Lawsuit Against Sony Highlights Cyber Insurance Shortcomings 99
CWmike writes "A brewing legal dispute between Sony and one of its insurers over data breach liability claims highlights the challenges that companies can sometimes face in getting insurance providers to cover expenses arising from cybersecurity incidents. Zurich American Insurance Co. asked the court last week to absolve it of any responsibility for defending or indemnifying Sony against claims arising from the recent data breaches at the company. The data breaches at Sony's PlayStation Network, Sony Entertainment Online and Sony Pictures resulted in account data on close to 100 million individuals becoming exposed and over 12 million credit and debit cards being compromised. The breaches have so far resulted in at least 55 putative class-action lawsuits being filed against Sony in the U.S and another three lawsuits filed against it in Canada. Sony expects to spend close to $180 million in the next year alone on breach-related costs. But analysts say insurance might not have even been worth it in Sony's case: 'There aren't many success stories where cyber insurance [has played] a significant role in reducing the cost of incidents,' said Gartner analyst John Pescatore. Um, better security as an insurance policy maybe?"
Re:Extortion works too! (Score:4, Funny)
Don't worry, it's got Windows servers. They already know something's going to happen to it.
Re: (Score:3)
Re: (Score:3, Insightful)
Let's see if my car analogy works.
It would be like me leaving my car parked in a public parking lot with the windows slightly down and the keys in it. I let it sit there for months and several concerned individuals drop by to tell me there are undesirable elements in the hood and they have been stealing cars.
Re: (Score:2)
Plan B? (Score:2)
Maybe they should just throw in the towel and hire LulzSec to handle their online security.
Re:Plan B? (Score:5, Insightful)
Re: (Score:3)
They already did an audit, actually more than just a single one, what else do you expect from them to do for free?
Re: (Score:1)
Keep auditing, till its safe... :P
Especially if you add the clause "you can use any credit cards you acquire, Sony will pay the bill", that should get them fixing things quickly.
the devil vs the devil (Score:5, Funny)
hmmm, on one side, an insurance company.
on the other side, sony.
hey, why does it have to be one or the other, though? can't they both lose? please?
(for great justice. and a plate of shrimp, to go.)
Re: (Score:1)
OT rant: What's wrong with the insurance company? Is it that some insurance companies are inclined to not pay on health?
Realize, different types of insurance are sold by different companies. For instance, Blue Cross and other insurance companies don't cover property damage or sell life insurance policies. With non-health insurance, you probably have a choice, and I don't hear near as many bad comments about them as I hear about health insurance. Why? Probably because you can easily switch insurance provider
Re: (Score:2)
>> With non-health insurance, you probably have a choice, and I don't hear near as many bad comments about them as I hear about health insurance.
Tell that to Katrina Victims .. and yes, I know the Flood Policy deal. But, there were people that loss whole houses to WIND ONLY and I am sorry, floods don't blow roofs away. Oh.. there was water in the wind so it doesn't count? WTF?
http://www.centerjd.org/air/pr/KATRINAREPORT.pdf [centerjd.org]
Re: (Score:2)
Re: (Score:3)
Is it that some insurance companies are inclined to not pay on health?
I lost my job and was on COBRA. that ran out and to keep health insurance, I had to buy 'private insurance'. if you don't, then the 'pre-existing condition exclusions' can really bite you. its a huge risk, in the US, to not have 'continuous insurance'.
anyway, I was a month into my new fairly expensive private no-group plan when I had a dental emergency. fortunately, I did have the dental coverage (thought I). I went to the dentist (o
Re: (Score:3)
I can.
Look at this hypothetical situation, and it is hypothetical, I'm not saying it's you:
Someone does not want to pay for insurance because they view it as a waste of money. Then, one day their tooth starts to hurt and it looks like it may need a root canal.
So they call and sign up for dental insurance and with the $96/year plan, they go ahead and get a $1500 (or whatever the cost) procedure done. Then cancel at the earliest convenience and wait until the
Re: (Score:2)
what would be fair: pay for the emergency stuff as long as I'm covered. I AM covered, why deny me?
now, you can ask^Hforce me to repay if I leave 'early'. its like getting corporate relocation on a new job. if you leave that job before X amount of months, you pay back that 'earned benefit' of relo.
why can't this be that way? sure, I'd be 'happy' to keep current for the next 6mos. I will anyway, dammit! why deny me coverage NOW for emergency stuff?
it cold and heartless and evil. its not the only way to
Re: (Score:2)
This is why a mandatory insurance scheme is such a good idea. In the UK we pay national insurance directly from our pay packets as part of the deducted tax. Everyone gets free treatment on the National Health Service, but you are of course free to sign up for private care too.
Re: (Score:2)
Not that I ever want to be on the side of the insurers.
Surely though you can see that you would never want to pass a law stating that there could be no waiting period.
The cost of insurance would skyrocket.
Smart people who are healthy would wait till they need some major work done. Then buy insurance. Keep it long enough to get the work done then drop it.
I know insurance companies can be evil. Just make sure when figuring how things should be to remember that people can be evil as well.
Re: (Score:2)
Sorry to hear about your situation. I have an opinion on why things are the way they are, and as I specified in my post, not having a choice is part of what is killing us, along with government underpaying on medicare which passes on the cost for medicare covered individuals on to the rest of us, as well as not going after tort reform, which forces doctors to bump their rates up $25 dollars an hour.
However, those companies are not the same company that's providing this insurance, although I suppose they cou
Re: (Score:2)
Well, it's the annoying habit insurance companies have collecting on insurance premiums and not paying claims, in all realms, not just health insurance. Health claims are just more pernicious because it deals with life and death.
I've personally had pretty good luck with car insurance, but my claims have almost always been totally one-sided (as in rear-ended or parked) and the fault 100% of the other driver.
Re: (Score:2)
OT rant: What's wrong with the insurance company? Is it that some insurance companies are inclined to not pay on health?
Realize, different types of insurance are sold by different companies. For instance, Blue Cross and other insurance companies don't cover property damage or sell life insurance policies. With non-health insurance, you probably have a choice, and I don't hear near as many bad comments about them as I hear about health insurance. Why? Probably because you can easily switch insurance providers for property insurance, and you had a choice when you bought your life insurance. Unfortunately, with health, most people are tied, by virtue of employer selected health care plans to a provider that they don't have any say in. I have the feeling if I had the cash that my employer pays Aetna for my insurance coverage, I could go select something else, I could probably get a better deal. I hear health insurance coops are a good alternative, although they have similar restrictions as the for profit organizations.
I think basically it's because the whole (non health) insurance industry has a reputation for doing whatever they can to screw their customers when a claim is actually filed. Couple that with the fact that in many locations insurance (auto insurance for example) is required by law and you can begin to see why people do not like insurance companies. They take your money from you and then do everything in their power to not pay out when they should.
Re: (Score:2)
I have the feeling if I had the cash that my employer pays Aetna for my insurance coverage, I could go select something else, I could probably get a better deal.
Wrong, unless you go buy very bad coverage. Most of the time, employer-based health insurance has serious advantages. First, the rates are much lower because there's a bigger risk pool (at least that's the theory--in reality, they are lower because it's a collective plan, which is related, but is also about bargaining power). An individual plan w
Re: (Score:2)
It's one of those "If they both jump off a tower, who hits the ground first?" "Who cares, as long as they both jump!" things, ain't it?
Re: (Score:2)
And they managed to involve the third devil: lawyers !
Re: (Score:2)
Why bother? (Score:2)
Re: (Score:2)
Is there possibly some fiduciary responsibility to shareholders that is the cause?
Yes. Sony is obligated to check out every avenue to offset this cost.
Re:Why bother? (Score:4, Insightful)
Little people obtain insurance to deal with the potential for low-probability catastrophes; but if you bring the finance guys into it, insurance is just another financial instrument to be fiddled with in the service of perceived optimization(also, once you bring the finance guys into it, not insuring something starts to look a lot like self-insuring something, at which point the question of whether to buy insurance or not really just comes down to whether to do something in-house or contract it...
Re: (Score:2)
Re: (Score:2)
Do you know when such an event will happen, how often, or how expensive one or more incidents may be? With insurance, you can balance the cost. You pay a set amount, and when it happens, you've already been paying for it over time. So this smooths out the lumps by spreading the cost over many years instead of focusing the cost all in one or two quarters.
For instance, as an individual, with health insurance, I know that at some point, I or someone in my household will end up in the hospital. I can either buy
Re: (Score:3)
Re: (Score:1)
I wonder if Lloyd's will insure people against rejected insurance claims?
Better security is no insurance (Score:4, Insightful)
Re: (Score:3)
Yes, but insurers don't typically give you a blank check to replace what you like for whatever happened. There are typically restrictions to what they'll cover and if you're behaving in an irresponsible fashion they aren't necessarily obligated to pay out. More commonly though they'll pay the claim then cancel the coverage.
Insurance fraud is a serious issue which causes all the other insured parties to have to pay more. I'm personally curious if they'll get away with refusing to pay, but given the degree of
Re:Better security is no insurance (Score:4, Informative)
Actually, from what I've read, the insurance company is trying to claim that cybersecurity breaches (or whatever you wanted to call this) wasn't part of the policy. So it's not that Sony was negligent, it's that Sony wasn't insured at all. (According to the insurance company, at least.)
Re: (Score:2)
You seem to be correct, Sony was covered for property damage and personal injury, not cybersecurity breeches. So, I'm guessing that this wouldn't be considered property damage or at least only a very small amount of the claim could be considered property damage.
Re: (Score:2)
Not being insured is the same thing as being negligent. If you are a large company doing something risky like storing personal data you need to have insurance to cover loss. In fact we should make it a law in the same way that car drivers must have insurance.
Re: (Score:2)
Only if they can't cover it out of pocket. (Car drivers are a special case: Increasing access to private transportation has massive economic advantages, but an accident can cause hundreds of thousands of dollars worth of damages, more than 90% of the population would be able to pay. By requiring insurance, we keep the cost of insurance down and make sure that someone can pay for damages in case of a massive accident.)
Re: (Score:2)
How depressing... (Score:3)
Re: (Score:2)
These are not the higher principles you are looking for....
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Why don't we shoot these people again?
Because we can't get good insurance salesperson shooting insurance for some reason...
Shouldn't have to pay (Score:5, Insightful)
At this point, it almost looks as if Sony's security team isn't just incompetent. That's pretty obvious. By this point, I'm almost wondering if some of them weren't/ aren't deliberately sabotaging Sony's security (well, those who actually know enough to do sabotage, which is looking like the minority at this point.) No patches/ firewall on their servers? Not using random numbers in the signature on firmware for the PS3 (thus revealing the master private key. Including that for Bluray.)? This? [slashdot.org] These aren't just huge, gaping flaws. Flaws require effort to exploit. These are just... not security. At all. Its like having theft insurance on a car, then leaving that car unlocked in a bad neighborhood. After removing the locks. Then putting a sign on it that says "plz dont steal." Then wanting the insurance money to cover the car after it gets stolen. Its simply not going to happen, at least if the court is anywhere near competent (or unless there is some weird clause in the contract).
Sony should be forced to pay, and probably have some punitive costs added as well, so that they learn to hire competent security designers. And pay them well. This whole episode is simply mind-boggling. Didn't know a company could be this incompetent and still exist.
Re: (Score:2, Informative)
(posting anon so I don't get sued by former employers - mega tech, mega bank, mega networking...)
This sort of crap is why I got out of IT security and secure network protocols as a formerly fun career path. The big companies don't give a flying ^&%# about actual security anymore, the MBA mentality has determined its cheaper to declare it secure and buy an insurance policy. HSM? That's too expensive... Password database, PKI? No, the spec says "encrypted", it doesn't specify anything about key manag
Re: (Score:2)
competent security designers where lay offed and (Score:2)
competent security designers where lay offed and they where not given the tools / funds to do there job.
Re: (Score:2)
Meanwhile, /.'s command of the English language deteriorates to new lows.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Most points have already been made, but allow me to elaborate why I do not necessarily see Sony's security team as incompetent. Chances are, they couldn't do a better job. Or rather, a combination of "they were not allowed to" and "they didn't get what's necessary to do it".
First of all, security is a cost position without revenue. It costs money but doesn't make any. It's a bit like an insurance, you pay for it to reduce the risk of something bad happening. When times are dire and money is short, what's th
Re: (Score:2)
I don't buy it. Patching Apache doesn't cost money, is extremely easy to do, is usually quite safe. Adding a firewall can cost as little as zero. Windows and Linux operating systems all come with reasonable firewalls that might not be as robust as a dedicated solution, but are certainly better than nothing, and are trivial to setup. The only cost for those two "fixes" was perhaps a few thousand dollars worth of IT guy time, at most, and likely it would have cost zero, as you simply do it at install time
Re: (Score:2)
Patching Apache doesn't cost money, is extremely easy to do, is usually quite safe.
Time is money. Patching takes time.
And "usually quite safe" is not "safe". It means once in a while the time you spend doing it balloons into a lot more time, or even worse system downtime... I've got a server that we don't do OS updates nearly as often as we should because the damned database server on it flakes out, and some of the tools don't work with new versions of Java and flake out if java updates are installed. So it
Re: (Score:2)
You already have the employees on the payroll. You can't say it cost more than their salaries if the time they spent setting it up is trivial.
And as for your shitty accounting software, that isn't comparable to a web server. In general, web servers use two port that are well documented, not 40 that are not well documented. Setting up the firewall for database is also very easy. I'm literally talking about a few minutes in Linux, just a few lines for exceptions in iptables.
I get that in some instances it
Re: (Score:2)
You sure you already have them on the payroll? Unless you're some REALLY big company, you might not have a guru for every kind of software you want to install, even if you might have someone who knows your chosen firewall appliance inside out, which is also anything but a given. Most are already overwhelmed when trying to configure something like Astaro sensibly.
And while your webpage example works as long as your web server only serves pages and nothing else, it already becomes a very different game as soo
Re: (Score:2)
So you have people who know how to load balance a range of services through multiple systems, but can't configure a firewall?
Re: (Score:2)
Not as odd as it may sound at first. Especially in this time and age where "knowing how to set something up" pretty much translates as "knowing where to push buttons in a given tool".
I'm actually the other way 'round. I can tighten your firewall (provided it's at least somehow related to any firewall technology that I'm familiar with, I try to avoid too proprietary solutions that have nothing in common with generic implementations anymore), but I doubt I could configure a load balancer sensibly. I'm not rea
Re: (Score:2)
I sum it up with my boss this way...
When it comes to network security, there are two kinds of people:
1. Paranoids
2. Idiots
Either you are one, or you are the other.
Re: (Score:2)
Oh, I know a lot of people who fit into both groups. Who have no idea, and hence are scared of whatever boogeyman some sales drone paints when he has some security snakeoil to peddle.
Re: (Score:2)
It costs time. And time is maybe the most valuable resource in a company environment. You'll rather see management approve buying something than having you spend time on doing something. Especially if your annual salary is in the 6 digits or at least getting close to it.
And please allow me to dispel the myth that firewalls don't need updating. They do. I wouldn't say that it's a sizable amount of audits that fail due to outdated firewall settings, but it does happen, especially in high security areas where
Automotive policy (Score:1)
Indeed, many automotive policies do not cover you in cases such as:
a) You have been drinking/driving and get into an accident
b) Your car is stolen when you leave the keys in the ignition (or leave it running, etc)
Depends on what's in Sony's policy, but I wouldn't be surprised if they had an anti-negligence clause.
Re: (Score:1)
The issue is, if yo
Re: (Score:2)
Never attribute to malice what can adequately be explained by incompetence.
A few years back I used to work in IT. This guy who was in charge of a multi-million pound turnover company's servers as a contractor was too scared to patch them. If the update went wrong he might have to take a trip up to London on the weekend to fix it, and being Server 2003 that occasionally did happen. Whenever there was a problem the staff would be on the phone every five minutes screaming at him and threatening lawsuits for lo
The summary nailed it! (Score:2)
Um, better security as an insurance policy maybe?
Yes. Every insurance policy you could possibly buy will require you to exercise the normal and accepted level of diligence with regard to security. No policy in the world will cover you if you're negligent, because insurers are sane; they're not going to accept that level of risk. They're only going to take on the risk that you do things reasonably well, and still get breached by some sophisticated and not-reasonably-expected attack.
Re: (Score:2)
Re: (Score:2)
I do wonder if the company did any assessments of Sony's security since if they did and signed off on it then the insurance company is going to have a hard up hill battle
Which is probably why you're not reading about "Sony's insurance company rejected the claim", but are instead reading about "Sony's insurance company is suing to be able to reject the claim". I'd speculate that Sony looked good enough on shallow inspection to validate their coverage, but Sony's hidden incompetence and malfeasance makes it
Re: (Score:2)
don't confuse insurance with the word assure or even ensure.
insure simply means to play legal gambling on statistical odds... ...and then they get to keep your money and you get to die.
Unjust enrichment? (Score:2)
Re: (Score:2)
They didn't buy coverage for that. (Score:5, Informative)
The actual court filing [state.ny.us] by the insurance companies says:
Notwithstanding, the claims set forth in the Class Action Complaints filed against SCEA and the other Sony Defendants, as well as the miscellaneous claims, arising out of the cyber attacks on the PSN and SOE Network and the unauthorized access to and theft of the named plaintiffs and putative class members' personal identification and financial information, do not assert claims for "bodily injury," "property damage" or "personal and advertising injury" so as to entitle SCEA to defense and/or indemnity under the ZAIC Primary Policy.
In other words, Sony didn't buy coverage against a liability of this type. They were covered if the product actually injured someone or damaged their property (shocked someone or caught on fire, for example) but not for an indirect financial loss.
What they needed was an "errors and omissions policy". This covers financial screwups. Banks, accountants, tax advisors, and brokers usually carry such policies, because they handle other people's money. What Sony's people didn't realize is that, by handling so many credit card numbers (and, apparently, improperly holding more credit card info than they should have), they had the exposure of a financial institution.
Any merchant who holds onto credit card info for recurring transactions needs that coverage. Merchants who just pass credit card data to the bank for a single transaction, but don't keep it on file, are less at risk.
Re: (Score:2)
Re: (Score:1)
Lesson: Insurance (the House) always wins.
Re: (Score:1)
No, the lesson is "read the fucking contract." It's the same line SCEA themselves fell back on when they yanked OtherOS.
I love the smell of schadenfreude in the morning.
Re: (Score:3)
OTOH, if the courts buy Sony's argument and classifies identity theft as injury or property damage, then the world gets a lot more interesting. Paypal loses your credit card and bank account info to hackers? Your ban
Re: (Score:1)
No, what they need is a Cyber Risks Policy, which they actually have.
"Sony does in fact have a cyber insurance policy, which covers losses related to the breach. But it is likely that the company was hoping to lean on Zurich to cover the expected high costs related to defending itself against the slew of class-action lawsuits."
http://www.zimbio.com/SC+Magazine/articles/3Uy-tu7oydf/Zurich+seeking+immunity+covering+Sony+over
Sony has a General Liability policy placed with Zurich, which has a clause that contai
Re: (Score:2)
What I can't understand is why Visa and Mastercard are not suing Sony. It costs them money to deal with fraud. I guess Sony is too big a customer to piss off.
As much as I hate insurance companies (Score:2)
As much as I hate insurance companies I don't think that Zurich American Insurance Co. is as bad as some and is probably reasonable in trying to avoid paying in this case. From my understanding Sony didn't do due diligence in securing their network or even follow what would have been reasonable precautions that a rational actor would take. It is interesting that the insurance company is going to court which probably means they feel they have a strong case since usually they will just deny the claim.
There i
"no firewall, out of date servers" (Score:2)
Re: (Score:2)
I don't know about a Google cache, but you could check the Apache release notes against the version of Apache running at the time. I did. And while the version was quite a few patchlevels old and there were quite a few bugs fixed in the more recent revisions, most of those bugs were for either denial-of-service vulnerabilities (attackers could use them to crash, lock up or overload the server but couldn't gain access to data through them) or vulnerabilities specific to Apache running on Windows (SOE was usi
Was it worth it Sony? (Score:2)
I know Sony is making a $Billion every second of every minute of every hour of every day, but that nearly $180M sounds like a lot of money to me. Is Sony still coming out ahead after all of this? Seems like it's possible -- there was a story here recently talking about PS3 overtaking the Xbox360... (though my guess is the Xbox360 market is saturated and in order to get something new, they finally got a PS3 too)
Whatever the case, I see the attacks on Sony not as a mere attack and security breech, but massi
Welcome (Score:2)
Welcome Sony, to the world the little guys live in. The one where you need insurance insurance for when your insurer finds a way to weasel out of a perfectly legitimate claim even though they faithfully cashed your check every month since forever.
Of course, since the only place you could get insurance insurance from is one of the weasels that looked even less reliable than where you bought your insurance from, good luck with that.