Download

A Key Misconception on Digitization

Many resist digitization because they think it means self-service and a diminished role for agents. Not so. Here is how to overcome the fears.

sixthings
The industry knows today’s customers are ready for digital insurance. It knows the expectation for anywhere, anytime responsive service is dictating how customers choose service providers. But are insurance professionals stepping up? Based on what we are seeing, they still need some convincing. How often is the digital path chosen? An interesting trend emerges when we look at technology that enables digital insurance, namely e-signatures. E-signature adoption rates approach 100% in unmediated channels, including online portals. As processes become mediated, though, especially in the hands of captive and independent agents, adoption declines. How do we explain this behavior when we know customers want to transact digitally and are doing so when managing transactions on their own? The answer is the belief by many captive and independent agents that digitization implies self-service, compromised personal attention and less of a role for agents to play in the transaction. We have seen enough e-signature implementations to know that the key to high opt-in rates, especially among independent agents, is change management. Managing digital change to get the highest agent adoption rates Here are some of the ways insurers can manage the transition to digital insurance and ensure agents adopt new technologies. See also: Digital Insurance, Anyone? Involve key stakeholders early: This is obvious, but it’s a practice that is not always followed. Early involvement from select agents or staff members, for example, will ensure that their feedback is captured and accounted for and that they will then have more personal investment in the success of the project. It also gives the project more credibility when key stakeholders are on board. Gain executive buy-in: It is not uncommon to encounter resistance when moving processes off of paper into the digital domain. Legal concerns may arise; perhaps IT will weigh in, and other lines of business may voice apprehensions. Without executive commitment, initiatives can get sidetracked. To gain that buy-in at the executive level, it’s imperative to focus on the business improvements the technology will bring. Implement e-signatures in phases: It’s best to start with a smaller, hand-chosen group of early adopters – your technology evangelists. Get them using the new solution, gather feedback and tweak processes if necessary. This is your opportunity to recruit champions and advocates, and to document testimonials that will be helpful in your communications efforts to roll out the project on a larger scale. Provide comprehensive training: This can be as simple as watching tutorials, but, in truth, nothing beats hands-on practice. Training should be designed for staff and agents in a way that allows them to gain comfort in the new process. You can create an operational sandbox account for your users so, when they are in front of a client, the process is practiced and smooth. Offer incentives: Incentives can be very effective in gaining rapid adoption and helping to ease learning curves. Gamification is a new trend that lends itself nicely to training. As an example, insurers can award points for every new business application submitted electronically and offer reps the ability to redeem points toward prizes. By delaying the eligibility for rewards and incentives until after a specified number of transactions is attained, you can ensure the initial learning curve hump is overcome. See also: Stretching the Bounds of Digital Insurance Communicate a lot and often: People need advance warning when big changes come, even if they’re good changes. Anticipate questions and answer them in advance. Make the process personal. Provide real examples of how it will help individuals in their day-to-day jobs. Don’t focus on the benefits to the company but rather emphasize the time saved, the convenience factor for both agents and their clients.   Use testimonials from the champions you recruited during your earlier phase rollout to help encourage adoption. Show the value of metrics: Monitoring and leveraging analytics from transaction data is a convincing way to maintain executive support for the new, digitized process. The “on-demand” customer mindset is changing the insurance business fast and fundamentally. A recent poll of insurance providers and insurance brokers shared at an industry event revealed “digitization” as the top response to major industry game-changers (or threats). Are you ready?

Andrea Masterton

Profile picture for user AndreaMasterton

Andrea Masterton

Andrea Masterton is the corporate marketing director for e-SignLive by Vasco. She oversees industry marketing strategy, market awareness and demand generation within key industry segments, specifically insurance and financial services.

Opioids Are the Opiates of the Masses

Employers can help head off chronic use of opioids before it turns into addiction by having independent analysis look for three key risk factors.

sixthings
One day in 2014, before most people could even spell “opioids” (two “i’s), the CEO of a company named Healthentic asked me to review a white paper based on the output of its new analytics tool. Healthentic’s tool is far more focused on the “80” of the “80-20” rule than competing tools are. So, rather than drowning readers in data, the tool is supposed to help certain figures jump off the pages and lead to action. As my role in life appears to be the thankless task of finding errors in other people’s work, I was pleasantly surprised that Healthentic called me to plausibility-check the tool early in the process, rather than disseminate it and wait for me to publish “highlights" of my analysis after the fact, as I am wont to do. As usual, I noticed some highly suspect information. In this case, it was prescriptions for Tramadol, Oxycontin and Hydrocodone. With my usual charm, grace and humility, I said: “These figures can’t possibly be right. This isn’t an NFL team in constant pain. If these figures were correct, it would mean that 40% of their employees filled a prescription for a synthetic opioid in a single year.” We rechecked the figure and the raw data several times. And yet the original statistic refused to bend. It was accurate. See also: Paging Dr. Evil: The War Over Opioids Ironically, the particular Healthentic customer profiled in the white paper was obsessed with employee health. Its staff could recite how many employees had high blood pressure or high cholesterol, participated in the “steps challenge” or the “biggest loser contest” or didn’t buckle their seat belts. But opiates and synthetic opioids -- the elephant in the room capable of magnitudes more damage to employee health and productivity than any of the wellness vendor siren songs -- had been completely overlooked. In the days that followed, we talked through four possible scenarios and ruled out three:
  1. Employees were being injured due to safety hazards and accidents -- but the company’s OSHA reports were clean and, in any event, those prescriptions would have shown up in workers’ compensation, not group benefits;
  2. Certain local doctors were prescribing way too many of these pills -- but the prescriptions seemed to be coming from many different doctors;
  3. Employees were reselling their prescription meds — but if that were the case they’d have enough sense not to purchase these pills through the PBM;
  4. A sizable number of employees were at-risk or already addicted to opiates.
It was definitely the last. Little did we know this was the leading edge of the belatedly discovered synthetic opioid epidemic. Healthentic analysis consistently finds that opioids are some of the most prescribed drugs for all employers. “Take two aspirin and call me in the morning” has become: “Take some Oxy and text me in the morning.” It wasn’t hard for a person with a few dental or medical procedures to have several months’ supply of the drug. Pain is no laughing matter. It is human nature to ease suffering. But the cost and consequences of treating chronic pain so freely with opioids is shockingly high. Not a week goes by without more national news being made on the topic, such as Prince’s death. Of course it isn’t just famous people who are susceptible. Opioids — synthetically designed cousins of heroin — are so addictive there’s a Super Bowl commercial for another drug to treat constipation from chronic use. Obviously a market has to be quite sizable to merit a Super Bowl ad. See also: Progress on Opioids — but Now Heroin? The good news is that it doesn’t have to be this way. Pursuing early detection of a large supply of opioids and putting treatment goals in place will help a great deal in avoiding chronic use and addiction. Employers can help to head off chronic use before it turns into addiction. Independent analysis of your data should identify the three key risk factors for this population:
  1. a 45-day or greater supply;
  2. 10 or more prescription refills; or
  3. overlapping synthetic opioid and benzodiazepine prescriptions.
As brokers and employers, you can flag this population to the medical carriers and providers. You yourselves won’t be aware who is at risk, in conformance with the new CDC guidelines. I emphasize the word “independent” because of how far behind the curve the payers are. One insurance carrier told an employer not to worry about the 150 people Healthentic had tagged for being at risk for chronic opioid use. “We know about these people. They are in our medication compliance program. Most are on palliative care.” That would be an obvious whopper even if these employees had worked at Chernobyl, and a quick analysis confirmed there wasn’t a single palliative care referral in the group. Employers’ obsession with wellness, and carriers’ unwillingness to run the data, is great for my business, and for Healthentic’s. Unfortunately, it is not so great for employees at risk for opioid addiction. The only good news is that at least they won’t be constipated.

The Case Against Whole Life Policies

Forty years ago, whole life insurance made a lot of sense as an investment vehicle. Today, it's as outdated as disco, hula hoops and pet rocks.

sixthings
One of the longest-running and most heated-discussions is about who is the greatest quarterback of all time. Many will say Joe Montana, but others will go with Tom Brady or Peyton Manning (among others). This discussion depends on your viewpoint and what you feel is valuable. At one time, the common answer may have been Johnny Unitas or Sammy Baugh, but their names don’t even enter the conversation for most of us any more. Another long-running argument concerns whether whole life or term life is the greater life insurance product. (For the purposes of this article, we are omitting other common types of life insurance, such as universal life, variable life and indexed life.)   My colleague and friend Chris Huntley, founder of Huntley Wealth & Insurance Services, is organizing a movement to promote awareness of term life insurance and some of the downfalls of investing in whole life. The Whole Life Rebellion fits into the Insurance Consumer Bill of Rights, which provides that consumers should purchase policies that match their needs. Whole life insurance remains a top-seller. In fact, the American Council of Life Insurers estimates that 64% of all policies purchased in the U.S. are whole life.   For the majority of consumers, term life insurance is a better fit. Yet, as with everything, it’s not quite so simple. See also: Bringing Clarity to Life Insurance The bottom line is that you need to be able to make that decision on your own, and the key is to become educated. The Insurance Consumer Bill of Rights is designed to provide guidance in knowing what questions to ask and what are reasonable expectations for your insurance agent and insurance company. Rather than starting with the question of whether whole life or term life is better, consider the following points:
  1. Do you need life insurance? If you have no need for life insurance, then you have no need for either term life or whole life. We’ll go through the various reasons why whole life is suggested when there is no need for life insurance; just remember that, if you don’t need life insurance, then you don’t need ANY type of life insurance. Some day, I might buy a Porsche, but I’m not going to buy auto insurance on the Porsche until I own it.   
  2. How long do you need the life insurance? This is the classic question that really gets at the heart of the debate. Life insurance is needed when someone is financially dependent on you. Most needs for life insurance are for a finite period, such as providing insurance for the benefit of your children, most of whom will be financially independent by the age of 18 to 25. You may also need insurance to make sure your family can pay the mortgage. Well, most mortgages are for a fixed period and can be matched with term life policies, almost all of which are guaranteed for a certain time.   
  3. Will you outlive your term life insurance? What if the need for life insurance is permanent, let’s say for a spouse?  Well, in a situation where there are no other investments available to you or you choose not to participate in them, some type of permanent life insurance may make sense. However, according to the Economic Life Cycle Planning Method developed by Dr. Laurence Kotlikoff, your need for life insurance will diminish as your other assets grow. See my article with Dr. Kotlikoff published in AM Best, “A Different Approach,” or visit Dr. Kotlikoff’s site and learn more about the Economic Security Planner.
  4. Isn’t it true that only 1% of term life policies pay a claim? Out of all the term life insurance policies issued, only 1% will result in a claim. But how many homeowners' policies pay out? Most people are happy if their home doesn’t burn down, and they don’t have to file a claim. Keep in mind that, while great statistics for whole life aren't available because insurers consider the information proprietary, estimates are that 15% to 20% of whole life insurance policies result in a claim. One of the big reasons that so few whole life policies result in a claim is that many owners let them lapse every year. A joint study by the Society of Actuaries (SOA) and the Life Insurance Marketing Research Association (LIMRA) on 2007 to 2009 found that, in year one, 7% to 9% of whole life policies lapsed; in year two, 6% to 7% lapsed; and in year three, 5% to 6% lapsed. You can find the study by clicking here
  5. What if you have someone who will always financially depend on you or have some other permanent need? Is this finally a reason to have whole life? Well, almost. However, something called guaranteed universal life insurance acts as a term life insurance policy up to age 120 and does not build cash value. The premium is lower than a whole life policy. And of what benefit is a cash value if you intend to keep the policy in-force for the rest of your life? A primary rule in investing is lowering expenses when looking at two similar financial vehicles.
  6. Can you buy term insurance and invest the difference? That doesn't work. With whole life insurance, there are very high surrender charges in the first few years of a policy, so when a policy lapses before the fourth or fifth year, the policy owner may only recoup 10% to 20% of the premiums paid. The question should really be, Will you still want to and be able to pay the premiums for a whole life policy?    
  7. Doesn’t whole life allow for tax-deferred cash accumulation? Yes, completely true. And so do 401(k)s, IRAs, etc. In these retirement accounts, you can have a wide variety of investments such as exchange traded funds with expense ratios of less than 1% per year. By contrast, whole life is a black box when it comes to quantifying expense. Costs and expenses are not fully disclosed and are at the discretion of the insurance company. And then, of course, there’s the fact that there’s no guarantee that the tax treatment for whole life insurance will continue. Almost every year, the U.S. Senate and House of Representatives discuss the cash value component of permanent life insurance and note that taxation of this “inside buildup” could yield $300 billion over 10 years. Hmmm, with a growing national debt....
  8. Whole life allows me to borrow from my policy: The key here is you are borrowing your own money, which you could do from many other vehicles such as a 401(k). And borrowing from your whole life policy may incur an interest rate that’s higher than interest rates on other types of loans and will also reduce the internal cash value build-up on your life insurance policy. Isn’t this the same as not investing the difference? And if you borrow too much money from your whole life policy, it can lapse without any value AND cause a phantom income tax gain. (See my A.M. Best article on the Pitfalls of Policy Loans.)
Consider that the CEO of Northwestern Mutual, John Schlifske, recently stated that face-to-face meetings are the best way to sell life insurance. Why face-to-face? The key word here is “sell.” What if the goal was to help consumers make the choice that works for them? Yes, it’s a subtle difference, but the tone of the conversation needs to be changed. If the only tool you have is a hammer, then every problem is a nail. If the only type of product your insurance agent has is a whole life policy, then every planning issue will be solved by whole life. See also: What’s Next for Life Insurance Industry? Having an efficient plan for your insurance and for your finances overall removes the need for whole life. Forty or more years ago, whole life insurance made a lot of sense,  especially as it was pretty much the only type of life insurance sold. But this was before the average consumer had easy access to the stock market through discount brokers, mutual funds and other modern ways to invest. So, yes, using whole life insurance as a savings vehicle did make sense a long time ago -- just like disco, hula hoops, pet rocks and Rubik’s cubes were hot items at one time.   In today’s financial world, where there are many different types of life insurance and consumers have access to a wide variety of investment options, it does seem like the time for whole life has passed us by. But the decision is yours. Knowledge is power. Become educated and use the Insurance Consumer Bill of Rights to guide you and your insurance portfolio.

Tony Steuer

Profile picture for user TonySteuer

Tony Steuer

Tony Steuer connects consumers and insurance agents by providing "Insurance Literacy Answers You Can Trust." Steuer is a recognized authority on life, disability and long-term care insurance literacy and is the founder of the Insurance Literacy Institute and the Insurance Quality Mark and has recently created a best practices standard for insurance agents: the Insurance Consumer Bill of Rights.

A 'Perfect Storm' of Opportunity (Part 3)

While regulatory changes to the NFIP may make it difficult for agents to sell flood insurance, emerging options can offer relief.

sixthings
This is the third of three parts in a series. The first part is here, and the second is here.  Change isn’t always easy. If you’re an insurance agent or Write Your Own (WYO) dealing with the April 1, 2016, regulatory changes to the National Flood Insurance Program (NFIP), you know this all too well. As the Federal Emergency Management Agency (FEMA) continues to phase out various rate subsidies, agents are dealing with increasing policyholder concerns around rate increases and affordability. These regulatory changes inject new complexities into an already complex program. For agents trying to serve their customers in this space, it’s challenging to stay ahead of the NFIP changes around eligibility, pricing and flood zone determination — all while making time to absorb periodic, substantive modifications. Furthermore, increased regulatory scrutiny creates greater demands on agents because producers must invest additional time to ensure compliance. These dynamics generate new frictional costs that leave many agents feeling like there’s less return for their efforts. Homeowners have also felt the impact of the rapidly evolving flood insurance environment by means of increased costs and added requirements. Those interested in buying flood insurance or in maintaining existing flood insurance are faced with shifting price points and new steps in the application process. Just recently, pockets of homeowners in South Carolina were newly mapped into mandatory purchase areas, forcing some mortgaged properties to purchase flood insurance for the first time. Such changes can impose significant burdens on homeowners, particularly those on fixed incomes. See also: Why Flood Is the New Fire (Insurance) Strategies for Managing Through Change While regulatory changes to the NFIP may make it difficult for agents to sell flood insurance, emerging options can offer relief. Previously, if a prospective consumer rejected flood insurance because of price, agents often did not have an alternative. Today, this is not the case. Keith Brown, the president and CEO of Aon National Flood Services, said, “The NFIP offers a widespread product, and that has significant application in today’s environment. ... However, agents will find that there are some customers who may not be an appropriate fit for the NFIP. Now, agents can present options for policyholders who struggle with affordability issues if charged full-risk rate premiums. These agents are able to present coverage options more tailored to individual homeowner needs in terms of lifestyle, financial planning and risk exposure.” There are some strategies for flood risks that agents can adopt to help manage change through an evolving regulatory environment and shifting consumer appetite. First, it is important that agents are mindful of map revisions and the fluidity of the geographic risk associated with flood. Mapping changes drive pricing and surcharges applied to individual risks. For instance, a customer who wasn’t required to have flood insurance yesterday may be required to have it today. Innovations and opportunities in this business do not follow a set schedule, and agents seeking means of differentiation must be vigilant. With the proper education and tools, flood insurance offers a means for agents to help customers better protect themselves and their investments. Talk to your WYO; familiarize yourself with product choices your customers may find attractive if they’re struggling with the impact of regulatory changes. When looking at the newly mapped areas as defined by the NFIP, there is a distinct line that defines the area where homeowners must have flood insurance as a condition of having a federally backed mortgage. On the other side of that line, homeowners are not required to have flood insurance to mortgage their home; however, floods do not recognize these lines. In many cases, the homes sitting on the non-insurance-required flood zone lines have just as much of a chance of falling victim to a flood catastrophe. So, as an agent, understanding flood maps and knowing how properties may move in and out of different flood zones is invaluable in educating your customers and helping them determine what insurance they may or may not need. There’s no doubt that, in today’s ever-changing environment, a long-term strategy is difficult for agents. A basic understanding of the requirements surrounding floods will get you by. But if you want to have the opportunity to be more successful and be viewed as a valued business adviser and resource for homeowners in your community, you have to be able to look beyond the basics of flood. By taking on a more holistic view of flood, recognizing how floods can affect communities and having the ability to articulate all flood options (including private solutions), you can set yourself apart from others adrift in a sea of change. For an overview on the NFIP changes, check out a handy visual guide NFS has put together: “Making Sense of NFIP Regulatory Changes.”

John Dickson

Profile picture for user JohnDickson

John Dickson

John Dickson is president and CEO of Aon Edge. In this role, Dickson oversees the delivery of primary, private flood insurance solutions as an alternative to federally backed flood insurance.

The Future of Insurance [Infographic]

Companies have high digital ambitions but acknowledge their low levels of digital maturity.

sixthings
With the Internet playing an increasingly important role in business operations across all sectors, companies now realize they need to adapt to the digital sphere to maximize their earning potential and customer reach. Research shows that businesses that embrace digital adoption see a five times greater impact on growth than those who resist going digital. In comparison with others, the insurance industry has been quite slow in using digital channels as a core part of business operations. 79% of insurers say they are still learning about digital, while more than half of insurance companies do not have operating models that can incorporate digital. This is extraordinary in an era where online operation is not a bonus but a prerequisite to become an industry leader. More than half of the world’s population spends time online every single day, indicating that customers want to be able to interact with companies through digital channels. A business that gets its digital operations right will deliver on customer expectations and retain those customers, who, in turn, will speak in a positive light about the brand. This word-of-mouth marketing is highly likely to result in more customers. It’s high time that insurers realize this and take action to allow for their customers to interact with them online. The infographic below, which was created by Top Quote, outlines the digital challenges faced by the insurance industry and what insurers can do to address these challenges. Going-Digital-The-Future-of-Insurance-Infographic

Damien Gallagher

Profile picture for user DamienGallagher

Damien Gallagher

Damien Gallagher works with Top Quote, Ireland’s premier insurance providers, based in Co. Donegal. They strive to provide a competitive motor policy with the most comprehensive benefits package around. To provide the best possible service, they concentrate exclusively on high-quality car, van and home insurance services.

Hacking the Human: Social Engineering

Here are seven social engineering tactics that hackers are using to trick employees, along with eight defenses.

sixthings
Virtually every business relies on a network to conduct its daily operations. This often involves the collection, storage, transfer and eventual disposal of sensitive data. Securing that data continues to be a challenge for organizations of all sizes and across multiple business sectors. Social Security numbers, W-2 forms, payment cards and intellectual property have significant value on the black market and provide motivation for hackers to steal. Many corporate IT departments respond to these threats by devoting vast amounts of resources to technological defenses. Criminal perpetrators, however, seem to remain one step ahead of even the best cybersecurity efforts. They have altered their strategies by perpetrating human-based fraud. One emerging tactic involves what we have come to know as "social engineering." This type of fraud occurs in a multi-stage process. Criminals first gather information, form relationships with key people and finally execute their plan. By exploiting our natural tendencies to trust others, criminals have been highly successful in convincing people to hand over some of their most valuable data assets. In fact, according to the FBI, from October 2013 to August 2015, more than 8,000 social engineering victims from across the U.S. were defrauded of almost $800 million (the average loss amounted to $130,000.) See also: Dark Web and Other Scary Cyber Trends There are several methods of social engineering that are seen frequently, including the following seven:
  • ­Bogus Invoice: A business that has a long-standing relationship with a supplier is asked to wire funds to pay an invoice to an alternate, fraudulent account via email. The email request appears very similar to one from a legitimate account and would need scrutiny to determine if it was fraudulent.
  • ­Business Executive Fraud/Email Phishing: The email accounts of high-level business executives (CEO, CFO, etc.) may be mimicked or hacked. A request for a wire transfer or other sensitive information from the compromised email account is made to someone responsible for processing transfers. The demand is often made in an urgent or time-sensitive manner.
  • ­Interactive Voice Response/Phone Phishing (aka "vishing"): Using automation to replicate a legitimate-sounding message that appears to come from a bank or other financial institution and directs the recipient to respond to "verify” confidential information.
  • ­Dumpster Diving and Forensic Recovery: Sensitive information is collected from discarded materials — such as old computer equipment, printers, paper files, etc.
  • ­Baiting: Malware-infected removable media, such as USB drives, are left at a location where an employee may find them. When an employee attaches the USB to her computer, criminals can ex-filtrate valuable data.
  • ­Tailgating: Criminals gain unauthorized access to company premises by following closely behind an employee entering a facility or by presenting themselves as someone who has official business with the company.
  • ­Diversion: Misdirecting a courier or transport company and arranging for a package/delivery to be taken to another location.
How to avoid being defrauded in the first place: Given the rising incidence of social engineering fraud, all companies should implement basic risk avoidance measures, including these eight:
  • Educate your employees so they can learn to be vigilant and recognize fraudulent behavior;
  • Establish a procedure requiring any request for funds or information transfer to be confirmed in person or via phone by the individual supposedly making the request.
  • Consider two-factor authorization for high-level IT and financial security functions and dual signatures on wire transfers greater than a certain threshold.
  • Avoid free web-based email and establish a private company domain, and use it to create valid email accounts in lieu of free, web-based accounts.
  • Be careful of what is posted to social media and company websites, especially job duties/descriptions, hierarchical information and out-of-office details.
  • Do not open spam or unsolicited email from unknown parties, and do not click on links in the email. These often contain malware that will give subjects access to your computer system.
  • Do not use the “reply” option to respond to any financial emails. Instead, use the “forward” option and use the correct email address or select it from the email address book to ensure the intended recipient’s correct email address is used.
  • Beware of sudden changes in business practices. For example, if a current business contact suddenly asks to be contacted via a personal email address when all previous official correspondence has been on a company email, the request could be fraudulent.
Despite these efforts, organizations can still fall victim to a social engineering scheme. These incidents can be reported to the joint FBI/National White Collar Crime Center - Internet Crime Complaint Center (IC3) at www.ic3.gov. See also: Best Practices in Cyber Security The initial concern after such an event often focuses on the amount of stolen funds. However, there could be an even greater threat because these incidents often involve the compromise of personally identifiable information, which can later be used for identity thefts from multiple people. This prospect for more theft will often trigger legal obligations to investigate the matter and to communicate to affected individuals and regulators. The thefts often then lead to litigation and significant financial and reputational harm to businesses. Costs can include fines, legal fees, IT forensics costs, credit monitoring services for affected individuals, mailing and call center fees and public relations costs. Fortunately, the insurance industry has developed insurance policies that can transfer these risks. Crime insurance policies can cover fraudulent funds transfers, while cyber insurance policies may cover costs related to unauthorized access of personally identifiable information. However, the insurance buyer needs to be wary of various policy terms and coverage limitations. For example, some crime policies can contain exclusionary language for cases involving voluntary transfer of funds, even though they were unknowingly transferred to a criminal. Other insurers might add policy language to crime policies to cover this situation. Cyber insurance policies can be customized to offer coverage for the following:
  • ­Network Security Liability: Liability to a third party as a result of a failure of your network security to protect against destruction, deletion or corruption of a third party’s electronic data; denial of service attacks against Internet sites or computers; or transmission of viruses to third-party computers and systems.
  • Privacy Liability: Liability to a third party as a result of the disclosure of confidential information collected or handled by you or under your care, custody or control. Includes coverage for your vicarious liability where a vendor loses information that had been entrusted to it in the normal course of business.
  • Electronic Media Content Liability: Coverage for personal injury and trademark and copyright claims arising out of creation and dissemination of electronic content.
  • Regulatory Defense and Penalties: Coverage for costs associated with response to a regulatory proceeding resulting from an alleged violation of privacy law causing a security breach.
  • Breach Event Expenses: Expenses to comply with privacy regulations, such as notification and credit monitoring services for affected customers. This also includes expenses incurred in retaining a crisis management firm, outside counsel and forensic investigator.
  • Cyber Extortion: Payments made to cybercriminals to decrypt data that has been encrypted by ransomware.
  • Network Business Interruption: Reimbursement of your loss of income or extra expense resulting from an interruption or suspension of computer systems because of a failure of network security or system failure. Includes sub-limited coverage for dependent business interruption.
  • Data Asset Protection: Recovery of costs and expenses you incur to restore, recreate or recollect your data and other intangible assets (i.e., software applications) that are corrupted or destroyed by a computer attack.
In summary, businesses need to be vigilant in addressing the ever-evolving risks related to their most valuable assets. The most effective risk management plans aim to prevent social engineering fraud incidents from happening and to mitigate the damages if they do. Turning your employees from your weakest link into your greatest assets in the battle is one way; risk transfer to insurance products is another.

John Farley

Profile picture for user JohnFarley

John Farley

John Farley is a vice president and cyber risk consulting practice leader for HUB International's risk services division. HUB International is a North American insurance brokerage that provides an array of property and casualty, life and health, employee benefits, reinsurance, investment and risk management products and services.

Thought Leader in Action: Chris Mandel

Chris Mandel, at Sedgwick after a distinguished career in risk management, says he stumbled into insurance (quite literally).

sixthings
Back in the '70s, Chris Mandel quite literally stumbled into insurance, as a result of a racketball injury at Virginia Polytech Institute when he suffered a detached retina. After two months of lying flat in a hospital bed, he had to forego his post-graduate job in retail management and start looking for employment in D.C. — he began an unexpected career in managing claims at Liberty Mutual. Mandel excelled in his job but realized a career in claims management wasn't what he wanted. So, in the early '80s, he moved to Marsh brokerage for five years and set up a risk management program for an AT&T spinoff that evolved into what is now Verizon. He then left Marsh to be Verizon’s first risk manager — building its program from scratch. By the '90s, he landed in several top corporate risk management positions at the American Red Cross, Pepsico/KFC and Triton Global Restaurants (YUM Brands). Mandel also began his six-year volunteer stint as the president of RIMS (1998-2004), after serving in many different key RIMS leadership roles. He earned an MBA in finance from George Mason University along the way. By 2001, Mandel was on several advisory boards (i.e. Zurich, AIG, FM Global and Liberty Mutual), before making a career and geographic move to the USAA Group in San Antonio. There, he built an enterprise risk management (ERM) program because he saw a “broken traditional approach” to risk management. After nearly 10 years of developing an ERM program lauded in the industry (including by AM Best, Moody’s and S&P), Mandel was promoted at USAA to head of enterprise risk management, as well as president and vice chair of Enterprise Indemnity, a USAA commercial insurance subsidiary. While at USAA, he was recognized as Business Insurance’s Risk Manager of the Year (2004). His dream was to be a corporate chief risk officer, but he saw that title more often going to “quants,” (like actuaries), rather than risk professionals. So, as a well-known and sought-out industry spokesperson and visionary, Mandel moved on from USAA in 2010 to found a Nashville-based risk management consulting group, then-called rPM3 Solutions, which holds a patent on a game-changing enterprise risk measurement methodology. Then, in 2013, he moved to Sedgwick as a senior vice president. He is responsible for conducting scholarly research, driving innovation, managing industry relations and forging new business partnerships. In early 2016, he was appointed director of the newly formed Sedgwick Institute, which is an extension of the firm’s commitment to delivering innovative business solutions to Sedgwick's clients and business partners — as well as the whole insurance industry. In 2016, Mandel was awarded RIMS' distinguished Goodell Award (see video below). When asked what he sees as critical strengths for someone entering risk management, Mandel said: “I try to hire managers who can think strategically and who can convince C-suiters and boards of the value of being resilient in addressing a company’s risk profile. Progressive leaders understand the strategy to leverage risk for value.” A holistic approach, as he describes it, “seeks a vantage point that can assess both the upside and downside of all foreseeable risks.” He believes true innovation evolves from a company’s risk-taking. “It’s not so much identifying what or when adversity is going to happen, it’s how a company responds to risk in order to minimize disruption,” he said. In assessing his personal strengths and accomplishments, Mandel feels that a person needs to be “emotionally intelligent” — able to adapt to different people in organizations. He doesn’t consider himself a people person but says he learned to be one the hard way. He advises: “Team spirit is putting other people first and helping them succeed. ... Admit your failures and build trustworthiness from your mistakes.” Besides writing, teaching, speaking and (still) playing racketball, he serves an active role as an advisory board member of Insurance Thought Leadership. He and his wife also serve in church ministries, where he often plays guitar alongside his grown children, who are ordained ministers. Mandel said, “I’m blessed by a Creator who’s had my back.”

Jeff Pettegrew

Profile picture for user JeffPettegrew

Jeff Pettegrew

As a renown workers’ compensation expert and industry thought leader for 40 years, Jeff Pettegrew seeks to promote and improve understanding of the advantages of the unique Texas alternative injury benefit plan through active engagement with industry and news media as well as social media.

Failures of Two-Factor Authentication

How can an organization become less secure by attempting to be more secure, such as through two-factor authentication? Let me tell you.

sixthings
How can a bank — or any organization — become less secure in its attempts to become more secure?  Let me tell you. Security must do two things: protect and enable. If your security doesn’t enable people to do what they have to do, they will inevitably circumvent it, creating all sorts of exception conditions as they do. And that is the path to perdition (and hacking). Security often fails because people who design security are much better at throwing up roadblocks than they are creating pathways. This month brought yet another story chronicling the theft of millions of passwords by hackers, once again highlighting the importance of implementing “not-just-password security” at places that really matter. See also: The Need for a Security Mindset But I’m about to turn off two-factor authentication for my bank, right at the moment when everyone seems hell-bent to turn it on. Why? Because it doesn’t make me safer if it doesn’t work; it just prevents me from accessing my money. Tangled in red tape I’ve run into classic red-tape headaches with my bank recently as I try very hard to use its two-factor authentication scheme. A quick review: Two-factor authentication adds a strong layer of security by requiring that two tests be met by a person seeking access — a debit card and a PIN code, for example, representing something you have and something you know. Online banks and websites are slowly but surely nudging everyone toward various forms of two-factor authentication because it really does make life harder for hackers. Most of these two-factor forms involve the use of smartphones, as they have become nearly ubiquitous. Log onto a website on a PC, and a confirmation code is sent to your phone — something you have (the phone) and something you know (the password). Simple but elegant, and far harder for bad guys to crack. It’s great — when it works. But what about when it doesn’t? Consumers get new phones all the time. If the code is tied to the physical handset, the code doesn’t work any longer. What then? It turns out that this can be a very vexing problem. I’ve been a USAA banking customer for decades. The financial services firm has ranked atop customer satisfaction surveys seemingly forever, and for good reason; it really does take good care of members. At least it did, until it tried to implement two-factor security. A Symantec app loaded onto your smartphone offers a temporary token — a six-digit code — that changes every 30 seconds. The token is tied to the physical handset. Only a person who knows your PIN and can access the token on that handset can log onto the website. Sure, it’s a tiny hassle to pull out the phone every time you want to log on to the website, but that’s a fair price to pay for security. New phone, new problems However, the hassle becomes immense when it becomes time to change handsets. So immense that I couldn’t fix my login and access my bank for 24 hours. And that’s happened to me twice in the past year. Why? Chiefly because USAA isn't set up to deal with the problem of new handsets. The real problem came next. People change phones roughly every two years, so this new handset problem must come up often enough. Yet it’s obvious USAA operators aren't ready to handle the problem when consumers call. Each time I reached an operator, I had to spend a lot of time explaining the problem. On the first call, the operator merely changed my mobile application login settings after putting me on hold for minutes. When I protested, she said she had to transfer me to a special department — and then the phone went dead. After a second call, where I again waited, the operator was sympathetic but put me on hold quickly and wasted a lot of time trying to set me up with a new phone number. It took awhile before I could convince her that “new phone” meant “new handset” not “new number.” We eventually agreed that all I needed was someone to turn off two-factor and issue me a temporary password so I could go in and re-establish the connection between my handset and my account. But after another long hold and transfers to two other operators, I was told they were having trouble issuing temporary passwords and was asked if I could call back. See also: Best Practices in Cyber Security I’ve left out many steps in this saga. At each stage, I was subject to strict authentication questions. That’s fine; I was asking for a new password, after all. But at the end of my fruitless journey through tech support, when I asked if I could somehow get express treatment when I called back just to find out if I could get a temporary password, I was told, “No.” So, next time, I will have to, once again, convince a primary operator who I am, that I am having token problems and that I need a temporary password. My experience last time was similar, so I know I'm not just the victim of bad luck. The last time this happened, I was sure to give the operator who finally liberated my account some specific feedback: There needs to be a tidy process for dealing with people who get new handsets. Obviously, that hasn’t occurred. So, the first thing I will do when I can access my account is disable the token. While I am afraid of hackers, I’m more afraid of not being able to access my money because my bank has poorly implemented a security solution. Leaving the country? Good luck! USAA is hardly the only firm having trouble dealing with two-factor issues. Independent security analyst Harri Hursti told me about the foibles consumers face when dealing with two-factor authentication that relies on text messages. “The moment you start traveling, all bets are off. Text messages over roaming are far from reliable — they either are never delivered, or they experience regular delivery delays over 10-15 minutes,” Hursti said. “Basically, in order to do banking when traveling internationally, you need to start by turning all security off. And yet you are knowingly getting into an increased security risk environment.” Gartner security analyst Avivah Litan says these kinds of issues not only threaten adoption of two-factor security but actually create more pathways for hackers. “Two-factor, in this case, actually weakens security rather than strengthens it,” Litan said. “I always tell our clients that their security is only as strong as its weakest link, and when they disable two-factor authentication on the account, they likely ask the account holder to verify their identity by answering easily compromised questions, which any criminal who can buy data on the Dark Web has access to. So not only does two-factor authentication without proper supporting processes annoy and greatly inconvenience good legitimate customers, it also does little to keep the bad guys out.” Perhaps this problem isn’t that common yet, as uptake on two-factor is still relatively small. But with each password hack, more people will turn on two-factor authentication. If companies blow the implementation, consumers will just as quickly turn it off again. Protect and enable, or we’re all at greater risk. This piece was written by Bob Sullivan. More related stories: As U.S. switches to EMV payment cards, fraudsters exploit still-open loopholes Convenience of mobile computing comes at a security cost Small banks, credit unions on front lines of cybersecurity war

Byron Acohido

Profile picture for user byronacohido

Byron Acohido

Byron Acohido is a business journalist who has been writing about cybersecurity and privacy since 2004, and currently blogs at LastWatchdog.com.

Prospects for Insurers as a Global Industry

Despite complex regulatory environments, many international insurers are starting to make acquisitions that cross borders.

sixthings
This material was presented at the Global Insurance Symposium in Des Moines, Iowa. The author, a senior official in the U.S. Commerce Department, has updated with a brief introduction.   TPPandInsuranceIndustryITL520_FINAL.pptx TPPandInsuranceIndustryITL520_FINAL.pptx (5) TPPandInsuranceIndustryITL520_FINAL.pptx (2) TPPandInsuranceIndustryITL520_FINAL.pptx (3) TPPandInsuranceIndustryITL520_FINAL.pptx (4) TPPandInsuranceIndustryITL520_FINAL.pptx (6) TPPandInsuranceIndustryITL520_FINAL.pptx (7) TPPandInsuranceIndustryITL520_FINAL.pptx (8)TPPandInsuranceIndustryITL520_FINAL.pptx (9)TPPandInsuranceIndustryITL520_FINAL.pptx (10)TPPandInsuranceIndustryITL520_FINAL.pptx (11)TPPandInsuranceIndustryITL520_FINAL.pptx (12)

Paul Thanos

Profile picture for user PaulThanos

Paul Thanos

Paul J. Thanos is the director for finance and insurance industries at the Commerce Department’s International Trade Administration. He is responsible for developing and executing policy, analysis and promotion initiatives pertaining to finance and insurance industries, trade and project finance, financial technology, impact investing and access to finance.

Data Science: Methods Matter (Part 1)

There is nothing worse than moving your business full-speed ahead in the wrong direction based on faulty analysis.

sixthings
Why should an insurer employ data science? How does data science differ from any other business analytics that might be happening within the organization? What will it look like to bring data science methodology into the organization? In nearly every engagement, Majesco’s data science team fields questions as foundational as these, as well as questions related to the details of business needs. Business leaders are smart to do their due diligence — asking IF data science will be valuable to the organization and HOW valuable it might be. To provide a feel for how data science operates, in this first of three blog posts we will touch briefly on the history of data mining methodology, then look at what an insurer can expect when first engaging in the data science process. Throughout the series, we’re going to keep our eyes on the focus of all of our efforts: answers. Answers The goal of most data science is to apply the proper analysis to the right sets of data to provide answers. That proper analysis is just as important as the question an insurer is attempting to answer. After all, if we are in pursuit of meaningful business insights, we certainly don’t want to come to the wrong conclusions. There is nothing worse than moving your business full-speed ahead in the wrong direction based upon faulty analysis. Today’s analysis benefits from a thoughtfully constructed data project methodology. As data mining was on the rise in the 1990s, it became apparent there were a thousand ways a data scientist might pursue answers to business questions. Some of those methods were useful and good, and some were suspect — they couldn’t truly be called methods. To help keep data scientists and their clients from arriving at the wrong conclusions, a methodology needed to be introduced. A defined yet flexible process would not only assist in managing a specific project scope but would also work toward verifying conclusions by building in pre-test and post-project monitoring against expected results. In 1996, the Cross Industry Process for Data Mining (CRISP-DM) was introduced, the first step in the standardization of data mining projects. Though CRISP-DM was a general data project methodology, insurance had its hand in the development. The Dutch insurer OHRA was one of the four sponsoring organizations to co-launch the standardization initiative. See also: Data Science: Methods Matter CRISP-DM has proven to be a strong foundation in the world of data science. Even though the number of available data streams has skyrocketed in the last 20 years and the tools and technology of analysis have improved, the overall methodology is still solid. Majesco uses a variance of CRISP-DM, honed over many years of experience in multiple industries. Pursuing the right questions — Finding the business nugget in the data mine Before data mining project methodologies were introduced, one issue companies had was a lack of substantial focus on obtainable goals. Projects didn’t always have a success definition that would help the business in the end. Research could be vague, and methods could be transient. Research needs focus, so the key ingredient in data science methodology is business need. The insurer has a problem it wishes to solve. It has a question that has no readily apparent answer. If an insurer hasn’t used data scientists, this is a frequent point of entry. It is also the one of the greatest differentiators between traditional in-house data analysis and project-based data science methodology. Instead of tracking trends, data science methodology is focused on  finding clear answers to defined questions. Normally these issues are more difficult to solve and represent a greater business risk, making it easy to justify seeking outside assistance. Project Design — First meeting and first steps Phase 1 of a data science project life cycle is project design. This phase is about listening and learning about the business problem (or problems) that are ready to be addressed. For example, a P&C insurer might be wondering why loyalty is lowest in the three states where it has the highest claims — Florida, Georgia and Texas. Is this an anomaly, or is there a correlation between the two statistics? A predictive model could be built to predict the likelihood of attrition. The model score could then be used to determine what actions should be taken to reward and keep a good customer, or perhaps what actions could be taken to remove frequent or high-risk claimants from the books. The insurer must unpack background and pain points. Does the customer have access to all of the data that is needed for analysis? Should the project be segmented in such a way that it provides for detailed analysis at multiple levels? For example, the insurer may need to run the same type of claims analysis across personal auto, commercial vehicle, individual home and business property. These would represent segmented claims models under the same project. See also: What Comes After Big Data The insurer must identify assumptions, definitions, possible solutions and a picture of the risks involved for the project, sorting out areas where segmented analysis may be needed. The team must also collect some information to assist in creating a cost-benefit analysis for the project. As a part of the project design meetings, the company must identify the analytic techniques that will be used and discuss the features the analysis can use. At the end of the project design phase, everyone knows which answers they are seeking and the questions that will be used to frame those answers. They have a clear understanding of the data that is available for their use and have an outline of the full project. With the clarity to move forward, the insurers move into a closer examination of the data that will be used. In Part 2, we will look at the two-step data preparation process that is essential to building an effective solution. We will also look at how the proliferation of data sources is supplying insurers with greater analytic opportunities than ever.

Jane Turnbull

Profile picture for user JaneTurnbull

Jane Turnbull

Jane Turnbull is an accomplished analytics professional with more than 20 years of experience. She has worked in team and project management and in technical, customer-facing and leadership positions. Her work has been in consulting, predictive modeling, analysis, sales support and product development.