Tag Archive for: Underwriter

How your commercial clients should be monitoring their cyber risk Canadian Underwriter


With a large number of employees working from home during the pandemic, commercial clients need some way of assigning a risk score to the cyber exposure posed by their users, software applications, and hardware devices, a Canadian information technology security expert suggests.

“In this day and age, many organizations are using SaaS [software as a service] applications and cloud apps,” Antoine Saikaley, technical director of IT security vendor Trend Micro Canada, said in a recent interview. “[Risk managers need to be] able to assess quickly what applications their organization is using, and the risk scores of those apps, so that they can make the decision of whether to sanction it or un-sanction those apps.”

Trend Micro recently released results of a survey of 2,303 information technology security and security operations decisionmakers, 101 of whom were Canadian. The survey found security operations centre and IT security teams are suffering from high levels of stress outside of the working day — with alert overload being a prime culprit, Trend Micro said May 26 in a release.

Canadian Underwriter asked Saikaley what advice commercial brokers should give clients about information security risk if they still have a lot of people working from home.

Your commercial clients should have tools that give them “risk ratings” for users, devices, and applications, replied Saikaley.

Clients should monitor their end-users for unusual activity, accessing risky applications, and e-mail based threats, Trend Micro advises.

To manage cyber security risk, it is not enough for your clients to monitor the computers, Internet traffic, and incoming mail. The client also needs to monitor devices such as printers and cameras, as well as third-party contractors that connect to the computer network, suggested Saikaley.

Trend Micro says its Vision One product lets organizations continuously audit and assess the risk of users, devices, and cloud applications using a calculated risk score. The idea is to let computer security staff take quick action to manage cyber risk.

Vision One provides a risk score of more than 30,000 cloud applications, based on web reputation, security compliance,…

Source…

Cyberattack targets Montreal health agency, forcing it to go offline Canadian Underwriter


MONTREAL – A Montreal health agency has been forced off-line as authorities deal with a cyberattack.

Quebec Health Minister Christian Dube said Thursday that specific attacks hit systems at the regional health agency covering west-central Montreal, which oversees the Jewish General Hospital among other facilities.

“Our teams quickly realized that there had been these attacks, and to protect the population’s data, particularly hospital data, the decision was taken to shut down the systems,” Dube told a news conference in Quebec City.

A statement from the agency said that as a preventive measure, “internet connectivity as well as external and remote access to our networks have been suspended.”

Access to patients’ records and data has been limited as a result, the statement said. “Frontline services have been slowed down – but not interrupted – while the situation is under investigation.”

Dube said the attack was possibly part of a broader campaign, but he didn’t make a direct link with a series of attacks that have hit American hospitals this week.

iStock.com/scyther5

A joint alert was issued in the U.S. Wednesday by the FBI and two other agencies, warning of a cybercrime threat aimed at hospitals and health-care providers in that country.

The warning said cybercriminals were hitting the U.S. health-care system with ransomware attacks designed to scramble hospital information systems that can only be unlocked with software keys once a ransom is paid.

Dr. Lawrence Rosenberg, head of the health agency, told a press briefing Thursday that an “anomaly” was detected during a daily verification of the system which they determined was a “cybersecurity intrusion.”

Officials said it was caught quickly but they were still investigating the source and weren’t in a position to confirm or deny the attack was linked to the U.S. incidents.

There hasn’t been a ransom request, Rosenberg added.

“We are going through a fairly rigorous process of trying to get to the bottom of what we’ve found, eliminate it and get back online,” Rosenberg said, adding the work could take up to four days.

Steve Waterhouse, an internet security expert, said he…

Source…

Investments to fight cyber breaches must include technology, people and risk transfer: WTW cyber head – Canadian Underwriter


Canadian Underwriter

Investments to fight cyber breaches must include technology, people and risk transfer: WTW cyber head
Canadian Underwriter
PHILADELPHIA – Considering human risk is essential when determining how best to combat data breaches and associated costs, but the human element is routinely overshadowed by technology in organizational efforts to bolster cyber security, says …

and more »

data breach – Google News

Data Breach- we are all at risk!! – Canadian Underwriter

Data Breach– we are all at risk!!
Canadian Underwriter
Over the past five years, financial institutions have been involved in numerous lawsuits related to data breach. These violations have targeted confidential data of a personal and commercial nature, exposing companies, employees, business partners and …

data breach – Google News