Download

Teamwork Lessons From Navy SEALs

You might have a plan, but be ready to make adjustments at any time -- our instructors always made drills just a little more interesting.

sixthings
Navy SEALS are the ultimate team. Through precision teamwork, they accomplish almost-impossible feats, such as safely hunting down Osama bin Laden at night in a foreign country. While each SEAL is a formidable fighting machine, it’s the team that does amazing things. Working in the insurance industry isn’t hazardous to life and limb, but it’s also a team endeavor. Success requires well-honed teams of underwriters, actuaries, agents, marketers, IT experts and others. No one succeeds without good teammates — something I was taught during team-building activities and something I was reminded of recently. After attending a Blue Cross Blue Shield conference in San Diego, 32 of us attended a Navy SEAL boot camp on Coronado Island. This “light” boot camp was a great experience, giving us a small insight into what our servicemen and -women go through during initiation and the importance of teamwork in the military and business. We were put into two teams of 16 that were then broken up into four boat crews with people of similar heights. There was the usual physical training, during which we were told we were too hot (so we had to cool off and get into ocean) and then too clean (so we had to roll in the sand) and then too dirty (so we had to get back into the ocean). There were team obstacle races, memory games, log drills, runs, cold ocean work and more — all starting at 5:30 a.m. So why wasn’t I in my comfortable hotel bed at that early hour? Because it was fun, and, once I started, I didn’t want to let my team — or myself — down. Finishing the boot camp was something I couldn’t have done on my own, but having teammates meant I didn't get an automatic pass. I still had to learn to work with those teammates in the same way mountain climbers must work with theirs — and you must work with yours. See also: The Keys to Forming Effective Teams Here are some lessons I learned while at the boot camp: Help, encourage and trust your teammates  While racing and carrying a log overhead, the first thing our four-man boat crew did was try and assess how we could best help each other carry the weight. We knew we needed to step in-time so that we would not trip on each other. Walter, an ex-Marine, called out the steps from the rear. During the race, another teammate’s shoulder became very sore due to a recent operation. I moved forward to take his weight. We stayed positive, encouraged each other — and we ended up beating the young guys. Communicate and establish a shared vision At first, it was a little hard to communicate (as none of us knew each other), but we knew that the sooner we could communicate the sooner we’d have an advantage. Together, we decided what the core mission and everyone’s role was. This might seem obvious, but it’s easy to lose sight of goals when faced with challenges. Whether you support your team by linking arms and sitting in the ocean while being pounded by waves or implement software or work to win market share, a shared vision will keep the team focused and on-track. Be flexible, keep it fun and stay warm You might have a plan, but be ready to make adjustments at any time. Just when we thought we understood a drill, our instructors would make it a little more interesting. Todd, my teammate with the sore shoulder, got our boat crew singing during our runs. I encouraged our crew to hug to stay warm when many began to shiver from the cold-water drills. Together, as a team, we finished the boot camp. There were some who gave up or got hurt; they grabbed a doughnut and a coffee and left. But we hung in there, breaking the boot camp activities down into one task at a time — and we got through each of those tasks together. All of us will inevitably have our own mountains to climb and oceans to cross. Yet, regardless of the landscape, we will require the help of others to reach our destination. Through the power of positive teamwork, we can harness skills beyond our own and achieve success we might not otherwise see.

Building a Strong Insurance Risk Culture

Having invested in risk processes and frameworks, insurers must devote resources to building a risk culture, to ensure adherence to policies.

sixthings
More than seven years after the onset of the global crisis, the financial sector continues to attract unwanted headlines, with the spotlight shifting somewhat from banks to insurers. Consequently, regulators are taking a heightened interest in organizations’ risk management and underlying cultures. In 2014, the International Association of Insurance Supervisors (IAIS) called for insurers to demonstrate “the ability to promote a sound risk and compliance culture across the group.” The Financial Stability Board (FSB), an international body that monitors and makes recommendations about the global financial system, has also issued guidance on risk culture, stating: “Supervisors should satisfy themselves that risk cultures are based on sound, articulated values and are carefully managed by the leadership of the financial institution. Furthermore, the FSB stated: “Institutions with a strong culture of risk management and ethical business practices are less likely to experience damaging risk events and are better placed to deal with those events that do occur.” Why risk culture matters Risk culture can be described as the way in which decision-makers (at all levels within an insurer) consider and take risks. When risk appetite is fully agreed and understood, all employees are conscious of risk in their everyday decision-making, appreciate the trade-offs between risk and reward and consider the interests of the wider organization above their individual objectives. However, defining risk culture and establishing a sound risk management framework is a considerable challenge. Traditionally, "risk" within insurance is seen as solely the domain of the actuary, and employees in customer-facing or product design positions may have never acknowledged there is a risk management element to their work. Consequently, many organizations fail to prevent excessive or inappropriate risk-taking, which can, in some cases, cause significant losses, penalties and negative publicity. One example is the recent U.K. payment protection scandal, where insurance companies and bancassurers have to pay billions in compensation for mis-selling of policies. In organizations with weak or undeveloped risk cultures, responsibility for risk management is unclear, with lack of board oversight and direction, low awareness of risks among employees and deficiencies in risk monitoring, reporting and controls. The risk management function itself is typically under-resourced and under-qualified, while key individuals such as the chief risk officer (CRO), the chief financial officer (CFO) and the approved actuary often have multiple risk decision-making roles that create an excessive workload. Perhaps more importantly, individuals are not measured or given an incentive for risk performance, and there is an over-tolerant attitude to breaches or mistakes, with those taking excessive or inappropriate risks rarely disciplined, implying that such behavior is acceptable. Within a branch network or telephone service center, staff may be under considerable pressure to meet targets, which can lead to sales of products that are not always a) in the customers’ best interests and b) in line with strategic goals. Incentive schemes are partly to blame; they reward salespeople primarily for goals set by their immediate managers, which may prioritize volume over quality. (These can apply both to direct sales and those made through intermediaries.) See Also: The Key to Building Effective Risk Culture Insurance companies’ reputations are also at daily risk from poor service quality resulting from slow, inaccurate or unfair claims handling or marketing messages that over-promise benefits (such as speed of replacement for stolen or damaged goods or availability of rental cars to replace damaged vehicles). A poorly designed online sales process can easily cause customers to self-select the wrong products. Compliance reporting for regulations — including Solvency II and International Financial Reporting Standards (IFRS) — can also highlight weaknesses in risk management. Insurers may be unable to demonstrate that controls are in place and are being adhered to, and they fail to produce accurate reporting that paints a true picture of the business. Consequently, regulators are raising the bar by demanding more risk-sensitive capital regimes as well as stress and scenario requirements. They are also, increasingly, requiring a clearly articulated risk appetite statement and better assessments of risk management frameworks and risk culture, as well as expecting senior executives to be rewarded directly for encouraging sensible risk-taking behavior that supports long-term corporate financial interests. From awareness to action Ultimately, culture is all about action — not policies or documentation. With regulators showing an increasing interest in risk culture and behavior, how can companies take a barometer of their current capabilities to make relevant improvements? There are three important questions to address:
  1. Does the organization have appropriate structures and processes in place to define the desired culture?
  2. Are those structures and processes adequate to create the desired culture?
  3. Do structures and processes drive effective behaviors in practice?
An in-depth evaluation involves close scrutiny of risk and compliance policies, past interactions with regulators and detailed observations of staff behavior at all levels. By seeking the views of a cross-section of employees and managers, leaders can better understand employees’ attitudes toward risk management and how risk management policies, procedures and systems work in practice, highlighting any gaps. Data analysis can reveal patterns of customer complaints, regulatory fines and requests for closer supervision and monitoring across different departments and locations. Such incidents should be monitored constantly and their root causes identified to offer a continuous indicator of cultural performance. This is a sizable investment requiring strong endorsement from leaders. Insurance companies with strong risk cultures are likely to exhibit four key characteristics: 1. Tone at the top The board and executive management should drive risk culture, with leaders exhibiting total consistency in words and actions, taking a visible lead in risk management activities — and being fully accountable when risk parameters are breached. By making risk a formal standing agenda item at board and management forums, the company's leaders can demonstrate risk management's importance to all stakeholders. They must ensure all employees are aware of the organization’s approach to risk management, reward positive behavior and act decisively when inappropriate risks are taken (if necessary through disciplinary action). It is very helpful to keep in touch with front-line activity through regular visits to branches and contact centers. Screen Shot 2016-04-13 at 2.20.12 PM 2. Communication Although leaders set the tone, they can’t be alone in delivering messages about the importance of risk. Senior managers of divisions and business units are also part of the communication process, which must filter down through the organization — and between departments — to the most junior people. In this way, everyone can understand the risk appetite and capacity at the individual, team, department and company level. In addition to recording sales calls, staff should engage in focus groups, surveys and one-on-one interviews to ensure they are continually aware of the risk culture and are conforming to procedures. Rather than acting as static recipients of advice, all employees should be encouraged to share information and feel safe to challenge unacceptable behavior and to escalate issues. This calls for clear channels for whistle-blowing, implying it is acceptable to criticize the business’ activities without fear of retribution. 3. Responsiveness In a risk-aware culture, issues are escalated and dealt with swiftly and decisively before they can become major problems, with a central point of contact for all employees for the management and treatment of risks. And, crucially, any learning from such incidents is assessed and built into future policies and behavior to avoid a recurrence. If something slips through the cracks, management should analyze why staff did not comply with protocols and re-educate people on the importance of such checks and balances — as well as stressing the need to act within the "spirit" of risk management. 4. Commitment Risk must become second nature to all, not something that applies only to actuaries or a central risk team. High-profile cultural transformation programs often fail to achieve lasting change because they don’t focus sufficiently on individuals or explain how people should behave to be more risk-aware. To make cultural change happen, leaders must understand the day-to-day dilemmas faced by staff — such as management pressure on sales numbers — and address these issues directly. Performance management and related compensation systems are key to gaining commitment and should balance local branch/office sales targets with wider organizational goals, as well as rewarding good risk management behavior. That will deter staff from taking unnecessary risks in pursuit of short-term profit. Whether selling in person, by phone, online, directly or through intermediaries, the same principles of fairness and appropriateness must apply. The approval process for new marketing initiatives has to be robust to ensure the business has the capability to meet any promises. Risk management also requires new skills to identify, assess and mitigate risks, which calls for tailored training and coaching. Good for compliance, good for the business As well as increasing the chances of remaining compliant, a strong risk culture gives the board and shareholders greater confidence in an insurer’s integrity and in its ability to meet customer expectations. Comparison websites may have made the sector more price-driven, but customers still appreciate doing business with companies that are seen to be acting in a customer's interests, often through a company offering relevant products, attentive customer service and a swift, fair claims process. See Also: Building a Risk Culture Having invested in risk processes and frameworks, insurance companies must also devote resources to building a risk culture, to bringing frameworks to life and to ensuring adherence to policies. Once this has been achieved, all employees — not just actuaries — will be able to say they are risk managers. In a strong risk culture...
  • The board and executive management drive risk culture
  • Every employee understands and embraces the organization’s risk appetite and risk management framework
  • Threats or concerns are identified and escalated swiftly, with employees comfortable (and encouraged) to raise issues
  • Individuals are clear about the risks inherent in their strategic and day-to-day decisions
  • Every employee continuously learns from the experiences of others
  • Personal and organizational interests are aligned via appropriate performance metrics; links to remuneration risk behavior is monitored regularly, with swift corrective actions taken after any breaches;  and staff are encouraged to consult with a superior when it is unclear whether a particular action is outside the organization’s risk tolerance
Questions for insurers
  • Is your board able to articulate the kind of risk culture it wants, and can it explain this clearly to all employees?
  • Does your board have a road map toward a strong risk culture, and can it demonstrate steps it is taking in this direction?
  • Are risks being identified, measured, managed and controlled in a manner consistent with the organization’s risk appetite?
  • Does your staff understand and adhere to the organization’s risk appetite — as it relates to their particular roles?
  • Do employee incentives promote long-term financial sustainability?
  • Do employees at all levels have the skills to manage risk effectively?
Reprinted from (Regulatory Challenges Facing the Insurance Industry in 2016,) Copyright: 2016 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative ("KPMG International"), a Swiss entity. All rights reserved. Printed in the U.S.A. The KPMG name and logo are registered trademarks or trademarks of KPMG International. All information provided is of a general nature and is not intended to address the circumstances of any particular individual or entity. Although we endeavor to provide accurate and timely information, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. No one should act upon such information without appropriate professional advice after a thorough examination of the facts of a particular situation. For additional news and information, please access KPMG's global web site.

Rob Curtis

Profile picture for user RobCurtis

Rob Curtis

Rob Curtis joined KPMG Australia on 1 April 2014 to lead the ASPAC Insurance Risk and Regulatory practice and continues to be KPMG’s global regulatory lead for insurance. Curtis has significant experience in regulation having developed the UK ICAS regime and leading the FSA’s Solvency II program.

Fixing the Economics of Securities Defense

The economic structures of typical securities defense firms result in costs that significantly exceed what is rational to spend in a usual class action.

sixthings
In my last D&O Discourse post, “The Future of Securities Class Action Litigation,” I discussed why changes to the securities litigation defense bar are inevitable: In a nutshell, the economic structures of the typical securities defense firms — mostly national law firms — result in defense costs that significantly exceed what is rational to spend in a typical securities class action. As I explained, the solution needs to come from outside the biglaw paradigm; when biglaw firms try to reduce the cost of one case without changing their fundamental billing and staffing structure, they end up cutting corners by foregoing important tasks or settling prematurely for an unnecessarily high amount. That is obviously unacceptable. The solution thus requires us to approach securities class action defense in a new way, by creating a specialized bar of securities defense lawyers from two groups: lawyers from national firms who change their staffing structure and lower their billing rates and from experienced securities litigators from regional firms with economic structures that are naturally more rational. See Also: Future of Securities Class Actions But litigation venues are regional. We have state and federal courts organized by states and areas within states. Because lawyers need to go to the courthouse to file pleadings, attend court hearings and meet with clients in that location, the lawyer handling a case needs to live where the judge and clients live. Right? Not anymore. Although the belief that a case needs a local lawyer persists, that is no longer how litigation works. We don’t file pleadings at the courthouse; we file them on the Internet from anywhere (even from an airplane). These days, in most cases, there are just a handful of in-person court hearings. And the reality is that most clients don’t want their lawyers hanging around in-person at their offices because email, phone calls and Skype suffice. Even document collection can be done mostly electronically and remotely. And with increasingly strict deposition limits and witnesses located around the country and the world, depositions don’t require much time in the forum city, either. In a typical Reform Act case, where discovery is stayed through the motion-to-dismiss process, the amount of time a lawyer needs to spend in the forum city is especially modest. If a case is dismissed, the case activities in the forum city (in a typical case) amount only to (1) a short visit to the client's offices to learn the facts necessary to assess the case and prepare the motion to dismiss and (2) the motion-to-dismiss argument, if there is one. Indeed, assuming a typical securities case requires 1,000 hours of lawyer time through an initial motion to dismiss, fewer than 50 of those hours — one-half of 1% — need to be spent in the forum city.  The other 99.5% can be spent anywhere. Discovery doesn’t change these percentages much.  Assume it takes another 10,000 hours of attorney time to litigate a case through a summary judgment motion (so 11,000 total hours). Four lawyers/paralegals spending four weeks in the forum city for document collection and depositions (a generous allotment) yields only another 640 hours. So, in my hypothetical, only 0.63% of the defense of the case requires a lawyer to be in the forum city. The other 99.37% of the work can be done anywhere. Because a biglaw firm would litigate a securities class action with a larger team, the total number of hours in a typical biglaw case would be much higher (both the total defense hours and the total number of hours spent in the forum city), but the percentages would be similar. And the cost of travel does not move the economic needle. Of course, if a firm is willing not to charge for travel time and travel costs to the forum city, there is no economic issue. My firm is willing to make this concession, and I would bet others are, as well. Even if a firm does charge for travel cost and travel time, the cost is minuscule in relationship to total defense costs. For example, my total travel costs (airfare and lodging) for a five-night trip to New York City are typically less than the cost of two biglaw partner hours. Of course, there are some purposes for which local counsel is necessary, or at least ideal: someone who knows the local rules, is familiar with the local judges and is admitted in the forum state. But the need to use local counsel for a limited number of tasks doesn’t present any economic or strategic issue, either — if the lawyers’ roles are clearly defined. Depending on the circumstances, I like to work either with a local lawyer in a litigation boutique that was formed by former large-firm lawyers with strong local connections or with a lawyer from a strong regional firm. I just finished a case where the local firm was a boutique and a case where the local firm was another regional firm. In both cases, the local firms charged de minimis amounts. In some cases, the local firm can, and should, play a larger role, but whatever the type of firm and its role, the lead and local lawyers can develop the right staffing for the case and work together essentially as one firm — if they want to. All of these considerations show securities litigation defense can and should be a nationwide practice. It is no longer local. We need to look no further than the other side of the “v” for a good example. Our adversaries in the plaintiffs’ bar have long litigated cases around the country, often teaming up with local lawyers from different firms. Like securities defense, plaintiffs’ securities work requires a full-time focus that has led to a relatively small number of qualified firms. The qualified firms litigate cases around the country, not just in their hometowns or where their firms have lawyers. This all seems relatively simple, but it requires us all to abandon old assumptions about law practices that are no longer applicable and embrace a new mindset. Biglaw defense lawyers need to obtain more economic freedom within their firms to reduce their rates and staffing for typical securities cases, or they must face the reality that their firms perhaps are better-suited only for the largest cases. Regional firms must recruit more full-time securities litigation partners and be willing not to charge for travel time and costs. And companies and insurers must appreciate that securities litigation defense will improve — through better substantive and economic results in both individual cases and overall — if they recognize a good regional firm with dedicated securities litigators can defend a securities class action anywhere in the country and can usually do so more effectively and efficiently than a biglaw firm.

Douglas Greene

Profile picture for user DouglasGreene

Douglas Greene

Douglas Greene is chair of the Securities Litigation Group at Lane Powell. He has focused his practice exclusively on the defense of securities class actions, corporate governance litigation, and SEC investigations and enforcement actions since 1997. From his home base in Seattle, he defends public companies and individual directors and officers in such matters around the United States.

Zenefits: Only the Start for Brokerages

Whether you agree with what Zenefits did or not, you can’t argue with its results -- so more brokerages will follow its example.

sixthings
As this election year unfolds, many are questioning what created Donald Trump. Why him? Why now? On the other end of the spectrum, the same could be said of Bernie Sanders. In the benefits world, I relate the political landscape to Zenefits and former CEO Parker Conrad. What is it that allowed Zenefits to come to be? As Zenefits now regroups to begin its post-Conrad journey, firms like Namely are getting press and stepping into the market in a similar way. Some say Silicon Valley breeds arrogance and often enables young entrepreneurs to create companies and attack the market and competitors with a vengeance. These young guns want to disrupt the market and change the rules of the game to deliver something new and better. See Also: How Likely Is Zenefits to Change? Whether you agree with the Zenefits model or not, you can’t argue with its results. According to Bloomberg, the company's revenue was close to $63 million annually as of the fourth quarter of 2015. This means: • $63 million in customers fired their broker because Zenefits promised something their current broker was not delivering; • $63 million in customers valued what I think is the equivalent of a $5 per-employee-per-month (PEPM) technology more than they valued the services delivered by their $25-$35 PEPM benefit broker; and • $63 million in customers did not care that there was no local service. While Conrad has left this stage, the conditions that allowed him to grow his business still exist. And I am sure the Zenefits executives and investors — including Andreessen Horowitz and Fidelity — are not going to let $63 million in revenue slip away without a fight. What Zenefits accomplished is to let the world know there are many employers out there that value what Zenefits promised to deliver. In fact, according to industry analyst and marketing guru Mark Mitchell of the Starr Conspiracy, there was $2.1 billion invested in the human capital management technology and services space in 2015 and $600 million in the first quarter of 2016. As Mitchell said at a recent conference, “Those checks are being cashed.” Soon, there will be a tsunami of new products, services and marketing in the human capital management (HCM) technology and service areas that are going to hit the market. Employers will be getting phone calls and webinar invites and attending conferences where these new solutions will be heavily promoted. Case in point: Have you ever seen a TV commercial or heard a radio commercial about HR technology before Zenefits and Namely? This is a hot market, and as one venture capital firm representative said to me, “We are only interested in investing in firms that go after the benefits commissions.” The commission is in play, and $2.1 billion in investment capital knows it. I have been in the benefit business since 1986, and many of the same problems still exist. Administration is still complex. Benefits are still confusing and are only getting more confusing. Costs are still going up. And now, in today’s world, cost shifting onto employees is creating financial stress on them. It is getting worse, not better. As long as the current market does not solve these problems, then there is an opportunity for someone else to do so. In the political arena, whether Trump wins or loses, the conditions that allowed him to secure the nomination aren’t going away. Certainly, the millions who support him won’t disappear overnight. They are still Americans living in our society. In the benefits world, whether Zenefits survives also doesn’t matter. The conditions that enabled it to enter the market and grow still exist. Employers still want what Zenefits promised. Managing benefits is still burdensome. Costs are still going up. People still don’t understand their health insurance. The market conditions have not changed. The opportunity for another company like Zenefits — or 10 of them or 100 of them -- still exists. And while Parker Conrad is in the rear view mirror, others are coming. And it will be a tsunami. This was originally written for Employee Benefit Advisor Magazine. The post can be seen here.

Joe Markland

Profile picture for user JoeMarkland

Joe Markland

Joe Markland is president and founder of HR Technology Advisors (HRT). HRT consults with benefits brokers and their customers on how to leverage technology to simplify HR and benefits administration.

Cyber and Physical Threats Are Colliding

Over the next four years, the number of connected devices is expected to grow to as many as 50 billion, and the risks are becoming physical.

sixthings
Overview A quarter of a century after the Worldwide Web began to transform the Internet into the indispensable tool we all rely on today, we’re entering a new digital revolution. Over the next four years, the number of connected devices is expected to grow to as many as 50 billion, according to the 2015 Ponemon Global Cyber Impact Report sponsored by Aon. Business is expected to make up a far larger percentage of Internet of Things (IoT) usage than the consumer — IoT is more about smart factories and computer-controlled office systems than shiny gadgets like smart watches and fitness trackers. The risks are becoming physical. Some of these new devices could cause serious real-world damage. We’ve already seen manufacturing plants seriously damaged by cyber attacks and electricity grids and automobiles shut down by hackers. It’s only a matter of time before such threats become more common and more physically dangerous to both people and property. With the rise of new technology comes fresh opportunity for business — but also new risk. In the workplace, every new connected device represents a new link in the IT chain. With the age of the Internet of Things upon us, what are the new risks and what do business leaders need to know to be prepared?
Projected growth of Internet-connected devices, 2013-2020

Source: 2015 Ponemon Global Cyber Impact Report, sponsored by Aon

In-Depth New Technology, Big Opportunities  The benefits of Internet connections are hard to overstate. For businesses, the Internet of Things offers the promise of quantified everything. Employers will be able to track productivity and leverage metrics to uncover new efficiencies. With connected sensors underpinning every square inch of an organization’s footprint — once-siloed data sets can be integrated, correlated and cross-referenced — it will become easier to identify new efficiencies and deliver new value. See Also: Cyber Threats to Watch This Year The benefits are immense – but so, potentially, are the risks. “As we move into having smart workplaces and offices, you’re really talking about a technology backbone that’s driving an organization,” says Stephanie Snyder Tomlinson, a cyber insurance expert at Aon. “What impact can that have on a business? What are the potential losses to an organization if you have a network security breach that results in property damage or bodily injury?” Digital Threats Turn Physical An unfortunate side effect to some of the highest-profile recent cyber breaches is that many people have come to regard cybercrime as solely a privacy issue. It can be far more complex than that. “If there is a failure of network security or systems,” Snyder Tomlinson warns, “there could be a resultant business income loss. It could be intangible loss in terms of loss of data information assets or, especially as we move into relying more heavily on technology and the Internet of Things, it could be tangible loss, as well.” You don’t need to look very far to get a sense of the potential risks to property and other physical assets when the Internet of Things begins to help run a workplace. As organizations grow increasingly dependent on technology to run their businesses and offices, the attack surface for cybercriminals increases dramatically. Each new device represents an additional access point for hackers. The scenarios that could result can sound like something out of a science fiction film:
  • Does your building have computerized entry or elevator systems, with smartcard keys for access? Hackers could take control and lock down your building, trapping employees and visitors inside.
  • Computer-controlled electricity or water supplies can be shut down, rendering working impossible.
  • Connected thermostats are becoming increasingly common and could be taken over — shutting off heating in winter or air conditioning in summer, driving temperatures to unbearable levels and making your office unusable.
  • Logistics servers managing orders and deliveries could be hacked, with real orders canceled, false orders placed or essential supplies redirected to the wrong locations, disrupting your supply chain.
  • Factory robots could be set to destroy rather than create your products.
  • HVAC systems in a company data center could be overridden, causing a rise in temperature that could render network servers inoperable.
  • Fire alarm systems could be turned off just as real-world arsonists attack.
These may sound far-fetched, but are already reality. A cyber attack on a German steel mill in late 2014 caused immense physical damage after hackers installed malware on the network. “It caused the blast furnace to be unable to be shut down, leading to massive property loss,” Snyder Tomlinson says. “The property loss arose from a network security breach. It’s a perfect example of the potential risks when you have companies that are relying on technology to run their business.” Understanding the level of risk “There’s always going to be some type of access point into a network, in one way, shape or form,” Snyder Tomlinson says. “You can have the best network security possible, but as everybody says, ‘It’s not if, it’s when.’” Consequently, many companies are revisiting their approach to cyber security. Organizations previously concerned only with safeguarding client privacy and personally identifiable information are suddenly contemplating a broader loss spectrum. “We’re seeing more interest in cyber insurance from manufacturers and critical infrastructure companies, because they recognize that their exposure isn’t necessarily just about private information or the liability arising out of a breach,” Snyder Tomlinson says. “We’re going to continue to see growth in the breadth of cyber coverage over the next several years, where we’re getting into the true property space, because there is the potential to have a property loss arising out of a network security breach or a systems failure.” Snyder Tomlinson says this is why businesses need to take a holistic view of their cyber vulnerability — “Cyber risk flows through an entire organization.” A good cyber risk management framework has three key elements, she says:
  1. Preparation – Identify and quantify your cyber risk exposures. Develop a breach response plan and business continuity plan. Consider taking out a cyber insurance policy, which can assist with the potential balance sheet impact of a breach.
  1. Practice – Speed of response can be vital to limit damage in the event of a breach. Identify the key stakeholders within the organization and perform a tabletop scenario exercise to ensure everyone knows the role they need to play should an incident occur.
  1. Execution – Engaging with appropriate vendors is critical to successful execution. An organization should have relationships with defense lawyers, a public relations firm and a computer forensics firm so that a firm can work with it to mitigate loss in the event of a breach.
With the rise of the Internet of Things, cyber crime is no longer simply about loss of information. Increasingly, you need to consider the possibility that cyber could be just as physically disruptive to your business as a natural disaster or a terrorist incident. This is no longer simply a data issue — today, property and, potentially, lives could be at stake.

John Bruno

Profile picture for user JohnBruno

John Bruno

John G. Bruno serves as Aon’s chief operating officer as well as chief executive officer of Aon’s data and analytic services solution line, which includes the firm’s technology-enabled affinity and human capital solutions businesses.

Verizon Strike: Silver Lining and a Lesson

The benefit: Managers are getting a first-hand look at what it’s like to be on the front-line, suffering from problems they will now fix.

sixthings
A strike of 40,000 Verizon employees could be the best thing that has ever happened to the telecom company’s customer experience. That’s not because the managers filling in for the front-line workers are better at serving customers (a company executive acknowledged as much in a recent Washington Post interview). Rather, it’s because these managers are getting a first-hand, unvarnished look at what it’s like to be on the front-line. They’re seeing, with their own eyes, the obstacles that hamper employees’ best efforts to deliver a consistently great customer experience. Verizon managers and professional staff who normally work with spreadsheets, reports and legal briefs are instead donning call center headsets, laying fiber optic cable and installing internet service. And, as the Wall Street Journal recently reported, when these organizational leaders temporarily take on a front-line role, they’re spotting a variety of improvement opportunities. An operations head whose management reports frequently showed wide variations in TV/internet installation times suddenly saw the reasons why such variations exist, putting him in a much better position to come up with solutions. An engineer who normally monitored Verizon’s network from an office cubicle quickly discovered how work schedules can be completely disrupted when installers don’t get the information they need (such as whether a customer’s residence has previously been wired for cable or Internet). Front-line annoyances — things that make workers’ jobs harder than they need to be — also came to light, such as how quickly the batteries drained in field technicians’ smartphones and tablets. (A Verizon manager is now exploring supplying the company’s installers with portable battery packs for their devices.) See also: Is Verizon About to Outmaneuver Insurers? These examples all illustrate the inherent limitations of relying on spreadsheets, reports and other traditional management information sources to reveal workplace impediments. The internal obstacles that undermine a company’s customer experience are frequently rooted in some of the most mundane and unglamorous activities. They involve things that often don’t make it into a management report and don't get discussed at an executive staff meeting. By periodically venturing “into the wild” and stepping into the shoes of employees, managers can guard against this blind spot. They can witness what’s really happening on the front lines and can gain insight that’s difficult to obtain in any other way. When armed with this unfiltered perspective, managers are much better equipped to develop actionable improvement plans — the kind that don’t just enhance the customer experience but the employee experience, too. Don’t wait for a worker strike or some other crisis situation before venturing out to your front line. Set aside time now and start walking a few miles in your staff’s shoes. As Verizon’s managers are fast learning, there’s no better way to understand and start overcoming the internal impediments that can sabotage your customer experience. This article first appeared at Watermark Consulting.

Jon Picoult

Profile picture for user JonPicoult

Jon Picoult

Jon Picoult is the founder of Watermark Consulting, a customer experience advisory firm specializing in the financial services industry. Picoult has worked with thousands of executives, helping some of the world's foremost brands capitalize on the power of loyalty -- both in the marketplace and in the workplace.

Secrets InsurTechs Need to Learn

By looking at the Italian best practices in telematics for cars, one can identify two critical success factors for other innovators.

sixthings
The insurance sector is becoming more innovative. Various initiatives and projects launched around the globe are proof of that — from the classic “call for ideas” and corporate venture capital to innovation labs and accelerators that involve the largest insurance companies. According to CB Insights, InsurTech — which involves rethinking one or more steps of the insurance value chain through the use of technology — received $650 million in funding in the first quarter of 2016, and the number of transactions more than doubled compared with the same period in 2015. The Italian insurance sector represents an interesting case history about InsurTech. Italy has the most advanced experience in combining the car insurance contract with hardware (the black box) and using that data throughout the insurance value chain. According to Bain Telematics, Connected Insurance & Innovation Observatory — a think tank Bain & Company developed with ANIA, AIBA and other insurance and non-insurance partners to help spread innovation culture in the insurance sector — telematics penetration reached 16% of all cars insured in Italy by the last quarter of 2015. See also: The Future of Telematics is... Italy In Italy, this type of approach is already mainstream — in contrast with other countries, where it is still a niche-value proposition. By looking at the Italian best practices, one can identify certain critical success factors. The most important element is telematics’ capacity to improve the insurance bottom line; a significant self-selection effect exists on customer acquisition and on material savings related to claims settlement (provided that adequate processes are in place and use the telematics information). The second aspect is represented by the benefit of introducing value-added services around the driver journey. The key element for both the client and the distributor is the partial kickback of the value generated by the telematics approach on the insurance bottom line to both the client (via a discount) and the distributor (via additional fees). The current discussion of how telematics will evolve focuses on gamification and reward mechanisms  mechanisms to manage client engagement and retrocession prizes other than insurance premium discounts. For example, in the U.S., Allstate has adopted a score- and prize-based system related to driving behavior. The best practice internationally is undoubtedly Vitalitydrive, the approach through which Discovery (South Africa) has created a motor-telematics policy based on driving behavior. In this case, the cash-back incentive for gasoline bought from partner gas stops replaces the premium discount. By comparing gamification use cases with Italian best practices, insurers can retain an incremental quota of generated value, through telematics solutions that provide rewards financed by partners instead of through premium discounts. This approach requires the creation of an ecosystem of partners to provide a tangible value for the customer. Rewards can be effective ways to steer behavior if they are built on mechanisms that result in frequent interaction with the client. From this point of view, the integration of monitoring driving behavior and the reward-system mechanism has a greater influence on behavior than a tariff that calculates the renewal premium based on those same variables. See also: InsurTech Forces Industry to Rethink The stakes are high for the insurance sector, and the auto insurance mandate has created the conditions for insurance companies to become relevant actors within the ecosystem. That said, the insurance sector faces a double challenge: first, to introduce this type of creative thought inside the product development process and, second, to become equipped with competencies and instruments that enable the management of both gamification dynamics and the partner ecosystem. These challenges are forcing insurance carriers to start thinking and acting like InsurTech entities.

Theranos: A Hard Lesson for Innovators

Silicon Valley often thinks it can live by a different set of rules than corporate America because it is innovating. Wrong.

sixthings
The Theranos saga hit another low when the company informed regulators that it was voiding two years of tests from its Edison blood testing devices and sending of tens of thousands of revised test results to doctors. This means thousands of patients received incorrect results and were likely given incorrect treatments.  These doctors and patients trusted Theranos, relying upon the brand value of the gilded names the company promoted as its governance oversight, presuming somebody truly conducted some genuine, diligent reviews. These names included diplomatic and military titans such as two former U.S. secretaries of state (Henry Kissinger and George Schultz), former U.S. senators (Sam Nunn and Bill Frist), a former U.S. secretary of defense (William Perry) and, surprisingly, the tough-minded former CEO of Wells Fargo, Richard Kovacevich. Didn’t Theranos CEO Elizabeth Holmes and her executive team realize they were risking lives by using unproven and faulty equipment? Didn’t the all-star board ask tough questions about the workings of the technology? Didn’t the leaders understand that ethics is a slippery slope, that once you compromise there is no turning back? Sadly, we have seen too many  ethical lapses and too much lack of disclosure to shareholders in the technology world. We have written about Silicon Valley’s careless and arrogant frat-boy culture; warned Uber’s CEO he risked being known as a modern-day robber baron for his dubious business practices; and battled tech titans who pay children to drop out of school before they have developed important social skills and ethical values. See also: The State of Ethics in Insurance We can list more than 50 tech firms that died when their governance failed long before their technology. One example was Informix — a fallen star of Silicon Valley and a darling of Wall Street. Founded in 1980, it towered over its rivals Oracle and Sybase as the first of the database giants to offer object relational database support with superior multi-media storage built in. Nonetheless, its poor governance drowned out its technological triumphs, as misstated revenue recognition and accounting fraud led to the imprisonment of celebrity CEO Phil White and to the firm’s ultimate collapse. Silicon Valley often thinks it can live by a different set of rules than corporate America because it is developing world-changing innovations and because start-ups need the freedom to innovate. Yes, we need to allow entrepreneurs to take risks and break some rules so they can do their magic. But these rules cannot be ethical ones. The lines on ethics are usually clear, as they were with Theranos, and there can be no compromise. Profiteers are always ready to exploit markets fueled by hope, hype and emotion.  Here are some lessons: 1. Question the over-hyped founders. Theranos’s CEO notoriously chased testimonial media appearances and self-aggrandizing promotional materials and strutted before cheering and unquestioning audiences of wannabe disrupters at TED talks. Instead, look for leaders who engage in debate with people who understand the core technology and may fortify or enhance the original concept. If you look at some of the biggest and most successful companies, some of the most vital names — Robert Noyce at Intel; Paul Allen at Microsoft, Steve Wozniak at Apple, David Filo of Yahoo; Sergey Brin of Google; etc. — are not the names attached to the company by the media, but, of course, they were crucial in each firm’s future technical, commercial and moral trajectory. The wisdom of Abraham Lincoln’s Team of Rivals has value beyond politics. 2. Beware of leaders who hide behind the cloaks of marquee names. Celebrity roll-ups are used as governance smoke screens from substance. It seems too obvious to state what must yet still be stated, that boards must be recruited from the ranks of those with relevant skill and knowledge, not from the gossip pages. The three board members who seemed to understand Theranos’s technology quit en masse three years ago. 3. Dissent is not disloyalty. Tech leaders should embrace outside critics and listen to internal challenges rather than disparage — and even threaten — dissenters. The chief science at Theranos killed himself, after reportedly telling his wife that the technology did not work. Frustrated internal whistleblowers revealed to The Wall Street Journal that the firm’s celebrated systems were no longer even used for most of the several types of tests they ran. The boards of start-ups must also be held to higher standards. When they join a board, venture capitalists have a fiduciary duty to represent the interests of all shareholders, not only their funds. While Theranos is not a publicly listed enterprise, members of the board still staked their good names to reassure investors, strategic partners, employees and the public — in this case not just verifying financial health but also physical health. During the dizzying days on the eve of the dot-com crash, many innovative firms skyrocketed as they disrupted the defensive old order. Anyone who questioned the hype was trashed as a neo-Luddites defending the past. Prominent governance apologists celebrated “e-board governance,” a self-righteous term replacing traditional diligent governance. Such new-age board oversight encouraged venture capitalist service on scores of boards, misleading pro forma financial reports, backdating stock options, illegally booked barter deals and following other reckless practices while waving away oversight through marquee names. Two decades later, “the Valley” should ascend from such governance lowlands. Jeffrey A. Sonnenfeld, a professor at the Yale School of Management, is the co-author of this article.

Vivek Wadhwa

Profile picture for user VivekWadhwa

Vivek Wadhwa

Vivek Wadhwa is a fellow at Arthur and Toni Rembe Rock Center for Corporate Governance, Stanford University; director of research at the Center for Entrepreneurship and Research Commercialization at the Pratt School of Engineering, Duke University; and distinguished fellow at Singularity University.

Healthcare Case on Cutting Corners

A settlement with Raleigh Orthopaedic is just the latest in a growing series of high-dollar resolution agreements about privacy standards.

sixthings
Healthcare providers, health plans, healthcare clearinghouses (covered entities) and business associates that provide services that deal with protected health information received another reminder to be prepared to prove they are properly handling and administering electronic and other protected health information. This came after the Department of Health & Human Services Office of Civil Rights (OCR) announced its latest in a growing series of high-dollar resolution agreements with a covered entity that was charged with violating the privacy and security standards of the Health Insurance Portability and Accountability Act (HIPAA). Raleigh Orthopaedic Charges and Resolution Agreement The Resolution Agreement and Corrective Action Plan announced by OCR on April 20 requires the Raleigh Orthopaedic Clinic, P.A. to pay $750,000 to settle charges that it violated the privacy rule. The clinic handed over the protected health information of approximately 17,300 patients to a potential business partner without first executing a business-associate agreement. Raleigh Orthopaedic is a provider group practice that operates clinics and a surgery center in the Raleigh, NC, area. OCR’s investigation indicated that Raleigh Orthopaedic violated privacy rules by releasing X-ray films and related protected health information of patients to an entity that promised to transfer the images to electronic media in exchange for harvesting the silver from the X-ray films. Raleigh Orthopaedic failed to execute a business associate agreement with this entity before turning over the X-rays and protected health information (PHI). Although the resolution only addresses charges OCR brought against the covered entity (Raleigh Orthopaedic), business associates need to keep in mind that both covered entities and business associates are now responsible for ensuring compliance with the business associate agreement requirements of the privacy rules — ever since the stimulus bill amended HIPAA to make most provisions of the privacy rule directly applicable to business associates, as well as covered entities. Takeaways for Covered Entities and Their Business Associates The resolution agreement includes a strong message for other covered entities and business associates: It's important for an entity to take seriously its responsibility under the privacy rule to ensure the business associate agreement requirements of the privacy rule are met before business associates are allowed to receive, access or use protected health information. Jocelyn Samuels, the director of the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR), said, “It is critical for entities to know to whom they are handing PHI and to obtain assurances that the information will be protected,” and “HIPAA’s obligation on covered entities to obtain business associate agreements is more than a mere check-the-box paperwork exercise.” In many cases, the process of evaluating the adequacy of current arrangement and of considering the advisability of changes to tighten existing practices will result in the discovery and discussion of potentially sensitive information. For example, it is possible that, in the course of review, parties may be unable to locate a signed business associate agreement that governs a relationship, or, in the course of review, information indicates breaches of protected health information or other privacy rule violations may have occurred. For this reason, most covered entities and their business associates will want to consider arranging it so this review and analysis is conducted within the scope of attorney-client privilege or under the direction of qualified legal counsel with HIPAA experience who has entered into a business associate agreement.

Cynthia Marcotte Stamer

Profile picture for user CynthiaMarcotteStamer

Cynthia Marcotte Stamer

Cynthia Marcotte Stamer is board-certified in labor and employment law by the Texas Board of Legal Specialization, recognized as a top healthcare, labor and employment and ERISA/employee benefits lawyer for her decades of experience.

The Need to Automate Reinsurance Programs

Most insurers still use the equivalent of a shoebox to keep track of reinsurance contracts and claims.

sixthings
"Do you know where your children are?” That was a popular catchphrase in a TV public service announcement. Do you know where your reinsurance program is? Many senior executives at insurers can’t say for sure. Many insurers find it a struggle to document their ceded reinsurance program (the risk they have transferred to a reinsurer) in a way that’s acceptable to regulators—and senior management—because they have not automated management of ceded reinsurance policies, data and claims. According to a recent survey, only 14% of primary carriers have a reinsurance system. Most insurers still use spreadsheets or other manual methods to keep track of their reinsurance contracts and claims. The NAIC Risk Management and Own Risk and Solvency Assessment Model Act (RMORSA) became effective in January 2015, and many states have adopted this model legislation. RMORSA requires insurers to have a systematic way of identifying, assessing and managing risk, and everything related to reinsurance is certainly part of it. Under it, insurers are required to submit an annual summary report to their primary regulator. A key part of complying with RMORSA, and other regulations, will be documenting reinsurance coverage in detail. It is possible to comply with RMORSA without a true reinsurance system. But it’s a difficult, time-consuming process that doesn’t guarantee good results. Using a spreadsheet and other manual methods to track contracts and claims doesn’t give you everything you need in one place for regulatory filings. For instance, an insurer might not being able to identify out-of-compliance policies. This can occur when a reinsurer requires one or more exclusions in the policies it reinsures. If the insurer issues the policies without the exclusions, the policies are out of compliance, and the reinsurer may deny liability when there’s a claim. But complying isn’t just a bureaucratic exercise. The RMORSA process also helps insurers get a clearer picture of their risks—and what could be more important for a company whose business is managing risk? Implementing a modern reinsurance management system enables complete automation, controls and audit trails. It will generate Schedule F and statutory reporting at a click of a button. This, in turn, will reduce Schedule F penalties to the bare minimum. Managing Risk Regulatory compliance is hardly the only reason to use dedicated software to track ceded reinsurance. Intricate reinsurance contracts and special pool arrangements, numerous policies and arrays of transactions create a massive risk of having unintended exposures. Inability to ensure that each insured risk has the appropriate reinsurance program associated with it is a recipe for disaster. An insurer must track and integrate many reinsurance processes. They include cession treaties and facultatives, claims and events, policy management, technical accounting (billing), bordereaux/statements, internal retrocession, assumed and retrocession operations, financial accounting, accounts payable, accounts receivable, regulatory reporting, statistical reports (such as triangulation per line of business, type of contract and region) and business intelligence. With fragmented solutions such as spreadsheets and manual processes, things often fall between the cracks because there are so many reinsurance-related items to manage. Financial information for trends, profitability analysis and exposures becomes unreliable. Automating processes can reduce the chances of missing something important to almost zero. Stanching Claims Leakage One of the biggest problems is claims leakage. How do you know when a reinsurer owes your company money? Answering that question is not as straightforward as it seems, given the complexity of many different types of reinsurance contracts. For instance, after implementing a reinsurance solution, a European insurer detected more than $1 million of overlooked claims. (You can’t file a claim if you don’t know you have one.) It contacted its reinsurer, which paid promptly. The situation for insurers that don’t automate will only get worse. Many of the experienced reinsurance administrators have retired or will be retiring in the next few years, and there are few in the pipeline coming up. With reinsurance becoming ever more complicated, the only feasible answer for insurers is a comprehensive reinsurance system that puts everything in one place. The effort and cost are well worth the benefits in staff productivity, risk reduction, better claims tracking and improved regulatory compliance—to avoid RMORSA remorse and a host of other problems.

Joseph Sebbag

Profile picture for user JosephSebbag

Joseph Sebbag

Joseph Sebbag is CEO of Effisoft USA in Dallas and an expert in reinsurance software for primary insurers and reinsurers. Sebbag was director of business development for Canada at MphasiS-Wyde, a provider of core insurance systems. Previously, he was assistant vice president, reinsurance, at SCOR.