Download

ID Theft: A Danger Even After Death

Just because you die, doesn't mean ID thieves will leave you alone. In fact, your death makes you and your heirs especially vulnerable.

Take your driver's license out of your wallet. Flip it over. Now look carefully at the back of it. There's no box to check for "identity donor." Yet when it comes to identity-related crimes, one of the greatest times of vulnerability is immediately after you die.

You can do everything right. You can use long and strong passwords and account-unique user names. You can check your financial accounts and monitor your credit on a regular basis, you can set up transaction alerts on your credit cards - even order a credit freeze - and then you die. Well, not entirely...

Include Identity in Your Estate Planning

A good identity thief can undo all your fraud precautions with a few phone calls. Most people don't think about this, because it's a wee bit late to refinance the family homestead - much less worry about interest rates - when you're dead. Regardless, the recently deceased continue to exist on paper, and this may be the case for some time. Meanwhile, many bankable facts - key among them your Social Security number and personally identifiable information - are just sort of there in the form of "zombie" purchasing power. An identity thief can use that purchasing power to drain your bank accounts, open new credit in your name and perpetrate all sorts of fraud that can harm your family and heirs.

Think of your post-mortem identity as a would-be extra on "The Shopping Dead." Now that you have that image in your head, take the time to arrange for the deactivation of your identity by making it part of your estate planning. This will mostly take the form of a to-do list for whomever will be handling your affairs, because nothing can be done till...well, you know, after the fact. There are many good resources, including this list from IDT911.

There are many different scams out there, ranging from the misappropriation of Social Security payments to the more old-fashioned practice of ghosting, whereby a person of approximately the same age assumes the identity of the deceased. In keeping with the proliferation of possible crimes, there are plenty of criminals out there who make a living in this post-mortem niche. They scan death notices in the local paper, read obituaries, even attend funerals and, make no mistake about it, can get a lot of shopping done with your available credit before the three credit reporting agencies and your current and future potential creditors are notified of your demise. Those same bad guys may also use your Social Security number to grab a big fat tax refund (if you're lucky enough to pass away during tax filing season).

How will they get the information needed to commit fraud? Sometimes the perpetrator is a family member, so he already has access. But more often, family members are distracted and distraught. There are visitors who come and go, unchecked, and of course the numerous demands of making final arrangements and dealing with matters of the estate. If there was a long illness, unsupervised healthcare workers may have had the run of the deceased's domicile - including the owner's most sensitive information. Maybe the wake was at the deceased's home, or people sat shiva there. The opportunities for fraud abound. Funerals, of course, provide a thief with a precise time to get what he or she wants. But instead of grabbing the television or the silver (too easy to miss), an envelope containing a financial statement or a copy of last year's tax return might go walkabout. From there, it's a race to apply for as much credit and buy as many pricy things for resale as possible before the money spigot coughs credit dust.

The Bigger Picture

Government agencies are famously slow to get the news of a person's undoing.

An audit of the Social Security Administration conducted by the Office of the Inspector General found approximately 6.5 million Social Security numbers belonging to people aged 112 or older whose death information wasn't in the system. Of those numberholders, only 13 people were still receiving payments; the rest consisted of "numberholders who exceeded maximum reasonable life expectancies and were likely deceased." The fact that their deaths were not recorded in Numident (the SSA's numerical identification system), and thus are also missing on the Master Death List, leaves plenty of runway for misconduct. According to the audit report, the "SSA received 4,024 E-Verify inquiries using the SSNs of 3,873 numberholders born before June 16, 1901."

On the off chance you missed the memo while diving for sunken treasure at the bottom of Loon Lake: Identity theft is now the third certainty in life, right behind death and taxes. When a loved one passes, there is a trifecta, which is why it's trebly important to protect against the threat of a different kind of life everlasting.

How to Help Veterans on Mental Health

Veterans may suffer a loss of identity, plus companionship and cohesion, when returning to civilian life. "Who has my back?"

||

The constant beat of the major media drum often paints a grim picture of veterans and suicide. Sometimes, we wonder if these messages become a self-fulfilling prophecy. Consistent headlines include data such as:

MRE

  • Approximately 22 veterans die by suicide each day (about one every 65 minutes).
  • In 2012, suicide deaths outpaced combat deaths, with 349 active-duty suicides; on average about one per day.
  • The suicide rate among veterans (30 per 100,000) is double the civilian rate.

Listening to this regular narrative, a collective concern and urgency emerges on how best to support our veterans who are making the transition back to civilian jobs and communities. Many veterans have a number of risk factors for suicide, contributing to the dire suicide statistics, including:

  • A strong identity in a fearless, stoic, risk-taking and macho culture
  • Exposure to trauma and possible traumatic brain injury
  • Self-medication through substance abuse
  • Stigmatizing views of mental illness
  • Access to and familiarity with lethal means (firearms)

Veterans show incredible resilience and resourcefulness when facing daunting challenges and learn how to cope, but employers and others who would like to support veterans are not always clear on how to be a "military-friendly community."

The Carson J Spencer Foundation and our Man Therapy partners Cactus and Colorado's Office of Suicide Prevention conducted a six-month needs and strengths assessment involving two in-person focus groups and two national focus groups with representation from Army, Air Force, Navy and Marine Corps and family perspectives.

When asked how we could best reach them, what issues they'd like to see addressed and what resources they need, here is what veterans and their advocates told us:

  • "I think that when you reach out to the vets, do it with humor and compassion...Give them something to talk about in the humor; they will come back when no one is looking for the compassion." People often mentioned they preferred a straightforward approach that wasn't overly statistical, clinical or wordy.
  • Make seeking help easy. A few veterans mentioned they liked an anonymous opportunity to check out their mental health from the privacy of their own home. Additionally, a concern exists among veterans, who assume some other service member would need a resource more. They hesitate to seek help, in part, because they don't want to take away a resource from "someone who may really need it." Having universal access through the Internet gets around this issue.
  • "We need to honor the warrior in transition. The loss of identity is a big deal, along with camaraderie and cohesion. Who I was, who I am now, who I am going to be..." The top request for content was about how to manage the transition from military life to civilian life. The loss of identity and not knowing who "has your back" is significant. Several veterans were incredibly concerned about being judged for PTS (no “D,” for disorder - as the stress they experience is a normal response to an abnormal situation). Veterans also requested content about: post-traumatic stress and growth, traumatic brain injury, military sexual trauma and fatherhood and relationships, especially during deployment.
  • The best ways to reach veterans: trusted peers, family members and leaders with "vicarious credibility."

Because of these needs and suggestions, an innovative online tool called "Man Therapy" now offers male military/veterans a new way to self-assess for mental health challenges and link to resources.

fubar

In addition to mental health support, many other things can be done to support veterans:

We owe it to our service members to provide them with resources and support and to listen carefully to the challenges and barriers that prevent them from fully thriving. Learn how you can be part of the solution instead of just focusing on the problem.

'Twas the Night Before Mediation

A holiday reflection on how mediation in workers' comp cases can save time and trouble and keep everyone out of court.

'Twas the night before mediation
And all through the firm
Not a creature was stirring,
Not even a worm

But then one lawyer
Asleep on a couch
Shot up, hit his head
And said with an "Ouch"

Oh my, I've got
That mediation tomorrow
I didn't do a brief
Much, much to my sorrow

Then what to his exhausted eyes should appear
But a mediator with news of good cheer

You don't need it fancy
You don't need it long
Just give me some clues
So the time's not spent wrong

Just send me an "e"
It's all confidential
Tell me the issues
What's the dollar potential?

With that she was gone
The lawyer banged out a brief
He'd be ready tomorrow
Oh what a relief.

This holiday season
When your time seems too short
Turn to mediation
And stay out of court.

Happy Holidays!

To Shape the Future, Write Its History

A powerful tool, the "future history," can help firms construct scenarios that will let them shape innovative ideas and then drive change.

[Editor's Note: While my frequent co-author is writing here about how companies, in general, can use a powerful tool to drive change, all those involved in the insurance ecosystem should pay particular attention. The tool, which draws from two books that Chunka and I wrote together -- found here and here -- is most valuable in industries where it's clear that dramatic disruption is coming but where the form of that change isn't yet defined: the very definition of insurance these days. -- Paul]  “History will be kind to me,” Winston Churchill said, “for I intend to write it myself.” When it comes to corporate innovation, my experience is that history will indeed be kinder if leaders take the time to write it themselves—but before it actually unfolds, not after. Every ambitious strategy has multiple dimensions and depends on complex interactions between a host of internal and external factors. Success requires achieving clarity and getting everyone on the same page for the challenging transition to new business and operational models. The best mechanism for doing that is one I have used often, to powerful effect. I call it a “future history.” Future histories fulfill our human need for narratives. As much as we like to think of ourselves as modern beings, we still have a lot in common with our earliest ancestors gathered around a fire outside a cave. We need stories to crystallize and internalize abstract concepts and plans. We need shared stories to unite us, and guide us toward a collective future. Future histories provide that story for companies. The CEO of a major financial services company occasionally still reads to internal audiences parts of the future histories that I helped him and his management team write in early 2011. He says they helped him get his team focused on the right opportunities. As of this writing, his company’s stock has almost doubled, even though his competitors have had problems. To create future histories, I have executive teams imagine that they are five years in the future and ask them to write two memos of perhaps 750 to 1,000 words each. For the first memo, I ask them to imagine that the strategy has failed because of some circumstance or because of resistance from some parts of the organization, investors, customers or other key stakeholder. The memo should explain the failure. The exercise lets people focus on the most critical assumptions and raise issues without being seen as naysayers. There is usually no lack of potential problems to consider, including technology developments, employee resistance, customer activities, competitors’ actions, governmental actions and substitute products. Articulating the rationale for failure in a clearly worded memo crystallizes thinking about the most likely issues. To heighten the effect, I sometimes do some formatting and structure the memo like an article from the Wall Street Journal or New York Times. Adopting a journalist’s voice helps to focus the narrative on the most salient points. And everybody hates the idea of being embarrassed in such publications, so readers of the memo pay attention to the potential problems while there’s still time to address them. The second memo is the success story. What key elements and events helped the organization shake its complacency? What key strategic or technological shifts helped to capture disruptive opportunities? How did the organization’s unity help it to out-innovate existing players and start-ups? This part of the exercise encourages war-gaming and helps the executive team understand the milestones on the path to success. Taken together, the future histories provide a new way of thinking about the long-term aspirations of the organization and the challenges facing it. By producing a chronicle of what could be the major success and most dreaded failures, the organization gains clarity about the levers it needs to pull to succeed and the pitfalls it needs to avoid. Most importantly, by working together to write the future histories, the executive team develops a shared narrative of those potential futures. It forges alignment around the group’s aspirations, critical assumptions and interdependencies. The process of drafting and finalizing the future histories also prompts the team to articulate key questions and open issues. It drives consensus about key next steps and the overall change management road map. In a few weeks’ time, future histories can transform the contemplated strategy into the entire team’s strategy. Future histories also facilitate the communication of that shared strategy to the rest of the organization. Oftentimes, senior executives extend the process to more layers of management to flesh out the success and failure scenarios in greater detail and build wider alignment. Future histories take abstract visions and strategies and make them real, in ways that get people excited. They help people understand how they can contribute—how they must contribute—even if they aren’t directly involved in the innovation initiative. People can understand the timing and see how efforts will build. People can also focus on the enemies that, as a group, they must fend off. These enemies may no longer be saber-toothed tigers, but they are still very real and dangerous to corporations. “Future histories” unite teams as they face the inevitable challenges.

How to Assess Costs of Business Interruption

The standard approach to calculations on business interruption overstates potential costs and leads to premiums that are too high.

||

As a professional loss accountant with more than 20 years of experience with business interruption (BI) valuation, I can understand why policyholders struggle with finding a repeatable, efficient system that produces an accurate measurement of their BI exposure. Over the years, some of my clients recognized the issues with the traditional BI values approach, and decided to make a change. Unfortunately, too many companies continue doing what they have always done, even when there is a better way available.

BI

Consider for a moment, just how important BI information is to your underwriter. The numbers you report give the underwriter the basis for writing coverage and calculating premium. Each renewal provides policyholders the opportunity to present their unique BI exposure. Unfortunately, this opportunity is often squandered because of a misunderstanding of business interruption values and the exposures they represent. The point of this article is to share a proven, alternative approach.

Understanding BI Values

First, there's the ratable value. It is the "big number" that is calculated for the business as a whole, assuming a 12-month, total shutdown of all revenue-generating operations. This worst-case and often unrealistic scenario is the information requested by the insurance company, usually in the form of a one-page worksheet. Without additional information, the underwriter will use this information to set limits and charge premium.

The ratable value calculated is somewhat meaningless, except that it establishes the base assumption that is used as the BI value in all other scenarios, such as unincurred cost categories. The ratable value is seldom a reflection of your exposures. Better ways to assess your exposures are to examine your maximum foreseeable loss (MFL) and probable maximum loss (PML) scenarios.

What Is Maximum Foreseeable Loss?

The MFL, as the name indicates, is the worst-case scenario. This is not as extreme as the ratable value scenario, but pretty close. The assumptions used here include a complete breakdown of protection and loss mitigating factors while you are hit where it hurts at the worst possible time. An example would be the loss of a unique distribution center to a retailer during the holiday shopping season -- say the distribution center that handles online orders goes up in smoke on Cyber Monday.

The factors used to measure the ratable value would be used in this scenario to determine the business interruption value. Certain assumptions may change depending on the duration of the loss scenario. For example, labor expense may be considered completely saved in the ratable value scenario because of the assumption that there is nothing left, but only partly saved in an MFL scenario.

What About the Probable Maximum Loss?

The PML is the same as the MFL, except that loss mitigation efforts and protections work properly. The PML also takes into account pure extra expenses used to retain customers. The PML can help with decision making on purchasing extra expense coverage.

What Happens in Underwriting?

Although I'm not an underwriter, I've typically seen insurance companies take an engineer's approach to MFL and PML scenarios that vary only in duration. This singular perspective does not account for the rest of the pieces of the puzzle. The other pieces are the finer details that actually occur during a claim. In a real claim, topics like seasonality, make-up and outsourcing would surely come up, but you won't see them on any BI worksheet.

The MFL and PML should be based on realistic loss scenarios and measured as if they were a claim. Simply applying the ratable value to loss-period assumptions produces misleading and inflated numbers. This is precisely why it is in your best interest to develop your own valuation method based on real scenarios.

Why Create Exposure Scenarios?

If BI values are based on assumptions, and you are using the worksheet, then the assumption is a 12-month loss scenario. Can you imagine a scenario in which your operations would only be affected for six months? The worksheet makes a blanket assumption of 12 months whether realistic or not. Coming up with various loss scenarios by location would flesh out a more realistic representation of the impact of each particular loss. The scenarios would also highlight high-risk locations along your supply chain, which could improve your business continuity planning.

An exposure analysis project is not only an accounting project; it's an integrated business exercise offering multiple benefits to an organization. The goal is to identify and examine loss scenarios and the resulting ripple effects.

It isn't necessary, nor is it practical, to anticipate every possible loss scenario. It's better to prioritize by perceived risk and probability. Then, develop a good sampling of loss scenarios from which you can determine the impact to operations and the mitigating actions that would be taken. Depending on the exposure, involve the appropriate internal personnel, e.g., operations, sales, business continuity, IT and accounting. The external experts you may involve are your broker, legal counsel and, of course, a forensic accounting firm that specializes in insurance work. Additionally, your company's business continuity plan (BCP) and incident response plan should be factored in. However your scenarios play out, the loss accountants can calculate the business interruption as though it were an actual claim.

As you can see, this approach would produce a more accurate BI value by location and overall. It's the right way to look at business interruption, so make it a part of your approach with underwriters.

The Rise of Panopticon Regulation?

Drawing on Bentham's panopticon, regulators may go "meta" -- using predictive analytics to monitor insurers' predictive analytics.

A radical shift is underway in how insurance markets are going to be regulated in the UK. The shift will transform the relationship between insurers, regulators and the public.

"Big data" promises a more personalized, customer-centric way of doing business. Yet, as insurers gain access to unprecedented levels of information about the lives of consumers, there could be problems with privacy.

This ability to track everyday lives begins to resemble an idea put forward by the 18th century reformer Jeremy Bentham. He envisaged a prison designed in the form of a ring, with a central tower from which prisoners could be monitored at all times, but in which those monitoring remained unseen. He called it the Panopticon. The idea underpinning Bentham’s design was that the monitoring would be so constant, yet so unknowing, that the prisoners would adopt more conforming behaviors.

Let’s think of a modern day panopticon, the ring filled not with prisoners but with millions of consumers, and a central tower full of firms gathering data about us. Data about our everyday activities would stream into that central tower, to be turned by the firms there into personalized products and services. A "digital panopticon."

Insurers are one such class of firm taking up position in that central tower. Underwriting and claims people would analyze all that consumer data, looking for patterns of behavior that signal a good or bad risk, an honest or dishonest claimant.

Then there's the UK regulator, the Financial Conduct Authority (FCA), talking about a new era of regulation based on a combination of data, technology and behavioral science. The FCA illustrated this new era in a recent review of the pay-day loan sector, drawing in vast amounts of loan data from firms and analyzing it to produce new rules on lending and servicing practice.

Insurance could be next on the FCA's list. Might the FCA start drawing in vast amounts of insurer data to analyze it for signs of consumer detriment? If so, does this mean the regulator is now constructing an observation tower of its own inside that "digital panopticon," one that sits within the insurance market's own tower? Are we seeing the emergence of "panoptic regulation"?

Such a "tower within a tower" could be a game-changing move. It could bring about a radical change in market attitudes toward ethics, fairness and culture. After all, the key idea behind the panopticon was for it to bring out better, more universal behavior, on the basis that what you were doing at any time might be under observation. Is the real future of regulation then simply the power derived from being in that innermost tower, using data to watch over a firm that could be yours, to watch over a person who could be you?

And if firms use predictive analytics to anticipate policyholder behavior, then could the regulator use its own predictive analytics to identify emerging patterns of misconduct? A regulator able to address misconduct before it became widespread would be powerful as well as controversial.

This could bring about a revolution in trust, for might consumer concerns about their personal data fall away, knowing that regulators are able to see everything insurers are doing with it?

The original panopticon proved too radical for the time and was never built. Yet something very similar is taking shape in the digital insurance market. The key question is: Is the insurance market and its regulators ready for the consequences that will flow from this?

To explore the concept of panoptic regulation in more detail, read this paper I wrote for the Chartered Insurance Institute earlier this year.

Is 'Direct' a Dirty Word for Insurers?

No, but "direct" is a dangerous word when you start talking about eliminating middlemen. There is a better, more inclusive approach.

The second-worst-kept secret of the year, after the launch of Google Compare in the U.S., is Berkshire Hathaway announcing its plans to sell insurance directly to business owners over the web. Quelle surprise.

I recently spoke with a C-suite exec who told me that "direct" is a dirty word.

Perception is reality.

In reality, though, "direct" is a lousy term that doesn't do justice to the implementations that today's technology has to offer that are often in direct alignment with an insurance company's business model.

The conversation becomes uncomfortable to some once the word "middlemen" is introduced. It doesn't have to be.

There are two primary outcomes to direct selling: (1) eliminating the middlemen or (2) empowering them. For visualization purposes, consider the following three brands:

Quotemehappy.com occupies the left extreme of selling directly to consumers. A spin-off of Aviva since 2011, the online insurer only provides phone support if a customer has a claim. For all other inquiries, there is browsing. Then there are the Geicos of the world, where insurers offer the convenience of buying on the web with the assurance of speaking to an agent, when needed. To the right extreme, Plymouth Rock provides an example of an insurer that has a patent-pending technology that matches online quotes to agents either pre- or post-purchase. There are several other players occupying the comfortable middle with direct-to-consumer models that offer varying degrees of human interaction.

Typically the outcome is determined by the company's original distribution channel: whether offline, web or mobile. The table below further illustrates how versatile "going direct" can be:

  • Geico, Policy Genius and Cuvva are examples of insurance companies that implemented a direct-to-consumer strategy from the get-go; here, direct is a no-brainer.
  • Plymouth Rock and Quotemehappy.com via Aviva signal companies that implemented a direct-to-consumer strategy in an attempt to address a change in the market.
  • Allstate acquired Esurance to buy its way into the direct market, and so did AmFam with the acquisition of Homesite.
  • Also, AmFam invested in insurance comparison site CoverHound.

When all is said and done, direct selling is first and foremost a marketing channel that empowers the consumer. Sans proper marketing and messaging, the online insurance journey is transactional at best, and players risk commoditizing their product.

"Commodity." Now there's a dirty word for you.

How to Limit Claims Post-Termination

It helps to recognize safe workers in a public setting. Lack of appreciation is a primary reason that people file fraudulent claims.

With increasing frequency, I am seeing post-termination claims being filed against employers who otherwise are doing an excellent job providing a safe work environment and comprehensive safety training.

It is impossible to develop statistics on this kind of claim, but anecdotal evidence indicates that there are more of them being filed. A slow economy exacerbates this problem.

It is important that we find strategies that will limit the number of these claims for the following reasons:

  1. They typically are litigated, so they are incredibly expensive.
  2. They are discouraging and disheartening to an employer who has cared about the safety of the workers and treated them well.
  3. The majority of these claims are without substance. "Fraudulent" is a term that should not be used loosely but is very often applicable here.

We never can completely wring fraud and abuse from the workers' compensation system. Soft-tissue claims are virtually impossible to prove or disprove, so we must rely on the injured worker to be honest. That means employers must do everything possible to influence employees to be honest.

Besides getting the terminated employee to sign a waiver that she is injury-free on her last day, here are a few additional recommendations:

  • After a layoff has been announced, but before the termination has taken place, honor those people who have worked safely and injury-free during their employment with the company. Adding a small gift card is a way to thank them. By recognizing them and thanking them in a public setting, you show your appreciation, and lack of appreciation is one of the primary reasons that people file fraudulent claims.
  • If the soon-to-be laid-off workers are part of a safety team or department, make sure that they are included in any awards or recognition that is given at the end of the measured safety time period.
  • Indicate to the workforce that the company policy is to contest and deny any claims that are filed after a layoff or termination. Don't just threaten, do it.
  • Gain agreement from your insurance carrier that it will contest any post-termination claim and not simply offer a settlement to have it go away.
  • Contact the physician who is issuing the cumulative trauma report and let him know that you intend to contest his finding. Your insurance carrier should be your ally in exposing repeat offenders.

Remember that an injury that occurs after a layoff has been announced, but before the termination takes place, sets up any post-termination claim as legitimate.

Treating employees well and creating the strongest possible safety culture are the best defenses, but incorporating additional strategies can help prevent a discouraging and expensive post-termination claim.


Joe Stevens

Profile picture for user Joe Stevens

Joe Stevens

Joe Stevens founded Bridge Safety Consultants in 2003 to provide companies and organizations with strategies and programs that strengthen their safety culture, reduce injuries and minimize fraudulent claims.

Stevens leads a fraud prevention task force composed of a legal team that specializes in workers’ compensation law and includes an investigation firm and a consultant. The task force determines a strategy and coordinates every case to minimize fraud and reduce costs.

Firms Ally to Respond to Data Breaches

As data breaches continue, security companies have begun to collaborate more on sharing and analyzing threat intelligence.

|

More companies than ever realize they've been breached, and many more than you might think have begun to put processes in place to respond to breaches.

A survey of 567 U.S. executives conducted by the Ponemon Institute and Experian found that 43% of organizations reported suffering at least one security incident, up from 10% in 2013. And 73% of the companies surveyed have data breach response plans in place, up from just 12% in 2013.

"Compared with last year's study results, survey findings show encouraging signs that organizations are beginning to better prioritize data breach prevention, but more needs to be done," says Larry Ponemon, namesake founder of Ponemon Institute.

Major data breaches have become a staple of news headlines. So it can't be that companies are complacent. The problem seems to be that big organizations just can't move quickly enough.

Home Depot was blind to intruders plundering customer data even as Target endured exposure and criticism for being similarly victimized just months before, possibly by the same gang.

In our connected world, it's hard to keep pace. The Ponemon study found 78% of companies do not account for changes in threats or as processes at a company change.

Rise of threat intelligence

That's where the trend toward correlating data from disparate threat sensors could begin to close the gap. It's a promising sign that ultra-competitive security companies have begun to collaborate more on sharing and analyzing threat intelligence.

Boulder, Colo.-based security vendor LogRhythm, for instance, has formed an alliance with CrowdStrike, Norse, Symantec, ThreatStream and Webroot to share sensor data and compare notes on traffic that looks suspicious.

LogRhythm supplies a platform for culling and analyzing data from its partner vendors "to help identify threats in our customers' IT environments more quickly, with fewer false positives and fewer false negatives," says Matt Winter, LogRhythm's vice president of corporate and business development.

Since announcing its Threat Intelligence Ecosystem last month, LogRhythm has received "considerable inbound interest from customers and channel partners," Winter says. "Feedback has been very positive."

Similar threat intelligence alliances, both formal and informal, are taking shape throughout the tech security world. The business model of Hexis Cyber Solutions, a year-old startup, relies on pooling threat sensor data from several security vendors, including antivirus giant Symantec and social media malware detection firm ZeroFOX.

Hexis applies analytics with the goal of accurately identifying - and automatically removing - clearly malicious programs.

"The state of the art today is a single-point security product triggering alerts on particular things and putting a warning on a screen," says Chris Fedde, president of Hexis. "We're all about analyzing alerts and taking action on them. Anything that's malicious we go ahead and remove."

In one recent pilot study, Hexis tracked 5,000 computing devices and 13,000 user accounts of a U.S. medical center for 30 days. Hexis intercepted 35,000 incidences of suspicious outside contacts and removed 23 malicious files.

Those malicious files that got inside the medical center's network included: Dirtjumper, a tool used to conduct denial of service attacks; Tsumani, malware used for spamming and data theft; a remote access tool (RAT) used to take full control of a compromised computer; and an adware Trojan.

There's a long way to go. But alliances to share threat sensor information, like the ones being pioneered by LogRhythm, Hexis and many other security vendors, seem destined to take root.

Someday in the not too distant future, it may not matter if intruders get inside the network, if robust threat intelligence systems are poised to cut them off from doing damage.


Byron Acohido

Profile picture for user byronacohido

Byron Acohido

Byron Acohido is a business journalist who has been writing about cybersecurity and privacy since 2004, and currently blogs at LastWatchdog.com.

No, Insurance Will Not Be Disrupted

Insurance will certainly change a lot. But here are six reasons it won't be disrupted as much as taxis (by Uber) and lodging (by Airbnb).

I recently had the pleasure of attending the Insurance Disrupted conference in Palo Alto (put on by the Silicon Valley Innovation Center in partnership with Insurance Thought Leadership). This was the single best insurance conference I have ever attended. I was surrounded by hundreds of hopeful, smart, problem-solving professionals from disparate backgrounds and industries all trying to make a difference in insurance without money being the prime motivator.

I was so encouraged by what transpired at the conference, the connections that I made and what I believe would be the promise of a new future that I began to pen this article on my flight home. But something just did not sit right with me as I wrote. Three weeks have gone by, and I am beginning to understand why I felt the way I did; at the end of the day, insurance will NOT be disrupted.

For all the promise of big data, the Internet of Things, autonomous vehicles and peer-to-peer insurance, there was nothing presented at this conference that struck me as disruptive in the way the tech industry is generally thinking of the term today. When technologists think of disruption, they immediately point to Uber and Airbnb, which disrupted the taxi/livery and travel accommodations industries. The taxi industry is literally fighting for its survival. No, that will not be the fate of insurance. Insurance will be a lot more difficult to shake up or disrupt.

Here's why:

  1. At the core, insurance customers are leasing the potential to access capital. That capital is sitting in predominantly liquid assets. Not real estate, not taxi medallions. How do you make a big pile of money irrelevant?
  2. The modern form of the industry is 300 years old, and the math is pretty solid (that's why they call it actuarial science). We sell a product whose costs are unknown at the time of purchase. That means scale and immense capital is required to cover worst-case scenarios, which rules out any new business model not having that potential. Peer-to-peer providers just won't be able to get sufficient scale to efficiently use capital to cover risk. And if they aggressively get scale, then they just become another insurance company, so what's the point?
  3. Getting a better glimpse into those unknown expenses can create massive competitive advantages. This is where big data and the IoT creators are looking to disrupt, as big data and IoT will generate incredibly large data sets to be used to accurately predict, avoid and mitigate future losses. I have no doubt that these new technologies will make an impact on the industry, but I am less convinced of their disruptive nature. Insurers have already established non-actuarial, big data departments where fraud detections and credit scoring are just a couple of many predictive models being created. IoT devices will slowly be adopted by most insurers as they look to get competitive edges, but the follow-the-leader paradigm of the industry will mean that any edge will disappear quickly, and we will all be running hard just to stay in place. These technologies are impressive. I would classify them as a solid innovations to the industry, but not disruptive. (Disclaimer: I bought a smart battery from Roost.)
  4. Autonomous vehicles represent the one area where some chaos can occur. But notice I use the word "chaos" and not "disruption." If autonomous vehicles can live up to expectations, then they will be a great service to society, reducing deaths and increasing efficiency. Risk will transfer from a personal lines business to commercial lines, and that could be chaotic for heavy personal lines auto writers such as State Farm and Progressive. But will this be disruptive? Will State Farm or Progressive be fighting for their survival the way that medallion owners in the New York City taxi system are? Again, I doubt it. State Farm is sitting on about $70 billion in surplus capital, and it generally writes at a 100 combined ratio, working the float and cash flow model. I think State Farm and large auto insurers like them will be just fine, and technologies such as autonomous vehicles will be more of an annoyance than an existential threat. And like others, I don't think autonomous cars are nearly as ready to take over our roads as many seem to think.
  5. For better or worse, state-by-state regulation of insurance is intense and nebulous. Ask Zenefits. The battlefield is already uncertain, and scrutiny by a regulator with political ambitions can kill your disruptive product quickly. Any technology that you think you can create that could potentially benefit the majority of buyers while subsequently raising the price for some other group, alone, would be grounds for a regulator to squash you, as that vocal minority raises their collective voices. In Florida, the state may even create a company to compete against you, writing business at a loss. Insurance regulation might be the ultimate disruption killer.
  6. There was not one presentation on natural catastrophes, which happen to be my area of expertise. How we underwrite, manage and think about natural catastrophe risk has changed quite a bit over the past 20 years. In fact, CAT models have been and may continue to be the most disruptive force in insurance, and yet there is little technology can do to disrupt that area of the industry. I would have been very excited if we had discussions about new business models to help customers with the problems the industry is currently facing with getting adequate flood or earthquake cover to homeowners. If someone had proposed a new product that removed the exclusions of flood and earthquake from the homeowners policy, now, THAT would be disruptive! Alas, nothing on NatCat, and so we will continue to have thousands of homeless families following big storms and earthquakes.

I don't think insurance will be disrupted, not in the way folks from Silicon Valley are used to doing it. But the future of insurance will look very different than today. Very digital. Streamlined. Less clunky, more efficient. If "disruption" comes to insurance, it is likely going to require the replacement of the current set of leaders with new ones cultured in this digital age and influenced by the successes of technology to make change happen to their business models.

Paul Vandermarck from RMS (a CAT modeling vendor) perhaps summed it up best when he said that no matter how all of this change to the industry plays out, we know of one sure winner: the customer. And that's how it should be.