Download

The Myth of the Protection Gap

The protection gap doesn't exist. We're just kidding ourselves -- while condescending to our customers.

sixthings

A friend and colleague, Chunka Mui, once said, "Marketing is when a company lies to its customers. Market research is when a company lies to itself." In the insurance industry, talk of the protection gap manages to combine both problems: It's something of a lie to customers and is an even bigger lie to ourselves.

People routinely talk about the protection gap -- the difference between losses incurred and the amount that are covered by insurance -- as though the number shows how much more insurance people and organizations should be buying. We comfort ourselves with the size of that number, because we think it represents opportunity for us. We also, frankly, get a little condescending about the people and organizations that aren't bright enough to buy our product to cover their losses.

But if you look at it from the customer standpoint, there isn't a gap. We're just kidding ourselves.

To make the math simple, let's pick a country at random and make up some numbers out of whole cloth. Let's imagine we're Gabon, and we, as a nation, incur $1.5 billion of losses a year, while only $500 million is covered by insurance. We're told we have a protection gap of $1 billion. We should buy $1 billion of additional coverage. It'll only cost us $1.3 billion. That's because -- again, in very rough numbers -- the insurer has to tack on 20% on top of the losses to cover expenses and needs its 10% profit margin to keep shareholders happy. But why would Gabon decide to overpay by $300 million a year?

The insurer's employees and shareholders are surely nice people who could use the money, but shouldn't Gabon take care of its citizens? I understand about peace of mind and surely believe that insurance plays a crucial role in the world economy, but, from a certain perspective (one that many customers take), I'd be better off going to a casino and playing the slot machines rather than buy insurance. The casino might even throw in free drinks and a show.

Insurance needs some new math to replace the protection gap, and we need to stop acting as though it's a real thing that a customer might care about. The first step is to cut expenses radically -- perhaps 50%. I use that number because a famous consultant/author with whom I have worked is going to argue in a book soon that every business needs to cut operating expenses by 50% within five years. I also see enough innovation happening around the edges in insurance that I think radical cost cuts are possible.

For instance, at the Global Insurance Symposium in Des Moines last week, I met the founder of RiskGenius, whose artificial intelligence could automate the work of whole swaths of people at brokerages who review the constant stream of changes in policies. But even that new math only shrinks the problem. Add half the previous expenses onto that $1 billion of insurance for Gabon, stir in the required profit, and you're still asking the country to pay $1.2 billion to cover $1 billion of losses.

The real change can only happen when insurance gets out of its product mindset and shifts to a service mentality. Then someone could go to Gabon and say, "Our insurance company knows an awful lot about how losses occur. How about if we advise your government, your companies and your citizens and help you prevent as many as we can?"

Then, perhaps, you shrink those losses by a third -- and keep some of that difference as profit. If you still take that whack at expenses, you could tell Gabon: "We'll take responsibility for your $1.5 billion of losses (both the insured and the uninsured), and it'll only cost you $1.25 billion. You'll come out $250 million ahead, while we cover all our expenses and earn $100 million profit." That $250 million gain is the kind of gap a customer will believe in.


Paul Carroll

Profile picture for user PaulCarroll

Paul Carroll

Paul Carroll is the editor-in-chief of Insurance Thought Leadership.

He is also co-author of A Brief History of a Perfect Future: Inventing the Future We Can Proudly Leave Our Kids by 2050 and Billion Dollar Lessons: What You Can Learn From the Most Inexcusable Business Failures of the Last 25 Years and the author of a best-seller on IBM, published in 1993.

Carroll spent 17 years at the Wall Street Journal as an editor and reporter; he was nominated twice for the Pulitzer Prize. He later was a finalist for a National Magazine Award.

Transparent Reinsurance for Health

Transparent reinsurance programs to address health insurance could emerge as significant opportunities.
sixthings

Transparent reinsurance programs could emerge as significant opportunities for healthcare providers, issuers, reinsurers, technology innovators and regulators to address health insurance. 

The message is clear. Having to factor in higher costs associated with new entrants to the healthcare system gives insurance firms license to charge higher rates. If these new people were put into a reinsurance pot for three to five years with costs spread over all insurers, no one insurer would be unnecessarily burdened. After this period, costs for these entrants could be reexamined and a decision could be made on how to proceed with them, depending upon the deviation from the remaining population. 

Several factors are coming into play.  United Health Group indicates it will be leaving all but a few of the 34 states where it is offering health insurance under Obamacare. A fresh Blue Cross Blue Shield study finds recent Obamacare entrants have higher rates of specific illnesses and used more medical services than early entrants. 

“Medical costs of care for the new individual market members were, on average, 19% higher than employer-based group members in 2014 and 22% higher in 2015. For example, the average monthly medical spending per member was $559 for individual enrollees versus $457 for group members in 2015,” the study found. 

What emerges in conversations with economists, regulators and healthcare actuaries is a sense that properly designed, fair and transparent reinsurance could—and would—advance industry and public policy goals to continue insurance for all at affordable prices. 

This approach would represent tangible improvements over inefficient, incumbent systems. Information would be used by insurers and reinsurers, providers and regulators and, crucially, insureds to establish best performances for healthcare outcomes and expenses. Virtually everyone knows that state or regional reinsurance would have to be mandated, as voluntary systems could be gamed. 

“The implementation of new policies, the availability of research funding, payment reform and consumer- and patient-led efforts to improve healthcare together have created an environment suitable for the successful implementation of patient-reported outcome measures in clinical practice,” fresh research in Health Affairs also indicates. Risk analysis technologies could help issuers, reinsurers, healthcare institutions and citizens rein in the healthcare system's enormous costs. 

Earlier this year, the Congressional Budget Office and Joint Committee on Taxation projected that, "in 2016, the federal subsidies, taxes and penalties associated with health insurance coverage will result in a net subsidy from the federal government of $660 billion, or 3.6% of gross domestic product (GDP). That amount is projected to rise at an average annual rate of 5.4%, reaching $1.1 trillion (or 4.1% of GDP) in 2026. For the entire 2017–2026 period, the projected net subsidy is $8.9 trillion.” 

CBO/JCT published this stunning projection amid consensus that $750 billion to $1 trillion of wasted spending occurs in healthcare in the U.S. “Approximately one in three health care dollars is waste,” Consumer Reports says. 

Key metrics should focus on estimates of risk using demographics and diagnoses; risk model descriptions; calculation of plan average actuarial risk; user-specified risk revealing and detailing information; drill-down capabilities clarifying research; monitoring and control; and calculation and comparison measures to address reinsurance validation. Several major refinements yielding and relying upon granular, risk-revealing data and metrics would support more efficient reinsurance. All would, and could, update reinsurance information and address customer experience, trust and privacy concerns. 

As the industry has noted, ledger technologies could play fundamental roles as blockchains. Indeed, blockchain technologies are just now being introduced in the U.K. to confirm counter party obligations for homeowners' insurance. 

“Advanced analytics are the key,” remarked John Wisniewski, associate vice president of actuary services at UPMC Health Plan. “Predictive capability that looks at the likelihood a patient admission may be coming is the information that we can give to doctors to deal with the matter. … Whoever develops algorithms for people who will be at risk—so providers can develop plans to mitigate risk—will create value for issuers, providers and members alike.” 

Available technologies support the connecting of risk assessments with incentives for risk information. Michael Erlanger, the founder and managing principal of Marketcore, said, “We cannot know what we cannot see. We cannot see what we cannot measure. These available technologies provide clarity for more efficient health insurance and reinsurance." 

Context: Three Rs: Reinsurance, Risk Corridors and Risk Adjustment 

When Congress enacted the ACA, the legislation created reinsurance and risk corridors through 2016 and established risk adjustment transfer as a permanent element of health insurance. These three Rs—reinsurance, risk corridors and risk adjustment—were designed to moderate insurance industry risks, making the transition to ACA coverage and responsibilities. 

The Centers for Medicare and Medicaid Services (CMS) within the Department of Health and Human Services (HHS) administers the programs. All address adverse selection—that is, instances when insurers experience higher probabilities of losses due to risks not factored in at the times policies are issued. All also address risk selection, or industry preferences to insure healthier individuals and to avoid less healthy ones. 

With the expiration of ACA reinsurance and risk corridors, along with mandatory reporting requirements this December, healthcare providers, issuers, reinsurers, technology innovators and regulators can now evaluate their futures, separate from CMS reporting. Virtually all sources commend reinsurance and risk adjustment transfer as consistently as they deride risk corridors. Reinsurance has paid out well, while risk corridors have not. Risk adjustment transfer remains squarely with CMS.  

ACA numbers 

While House Republican initiatives try and fail to repeal the ACA, and some news programs and pundits say it is unsustainable, approximately 20 million subscribers are enrolled in Obamacare: with 12.7 million as marketplace insureds, with others through Medicaid and as young adults on parent plans. 

President Obama, in March, remarked: “Last summer we learned that, for the first time ever, America’s uninsured rate has fallen below 10%. This is the lowest rate of uninsured that we've seen since we started keeping these records." 

Subscription ratios are off the charts. Premium increases have been modest, approximately 6% for 2016, experts find. “I see no risk to the fundamental stability of the exchanges,” MIT economist Jonathan Gruber observed, noting “a big enough market for many insurers to remain in the fold.” 

Transitional Reinsurance 2014-16: Vehicle for Innovation  

One of the great benefits of the ACA is eliminating pre-existing conditions and premium or coverage variables based on individual underwriting across the board. Citizens are no longer excluded from receiving adequate healthcare, whether directly or indirectly through high premiums. Prices for various plan designs go up as coverage benefits increase and as co-pays and deductibles decrease, but the relative prices of the various plans are calculated to be actuarially equivalent. 

To help issuers make the transition from an era when they prided themselves on reducing or eliminating less healthy lives from the insureds they covered, to an era where all insureds are offered similar ratings, the ACA introduced reinsurance and risk corridors to cover the first three years (2014 through 2016), in addition to risk adjustment transfer, which will remain in force. 

The concept is relatively simple: Require all issuers to charge a flat per-dollar, per-month, per-"qualified" insured and create a pot of money with these "reinsurance premiums" that reimburses issuers for excess claims on unhealthy lives. Issuers would be reimbursed based on established terms outlined in the ACA. Reinsurance reimburses issuers for individual claims in excess of the attachment point, up to a limit where existing reinsurance coverage would kick in. Individuals involved with these large claims may or may not be identified in advance as high-risk. The reimbursed claim may be an acute (non-chronic) condition or an accident. The individual may otherwise be low-risk. 

The important aspect is that all health insurance issuers and self-insured plans contribute. By spreading the cost over a large number of individuals, the cost per individual of this reinsurance program is small to negligible. Non-grandfathered individual market plans are eligible for payments. A state can operate a reinsurance program, or CMS does on its behalf through this year. As a backstop, the federal government put some money in the pot through 2016—just in case the pot proved inadequate to provide full reimbursement to the issuers. 

In a worst-case scenario, the sum of the reinsurance premiums and the federal contribution could still be inadequate, in which case the coinsurance refund rate would be set at less than 100%. As it turned out, 2014 reinsurance premiums proved to be more than adequate, so the refund rate was 100%, and the excess funds in the pot after reimbursement were set aside and added to the pot for 2015, just in case that proves inadequate.

CMS transferred approximately $7.9 billion among 437 issuers—or 100% of filed claims for 2014, as claims were lower than expected— and it has yet to release 2015 payments. The results for 2015 are coming this summer. From the outset, states could, and would, elect to continue reinsurance, the CMS contemplated. In 2012, the CMS indicated that “states are not prohibited from continuing a reinsurance program but may not use reinsurance contribution funds collected under the reinsurance program in calendar years 2014 through 2016 to fund the program in years after 2018." 

Subsequent clarification in 2013 did not disturb state discretion. Current regulation specifies that “a state must ensure that the applicable reinsurance entity completes all reinsurance-related activities for benefit years 2014 through 2016 and any activities required to be undertaken in subsequent periods.” One course of action going forward from 2017 and varying from state-to-state could be mandatory reinsurance enacted through state laws. Healthcare providers, issuers, reinsurers, regulators and legislators could define the health reinsurance best suited to each state’s citizens. 

Reinsurers could design and manage administration of these programs possibly at a percentage of premium cost that is less than what is charged by the federal government today. While these reinsurance programs would be mandated, they could include a component of private reinsurance. For example, reinsurers could guarantee the adequacy of per-month reinsurance premiums with provisos that if these actuarially calculated rates turned out to be inadequate in any given year or month, there will be an adjustment to account for the loss in the following year. Conversely, if those rates turn out to be too high, 90% or more is set aside in an account for use in the following year. This way, reinsurers could participate by providing a private sourced solution to adverse claims. 

Risk Corridors 

Risk corridors apply to issuers with Qualified Health Plans (exchange certified plans) and facilitate transfer payments. The CMS noted: “Issuers whose premiums exceed claims and other costs by more than a certain amount pay into the program, and insurers whose claims exceed premiums by a certain amount receive payments for their shortfall.” Technically, “risk corridors mean any payment adjustment system based on the ratio of allowable costs of a plan to the plan’s target amount,” as the CMS designated. Issuer claims of $2.87 billion exceeded contributions, so the CMS transferred $362 million among issuers; that is, a 12.6% proration or a $2.5 billion shortfall in 2014. Risk corridors are politically contentious. Sen. Marco Rubio (R-Florida) likened risk corridors to bailouts. The HHS acknowledged it will “explore other sources of funding for risk corridors payments, subject to the availability of appropriations… includ[ing] working with Congress on the necessary funding for outstanding risk corridors payments.” And, a knowledgeable analyst, Dr. David Blumenthal, noted that risk corridors are not bailouts. Going forward, evaluations of risk corridors will demand due diligence. Several health exchanges failed from any number of factors—from too little capital for growth experienced, inadequate pricing, mismanagement or risk corridor payments. Whether innovation can yield effective risk corridors or whether risk corridors will simply fade out as transitional 2014-2016 regulation will depend on institutional and industry participants. Risk corridors did not score unalloyed approbation among sources. 

Risk Adjustment: Permanent Element of ACA 

Risk adjustment remains in force and impels issuers with healthier enrollees to offset some costs of issuers with sicker ones in specific states and markets and of markets as a means toward promoting affordable health care choices by discouraging cherry picking healthier enrollees. The HHS transferred approximately $4.6 billion for risk adjustment among issuers for 2014. At first blush, one might postulate that risk adjustment does the job and that reinsurance and risk corridors could just as reasonably fade out. There is some logic to that argument. On the other hand, state or regional level reinsurance could make up for risk adjustment shortfalls. In some instances, risk adjustment seems to be less friendly to issuers that take on higher-risk individuals, rather than rewarding high tech issuers and providers with back office capabilities coding claims in such a way as to tactically game risk adjustment. Evaluating and cultivating these opportunities are timely amid the uncertainties of the presidential and congressional elections that may yield executive and legislative lawmakers intent on undoing ACA provisions, starting with risk corridors. Such legislation could produce losses for issuers and reinsurers. 

Nelson A. Rockefeller Precedent 

In 1954, then-Undersecretary of Health Education and Welfare Nelson A. Rockefeller proposed reinsurance as an incentive for insurers to offer more health insurance. S 3114, A Bill to Improve the Public Health by Encouraging More Extensive Use of the Voluntary Prepayment Method in the Provision of Personal Health Services, emerged in the first Eisenhower administration to enact a federally funded health reinsurance pool. Rockefeller intended the reinsurance as a means toward an end, what would eventually be dubbed a "third way" among proponents of national health insurance. President Truman and organized labor championed the approach into the mid-'50s. So did the Chamber of Commerce and congressional Republican adversaries of the New Deal and Fair Deal, who were chaffing to undo Social Security as quickly as they could. The American Medical Association also supported this third way because it opposed federal healthcare reinsurance as an opening wedge for socialized medicine. Despite limiting risk and offering new products, insurers demurred because of comfort zones with state regulators and trepidation about a federal role.  

Nelson Rockefeller’s health reinsurance plan would “achieve a better understanding of the nation’s medical care problem, of the techniques for meeting it through voluntary means, and of the actuarial risks involved,” HEW Secretary Oveta Culp Hobby testified to a Senate subcommittee in 1954. Rockefeller’s health reinsurance plan did not make it through the House. Organized labor decried it as too little, the AMA said it was too intrusive. Upon hearing news of the House vote, a frustrated Dwight Eisenhower blistered to reporters, “The people that voted against this bill just don’t understand what are the facts of American life,” according to Cary Reich in The Life of Nelson A. Rockefeller 1908-1958. “Ingenuity was no match for inertia,” Rockefeller biographer Richard Norton Smith remarked of industry and labor interests in those hard-wired, central-switched, mainframe times.  

The idea of national health insurance went nowhere despite initiatives by Sen. Edward M. Kennedy (D-Massachusetts) in the late '70s and President Bill and First Lady Hillary Clinton roughly 20 years ago, until Congress legislated Obamacare. 

Innovative, Transparent Technologies Can Deliver Results 

Nowadays, more than 60 years after Rockefeller's attempt, innovative information technologies can get beyond these legislative and regulatory hurdles. Much of the data and networking is at hand. Enrollee actuarial risks, coverage actuarial values, utilization, local area costs of business and cost-sharing impacts on utilization are knowable in current systems. Broadband deployment and information technology innovations drive customer acquisition and information management costs ever lower each succeeding day. Long-term efficiencies for reinsurers, insurers, carriers, regulators, technology innovators and state regulators await evaluation and development. 

Reinsurance Going Forward From 2017 

So, if state reinsurance programs can provide benefits, what should they look like, and how should they be delivered? For technology innovators—such as GoogleMicrosoftOverstockZebra or CoverHound—these opportunities with reinsurance would apply their expertise in search, processing and matching technologies to crucial billion-dollar markets and functions. The innovators hope to achieve successes more readily than has occurred through retail beachheads in motor vehicle and travel insurance and credit cards and mortgages. One observer noted that some of those retail initiatives faltered due to customer experience shortfalls and trust and privacy concerns. Another points out that insurers view Amazon, Apple and Netflix as setting new standards for customer experiences and expectations that insurers will increasingly have to match or supersede. A news report indicated that Nationwide already pairs customer management data with predictive analytics to enhance retention. 

Reinsurers including Berkshire Hathaway, Munich Reinsurance Company, Swiss Reinsurance Company Limited and Maiden Holdings could rationalize risks and boost earnings while providing a wealth of risk management information, perhaps on a proprietary basis. For issuers, state-of-the-art transparent solutions improve the current system by enabling issuers to offer more products and services and becalm more ferocious industry adversaries while lowering risks and extending markets. Smaller, nimbler issuers may provide more innovative solutions and gain market share by providing the dual objectives of better health outcomes with lower costs. For regulators, innovative, timely information sustains the indispensability of state regulators ensuring financial soundness and legal compliance—while allowing innovators to upgrade marketplace and regulatory systems, key regulatory goals that Iowa's insurance commissioner, Nick Gerhart, pointed out recently. 

Commissioner Gerhart envisions regulators as orchestra conductors, acknowledging that most insurance regulatory entities are woefully understaffed to design or operate such reinsurance programs themselves, but they will, and they can lead if the participants can provide turnkey capabilities. Think of health insurance and reinsurance as generational opportunities for significant innovation rather like the Internet and email. When the Department of Defense permitted the Internet and email to evolve to civilian markets from military capabilities in the 1980s, the DOD initially approached the U.S. Postal Service. Senior Post Office management said it welcomed the opportunity to support email: All users need do is email correspondence to recipients’ local post offices by nine p.m. for printing, enveloping, sorting and letter-carrier delivery the following day. Similarly, considerable opportunities chart innovative pathways for state and regional health reinsurance for 2017 and beyond. 

One path, emulating the post office in the '80s, keeps on coding and bemoans a zero sum; it would allow the existing programs to fade away and will respond to whatever the president and Congress might do. Another path lumps issuer health reinsurance as an incumbent reinsurer service without addressing the sustainability of state health exchanges or, indeed, any private health insurers in the absences of risk spreading with readily available information technologies. The approach suggested here—mandated state health reinsurance—innovates to build sustainable futures. Enabling technologies empower all stakeholders to advance private and public interests through industry solutions advancing affordable healthcare.

How to Use Risk Maturity Models

Here is a simple yet comprehensive view of the seven most important factors for managing any risk within your purview.

sixthings
Over the last 10 years of the “risk leader” portion of my career, as the head of enterprise risk management at USAA (2001-10), as well as during my subsequent work as an ERM consultant, I was challenged by several questions that affect risk management results and, by extension, ultimate success. All fell under the header of “risk management maturity,” and focusing on it can provide huge benefits to you and to your organization. To start, we need to get two things straight. First, how are you defining “risk,” and have you driven a consensus among key stakeholders about that definition? Second, which risks are you going to manage, and where on the loss curve do they fall? These questions may sound simple, but the reality is that many risk leaders have responsibilities for only a portion of the risks that organizations face -- often, only the insurable risks. If that’s the case, you have your answer to both questions nailed. See Also: How to Develop Risk Maturity If, on the other hand, you are a risk leader with broader accountability for more or all risks (via enterprise risk management, or ERM) that could affect an organization (both negatively and positively), then the first question -- "how does your firm define risk?” -- requires clear definition. The most commonly accepted definition of risk is “uncertainty.” I like this simple definition, and it captures the most central element of concern. However, the real challenge remains the question about the level of uncertainty (aka frequency/likelihood). To many, even more important is the level of impact or severity. My favorite chart to help illustrate this concept is one where the “tail” of the loss distribution represents where the proverbial “black swans” live. A typical loss curve has as its peak the expected level of loss, and the black swan sits out on the tail of this curve, where the x-axis is impact of severity of loss and the y-axis is the frequency or likelihood of loss. While many hazard-focused leaders put their attention on risks at expected level or to the left along the x-axis where certainty of loss rises, the challenge is where in this region of the curve to the right should one be managing? While the possibility of loss becomes increasingly remote as you move out toward the tail of the curve, the impact of events become more destructive. Key questions that must be answered include:
  • Do we care more about likelihood or impact, or are they equal?
  • What level of investigation do we apply to risks that are remotely likely?
  • How do we apply limited resources to risks that are remotely likely?
  • Do we have a consensus among key stakeholders as to what risks we should focus on and how?
  • Do have or need a process to manage emerging risks?
  • Do we have a consensus on and clear understanding of how we define risk in our organization?
These issues are the starting point to the risk management maturity question, which, if handled well, facilitates organizational success. From these answers, you can chart your course for your firm. The answers will define the process elements of maturity. But we need to define what risk maturity is to track progress toward it and to ensure that stakeholders are aligned around the chosen components. The various components among the numerous risk maturity models tend to overlap considerably. Here’s one generic set of attributes of maturity:
  • Risk is managed to specifically defined appetite and tolerances
  • There is management support for the defined risk culture and direct ties to the corporate culture
  • A disciplined risk process is aligned with other functional areas
  • There is a process for uncovering the unknown or poorly understood risks
  • Risk is effectively analyzed and measured both quantitatively and qualitatively
  • There is collaboration on a resilient and sustainable enterprise
The first, and I think most thoroughly developed, model comes from the Risk and Insurance Management Society (RIMS). It was developed some 10 years ago or so but remains in my opinion a simple yet comprehensive view of the seven most important factors that inform risk maturity and that, when well implemented, should drive an effective approach to managing any risk within your purview. The components of the RIMS model include a focus on:
  • The degree to which an enterprise-wide approach is supported by executive management and is aligned with other relevant functions
  • The degree to which repeatable and scalable process is integrated in the business and culture
  • The degree of accountability for managing risk to a detailed appetite and tolerance strategy
  • The degree of discipline applied to using the elements of good root-cause analysis
  • The degree to which a robust emerging risk process is used to uncover uncertainties to achieving goals
  • The degree to which the vision and strategy are executed considering risk and risk management
  • The degree to which resiliency and sustainability are integrated between operational planning and risk process
As with all risk management strategies (no two of which that I’ve seen are exactly the same), there is no one way to accomplish maturity. Every risk leader needs to do for her organization what the organization needs and will support. Another maturity model that is worthy of note is the Aon model. Like RIMS’ model, it enables multiple levels of maturity and methodology for charting progress toward an ideal state. Characteristics of the Aon model include:
  • Ensuring the board understands and is committed to the risk strategy
  • Establishing effective risk communications
  • Emphasizing the ties among culture, engagement and accountability
  • Having stakeholder participation in risk management activities
  • Using risk information for decision making
  • Demonstrating value
This is not to say that the RIMS model ignores these issues. There is simply a different emphasis. Also noteworthy is Protiviti’s perspective on the board of directors' accountability for risk oversight. A few highlights include:
  • An emphasis on the risks that matter most
  • Alignment between policies and processes
  • Effective education and use of people and their place in the organization
  • Assumptions that are supportable and understood
  • The board’s knowledge of the right questions to ask
  • Focus on understanding the relationship to capability maturity frameworks
Certainly, the good governance of organizations is critical, and the board’s role is paramount. If the board is engaged and accountable for ensuring that its risk oversight is effective, the strategy is likely to be executed successfully and, by inference, risk will have been effectively managed, as well. See Also: How to Link Risk and Strategy To complete the foundation for the business case for using a risk maturity model to track progress, consider these key points:
  • There is no one right approach; each organization must chart its own course aligned with its culture and priorities
  • Risk must be treated as an integral aspect of strategy
  • There must be a focus on additive value, as with all corporate processes
  • Risk maturity has produced documented valuation premium for studied users
With the effective use of risk maturity models, you should be able to better chart your risk evolution journey, and how a good maturity strategy related to corporate strategy and priorities is the ultimate nexus for success. Risk and risk management should drive performance results and what remains to be done to achieve longer-term aspirations. This approach to managing your risk strategy should allow you to:
  • Translate the component of risk maturity into a successful ERM journey
  • Refer to ERM results and impacts achieved by others to buttress your efforts
  • Understand key tactics to exploit and pitfalls to avoid as you perfect your risk management strategy.
Using a risk maturity model will, if nothing else, provide the guard-rails and discipline that may otherwise be missing from your current attempts to make a difference in the success of your enterprise.

Christopher Mandel

Profile picture for user ChristopherMandel

Christopher Mandel

Christopher E. Mandel is senior vice president of strategic solutions for Sedgwick and director of the Sedgwick Institute. He pioneered the development of integrated risk management at USAA.

An Eruption in Disruptive InsurTech?

Not so much: "Nothing I saw in these presentations made me believe this group of companies would be genuinely disruptive."

sixthings
I attended an InsurTech “boot camp” at the magnificent Christ Church, Spitalfields, U.K., my first such event, and I was intrigued to see what would be presented and how the audience would react. The organizers billed the day’s theme as “Experience the Eruption.” Their website stated the aim was to “recognize the fast-paced appearance of insurance start-ups, which are creating seismic shifts behind the scenes that will lead to the emergence of a new identity within the insurance sector as we know it today. An 'eruption,' which will allow new disruptive entrants to break out into the mainstream and support an industry that needs to engage differently in a highly customer-centric and digital-friendly world.” Was that lofty ambition that labors excessively on hyperbole, or did the afternoon live up to the hype? The format of the afternoon was a series of Dragons' Den (a U.K. TV show) style pitches (without the interrogation) for investment or partnerships from the incubated firms selected for Startupbootcamp’s program (which includes investment from them, meaning there is an element of self-interest that firms do well). The pitches were preceded by a fireside chat from the chief strategy officer of Knip, a Swiss-based app that acts as a portal and broker for insurance policies. See Also: InsurTech Forces Industry to Rethink Were any truly disruptive? My view is that they all fell into one of three broad camps of focus: Distribution and Sales I’d put four firms in this bracket: MassUp, Spixii, Buzzmove and MyFutureNow — but all had a different focus with different levels of potential disruption. MassUp was all about making buying insurance for "stuff' easier by making it an add-on for any purchase. The company had a good story and was slick, but it didn’t feel truly disruptive. Credit card companies have been offering similar protection for years, and MassUp will do well to distinguish itself from extended warranty products that savvier consumers tend to decline. That, perhaps, is the problem with the business model for me — while tech may make it easy for the consumer to purchase the insurance (and for sales companies to add it as an option), it doesn’t obviously increase the value for the customer. BuzzMove is a successful online removals broker, a portal to help customers find a removal firm when they move houses. The company has added to its capability by recognizing that a key element of quoting for removals is an inventory of the things that need to be moved. Typically, individuals don’t do this when they take out contents insurance (or, indeed, don’t update it when they buy new things), so they run the risk of being under-insured. Linking the life event with an inventory that can be used to underpin an insurance quote is a smart way to add value to the customer — without additional effort. As such, it is effectively looking to take over the customer by owning the life event in the same way banks have looked to do — e.g. take out a mortgage, and they will try to convince you to re-visit your life insurance levels. As such, the concept is not disruptive, but the concept of the home inventory and the tech underlying how this is put together is something insurers (and others) will undoubtedly embrace, so it is therefore significant. I’ll return to this later, as the ownership of this data becomes key. MyFutureNow has a reasonably simple proposition; it is an online portal for customers to manage disparate pension plans by consolidating them into a single plan that is offered through the site. On the surface, its proposition is attractive and is reinforced by a slick implementation of the website and the app — the economics are being driven by a percentage fee on the value of the pension fund when transferred in. The key to success will be to differentiate the consumer experience. However, as regulated financial advisers will tell you, this is a complex area, and the consolidation of old plans is not necessarily the appropriate outcome for all consumers. It is unclear to me the extent to which MyFutureNow has have thought through the compliance and advice issues. Again, the focus is to try and take over ownership of a particular part of a customer's portfolio (in this case, pensions). Spixii’s proposition was timely, what with Facebook’s recent announcement of the addition of "bots" to its Messenger app. Essentially, Spixii offers a message bot that sells insurance (currently just travel insurance, but the concept could obviously be extended quite easily.) Inevitably, all financial service providers will add bots as way of communicating and selling, as will the price comparison websites, so this is definitely an "on-trend" area to watch. Customer Experience Three firms fall into this category: RightIndem, Domotz and Quantifyle. RightIndem looks to enhance claims management by allowing insurers to offer a self-service claims platform and by increasing the transparency of the claims process. Claims is an area consumers point to as frustrating, so any steps to enhance the offering will be hugely positive; it is an area we will see all insurers developing in the coming years. Domotz is a little more difficult to classify as it is not strictly an insurance proposition. The company plays in the space of the Internet of Things and the smart home. The insurance angle is providing information to the customer that will help reduce claims through smart home management (e.g. the customer gets an alert if running water is detected and nobody is home). Insurers might therefore offer discounts to those who install such systems. As such, it is perhaps similar to the wave some years ago when insurers encouraged drivers to fit alarms and immobilizers in their cars before they were standard issue. Quantifyle’s proposition is based on driving good customer behavior for wellness by motivating people to achieve fitness goals. Insurers have already played in this area — most noticeably Vitality, whose entire proposition is built around rewarding customers for their lifestyle. Big Data The last firm presenting is alone in this category, although others touched upon it. Fitsense­ demonstrated how it can harness the data collected from wearable tech (such as fitness trackers and smartphones) and overlay that with environmental information to provide the insurer insight into a customer's lifestyle and behavior. Undoubtedly, there is great insight to be had, but the key element here will be the willingness of consumers to adopt and provide that information to insurers. (Location-aware information was also touched on by Spixii, which speculated that its app could provide, for example, travel insurance options that depend on the travel profile of the individual.) This leads us into the important area of privacy and ownership of that information, with consumers rightly being concerned about the erosion of their privacy. While the youngest generation of consumers are likely to be increasingly less concerned, the adoption will need to happen slowly to bring customers along. There is also the risk of consumer self-selection (similar to the current adoption of "driving standards" apps by motor insurers), and it raises the moral question of whether increasingly individualized risk pricing is at odds with the original insurance principle of pooling of risks. So, What Was Missing? Invariably, InsurTech "innovation" majors on the three areas highlighted above — they are usually the easiest to move elements of the insurance process forward into the digital world but, therefore, are not necessarily disruptive, instead shifting the margin of current offerings. Two areas of development were conspicuous by their absence: Peer-to-Peer insurance This is an area where there are a few start-ups dabbling, but they haven't yet reached any critical mass. Key inhibitors are traditional barriers to entry to the world of insurance, namely regulation and, in particular, capital requirements. It is a fast-moving area and one where, potentially, blockchain technology will grow out of its hype to provide a compelling proposition that satisfies regulators. In particular, recent work suggests that using the Lloyd's of London model as template and porting to a blockchain model could provide the tipping point. Consumer-Owned Risk Assessment While big data has been touted as a way for insurers to get rich, detail on their customers and individualized risk assessment (which, in and of itself is simply a further iteration of the traditional model with more data) leads to issues of privacy and the moral question of individual versus pooling of risk. There is a paradigm shift in the interaction of consumers with institutions in the digital age that isn’t reflected here — that in which the consumer has more power and takes ownership of his or her own data. As such, this could break the mold of the traditional insurance product silos and be truly disruptive. In the new age, the dynamic is reversed, and the richness of data and the assessment of risks an individual faces do not belong to the institution — instead, control is with the individual, who, in turn, get the insight that allows them the power to manage a risk profile. See Also: A Mental Framework for InsurTech This shift has started in wealth management, and it seems natural that insurance will follow. New players in this sector will not be the traditional insurer, as the focus will need to be on providing the value to the consumer with the ownership of the data and allowing the consumer to manage it. This sits more easily with the business model of companies such as Google or Facebook than with the incumbents in the insurance market. Conclusion?  Nothing I saw in these presentations made me believe this group of companies would be genuinely disruptive (or, indeed made me reach for the checkbook to invest). When compared with the broader FinTech spectrum or tech-centric events, the afternoon felt less slick and less innovative. InsurTech is still young, so there is still a lot of maturing to do, but there were one or two hints from these companies that may stimulate discussion, which, in turn, might lead to genuine innovation.

Adam Tyrer

Profile picture for user AdamTyrer

Adam Tyrer

Adam Tyrer has 25 years of experience advising insurers around the globe in implementing change, defining strategy and providing risk and actuarial modeling capabilities. He founded Quintant Partners in 2011 as a boutique consulting firm to work with insurance clients on the use and strategy of modeling tools and technology.

What Comes After Big Data?

Predictive modeling is but an early step; we must see beyond the fleeting ability to increase underwriting profit or fast-track a claim process.

sixthings
The force of transformation in our technological age is undeniable, unpredictable, rapid and without controls to slow or stop. No industry can freeze a convenient moment in time when its commodity has high value that is safe from competitive disruption and in perfect alignment with technology. Any and every business can be blindsided by a competitor’s next-generation upgrade of IT, or an upstart’s reinvented consumer acquisition and interaction experiences. What is new today becomes old in a flash. In the risk and insurance industry, investment is booming in predictive analytics and big data. Many proponents envision the death rattle of stodgy experience mod rating, which would give way to “Moneyball” fantasies flush with evergreen underwriting profits. While Moneyball fantasies may pan out for now, our industry cannot control the genie emerging from this bottle. I suggest we consider when and how big data might mature as a cheap ubiquitous commodity and how to hone the next logical step that capitalizes on its inevitable demise. First, we must accept that the devaluation of predictive analytics is imminent, whenever that comes. Consider these questions: --Will analytics still create any underwriting advantage when all companies are applying similar models? --How will the “smart money” know when to stop huge investments in model-building? When 900 data points show no more appreciable value than 400? When the burdensome collection of data at the adjuster’s interface limits, dumbs down, dehumanizes and fast-tracks the front-line adjusting operation so as to, ironically, become a detriment to claim outcomes in and of itself? See Also: Competing in an Age of Data Symmetry --What happens when the first major broker or marketing interest cracks the dam and applies analytics as a loss-leader to fish for clients or tangentially grow a related market share? For example, offering to analyze a prospect’s work comp for free as part of winning a lucrative global property program. Can you beat the rush as more consumers expect predictive analysis “freebies” as part of the entry expense for winning customer contracts? --How soon will some website’s appetite for “click-bait” mean that it offers free, robust, on-line predictive analytic calculators simply to build email lists of potential WC customers? --What if government interests unleash the ability to apply top-notch WC analytics on an open-source employer platform for the good of the state? Can self-use, cost-saving analytics become a public “right” and not a paid-for “privilege”? Today’s reality is simple: Information is vast, easily accessible and free. This fact not only foretells the demise of the value of big data in our industry, but it also instigates the next step in creating opportunity. This next step will arise from the changing nature of higher education and future job seekers. I was recently privileged to hear a talk by the headmaster of an esteemed college preparatory school, who espoused a necessary wholesale change in education. His premise: There is no longer any value in teaching students facts and information because all of it is available and accessible for free. He considers it educational malpractice to make students learn facts. He has shifted a good part of his school curriculum to project-based learning. Student teams are presented with issues or situations and create solutions or new perspectives that open higher possibilities. One of the project teams tackled the challenge of cross-teaching Mandarin and English languages. Their research discovered that the Chinese have a passion for U.S. basketball. The team produced a video of instructional interactive basketball drills that taught language during the real-time experience of following drill instructions. Their first module is now actually being used in China to support prospective students interested in American schools. The headmaster jokingly said his school may have to forego non-profit status to look for investor money and make the concept a complete language package. Mind you, these creators are teenagers with no real budget who were able to use the Internet and common technology to research, design and produce this valuable product and change notions of language-learning. The bottom line is that future employee talent will not care to know facts but will find its highest value in being able to ignore the conventional, ask the right questions and conceive whole new visions from abundant data and information. This is where our industry must pick up a focus as big data’s intrinsic value declines. Specifically: We need to cultivate real seat-of-the-pants critical thinking around micro-employer data and macro-industry data. We need thinkers who will ask incendiary, never-before-imagined questions and propose changes and interventions that will reinvent how any employer’s WC program might be constructed and operated and how vendors will provide action and service. While vast, yet soon-to-be-cheap, data points will still garner some valid predictions, monetizing the employer’s change proposition and perhaps having a stake in the outcome will be where the future profit lies. Not just any claims expert can provide value at this needed level, as most in today’s world only know templates and best-practice concepts. Very few have skill in ground-up, project-based problem solving. The next wave of industry smart money must seek out and hire a new army of solution-prone human capital. Our industry must admit that predictive modeling is but an early step toward other means of value beyond just the current fleeting ability to increase underwriting profit or fast-track a claim process. The ancient industry construct that silos underwriting, sales and claims needs a re-assessment of where priority human capital investment lies and of how cross-skills must work together. See Also: The Science (and Art) of Data, part 1 Perhaps current position value will flip-flop… the soon to be data-rich yet bulk-automated underwriting process might become an offshore, outsourced common function while the adjuster will emerge as a future kingpin in protecting profitability and holding the highest salaried function – abundant with talent and intuition while provided ample time to ask the right questions employer by employer and claim by claim. I welcome any entity that wants to explore and build the next value-wave on the downside of big data to please contact me.

Barry Thompson

Profile picture for user BarryThompson

Barry Thompson

Barry Thompson is a 35-year-plus industry veteran. He founded Risk Acuity in 2002 as an independent consultancy focused on workers’ compensation. His expert perspective transcends status quo to build highly effective employer-centered programs.

Key Regulatory Issues in 2016 (Part 2)

Large insurers must understand and manage regulatory mandates across more jurisdictions and services than ever before.

sixthings
The complexities of the current regulatory environment undoubtedly pose significant challenges for the broad spectrum of financial services companies, as regulators continue to expect management to demonstrate robust oversight, compliance and risk management standards. These challenges are generated at multiple, and sometimes competing, levels of regulatory authority, including state and local, federal and international, and, in some cases, by regulatory entities that have been newly formed or given expanded authority. Their demands are particularly pressing for the largest, most globally active firms, though smaller institutions are also struggling to optimize business models and infrastructure to better address the growing regulatory scrutiny and new expectations. In the first part of this two-part series, we covered the first five key regulatory issues we anticipate will have an impact on insurance companies this year. Here are the final five: 6. Transforming the Effectiveness and Sustainability of Compliance Compliance continues to be a top concern for financial institutions and insurance companies as the pace and complexity of regulatory change, coupled with increased regulatory scrutiny and enforcement activity, have pushed concerns about reputation risk to new levels. These firms need to be able to respond to changes in their internal and external environments with flexibility and speed to limit the impact from potentially costly business shifts or compliance failures. To do so, however, can demand enhancements to the current compliance risk management program that build adaptability into the inter-relationships of the people, processes and technologies supporting compliance activities; augment monitoring and testing to self-identify compliance matters and expand root cause analysis; and integrate compliance accountability into all facets of the business. Compliance accountability starts with a strong compliance culture that is supported by the “tone from the top” and reaches across all three lines of defense, recognizing that each line plays an important role within the overall risk management governance framework. Transforming compliance in this way allows it to align on an enterprise-wide basis with the firm’s risk appetite; strategic and financial objectives; and business, operating, functional and human capital models. 7. Managing Challenges in Surveillance, Reporting, Data and Control Driven largely by regulatory requirements and industry pressures for increased speed and access, trade and transaction reporting has become increasingly complex. Capturing and analyzing vast amounts of data in real time remains a massive challenge for financial services firms, as regulators continue to initiate civil and criminal investigations and levy heavy fines on broker-dealers, investment banks and insurance companies based on failures to completely and accurately report required information. In addition, ensuring compliance with federal and state laws prohibiting money laundering, financial crimes, insider trading, front running and other market manipulations and misconduct remains critically important. In the coming year, it will be essential for financial institutions and insurance companies to reassess the strength and comprehensiveness of their compliance risk management programs to better manage and mitigate both known and emerging regulatory and legal risks and respond to prospective market structure reforms. See Also: Should We Take This Risk? 8. Reforming Regulatory Reporting The financial services industry, including the insurance sector, continues to face challenges around producing core regulatory reports and other requested financial information, as demands from both regulators and investors have increased exponentially in the wake of the financial crisis. For insurance companies, the IAIS faces a significant challenge as there is no common basis of accounting applied across jurisdictions, either for regulatory or financial reporting purposes. The need for consistent regulatory reporting has been highlighted by the efforts of the IAIS to develop an insurance capital standard for IAIGs as well as basic capital requirements (BCR) and a higher loss absorbency (HLA) for global systemically important insurers. The IAIS is moving toward a market-consistent basis of valuation for both assets and liabilities to underpin this effort. Complementing the work previously performed by the Financial Stability Oversight Council, which solicited comment on certain  aspects of the asset management industry that included requests for additional financial information that would be helpful to regulators and market participants, the SEC published rules to modernize and improve the information reported and disclosed by registered investment companies and investment advisers (Investment Company Reporting Modernization, proposal published in June 2015). Among other areas of reform, the SEC’s rule is intended to provide enhanced information that will be used to monitor risks in the asset management industry as a whole and increase the transparency of individual fund portfolios, investment practices and investment advisers, particularly for derivatives, securities lending and counterparty exposures. Fund administrators and managers will likely need to carefully contemplate and implement new governance, operational and reporting capabilities that will be necessary to support enhanced reporting and disclosure requirements. 9. Examining Capital Recovery and Resolution Planning and the EPS for large U.S. bank holding companies, foreign banking organizations and insurance and nonbank financial companies have brought capital planning and liquidity risk management to the forefront, as regulators have sought to restore both public and investor confidence in the aftermath of the financial crisis. Financial institutions, including nonbank SIFIs, are required to demonstrate their ability to develop internal stress testing scenarios that properly reflect and aggregate the full range of their business activities and exposures, as well as the effectiveness of their governance and internal control processes. A growing number of state regulators have adopted the Own Risk and Solvency Assessments (ORSA) requirement to support insurers’ risk management and capital adequacy. The international development of an insurance capital standard for IAIGs continues along with BCR and HLA requirements. In the U.S., the NAIC and state regulators are working closely with the Federal Insurance Office, the Federal Reserve and industry participants to develop a group capital assessment. Insurers, however, are challenged to fit capital requirements originally designed for banks into the insurance business model along with group capital into local entity capital requirements. The potential variability and current uncertainty resulting from these and other pending requirements may limit funding flexibility and make capital planning difficult, as financial institutions will need to consider the ties between capital and liquidity in areas such as enterprise-wide governance, risk identification processes, related stress testing scenarios and interrelated contingency planning efforts. 10. Managing the Complexities of Cross-Border Regulatory Change The largest financial institutions and insurance companies must now understand and manage regulatory mandates across more jurisdictions and services than ever before. Regulatory obligations and cross-border pressure points continue to challenge global financial firms to move past their current reactionary mode of response to tackling high-impact regulatory change. For insurers and their regulators (both international and domestic), the integration of ComFrame (Common Framework) into local entity requirements as they are adopted by individual jurisdictions will be such a challenge. Anticipating the recognition of “equivalence” or a covered agreement for certain U.S. regulations under Solvency II for U.S. insurers operating in Europe is another. However, to address these challenges, financial institutions and insurance companies will need to consider implementing a regulatory change management framework that is capable of centralizing and synthesizing current and future regulatory demands and incorporates both internally developed and externally provided governance, risk management, and compliance regulatory change tools. This framework will enable financial entities to improve coordination across their operations and gain insights that can improve overall performance, ensure risk management and compliance controls are integrated into strategic objectives, avoid redundancy and rework and better address regulatory expectations in a practical and efficient way. This piece was co-written by Amy Matsuo, Tracey Whille, David White and Deborah Bailey.

Stacey Guardino

Profile picture for user StaceyGuardino

Stacey Guardino

Stacey Guardino is a New York based partner in KPMG’s financial services regulatory practice. She has more than 25 years of experience serving diversified financial institutions focusing on insurance and bank holding companies.

It's Time for a Consumer Bill of Rights

It is time for the insurance industry to wake up -- or it will have further fiduciary regulations and scrutiny thrust upon it.

sixthings
On April 6, 2016,  the Department of Labor (DOL) released its long-awaited fiduciary rule. It is clear that things will never be the same. While the fiduciary rule is limited in the products that it applies to, it is a clear sign that the time has arrived for the Insurance Consumer Bill of Rights. Some complain bitterly about the rule -- William Shakespeare has Queen Gertrude say in Hamlet, "The lady doth protest too much, methinks" -- but there is clearly a trend, with the DOL's fiduciary rule, the proposed rule by the SEC, new consumer protection rules for seniors and the amount of complaints to the Consumer Financial Protection Bureau. To go from Shakespeare to a more modern poet: Bob Dylan sang, "The times they are a-changing." It is time for the insurance industry to wake up. If the way business is conducted remains as is on products not covered by the fiduciary rule, there will be further regulations and scrutiny thrust upon the insurance world, and there will less opportunity to have a voice at the table. Insurance Agents, Distribution Systems and Reasonable Compensation: The traditional agent system has been fading away over the last couple of decades. There are very few companies that still have their own "captive" agents. "Captive" agents are those who primarily represent one specific insurance company such as Northwestern Mutual Life, New York Life, Mass Mutual, State Farm, Farmers, Allstate, etc. and who receive office space and other support from that company. Most insurance is now sold by agents who represent multiple insurance companies and who try to find the optimal coverage for their clients at the most affordable premiums. Of course, there are agents who are driven by commissions, and those are the ones who are most affected by the fiduciary rule and whatever comes next.  Acting in the best interests of a client is something the majority of agents strive to do, but enough agents don't that this type of regulatory change is warranted. Insurance companies are rethinking their distribution strategies, as shown by MetLife and AIG. MetLife recently sold off its Premier Client Group (retail distribution entity with approximately 4,000 advisers). American International Group (AIG) sold off its broker-dealer operation. And a number of insurance companies have withdrawn from the U.S. variable annuity marketplace over the last few years: Voya (formerly ING), Genworth, SunLife and Fidelity stopped selling MetLife Annuities. The real concern for insurance companies and agents is that they will no longer be able to sell a product that can't be fully justified as suitable to clients. In other words, selling the annuity with the highest commission and the best incentives will no longer cut it. While the DOL rule only applies to those annuities sold in qualified plans, is it really a stretch of the imagination to consider class action lawsuits against agents who are not following the same practices outside of qualified plans? And of course there is the issue of reasonable compensation. Reasonable compensation under the BICE is not specifically defined and is certainly open to interpretation. The DOL notes several factors in determining reasonable compensation: market pricing of services and assets, the cost and scope of monitoring and the complexity of the products. There is the interpretation that advisers who have more education (certifications, degrees, licenses, etc.) may be able to justify higher fees or commissions. This is also a good thing as this will encourage advisers to improve their skill set and be of better service to their clients. The Insurance Quality Mark is a great way for agents to show their level of expertise and professionalism. That Ticking Sound You Hear? The current distribution system is ineffective with the types of products sold and the accompanying incentives. Agents receive higher compensation for less competitive products, and they receive incentives for making sales targets. This is traditional for sales in any industry. However, as we've seen in the investment community, there are few traditional commissioned stock brokers and investment advisers, while the majority are now fee-based planners. Consumers expect more and are more financially literate. The Internet especially has changed the way financial products are sold. And insurance is part of the financial world. The Securities Exchange Commission may finally be spurred to move forward with its own fiduciary regulation. SEC Commissioner Mary Jo White has stated that fiduciary reform is in order at the commission, and that the SEC should harmonize the rules for investment advisers and broker-dealers serving retail clients. And will FINRA (Financial Industry Regulatory Authority),  NAIC (National Association of Insurance Commissioners), the CFPB (Consumer Financial Protection Bureau), the U.S. House of Representatives, the U.S. Senate or some other body move forward with their own set of rules and regulations? The marketing material that I see from many firms is, "We put our customers first." Thomas E. Perez, the secretary of labor, said in an interview: "This is no longer a marketing slogan. It's the law." The pressure is on annuity companies and insurance companies to design simpler products with lower fees and increased transparency. Everyone needs to rethink the entire sales and policy management process and follow the best practices outlined in the Insurance Consumer Bill of Rights. It requires insurance agents to place their clients' (insurance consumers) best interests first to the best of their ability. The Insurance Consumer Bill of Rights focuses on common-sense, thorough communication and providing quality service in a way that benefits everyone. Following the Insurance Consumer Bill of Rights is a win for everyone. The Bottom Line:  Insurance agents, insurance brokers and insurance companies can be the leaders in providing insurance consumers with rights or can be led by follow-ups to the DOL's fiduciary rule. The DOL's fiduciary rule is not the end, it is only the beginning. Again, it is good business for everyone when firms must fairly disclose fees, compensation and material conflicts of interest associated with their recommendations and not give their advisers incentives to act contrary to their clients' interests. (It's a sad state that such a requirement is necessary.) The future is up to us. If we start to treat annuities and cash value life insurance as the complex financial vehicles that they are and start to better educate our clients and ourselves and carefully service them, then there will be positive outcomes. If we continue with the current approach, lack of education and disclosure, more contracts will terminate and there will be significant negative consequences for policy/contract owners and their beneficiaries, and agents may very well find themselves as defendants in litigation. The Insurance Consumer Bill of Rights:
  1. The Right to Have Your Agent Act in Your Best Interest: to the best of her ability. Keep in mind that agents are not fiduciaries and are agents of the insurance company(ies). An agent recommendation should not be influenced by commissions, bonuses or other incentives (cash or non-cash). An agent should not collect a fee and a commission from the same client for the same work.
  2. The Right to Receive Customized Coverage Appropriate to Your Needs: An insurance agent should review your potential coverage needs per each line of coverage under consideration and take into account any existing coverage. Any new recommended coverage must fill a need (gap in coverage). Any replacement must be carefully reviewed with all pros and cons considered and presented in writing to the consumer.
  3. The Right to Free Choice: You have the right to receive multiple competitive options and to choose your company, agent and policy. Agents, brokers and companies must inform you in simple language of your coverage options when you apply for an insurance policy. Different levels of coverage are available, and you have the right to know how each option affects your premium and what your coverage would be in the event of a claim.
  4. The Right to Receive an Answer to Any Question: You're the buyer, so you have the right to ask any question and to receive an answer. The answer should fully and completely address your question or concern in full and be understandable. If you don't understand something, you as as the buyer have a duty to ask questions, and, if you still don't understand, you shouldn't buy that policy.
  5. The Right to Pay a Fair Premium: There must be full disclosure on how policy premiums are calculated and the impact of different risk factors specific to the type of coverage proposed. Also, information should be provided on factors that may reduce the premium in the future.
  6. The Right to Be Informed: You need to receive complete and accurate information in writing – anything said or promised orally must be put in writing. This includes full Information on any recommended insurance company, including name, address, phone number, website and financial strength rating(s).
  7. The Right to be Treated Fairly and Respectfully: This includes the right to not be pressured. If there is a deadline, the reason must be presented. If an offer is too good to be true, then it most likely is too good to be true. Insurance agents and companies should keep information private and confidential.
  8. The Right to Full Disclosure and Updates: You must receive notice of any changes in the coverage in easy-to-understand language and any relevant changes in the marketplace. All relevant information and disclosure requirements (required or not) on an insurance product must be presented to the client. You must receive in writing a summary of all surrender charges, length of surrender period and any additional costs for early termination. In any replacement situation, all pros and cons must be submitted in writing.
  9. The Right to Quality Service – You must be able to have your coverage needs reviewed at any time upon request, whenever a major event would affect coverage and at least annually. The agent must determine if changes have occurred with the client or in the marketplace that would dictate changes to the insurance coverage. This includes prompt assistance on any claims.
  10. The Right to Change or Cancel Your Coverage: This right must come without any restrictions or hassles.
View the Department of Labor conflict of interest final rule by clicking ere. Support the Insurance Consumer Bill of Rights by signing the petition and sharing this post.

Tony Steuer

Profile picture for user TonySteuer

Tony Steuer

Tony Steuer connects consumers and insurance agents by providing "Insurance Literacy Answers You Can Trust." Steuer is a recognized authority on life, disability and long-term care insurance literacy and is the founder of the Insurance Literacy Institute and the Insurance Quality Mark and has recently created a best practices standard for insurance agents: the Insurance Consumer Bill of Rights.

Moving Past ERM: New Focus Is ERRM

When ERM is practiced in a mature and robust fashion, it should boost an organization’s resiliency and add an R to the acronym.

sixthings
No, the title does not have a typo. ERRM refers to Enterprise Risk and Resiliency Management. And, no, it is not necessarily new. When ERM is practiced in a mature and robust fashion, it should add to an organization’s resiliency. Resilience refers to both the ability to rebound after a loss has occurred due to risk that could not be fully mitigated or was unrecognized and also the ability to capitalize on the upside risk. Let's look at two scenarios. Company A, an industrial manufacturer, implemented ERM several years ago. Its risk committee, recognizing changing climate conditions and weaknesses in an aging facility, got approval for a multi-year investment in flood protection. This decision was made part of the strategic plan. Not only did the company invest in flood gates for its access points to lower levels, but it also cemented over unneeded windows and redesigned storage racks at sub-levels. All drainage lines around the facility were tested and repaired, if required. Very importantly, its business continuity and disaster recovery plans were updated and had been rehearsed doing table top rehearsals. So, when a one-in-50-year flood occurred and crippled other businesses in the area for weeks, Company A was virtually unaffected. It was able to resume full business operations in two days. On top of that, it was able to capitalize on the excellent press coverage it got locally, which enhanced its ability to attract the talent it had been seeking from the area. For this company, ERM was more than identifying risks and creating reports. It was about taking action to build true resiliency in the face of risk. See Also: How to Measure the Value of ERM Company B, a woman’s clothes design and manufacturing company, practiced ERM with a very strategic approach. By that is meant, the risks to the company’s strategic direction were focused on first and became a key component of the risk identification and mitigation processes. When changes in customer preferences and buying habits were identified as risks to the current strategy, the strategy was adjusted accordingly. Since women were trending toward buying fewer and more basic garments, (for example, slacks that could be worn with multiple tops), while buying more accessories at more expensive prices, the company added new product lines such as jewelry and handbags. As margins became squeezed at less diversified companies, this company prospered. Its quick reaction to emerging risk by adding product lines was rewarded with year-over-year return on equity (ROE) increases for each year of the strategic plan period. In other words, the company found the upside of risk and enhanced its resiliency because of it. These hypothetical companies, based loosely on actual ones, illustrate that ERM is not just about risk; ERM is about resiliency. It is about the ability to address risk in such a way as to wind up in as good or better a position as the company was before having dealt with the risk or its impact. How do companies embed resiliency into their ERM programs?   Each of the following points enables greater resiliency, when practiced consistently:
  • ERM needs to be strategic. First, risks to the strategy must be analyzed as well as operational and other risks. Second, risk mitigation plans for all risks that require a significant commitment of organizational resources need to be documented in the strategic plan to ensure there is proper allocation of such resources. In its fifth annual risk report, PwC has a recommendation that reinforces this idea while adding the element of business continuity planning, “Ensure strong triangulation between strategy, risk management and business continuity management.”
  • ERM must be seen to offer insights not only to the downside of risk but also to the upside. How does a given risk offer an opportunity in addition to or instead of a threat? If rising raw material costs are posing a risk to profitability, how can buying consortiums, vertical integration, multi-year contracts or changing the material composition of products pose opportunities? Innovation has a role to play in seeing and responding to the upside of risk. Indeed, risk and managing risk can be catalysts for innovation.
  • ERM mitigation plans need to be as bold as necessary to meet the potential impact level posed by the risk. For example, it does little good to mitigate a reputational risk by issuing a statement of corporate values when hiring a new senior team is what is needed. A particular mitigation plan may need to be as big as entering a new market or leaving an established one, moving a manufacturing center to a new location or making a sizeable technology investment to stay competitive or safeguard property.
  • Business continuity and disaster recovery plans are not sufficient to create resiliency. Public relations plans are also necessary to support resiliency. When there is a serious, public risk event, stakeholders want to know the what, why and how it will be handled. Companies such as British Petroleum (during the BP oil spill in the Gulf) and Toyota (during the faulty power window allegations and recall) learned that statements by CEOs could make the situation worse than it already was thereby heightening the risk. PR plans need to spell out how the company will communicate in terms of transparency, tone and types of meaningful responses it is prepared to make to address the issue in question.
  • ERM must be a continuous process where risks are updated and mitigation plans are monitored and adjusted on a regular basis. Given the pace of change, the ERM process must be as dynamic as the environment within which it exists. When a risk morphs, the actions planned to address it must morph with it, when new risks emerge, tactics to deal with them must be developed. Complacency or slow reaction time will sabotage an ERM process. As such, neither must be allowed to invade the process. If they do, resiliency will surely be sacrificed.
The marketplace continues to see seismic disruption and more massive shocks than ever before. Companies lacking the ability to bounce back from the effect of these will not be able to survive long-term. That is why every effort must be made to create a resilient form of risk management that deserves to be labeled ERRM.

Donna Galer

Profile picture for user DonnaGaler

Donna Galer

Donna Galer is a consultant, author and lecturer. 

She has written three books on ERM: Enterprise Risk Management – Straight To The Point, Enterprise Risk Management – Straight To The Value and Enterprise Risk Management – Straight Talk For Nonprofits, with co-author Al Decker. She is an active contributor to the Insurance Thought Leadership website and other industry publications. In addition, she has given presentations at RIMS, CPCU, PCI (now APCIA) and university events.

Currently, she is an independent consultant on ERM, ESG and strategic planning. She was recently a senior adviser at Hanover Stone Solutions. She served as the chairwoman of the Spencer Educational Foundation from 2006-2010. From 1989 to 2006, she was with Zurich Insurance Group, where she held many positions both in the U.S. and in Switzerland, including: EVP corporate development, global head of investor relations, EVP compliance and governance and regional manager for North America. Her last position at Zurich was executive vice president and chief administrative officer for Zurich’s world-wide general insurance business ($36 Billion GWP), with responsibility for strategic planning and other areas. She began her insurance career at Crum & Forster Insurance.  

She has served on numerous industry and academic boards. Among these are: NC State’s Poole School of Business’ Enterprise Risk Management’s Advisory Board, Illinois State University’s Katie School of Insurance, Spencer Educational Foundation. She won “The Editor’s Choice Award” from the Society of Financial Examiners in 2017 for her co-written articles on KRIs/KPIs and related subjects. She was named among the “Top 100 Insurance Women” by Business Insurance in 2000.

What to Do When Catastrophes Go Viral

To avoid getting left behind, companies need to prepare for how they will communicate using social media when a catastrophe strikes.

sixthings
The power of social media is undeniable. Whether it’s political movements, disasters, or breaking news, social media delivers unfiltered information instantaneously to people around the world. When a catastrophe occurs today, comments, pictures and video are likely to appear on the Internet as it happens. For instance, a deadly explosion at a Texas fertilizer plant was caught live on video and posted to social media, as was an enormous explosion that rocked the Chinese port of Tianjin. But when social media posts about a catastrophe go viral, the company involved can be in for a struggle. To avoid getting left behind, companies need to prepare for how they will communicate using social media when a catastrophe strikes. A company that plans ahead and is able to mount a robust response may not only salvage its reputation, but may actually enhance its public image if it is seen as managing a difficult situation well. Because many companies lack this kind of communications expertise, they may want to work with consultants that can help them prepare for a disaster and respond appropriately. In addition, they should consider insurance that provides coverage for experienced public relations catastrophe management services to protect their corporate reputation. Social Media Plays a Crucial Role in a Crisis When it comes to disasters, mobile apps and social media are seen by the public as crucial ways to get information, according to a Red Cross survey. During Superstorm Sandy in 2012, social media played a significant role in providing official information and combating rumors. When Cyclone Tasha struck Australia in 2010, the Queensland Police Service made extensive use of Twitter to provide information to people spread over a vast area. Social media, however, is widespread and public information, which means that if there is an explosion, fire, or other disaster, chances are someone may be streaming it live to the Internet, tweeting about it, posting it to Facebook or uploading pictures to Instagram even before the affected company is aware of it. In essence, that means public opinion about the incident, as well as the company involved, is already being shaped, possibly without any direction from corporate communications. Because information travels so quickly through social media, the public no longer has to wait for the evening news to receive the most up-to-date information. Therefore, companies are not afforded the luxury of time to gather all available facts before addressing the public. Traditional media and news organizations are also feeling an increased amount of pressure. Since social media has enabled news to travel quicker, stories may not receive the same level of scrutiny as they once did. That leaves plenty of opportunity for the spread of misinformation, which can be very difficult to counteract. On the Internet, inaccurate information may persist long after it has been thoroughly discredited elsewhere. Embrace Social Media in Crisis Communications To handle the social media aspect of a crisis, companies need to be able to act immediately or risk allowing reporters and “citizen journalists” to tell the story they want to tell, which may not provide a complete and accurate picture. Being unprepared can lead to inconsistent messaging, or even misstatements that may create confusion and ultimately damage a corporation’s reputation. A company that is seen as clumsy in its media response to a crisis risks losing credibility. See Also: Should Social Media Have a Place? When a disaster is handled well – by providing the public with timely and accurate information as well as proper reassurances about its products and services – an organization can actually bolster its reputation. While social media accelerates the media cycle, it can also enable a company to take control of its image by acting as a primary and reliable source of information when a catastrophe occurs. This requires planning and preparation. An initial step is to review the corporate crisis communication plan to understand its limits in social media. A traditional crisis plan provides for one-way, controlled communication through prepared statements, press conferences, marketing tools, and commercials. Such an approach is likely to be viewed as unresponsive by the public seeking immediate information. Incorporating social media into the traditional plan provides for two-way communication that allows for debate, insight, and opposing viewpoints that can guide the company’s responses. The social media plan, however, should remain consistent with the company’s traditional media efforts. The company should provide consistent messaging in both traditional and social media about its culture and philosophy, the actions it is taking and the expected results, and its concern for those who have been affected.
Screen Shot 2016-04-29 at 12.48.53 PM
  Develop a Detailed Social Media Plan The plan should delineate the policies and procedures to be followed in the event of a catastrophe, and – most importantly – assign roles and responsibilities to specific staff. This ensures that someone who understands the company’s message will maintain control, which can help lessen potential mistakes. Both external and internal policies should be covered so that the information communicated to and among employees and the public is timely, accurate and consistent. The written policy should detail the information to be provided – for instance – pre-vetted information about the company and its corporate philosophy. It should establish guidelines pertaining to the types of social media posts that necessitate a response. Not every post merits a reply. Anyone who uses a computer or smartphone can post information to the Internet. Identifying legitimate posts and inquiries and providing necessary information can help preserve a company’s reputation. Because the social media landscape is dynamic, companies shouldn’t limit themselves to just one outlet, but rather those that are most appropriate for the business, the audience and the geographic region. If an incident occurs abroad, companies should use the social media outlet most appropriate for that region. With their massive user base, Facebook, Twitter and YouTube are obvious choices for domestic and international audiences. Others such as Instagram, Snapchat and Tumblr, should be considered. Companies active in Europe and Russia should consider the social networking site VK. Prepare the Response While it may not be possible to prepare material for every potential catastrophe, companies can still organize information ahead of time that can be released as soon as something happens. Information can be prepared for a “dark page” for the corporate website that can be published in the event of an emergency; however, companies should be careful not to publish a “dark page” until a crisis actually occurs. The site can include background information about the company and its specific businesses as well as the corporate philosophy during times of crisis. Other information might be media contacts and toll-free phone numbers for claims intake. Preparing the information ahead of time makes it possible to have it reviewed by a company’s legal department, public relations, and senior management. Once the page is live, it should be monitored and updated so that it always provides the most current information. Whether information is prepared ahead of time or developed in response to a particular incident, it should be presented in a way that is accessible for the audience. Written material should be understandable by a wide range of people. Companies should avoid industry jargon and acronyms, which may be unclear or even misunderstood by the general public. Screen Shot 2016-04-29 at 12.53.03 PM Monitor and Test When not in crisis mode, it is helpful for companies to monitor social media. Viewing the social media environment in the normal course of business can help companies ascertain how their brand, products and services are viewed by the public. Companies can purchase monitoring services or build these capabilities in-house. While monitoring social media is an important part of regular business, it becomes essential after a catastrophe to identify issues that need immediate attention. This helps to ensure that the traditional and social media messages the company is sending are having the desired impact. If the same questions continue to be asked on social media, it’s a clear sign that the message is not getting across. As part of their overall catastrophe preparation, companies should test their communication response plan to assess their procedures as well as their staff. Testing can help ensure that everyone understands their roles and responsibilities and is able to react quickly. Drills assist in identifying blockages and help address uncertainties in the process. After the test or following an actual event, the company should conduct a thorough reevaluation and debriefing to identify the areas that worked well and those that need improvement. Preserve the Corporate Reputation Today, a story about a disaster can be trending on social media even before the company involved is aware of the loss. Organizations that wait too long to respond can cause lasting damage to their reputation. A company that is perceived as avoiding or failing to address a story may soon realize that its lack of response becomes the subject of that story. Undoing the damage caused by a tardy or ill-conceived response can be very difficult. Many people realize that companies may make mistakes, but how these companies react and the decisions they make when faced with a disaster can potentially lessen confidence among customers and the wider public. Knowing how and when to respond helps project an image of competence and concern. Social media is the fastest way to reach people, project the company’s message and protect its reputation. To become better prepared, companies have to identify their most likely risks and develop plans to mitigate those exposures, whether they are health, safety or environmental. Companies need to know how best to respond on social media if a disaster were to affect their business. To do so, companies may want to work with consultants that can provide risk analysis and mitigation services and help to prepare a crisis response. In addition, to help plan how they will respond to a crisis on social and traditional media, companies should also consider insurance that can defray the costs of hiring expert help when a disaster strikes. No one knows when a catastrophe may occur, but being prepared can help lessen the damage. Customers will look to these companies for information– companies that can provide that information are more likely to weather a crisis with their reputation unscathed.

Lori Brassell-Cicchini

Profile picture for user LoriBrassell

Lori Brassell-Cicchini

Lori Brassell-Cicchini is vice president for ESIS Catastrophe Services. Based in El Dorado Hills, CA, Brassell-Cicchini is responsible for the development of customized programs for clients that have sustained third party catastrophic losses.

Best Practices in Cyber Security

How can technology solutions be used to disarm hackers and prevent cyber losses, avoiding possibly significant claims?

sixthings
Cyber crime is the fastest-growing segment of the global criminal economy, now including state-sponsored hacking from the likes of North Korea, China and Russia. According to a 2015 FBI report, cyber crime has now overtaken illegal drug activity, moving into first place. As a result, the cyber liability insurance market is surging. Premiums are expected to top $5 billion by 2018. More than 60 companies currently offer cyber liability coverage on a standalone basis. Much of the underwriting for cyber risks includes the company-specific details and security breach data available in the public domain through websites such as Privacy Rights.  According to Privacy Rights, nearly one billion records have been stolen from organizations of all sizes that are all running anti-virus software and firewalls. Unfortunately, anti-virus software misses as much as 30% of malware. Firewalls are perimeter traffic cops with no intranet security capabilities. Screen Shot 2016-04-25 at 2.42.40 PM How does a savvy cyber insurance or reinsurance underwriter determine when breach-prevention measures have been taken by a given risk? How can today’s technology solutions be used to disarm the hackers and prevent cyber losses, reducing the potential for a significant claim? Today, like never before, we face the frequent barrage of spear phishing attacks, new forms of very creative and nasty malware such as remote access Trojans (RATs), ransomware, zero-day malware (that means your antivirus doesn’t yet have a signature for the malware), not to mention the risks of malicious insiders, infected laptops coming and going behind our firewalls. In addition, many small and medium-sized businesses (SMBs) face increased scrutiny by government regulators. Cyber crime is growing at a tremendous rate – it’s become an organized, big business opportunity for criminals, projected to grow to $600 billion this year, larger than any other form of crime, according to the World Bank. Cyber liability underwriters will want to appreciate what a network security, cyber risk management-focused, underwriting prospect looks like relative to the broader market. Screen Shot 2016-04-25 at 2.44.21 PM All cyber liability enterprise policyholders are not equal when measuring breach prevention methods and techniques that may be deployed with an eye toward mitigating significant future losses. You might ask – why would my smaller business be a target – we’re not Bank of America – we’re not Home Depot or TJMAXX or Anthem? Yes, they all are big targets for big hackers, but cyber criminals don’t discriminate. In fact, they find SMBs easier targets because, traditionally, your level of defenses against cyber crime might not be as advanced as those at Bank of America – which has a $400 million annual information security budget. To the cyber criminals in in the dark corners of the Internet, you’re called a "soft" target – they feel you are easier to exploit. One piece of ransomware and you might be out of business. Some of the latest ransomware exploits will not only encrypt your laptop or desktop, but they also look for file servers and do the same, automatically. Then, you won’t have any access to your own files – or, even worse, customer records – until you pay the ransom. The FBI even recommends you pay the extortion fee. We find this all wrong. It’s completely backward. We cannot let ourselves be victims. It’s time to get more active and be one step ahead of the next attack – you are a target but you don’t have to be a victim. It all starts with best practices. For example, if you did frequent daily backups and tested these backups, then, when you’ve been victimized by ransomware, instead of paying the extortion fee, why not wipe the infected computer, re-image it then restore the latest backup? When asked, most SMBs say "I don’t do frequent, daily, backups” or “I haven’t figured out how to wipe and re-image all of our systems in the event they get infected.” So, it’s that simple, one best practice – Backup and Restore -- would save you thousands of dollars in extortion fees. You could thumb your nose at the cyber criminals instead of giving them some of your hard-earned revenue. Cyber liability policy terms and conditions should reflect more favorably on “Breach Prevention”-focused organizations. Best practices are things you do - steps you take - actions and plans, risk management and claims mitigation techniques. Within those plans, we are certain you will include which security countermeasures to budget for this year. Seven Best Practices to Reduce Risk Although we thought about going into details about recent security concepts, such as next-generation endpoint security or network access control, it seems more appropriate to focus on the best practices instead of the best security tools you might consider deploying. For example, we consider encryption a best practice and not a product or tool. We are sure you'll find many commercial and freely available tools out there. You can always evaluate those tools that you find most suited for your own best-practice model. So let’s consider the following as MUST-DO best practices in cyber security to defend your SMB against the risk of a breach: 1) Roll out corporate security policies and make sure all your employees understand them. 2) Train employees and retrain employees in key areas – acceptable use, password polices, defenses against social engineering and phishing attacks. 3) Encrypt all records and confidential data so that it’s more secure from prying eyes. 4) Perform frequent backups (continuous backups are even better than daily backups) and have a re-image process on hand at all times. 5) Test your system re-imaging and latest backups by restoring a system to make sure the backup-restore process works. 6) Better screen employees to reduce the risk of a malicious insider. 7) Defend your network behind your firewall using network access control (NAC) – and make sure you can block rogue access (for example, the cleaning company plugging in a laptop at midnight) and manage the bring your own device (BYOD) dilemma. Screen Shot 2016-04-25 at 2.46.20 PM More Than 95% of Breaches Happen Behind Firewalls – It’s Usually an Employee Mistake How many times have you heard of a trusted insider falling for a phishing scam or taking a phone call from someone sounding important who needed "inside" information? It's happening too frequently to be ignored. Some employees love browsing Web sites they should not or gambling online or chatting using instant messenger tools. You need to educate them about acceptable usage of corporate resources. They also usually don't know much about password policies or why they shouldn't open the attachment that says "you've won a million - click here and retire now." It's time to start training them. Invite employees to a quarterly "lunch and learn" training session. Give them bite-sized nuggets of best practice information. For example, teach them about the do's and don't's of instant messaging. If you are logging e-mail for legal purposes, which in some cases is required by law (SEC requirements for financial trading firms), let them know that you are doing it and why you are doing it. Give them some real-world examples about what they should do in case of an emergency. Teach them why you've implemented a frequent-password change policy and why their password should not be on a sticky note under their keyboard. Let these sessions get interactive with lots of Q&A. Give an award once per year to the best security compliant employee who has shown initiative with your security policies. If you can keep them interested, they will take some of the knowledge you are imparting into their daily routines. That's the real goal. Are My Best Practices Working? Time for Self-Assessment Before an Audit Perform your own security self-assessment against these best practices recommendations I’ve listed above. Find all of the holes in your information security environment so that you can, document them and begin a workflow process and plan to harden your network. Network security is a process, not a product, so to do it right, you need to frequently self-assess against the best guidelines you can find. Boards of directors, CEOs, CFOs and CIOs are under extreme compliance pressures today. Not only are they charged with increasing employee productivity and protecting their networks against data theft, but they are also being asked to document every aspect of IT compliance. We recommend, whether or not an outside firm is performing IT compliance audits, that you begin performing measurable compliance self-assessments. You'll need to review those regulations that affect your organization. In the U.S., these range from GLBA for banks to HIPAA for healthcare and insurance providers to PCI for e-tail/retail to CFR-21-FDA-11 for pharma to SOX-404 for public companies. Some states have their own regulations. In California, for example, if there has been a breach in confidentiality due to a successful hacker attack, companies are required by law to publish this information on their Web sites. The California Security Breach Information Act (SB-1386) requires the company to notify customers if personal information maintained in computerized data files has been compromised by unauthorized access. California consumers must be notified when their name is illegitimately obtained from a server or database with other personal information such as their Social Security number, driver's license number, account number, credit or debit card number, or security code or password for accessing their financial account. If you are a federal government agency, you need to comply with Executive Order 13231, to ensure protection of information systems for critical infrastructure, including emergency preparedness communications and the physical assets that support such systems. Also, if you are a non-profit organization, you are not exempt from the reporting requirements of regulations in your industry (banking, healthcare, etc.). Please make sure to seek legal counsel if you are not sure of which regulations you'll need to address. The easiest thing you can do to prove you are in compliance is to document your steps of protecting data. Document Your Best Practices Documentation showing that you’ve implemented best practices for risk reduction and against cyber crime will come in handy if you ever have a breach and need to defend yourself to enforce your cyber insurance policy or to keep the government regulators off your back. This kind of documentation is also good in the event someone sues your organization. You should be able to prove that you have in place all the best policies and practices as well as the right tools and INFOSEC countermeasures for maintaining confidentiality, availability and integrity of corporate data. By frequently assessing your compliance posture, you'll be ready to prove you "didn't leave the keys to the corporate assets in the open." If your network is ever hijacked and data is stolen, you'll have done your very best to protect against this event and it will be less of a catastrophe for your organization. Do you have a cold, warm or hot backup site in case of a critical emergency? If not, you should start planning one. If you can't afford one, could you create a "virtual" office telecommuting situation where your organization could continue to operate virtually until you've resolved your emergency situation? Knowing we are under constant attack and risk, now is the best time to begin implementing these seven best practices for network security. Hackers, malicious insiders and cyber-criminals have had their field day this year, and it’s only going to get worse - hijacking our SMB networks and placing most organizations at risk of being out of compliance, tarnishing our brands, reducing our productivity and employee morale -- placing most of us in the passenger seat on a runaway Internet. By taking a more active approach, setting measurable goals and documenting your progress along the way, you might find yourself in the drivers’ seat of cyber security.

Brian Harrigan

Profile picture for user BrianHarrigan

Brian Harrigan

Brian Harrigan, CEO of InsurIQ, a provider of insurance technology solutions, has spent over 40 years in the insurance industry, helping agents and carriers manage the purchasing of insurance and personal protection products.