Cyber Risk: Are You the Weak Link?
Scam artists are getting far more sophisticated, and the first line of defense against "social engineering" is you.
Scam artists are getting far more sophisticated, and the first line of defense against "social engineering" is you.
Get Involved
Our authors are what set Insurance Thought Leadership apart.
|
Partner with us
We’d love to talk to you about how we can improve your marketing ROI.
|
Scott Aurnou is a cyber security consultant, attorney and vice president at Soho Solutions, an IT consulting and managed services company based in New York. He helps organizations identify and address the kind of critical technology-related risk and market exposure that keep executives, management committees and corporate boards awake at night.
A WCRI study found that new rules in Georgia cut prices by 25% to 40% -- though prices are still much higher than at pharmacies.
Get Involved
Our authors are what set Insurance Thought Leadership apart.
|
Partner with us
We’d love to talk to you about how we can improve your marketing ROI.
|
Ramona Tanabe is executive vice president and counsel at the Workers Compensation Research Institute in Cambridge, MA. Tanabe oversees the data collection and analysis efforts for numerous research projects, including the CompScope Multistate Benchmarks.
A study reveals the ROI of a great customer experience -- and the penalty for a bad one.
The study calculated the cumulative total stock returns for two model portfolios -- composed of the Top 10 (“leaders”) and Bottom 10 (“laggards”) publicly traded companies in Forrester Research’s annual Customer Experience Index rankings.
For the seven-year period ending in 2013, the Customer Experience Leader portfolio outperformed the S&P 500 market index by an astounding 26 percentage points. Perhaps even more striking was the performance of the Customer Experience Laggard portfolio, which posted a 2.5% decline in value, despite a big rally in the broader market.
The results underscore the benefits enjoyed by companies that invest in, and effectively execute on, a customer-experience strategy: higher revenues (because of better retention, less price sensitivity, greater wallet share and positive word-of-mouth) and lower expenses (because of reduced acquisition costs, fewer complaints and the less intense service requirements of happy, loyal customers).
Conversely, the study also provides a sober reminder of how customer dissatisfaction saps business value, by depressing revenues and inflating expenses.
Whether your firm is a public or private entity, the lesson here is clear: The market believes that companies that deliver a great customer experience over the long-term are simply more valuable than those that do not.
And that’s a message that insurance traditionalists should take to heart, because a great policyholder experience really is good for business.
Note: A complimentary report describing the 2014 Customer Experience ROI Study, including commentary on how the leading firms differentiate themselves, is available from Watermark Consulting.
Get Involved
Our authors are what set Insurance Thought Leadership apart.
|
Partner with us
We’d love to talk to you about how we can improve your marketing ROI.
|
Jon Picoult is the founder of Watermark Consulting, a customer experience advisory firm specializing in the financial services industry. Picoult has worked with thousands of executives, helping some of the world's foremost brands capitalize on the power of loyalty -- both in the marketplace and in the workplace.
Epidemic diseases require careful thinking, and terms of coverage vary widely.
Get Involved
Our authors are what set Insurance Thought Leadership apart.
|
Partner with us
We’d love to talk to you about how we can improve your marketing ROI.
|
Vince Capaldi is the president of the Bay Oaks Wholesale Brokerage, a national wholesale insurance broker specializing in self-insured workers’ compensation programs. Capaldi has developed and maintained numerous individual and group self-insurance plans in both the public and private sectors nationwide.
This article is the first of a series on how the evolution of catastrophe models provides a foundation for much-needed innovation.
Get Involved
Our authors are what set Insurance Thought Leadership apart.
|
Partner with us
We’d love to talk to you about how we can improve your marketing ROI.
|
Nick Lamparelli is the managing partner of Insurance Nerds and chief program officer for Latin International Reinsurance Group.
He is also CEO of the Insurance Advocacy Forum of Florida.
Lamparelli is a three-decade insurance executive, starting as a local agent and evolving to middle market broker, wholesaler, underwriter and catastrophe insurance expert.
James Rice is senior business development director at Xuber, a provider of insurance software solutions serving 180+ brokers and carriers in nearly 50 countries worldwide. Rice brings more than 20 years of experience to the insurance technology, predictive analytics, BI, information services and business process management (BPM) sectors.
The exodus of Baby Boomers from the workforce will create huge knowledge gaps, but few insurers have yet to take notice.
Get Involved
Our authors are what set Insurance Thought Leadership apart.
|
Partner with us
We’d love to talk to you about how we can improve your marketing ROI.
|
Dan Holden is the manager of corporate risk and insurance for Daimler Trucks North America (formerly Freightliner), a multinational truck manufacturer with total annual revenue of $15 billion. Holden has been in the insurance field for more than 30 years.
Insurance and reinsurance are not alternatives to ERM; cyber risks must be assessed and mitigated like all other risks.
The bottom graph shows the situation prior to reinsurance, where small claims are aggregated and a long tail cuts into the companies’ risk-based capital limits. The top graph shows a leaner risk situation after the application of reinsurance, bringing it back in the comfort zone.
The standard deviation process will depend on how the regulator views cyber risk and solvency. Currently, solvency models are geared on average to a 1-in-200-year event, which may be suitable for earthquake and other peril risks but is likely to be different for cyber risks and to vary by country risk appetite.
Other risk transfer mechanisms. In addition to reinsurance, cyber captives are used to address continuing risk. A point worth noting is the potential to mathematically create a “cyber index” in the same manner that weather and stock market indices appear in the macroeconomic models representing market risk exposure correlation to other enterprise risks. This cyber index could be created from the data patterns of the cyber catastrophe models and other data and then used as a threshold to trigger a data breach claims process following notification of a data breach.
Special-purpose vehicles (SPVs). This risk transfer approach is used in conjunction with capital market investors and sponsors, and it is similar to the catastrophe bond investments that protect countries from earthquake risk. It creates a bond shared by government and private industry to pay and share claims by loss bands in the event of a large or black-swan event. While these partnerships are very effective, such bonds often have a 10-year span, and a shorter life-span vehicle will be more suitable to cyber.
Sidecars. For natural catastrophes, these two-year vehicles have been referred to as sidecars, an SPV derivative of a captive where investors invest in a risk via A-rated hedge funds. If the event has not taken place within a given time frame, investors receive their money back with interest. This makes cyber risk part of an uncorrelated portfolio investment for chief investment officers. They can also base investment on the severity level of the attack, so investments are not lost on all events.
It will take time for this SPV approach to evolve over reinsurance and captives, but with good data quality, proper event models, ratings and adoption of KSI and other standards in the IT space, the capability to use capital markets to risk-transfer cyber risks will emerge. Data integrity standards would increase investor confidence in such SPVs.
For the full report on which this article is based, click here.
Get Involved
Our authors are what set Insurance Thought Leadership apart.
|
Partner with us
We’d love to talk to you about how we can improve your marketing ROI.
|
Shaun Crawford leads Ernst & Young's $1.4 billion global insurance business. He has been in the financial services industry for 27 years, having worked both in consulting or line management with the majority of European life assurers and U.K. retail banks at some point.
A little-known regulation may provide a powerful tool outside of workers' comp law that can reduce fraud and lost work time.
It may be possible for employers to take a whole new approach to workers' comp cost containment based on an OSHA regulation that allows an employer to require injured workers to undergo a prompt medical exam outside of the workers' comp system and to obtain the release of prior medical records.
Most employers are unaware that they can utilize this little-known and virtually untried regulation that allows for employers to pay for second medical opinions under OSHA recordkeeping requirements and regulations. The regulation can be found in §§ 1904.7(b)(3)(ii) and (b) (4)(viii).
There are two major facets to this statute. First, employers must pay 100% of the medical exam costs outside of the workers' comp system. Second, insurance companies and third-party administrators (TPA)s cannot schedule such exams or pay for such exams because they cannot work outside the state workers' comp system.
The costs of such exams are not included in an employers' overall workers' comp claim costs, nor are they included in experience modification calculations. The costs for such a program would have to come out of another budget, like risk management or safety.
Of major significance is that, while the regulation states such exams are outside workers' comp regulations, with proper procedure they and the related medical records are discoverable. They may be released and used in workers' comp claim adjudication.
This approach would not necessarily require any change in how medical professionals provide exams for injured workers. What would change is how these exams would be scheduled and paid for, outside workers comp.
A key issue is that these employer-directed exams would have to be "contemporaneous." OSHA defines this as, "no change in workers' condition" between the medical exams.
There would be a very short window, in my opinion, to utilize this OSHA prompt medical exam. These exams would need to be scheduled at the same time as the initial injury reporting.
The intent of OSHA is to allow employers to choose between two conflicting medical opinions (employee medical provider vs. employer medical provider) as to whether an injury or illness is "recordable" under OSHA regulations based on "authoritative" medical opinion.
OSHA regulations are silent on two fronts: 1) the actual timelines beyond "contemporaneous" and 2) whether these medical exams and prior medical records can be used through subpoena to question the need for continuing medical treatment and lost time under state workers' comp.
But I see no reason why the results of such an exam could not be used even after a claim is determined to be "recordable" under OSHA regulation, because the prompt medical exam and second medical opinions and reports are "discoverable" under proper procedure in state work comp systems, according to OSHA.
The employer can simply say, "We paid for a prompt medical exam under OSHA regulations, and this is what we found out." The employer would then have the right to share this information with its insurance company or TPA because the injured worker must agree to the exam and release of prior medical records.
This approach would be a great tool for employers in states such as Illinois whose workers' comp laws allow the employee to select the medical provider.
The recent federal court case in Illinois decided against Fed Ex may well have had a different outcome if the company had used federal OSHA regulations to support its policy of requiring employees to promptly report medical care.
Illinois state workers' comp law, among many others, clearly gives the employee the right to select the treating medical provider. Most people in the industry would say, "case closed!" But OSHA regulations (federal law) clearly also give employers the right to schedule a prompt medical exam and to choose between two conflicting medical opinions to determine the "most authoritative." OSHA also refers to Department of Transportation exams as an example of intermediary exams available to employers. Those exam records and results are not part of the comp record, but, with proper procedure and use of subpoena, records may become discoverable in work comp cases.
Employers have always felt powerless in states that allow the injured worker to select the treating medical provider, such as Illinois and New York. By using OSHA regulations, employers may very well have a powerful management tool in their arsenal that they didn't even know about to address potential fraud, abuse and inappropriate medical care and lost-work time.
Hence, I believe a little-known, rarely utilized outside of state workers' comp is available to employers under OSHA and could be very powerful.
Stay tuned.
Get Involved
Our authors are what set Insurance Thought Leadership apart.
|
Partner with us
We’d love to talk to you about how we can improve your marketing ROI.
|
Dan is Director of Strategic Partnerships at First Managed Care Option (FMCO) in Morris Plains, NJ.
If driverless cars end personal auto insurance, how will that affect other products? How do we assess the risk of a 3D-printed structure?
Get Involved
Our authors are what set Insurance Thought Leadership apart.
|
Partner with us
We’d love to talk to you about how we can improve your marketing ROI.
|
Denise Garth is senior vice president, strategic marketing, responsible for leading marketing, industry relations and innovation in support of Majesco's client-centric strategy.
The watch is designed to bolster the iPhone -- but innovators must be willing to move beyond old products and business models.
Figure 1 — Apple Device Sales
Now the iPhone has a loyal following but a small share of the smartphone market. Will Tim Cook limit the Apple Watch’s success to iPhone owners, or will Cook free it to dominate the potentially larger wearable devices space?
Freeing the Watch is a strategic imperative.
History tells us that market-leading technology products like the iPhone inevitably fade. The companies that depend on them must innovate into the succeeding categories or fade as well. Kodak, Polaroid, IBM, DEC, Nokia, Motorola, Blackberry, Intel, Sony, Dell and Microsoft are among those fading or faded companies.
All of those other companies underutilized disruptive advances in information technology for (at best) incremental enhancements to their dominant products. By doing so, they missed out on new killer products, business models and industries that coalesced around the new platforms enabled by those technology advances.
Thus, Kodak wasted decades trying to deploy digital photography (which it invented) as an enhancer to its dominant film-driven businesses. Microsoft was slow to the web and the cloud and killed its early e-reader and tablet devices because of internecine struggles over how those new categories related to its Windows and Office businesses. The list goes on: IBM did not lead in minicomputers. DEC and every other leading minicomputer maker missed out on personal computers. Motorola and Nokia were killed by smartphones, and Blackberry is near death.
Limiting the Watch to a peripheral role in the iPhone-centric ecosystem would repeat the same mistake made by those earlier market-leading technology companies.
That’s not to say there is not a lot of money to be made in the defend-the-cash-cow approach. Just look at the more than $650 billion in revenue and nearly $250 billion in earnings that Steve Ballmer delivered in his tenure as Microsoft CEO. Ballmer achieved those impressive numbers by defending and milking Microsoft’s dominant Office and Windows products. Ballmer, Microsoft and its investors missed out, however, on the market value created by Google, Apple, Facebook, Twitter and others that capitalized on search, big data, cloud computing, mobile devices and social media. Ballmer’s inability to grow beyond the core products that he inherited stagnated Microsoft’s market value for a decade.
Likewise, Tim Cook could nurse Apple’s iPhone-driven revenue stream for a long time. I doubt, however, that Tim Cook would be satisfied with a value-creation legacy comparable to Steve Ballmer’s.
It is too early to dismiss the Apple Watch’s potential to transcend the iPhone. We’ll get a measure of Apple’s foresight when it releases the software development kit (SDK) for the Watch. That will show how fundamentally tethered the Watch is to the iPhone and whether Apple has laid the groundwork for the Watch to be standalone at some point.
The real gut check for Tim Cook is further out in time, when technology and creativity enables wearable devices like the Watch to not only stand alone from the iPhone but also to replace it.
Will Tim Cook allow the Watch to cannibalize iPhone sales—as Apple previously allowed the iPhone to eat away at the iPod and risked the iPad's doing the same to the Mac? Or will Apple stagnate as competitors and new entrants out-innovate it? Will Apple fade away as the riches from new killer apps, devices, ecosystems and business models that coalesce around emerging wearables-centric platforms flow to others?
Get Involved
Our authors are what set Insurance Thought Leadership apart.
|
Partner with us
We’d love to talk to you about how we can improve your marketing ROI.
|
Chunka Mui is the co-author of the best-selling Unleashing the Killer App: Digital Strategies for Market Dominance, which in 2005 the Wall Street Journal named one of the five best books on business and the Internet. He also cowrote Billion Dollar Lessons: What You Can Learn from the Most Inexcusable Business Failures of the Last 25 Years and A Brief History of a Perfect Future: Inventing the World We Can Proudly Leave Our Kids by 2050.