. Again, the supplier can be rendered bankrupt leaving them unable to provide financial reimbursement to client manufacturers.
“Until companies recognize the true magnitude of the financial risk and account for each of three components of a contamination, they can’t effectively protect their balance sheet. Businesses can end up buying too little or no coverage at all, and before they know it, their business is gone.”
— Robert Nevin, vice president at Lexington Insurance, an AIG company
Loss of Market
While the manufacturer is focused on recall and cleanup, the world of commerce continues without them. Customers shift to new suppliers or brands, often resulting in permanent damage to the manufacturer’s market share.
For manufacturers providing private label products to large retailers or grocers, the loss of a single client can be catastrophic.
“Often the customer will deem continuing the relationship as too risky and will switch to another supplier, or redistribute the business to existing suppliers” said Alexandru. “The manufacturer simply cannot find a replacement client; after all, there are a limited number of national retailers.”
On the consumer front, buyers may decide to switch brands based on the negative publicity or simply shift allegiance to another product. Given the competitiveness of the food business, it’s very difficult and costly to get consumers to come back.
“It’s a sad fact that by the time a manufacturer completes a recall, cleans up the plant and gets the product back on the shelf, some people may be hesitant to buy it.” said Nevin.
A complicating factor not always planned for by small and mid-sized companies, is publicity.
The recent incident surrounding a serious ice cream contamination forced both regulatory agencies and the manufacturer to be aggressive in remedial actions. The details of this incident and other contamination events were swiftly and highly publicized. This can be as damaging as the contamination itself and may exacerbate any or all of the three elements discussed above.
Estimating the Financial Risk May Save Your Company
“In our experience, most companies retain product contamination losses within their own balance sheet.” Nevin said. “But in reality, they rarely do a thorough evaluation of the financial risk and sometimes the company simply cannot absorb the financial consequences of a contamination. Potential for loss is much greater when factoring in all three components of a contamination event.”
This brief video provides a concise overview of the three elements of the product contamination event and the NOVI tool and benefits:
“Until companies recognize the true magnitude of the financial risk and account for each of three components of a contamination, they can’t effectively protect their balance sheet,” he said. “Businesses can end up buying too little or no coverage at all, and before they know it, their business is gone.”
This article was produced by the R&I Brand Studio, a unit of the advertising department of Risk & Insurance, in collaboration with Lexington Insurance. The editorial staff of Risk & Insurance had no role in its preparation.