Download

Cyber Risk: Are You the Weak Link?

Scam artists are getting far more sophisticated, and the first line of defense against "social engineering" is you.

In 2012, a young scam artist based in Asia posing as a private investigator simply purchased the personal information for more than 200 million users directly from credit reporting giant Experian and then posted it for sale online. The only reason we know about the incident is that the U.S. Secret Service caught it.  Experian didn’t. Cyber criminals know that the weakest link in most computer networks is the people using it. Verizon’s highly respected Data Breach Investigations Report has repeatedly noted that most attacks start with employees. Attackers use “social engineering” to trick their victims into allowing unauthorized system access, data theft and even specialized stealthy attacks used to quietly steal massive amounts of sensitive data over time. These attacks frequently exploit our natural tendency to want to help others. They can be in person, electronic or over the telephone, and there are a variety of ways they can be used to take advantage of you: “Phishing” attacks are designed to steal your personal, financial or log-in information through an email, text message (referred to as “smishing”) or even an automated phone call (“vishing”). The attacks often appear to come from well-known and trusted companies like banks, airlines or industry groups and contain attachments or links to websites that look legitimate but are really there to steal account log-in information or host malware ready to attack the recipient’s computer as soon as he clicks on any of the links. These emails and messages can also be used to lure victims into contact with scam artists posing as potential clients or officials offering to release substantial funds if only the target would be so kind as to hand over detailed personal information or a sum up front. A spear phishing email is a personalized version of a phishing attack looking for the weak link in an otherwise strong network. It will be aimed at a specific target (rather than a general phishing email intended to ensnare whoever falls for it) and typically includes personal or professional information to make the recipient trust the sender. These details can come from online sources like LinkedIn, Facebook and other social networks and contain information available via business-related websites, as well as particulars obtained directly from coworkers via social engineering. Spear phishing emails often appear to come from a familiar source like a friend, family member, colleague or a business you deal with regularly. This is because of a process known as "spoofing," in which the actual sender hides his identity, and the “from” field in the email shows the fake sender’s name, not the real one. The data breach at Forbes earlier this year began with an early morning spear phishing attack against a senior executive. Whaling is an attack that deliberately goes after senior executives, partners and other high-profile targets within a business. The idea behind this approach is that these targets are “big fish” who have wide access within the network yet may not take the precautions needed to keep their own accounts secure. Pretexting is effectively in-person phishing to gain information or access to a restricted area. The term “pretexting” refers to the setup used to convince the target that there is a justifiable reason (or pretext) to divulge the information or access the person is after. These attacks can take a wide variety of forms, often revolving around someone (or a team) creating a distraction or masquerading as someone who could have legitimate access to the system they're targeting. It could be someone who claims to be from "corporate," a fake contractor, fake IT personnel or something as random as a "fire inspector" allegedly checking the office for imagined safety hazards while an assistant/accomplice surreptitiously places devices to monitor or siphon sensitive data from the victim network. Another in-person bit of trickery is “tailgating.” That’s when someone who claims to have forgotten their company ID, etc. asks you to hold the door behind you, allowing him into a restricted area. The same term is also sometimes used to describe someone asking to briefly borrow your phone, tablet or laptop to check something quickly and actually downloading malware instead. Live social engineering attacks can also come by phone, such as fake “technical support” calls offering to fix imaginary problems with your computer if you will just allow the caller to briefly take control of it remotely. Baiting is a type of attack in which a piece of portable electronic storage media like a CD-ROM, laptop or USB stick drive is left at or close to the target's workplace to tempt the curious victim into seeing what's on it. These will often include an official-looking logo or markings to make them especially tempting. How curious would you be to look at something labeled “Senior Executive Compensation – 2014” (with your company’s logo on it)? Of course, once the card, laptop or stick drive is connected, it will quietly download malware onto the network. And, yes, this initial intrusion into the network will likely be traceable back to you. What can you do to avoid being the weakest link? The one thing these attacks all have in common is that they rely on you to go along with the story they’re selling. The single best thing you can do whenever you receive an unsolicited electronic message or call from a business or someone you don’t know personally is to assume that it’s fake. Never click on links, open attachments, call phone numbers or use any other method of contact contained in any unsolicited emails, texts or calls. If you think the email, etc. could be legitimate, contact the alleged sender via phone or their official website. If an email that appears to be from someone you know seems out of character, unexpected or strange in any way, give the sender a call to see if it really came from her. When someone asks you to help her access something – or someplace – restricted, ask yourself why she needs your help. Also, it never hurts to take a moment to check out the story you’re given. A quick phone call (not using a number she gives you) can derail a social engineering attack before it starts. Tempting though it may be, opening that conveniently abandoned stick drive, etc.  yourself is a bad idea. Take it to your company security or IT personnel. Speaking of which, an IT department can (and should) take steps to help protect a network from electronic intruders, including the installation of network security software, but don’t forget that the first line of defense against a social engineering attack is you.

Scott Aurnou

Profile picture for user ScottAurnou

Scott Aurnou

Scott Aurnou is a cyber security consultant, attorney and vice president at Soho Solutions, an IT consulting and managed services company based in New York. He helps organizations identify and address the kind of critical technology-related risk and market exposure that keep executives, management committees and corporate boards awake at night.

Cutting Prices of Drugs Dispensed

A WCRI study found that new rules in Georgia cut prices by 25% to 40% -- though prices are still much higher than at pharmacies.

A new study from the Workers Compensation Research Institute (WCRI) showed that Georgia’s changes to the reimbursement rules for physician-dispensed drugs reduced the average price per pill paid by 25% to 40% for most of the drugs commonly dispensed by physicians. However, the post-reform prices paid for physician-dispensed drugs were still 20% to 40% higher than the prices paid to pharmacies for the same drug. “In many states across the country, policymakers are debating whether doctors should be paid significantly more than pharmacies for dispensing the same drug,” said Dr. Richard Victor, WCRI’s executive director. “Policymakers in Georgia adopted new rules to narrow the price difference, and the research continues to show the new regulations did not discourage physicians from continuing to dispense these drugs at lower prices, which was a concern.” The study, Impact of Physician Dispensing Reform in Georgia, 2nd Edition, is an update to the 2013 WCRI study that examined the early results of Georgia’s reform using pre- and post-reform data. With an additional year of data, the study found that there was little change in the prevalence of physician dispensing in the second post-reform period after an initial drop (from 36% pre-reform to 28% in the first post-reform period and 27% in the second post-reform period) while the share of drug costs for physician-dispensed prescriptions had a further five-percentage-point decrease (from 49% to 34% and now 29%). Georgia’s rule changes, effective in April 2011, capped the reimbursement amount for physician-dispensed prescriptions to the average wholesale price (AWP) of the original drug product used in the repackaging process if a repackaged drug is dispensed. The reform did not limit physicians’ ability to dispense prescription drugs. Georgia is one of the 16 states that have made legislative or regulatory changes to address cost issues related to physician dispensing. Before the rule change, for example, a prescription for hydrocodone-acetaminophen was paid at $0.48 per pill when filled at a pharmacy, but $1.06 per pill when filled at the doctor's office—a price difference of 121%. In the two post-reform periods, the price difference for the same drug was significantly reduced but still at 34% to 39%. The data used in this analysis of Georgia’s pharmacy fee schedule reform came from payers in Georgia that represented 46% of the claims in the state workers’ compensation system. The pre-reform data consist of claims from 3,851 injured workers with more than one week of lost time. These claims arose between April 1, 2010, and Sept. 30, 2010, with 24,672 prescriptions filled through March 31, 2011. The data for the first post-reform period consist of 3,960 claims that arose between April 1, 2011, and Sept. 30, 2011, with 24,925 prescriptions filled through March 31, 2012. The data for the second post-reform period consist of 4,164 claims that arose between April 1, 2012, and Sept. 30, 2012, with 25,325 prescriptions filled through March 31, 2013.

Ramona Tanabe

Profile picture for user RamonaTanabe

Ramona Tanabe

Ramona Tanabe is executive vice president and counsel at the Workers Compensation Research Institute in Cambridge, MA. Tanabe oversees the data collection and analysis efforts for numerous research projects, including the CompScope Multistate Benchmarks.

Why Focus on Customer Experience? Here's Why

A study reveals the ROI of a great customer experience -- and the penalty for a bad one.

|
Let’s face it, insurance is not an industry known for the quality of its customer experience. Rather, it’s an industry known more for its complexity, its lack of transparency and its stubborn adherence to old-fashioned ways of doing business. Granted, some insurance providers are trying to counter this reputation -- a few have even been so bold as to appoint chief customer officers (yes, sadly, that qualifies as “bold” in the staid insurance industry). Still, the idea of investing in a better customer experience is often met with skepticism in the insurance C-Suite. Those occupying the corner office may publicly affirm the importance of the customer experience, but, privately, they question the value of customer experience differentiation, unsure of the financial return it really delivers. In an industry where actuaries are kings and numbers rule the day, the seemingly “soft” benefits of a great customer experience don’t carry much weight when it comes to allocating capital. In reality, those benefits are far from soft -- it’s just that many firms aren’t well-versed in the economic calculus of customer experience, which requires a holistic, cross-silo view of financial impacts. (For example, the benefits of a plain-language policy summary from an underwriter may only manifest themselves downstream -- by reducing customer confusion, and preempting phone calls, to a service center.) What many numbers-oriented insurance executives seem to crave is quantifiable evidence that, at least at a macro level, a great customer experience really does pay dividends. And now they have that evidence. The graphic below illustrates the results of Watermark Consulting’s “2014 Customer Experience ROI Study.” The Watermark analysis sought to determine the long-term value of customer experience differentiation using a language that most any CEO would understand – shareholder value. Screenshot 2014-10-22 17.27.28 The study calculated the cumulative total stock returns for two model portfolios -- composed of the Top 10 (“leaders”) and Bottom 10 (“laggards”) publicly traded companies in Forrester Research’s annual Customer Experience Index rankings. For the seven-year period ending in 2013, the Customer Experience Leader portfolio outperformed the S&P 500 market index by an astounding 26 percentage points. Perhaps even more striking was the performance of the Customer Experience Laggard portfolio, which posted a 2.5% decline in value, despite a big rally in the broader market. The results underscore the benefits enjoyed by companies that invest in, and effectively execute on, a customer-experience strategy: higher revenues (because of better retention, less price sensitivity, greater wallet share and positive word-of-mouth) and lower expenses (because of reduced acquisition costs, fewer complaints and the less intense service requirements of happy, loyal customers). Conversely, the study also provides a sober reminder of how customer dissatisfaction saps business value, by depressing revenues and inflating expenses. Whether your firm is a public or private entity, the lesson here is clear: The market believes that companies that deliver a great customer experience over the long-term are simply more valuable than those that do not. And that’s a message that insurance traditionalists should take to heart, because a great policyholder experience really is good for business. Note:  A complimentary report describing the 2014 Customer Experience ROI Study, including commentary on how the leading firms differentiate themselves, is available from Watermark Consulting.

Jon Picoult

Profile picture for user JonPicoult

Jon Picoult

Jon Picoult is the founder of Watermark Consulting, a customer experience advisory firm specializing in the financial services industry. Picoult has worked with thousands of executives, helping some of the world's foremost brands capitalize on the power of loyalty -- both in the marketplace and in the workplace.

Ebola and Beyond: Protecting Self-Insured Work Comp Plans

Epidemic diseases require careful thinking, and terms of coverage vary widely.

sixthings
Epidemic diseases such as Ebola present a significant threat to the safety of both victims of the disease and the individuals who come into contact with those who are infected. Even with advanced medical facilities and protocols, healthcare workers are particularly vulnerable to outbreaks of infectious diseases because they work in close proximity to the victims for extended periods. Further, the facilities themselves tend to be densely populated with workers who run the risk of secondary exposure from medical equipment and other workers who may have been exposed to the disease. Self-insured workers’ compensation plans are very popular among the large health facilities that are likely to deal with these outbreaks. It is therefore important for risk managers and hospital executives at these facilities to not only prevent these infectious diseases from spreading to their employees, but to protect the hospital financially if such an outbreak does occur. An excess workers’ compensation policy provides reimbursement to self-insured employers for any workers’ compensation claim that exceeds the policy’s self-insured retention (SIR). Under most policies, a claim is defined as an occurrence or event that causes a loss. This provision allows the self-insured employer to combine the losses from multiple individuals injured in the same event under a single SIR rather than individually for each employee. Most policies however, require a separate SIR per employee for claims of occupational disease and illness. Therefore, if 10 employees contract the same disease in the course of their employment, the self-insured employer would be required to retain the SIR 10 times (once for each employee) under most basic policy forms. Clearly, this is an area of potential concern for self-insurers especially because most excess workers’ compensation carriers require minimum SIRs of $500,000 (or more). To help self-insured employers manage the expense of occupational disease claims, many excess workers’ compensation carriers offer a communicable disease coverage either as part of their policy form or as an endorsement to the underlying policy. A communicable disease coverage combines the losses of multiple employees suffering from the same disease or illness under a single claim and, therefore, a single SIR. Unfortunately for self-insurers, not all communicable disease coverage is created equally. Unlike traditional workers’ compensation policies, where carriers use the same policy form, each excess workers’ compensation policy is unique. My current excess policy has a communicable disease endorsement, so I don’t need to worry… right? Just because an excess workers’ compensation policy contains a communicable disease provision doesn't mean the policyholder is fully protected from this exposure. Communicable disease coverage is unique to the underlying policies to which it is attached and the carriers that issue them. In many instances, the only consistency between various carriers’ coverage forms for this potentially serious exposure is the name of the coverage itself. Each communicable disease coverage has its own set of definitions, rules and limitations, so it’s important for the policyholder to understand the key provisions that determine how the coverage is triggered and how it responds to potential claims. In general, communicable disease coverage can be compared using four basic criteria: covered diseases, transmission sources, symptom manifestation and coverage limits.  What’s in a name? The definition of a communicable disease is extremely important. Some coverage forms define communicable disease in very broad terms while others define such illnesses very narrowly. Forms that use the terms “disease” or “illness” generically but do not specifically enumerate covered or excluded diseases are most favorable to the policyholder. Forms with non-specific definitions can provide the policyholder with coverage for virtually any type of work-related communicable disease ranging from the common cold to meningitis. Some carriers’ communicable disease forms will specifically list the names or types of diseases that will be covered or the types of diseases that will be excluded under the policy. Much like a named-peril insurance policy, a communicable disease form that lists specific illnesses will only respond if two or more employees contracted a disease that was listed on the coverage form. If the policyholder suffers a claim that does not appear on the list of covered diseases, it’s not likely to be subject to the communicable disease coverage. Narrow definitions of covered losses can be particularly problematic when an outbreak of a previously unknown illness occurs. Again, if it isn't listed, it’s probably not covered. Conversely, coverage forms that exclude specific diseases not only prevent the self-insurer from seeking coverage for such losses under the communicable disease provisions but may also exclude coverage under the basic occupational illness section of the underlying excess workers’ compensation policy, as well. Consider the source One of the few universal components among communicable disease coverage forms is that the disease must be transmittable between individuals to be covered. Diseases such as black lung and asbestosis are often considered to be occupational illnesses but are not subject to communicable disease coverage because they cannot be transmitted from person to person. These specific diseases can only be contracted by prolonged exposure to coal dust and asbestos, respectively, and not merely by being in close contact with someone suffering from those diseases. The term “transmission” (or some similar term) appears in all communicable disease forms, but the manner in which the disease is transmitted is far more important. Generally speaking, some policies require a disease to be transmitted directly from one person to another to qualify for communicable disease coverage while others allow for both direct and indirect transmissions. Indirect transmissions are commonly referred to as source-to-source exposures. Forms that require a disease to be transmitted directly from person to person are far more restrictive than those that permit diseases to be transmitted from source-to-source. For example, if a group of hospital workers contracts swine flu after being exposed to an infected patient or even another co-worker who was previously exposed, the incident would likely be covered under both the person-to-person and source-to-source rules. If, however, a janitor and a nurse contracted swine flu after handling a soiled pillowcase, communicable disease coverage would only be triggered under a policy with a source-to-source provision because the individuals contracted the disease from an object and not directly from another person. Tell me the truth – how long do I have? Communicable disease coverages typically require individuals to contract the same disease or manifest symptoms within a specified period to be eligible for the coverage. If two employees treat a patient suffering from SARS and both exhibit symptoms of the disease a couple of days later, this would likely meet the coverage triggers required under most communicable disease forms. Conversely, if one employee develops SARS within a few days of exposure and the second begins to exhibit symptoms eight weeks later, the communicable disease coverage would be unlikely to respond. The incubation period for this particular disease is normally seven days, therefore, even though both employees ultimately contracted the same disease, it is highly unlikely that they contracted it from the same exposure. Thus, their claims would not be combinable. Illnesses with long incubation periods are sometimes more difficult to classify under communicable disease coverages because of the time constraints required under some forms. Some forms set forth very specific time frames in terms of hours or days between the time when a group of employees is first exposed to a particular disease and the time the symptoms manifest. Coverage forms that allow symptoms to be manifested at some point during the policy period are generally more favorable to the policyholder. Such forms can combine losses for a successive string of employees infected by one another over a prolonged period (weeks or even months) as long as the infections took place during the policy period and their respective illnesses can be traced back to the same original source. One potential downside to the policy period provision can occur when the event straddles two different policy periods. If an infection occurs during one policy period and continues to affect employees through a second policy period, it is likely that two separate claims would be developed, thus requiring the employer to satisfy the SIR twice. In this instance, the communicable disease coverage from the first policy would respond to the employees who exhibited symptoms from the time of exposure up until the end of the policy period. Any employees who exhibit new symptoms after the effective date of the new policy period would constitute a separate claim under the new policy’s communicable disease coverage. Take it to the limit Coverage extensions and endorsements sometimes share the same limits as the underlying policies to which they are attached. In other cases, coverage extensions carry their own limits in addition to the underlying policy limits or sub-limits, which may erode the underlying excess policy’s shared limit. These limits can be provided on an occurrence basis, aggregated basis or both. Communicable disease forms that carry coverage limits outside of the underlying policy’s basic limits can pose a very significant (and hidden) exposure to the policyholder and therefore should be examined closely. If communicable disease coverage shares its limits with the underlying policy, the policyholder need only determine an adequate coverage limit for the underlying policy. If, however, the communicable disease coverage carries its own limits, it’s important for the policyholder to make certain those limits will provide adequate protection in the event of a loss. In some instances, communicable disease coverage can carry per-occurrence or aggregated limits as low as $1 million. Although the policyholder gets the benefit of combining multiple claimants under a single SIR, the collective losses can also serve to erode the occurrence limit very quickly, especially for diseases that require significant amounts of treatment and lost time. Aggregated limits are typically shared over the course of a policy period and are likewise eroded by each communicable disease claim filed during the policy period, thus leaving less coverage available for future claims. More importantly, once the limit is exhausted under communicable disease coverage, any amounts exceeding the coverage limit would be ineligible for reimbursement under the communicable disease coverage and possibly the underlying excess policy, as well. Depending on the circumstances of a given loss and the coverage provided under the applicable communicable disease form, it is possible that the communicable disease coverage could actually end up costing the employer more than a basic, unendorsed policy. That’s great information, but what can I do with it? Many excess insurance carriers do allow at least some flexibility in the coverage they offer. In many instances, limits are negotiable on the underlying coverage, and those limits can sometimes be increased even after the policy has been issued. There may be an additional premium required to add communicable disease coverage to an underlying excess policy or to increase the limits on existing communicable disease coverage but the cost is typically modest as compared to the excess policy and the overall self-insurance program. Self-insurers may also want to consider adding aggregate excess coverage to limit the collective unreimbursed costs resulting from multiple occupational disease or communicable disease claims occurring during a single policy period. Lastly, it may be prudent for self-insurers to take the terms and limitations of various communicable disease coverage forms into consideration when choosing an excess workers’ compensation policy. Epidemic diseases represent potentially one of the greatest financial risks to self-insured employers with exposures to such claims, especially hospitals and other healthcare providers. It is therefore important for those self-insured employers to make the communicable disease and occupational disease coverage a priority and not simply an add-on. Again, not all communicable disease coverage forms are created equally. Choose carefully.

Vince Capaldi

Profile picture for user VinceCapaldi

Vince Capaldi

Vince Capaldi is the president of the Bay Oaks Wholesale Brokerage, a national wholesale insurance broker specializing in self-insured workers’ compensation programs. Capaldi has developed and maintained numerous individual and group self-insurance plans in both the public and private sectors nationwide.

When Nature Calls: the Need for New Models

This article is the first of a series on how the evolution of catastrophe models provides a foundation for much-needed innovation.

sixthings
The Earth is a living, breathing planet, rife with hazards that often hit without warning. Tropical cyclones, extra-tropical cyclones, earthquakes, tsunamis, tornados and ice storms: Severe elements are part of the planet’s progression. Fortunately, the vast majority of these events are not what we would categorize as “catastrophic.” However, when nature does call, these events can be incredibly destructive. To help put things into perspective: Nearly 70% (and growing) of the entire world’s population currently lives within 100 miles of a coastline. When a tropical cyclone makes landfall, it’s likely to affect millions of people at one time and cause billions of dollars of damage. Though the physical impact of windstorms or earthquakes is regional, the risk associated with those types of events, including the economic aftermath, is not. Often, the economic repercussions are felt globally, both in the public and private sectors. We need only look back to Hurricane Katrina, Super Storm Sandy and the recent tsunamis in Japan and Indonesia to see what toll a single catastrophe can have on populations, economies and politics. However, because actual catastrophes are so rare, property insurers are left incredibly under-informed when attempting to underwrite coverage and are vulnerable to catastrophic loss. Currently, insurers’ standard actuarial practices are unhelpful and often dangerous because, with so little historical data, the likelihood of underpricing dramatically increases. If underwriting teams do not have the tools to know where large events will occur, how often they will occur or how severe they will be when they do occur, then risk management teams must blindly cap their exposure. Insurers lacking the proper tools can’t possibly fully understand the implications of thousands of claims from a single event. Risk management must place arbitrary capacity limits on geographic exposures, resulting in unavoidable misallocation of capital. However, insurers’ perceived success from these arbitrary risk management practices, combined with a fortunate pause in catastrophes lasting multiple decades created a perfect storm of profit, which lulled insurers into a false sense of security. It allowed them to grow to a point where they felt invulnerable to any large event that may come their way. They had been “successful” for decades. They’re obviously doing something right, they thought. What could possibly go wrong? Fast forward to late August 1992. The first of two pivotal events that forced a change in the attitude of insurers toward catastrophes was brewing in the Atlantic. Hurricane Andrew, a Category 5 event, with top wind speeds of 175 mph, would slam into southern Florida and cause, by far, the largest loss to date in the insurance industry’s history, totaling $15 billion in insured losses. As a result, 11 consistently stable insurers became insolvent. Those still standing either quickly left the state or started drastically reducing their exposures. The second influential event was the 1994 earthquake in Northridge, CA. That event occurred on a fault system that was previously unknown, and, even though it measured only a 6.7 magnitude, it generated incredibly powerful ground motion, collapsing highways and leveling buildings. Northridge, like Andrew, also created approximately $15 billion in insured losses and caused insurers that feared additional losses to flee the California market altogether. Andrew and Northridge were game changers. Across the country, insurers’ capacity became severely reduced for both wind and earthquake perils as a result of those events. Where capacity was in particularly short supply, substantial rate increases were sought. Insurers rethought their strategies and, in all aspects, looked to reduce their catastrophic exposure. In both California and Florida, quasi-state entities were formed to replace the capacity from which the private market was withdrawing. To this day, Citizens Property Insurance in Florida and the California Earthquake Authority, so-called insurers of last resort, both control substantial market shares in their respective states. For many property owners exposed to severe winds or earthquakes, obtaining adequate coverage simply isn’t within financial reach, even 20 years removed from those two seminal events. How was it possible that insurers could be so exposed? Didn’t they see the obvious possibility that southern Florida could have a large hurricane or that the Los Angeles area was prone to earthquakes? What seems so obvious now was not so obvious then, because of a lack of data and understanding of the risks. Insurers were writing coverage for wind and earthquake hazards before they even understood the physics of those types of events. In hindsight, we recognize that the strategy was as imprudent as picking numbers from a hat. What insurers need is data, data about the likelihood of where catastrophic events will occur, how often they will likely occur and what the impact will be when they do occur. The industry at that time simply didn’t have the ability to leverage data or experience that was so desperately needed to reasonably quantify their exposures and help them manage catastrophic risk. Ironically, well before Andrew and Northridge, right under property insurers’ noses, two innovative people on opposite sides of the U.S. had come to the same conclusion and had already begun answering the following questions:
  • Could we use computers to simulate millions of scientifically plausible catastrophic events against a portfolio of properties?
  • Would the output of that kind of simulation be adequate for property insurers to manage their businesses more accurately?
  • Could this data be incorporated into all their key insurance operations – underwriting, claims, marketing, finance and actuarial – to make better decisions?
What emerged from that series of questions would come to revolutionize the insurance industry.

Nick Lamparelli

Profile picture for user NickLamparelli

Nick Lamparelli

Nick Lamparelli is the managing partner of Insurance Nerds and chief program officer for Latin International Reinsurance Group. 

He is also CEO of the Insurance Advocacy Forum of Florida.

Lamparelli is a three-decade insurance executive, starting as a local agent and evolving to middle market broker, wholesaler, underwriter and catastrophe insurance expert.


James Rice

Profile picture for user JamesRice

James Rice

James Rice is senior business development director at Xuber, a provider of insurance software solutions serving 180+ brokers and carriers in nearly 50 countries worldwide. Rice brings more than 20 years of experience to the insurance technology, predictive analytics, BI, information services and business process management (BPM) sectors.

The Aging Workforce and Succession Plans

The exodus of Baby Boomers from the workforce will create huge knowledge gaps, but few insurers have yet to take notice.

In 1969, Neil Armstrong became the first man to set foot on the moon, marking the culmination of a $24 billion NASA space program. Ten years later, NASA sheepishly admitted they could not return to the moon even if they wanted to -- they couldn’t remember how. This is a perfect example of what is referred to as the “knowledge gap”: the loss of critical information when employees leave their place of employment. In the case of NASA, all the key people involved in the original Apollo 11 project had retired…and no one thought to jot down what they knew. To make matters worse, blueprints for Saturn V, the only rocket powerful enough to travel to the moon, were lost. Even though this NASA fumble took place 30 years ago, the exact scenario is being played out in spades as Baby Boomers (those individuals born between 1946 and 1964) are reaching retirement age. Most employers have made no effort to capture the Boomers’ knowledge before they eventually leave. In the next 20 years, 76 million Boomers will sing the Johnny Paycheck song as they walk out the door, taking with them an entire generation's worth of knowledge that can never be replaced. There is an inconvenient truth in the potential calamity, and most companies aren't ready for the aftermath. Boomers make up more than one third of the nation's work force. They fill many of its most skilled and senior jobs. Thanks to their near-workaholic habits, they are among the most aggressive, creative and demanding workers in the market today. Economists predict their exit will cause a great, sucking hole in the workplace universe. Companies need to bear in mind that the coming retirement years are going to be larger than at any other time in U.S. history. With 76 million Boomers leaving the workforce and only 46 million Generation Xers (those born between 1965 and 1980) available to take the newly vacant roles, there will be a deficit of 30 million workers. So while the Millennials (also known as Generation Y -- those born between 1981 and 1995) number approximately 100 million, the oldest of them are still too young and inexperienced to step into leadership roles. A study earlier this decade by the Bureau of Labor Statistics reported that more than 17% of Boomers holding executive and managerial positions are expected to leave their careers by 2010. While some companies have begun scrambling to hire trainees, and close the potential knowledge gap created by the Boomer exodus, most companies haven't even taken notice, according to Elizabeth Kearney, founder and president of Kearney & Associates, a nationwide alliance of experts who specialize in this trend. In fact, according to the Institute for Corporate Productivity (i4cp), only 29% of responding organizations report that they incorporate retirement forecasts into their knowledge transfer practices. Furthermore, i4cp found that only a third add "skills gap analysis" into those forecasts; less than half say they train their managers to identify critical skills; only 23% are educated in critical skills transfer; and most companies admit they do not formally measure the effectiveness of their knowledge transfer practices. Cornerstone OnDemand has released a whitepaper finding that most organizations, particularly larger ones, are not ready for the pending talent shortage caused by the looming retirement of Boomers. The paper, titled, "Managing Talent in the Face of Workforce Retirement," summarizes key findings of Knowledge Infusion's "2010 Talent Readiness Assessment," which indicates, among other things that:
  • Organizations with more than 2,500 employees indicated that approximately one in five workers are over the age of 55;
  • More than 50% of respondents said the retiring workforce will cause a knowledge/skill gap; and yet,
  • Less than 30% of organizations that responded had a knowledge retention plan in place.
David DeLong, author of the book Lost Knowledge: Confronting the Threat of an Aging Workforce, recently pointed out that there are direct and indirect costs associated with lost knowledge. Direct costs occur through the loss of workers with specific knowledge through retirement and attrition. When these experts are no longer around, it accentuates the indirect costs of knowledge loss: poor documentation and storage. A holistic approach is necessary to deal with an aging workforce and knowledge retention problems, according to DeLong. The approach combines effective knowledge transfer practices, knowledge recovery initiatives, strong knowledge management technologies and finally, more effective HR processes and practices to deal with the problem on a more systemic level. Here are three things DeLong recommends companies should be doing to deal with aging workforce problems:
  • Harvest critical information now and make it available at point-of-need. Companies should begin by identifying where they are most at risk from the loss of knowledge and experience. This involves, in part, establishing performance management and career development processes that identify employees with the most critical knowledge and expertise. For example, to sustain business after the 9/11 attacks, Delta Air Lines was forced to make workforce cuts to remain competitive. This meant that Delta had less than two months to identify which of the 11,000 laid-off employees had jobs for which no backups or replacements had been trained, and then capture that knowledge before it walked out the door. Supervisors worked with a team from Delta’s learning services unit to narrow the list down to those veterans whose departure would represent a critical job loss. Once these outstanding performers were identified, they were interviewed about their roles at the company. This way, Delta retained as much critical knowledge as possible on very short notice.
  • Use real-time collaboration tools to enable workers to interact with colleagues. As collaboration and knowledge management have grown, relevant technologies and tools have become increasingly sophisticated. Things like workspace portals are revolutionizing knowledge management and collaboration solutions by giving workers access to enterprise data and applications, productivity and virtual collaboration tools, and documented knowledge, all of it personalized.
  • Use advanced e-learning techniques. Performance simulation gives employees the opportunity to practice, in real time, the key skills and competencies they must acquire to address knowledge drain.
  • Employ better workforce planning and targeted knowledge retention initiatives to address the brain drain that now threatens entire industries.
"Companies need to proactively assess their organizations and determine a plan of action before this threat becomes a reality," said Adam Miller, president and CEO, Cornerstone OnDemand. "Understanding the overall goals of the organization and which employees are key to achieving these goals including their role, skills and level within the company is important to implementing a retention plan." Not all employers are ignoring the inevitable. The i4cp study found that there are a number of up-and-coming practices in use or under consideration. "Communities of practice" are utilized by a third of all responding companies to transfer knowledge, and the use of Webcasts and services such as "Lunch and Learn" and "SharePoint" are on the rise. Harvesting the knowledge is only part of the equation. The captured knowledge must then be reformatted into a usable database with easy access by the employer. It does no good to house the data in a three-ring binder and then place it on a dusty shelf, never to be seen again. Northrop Grumman has been on the forefront of knowledge management for many years. In 1997, with the Cold War behind them, thousands of NG engineers, who had helped design and maintain the B-2 bomber, were asked to leave the integrated systems sector. In a short period, 12,000 workers filed out the door, leaving only 1,200 from an original staff of 13,000 employees, to help maintain the current fleet of bombers. The 12,000 took with them years of experience and in-depth knowledge about what was the most complex aircraft ever built. Without appropriate measures, this could have been a disaster of epic proportion. Instead, before the exodus, NG formed a “Knowledge Management Team” who identified the top experts and videotaped interviews with them. To this day, the company uses a variety of tools to retain and transfer knowledge from its engineers -- before they retire. The company has implemented document management systems, as well as common work spaces to record how an engineer did her job for future reference. NG also brings together mature and young engineers across the country to exchange information via e-mail or in-person about technical problems. No company wants to be in the position in which NASA found itself -- having to explain why it can’t recreate the single greatest event in modern history. If employers don’t plug the knowledge gap prior to the great Boomer exodus, it’s going to be more than just Houston that has a problem.

Daniel Holden

Profile picture for user DanielHolden

Daniel Holden

Dan Holden is the manager of corporate risk and insurance for Daimler Trucks North America (formerly Freightliner), a multinational truck manufacturer with total annual revenue of $15 billion. Holden has been in the insurance field for more than 30 years.

How to Apply ERM to Cyber Risks

Insurance and reinsurance are not alternatives to ERM; cyber risks must be assessed and mitigated like all other risks.

sixthings
The advent of new technologies has enabled risk stakeholders to perform enhanced data analytics to gain more insights into the customer, risk assessment, financial risk management and quantification of operational risk. Companies manage many risks aligned to their risk profile and risk appetite. They do so by risk awareness and risk assessment. The visionaries and early adopters do so dynamically by use of mathematics (stochastically or actuarially) and simulations for the future based on the historical loss data to correlate all the risks of the enterprise into one holistic view. Factors to consider include: Cyber risk. Operational risk affects every organization on an equal basis and is often quantified as a percentage of gross written premiums. Cyber risks are no different from any other risk in terms of risk management and risk transfer. However, IT departments, even with the best of intentions, can increase  cyber risk by their strategy — and there is no silver bullet to protect the company. Keyless signature infrastructure (KSI) enables companies to plan data breach strategies where systems administrators are no longer involved in the security process. This will bring great comfort to risk managers who see  new technology being introduced that will increase cyber risk. Risk mitigation. Insurance and reinsurance are not alternatives to enterprise risk management (ERM).  Risk transfer programs should be used to address structural residual risk. From EY’s experience, companies can identify risks and adopt leading practices to ease the process of finding the right cover at the right price — with the correct reinsurance optimization. The insurance industry should insist upon this enterprise level of risk mitigation before it issues cover for large risks and data breaches. Risk modeling. The exercise in Figure 1 uses a robust industrial risk modeling tool to look at cyber risk.  The red is the tail value at risk (TVAR) and the area that needs to be mitigated by risk transfer mechanisms. Reinsurance, the most obvious mechanism, is not the replacement for leading-practice risk management. The assumption is that data integrity standards have already been adopted here, so we are looking at the residual risk mitigation following that implementation. Capture The bottom graph shows the situation prior to reinsurance, where small claims are aggregated and a long tail cuts into the companies’ risk-based capital limits. The top graph shows a leaner risk situation after the application of reinsurance, bringing it back in the comfort zone. The standard deviation process will depend on how the regulator views cyber risk and solvency. Currently, solvency models are geared on average to a 1-in-200-year event, which may be suitable for earthquake and other peril risks but is likely to be different for cyber risks and to vary by country risk appetite. Other risk transfer mechanisms. In addition to reinsurance, cyber captives are used to address continuing risk. A point worth noting is the potential to mathematically create a “cyber index” in the same manner that weather and stock market indices appear in the macroeconomic models representing market risk exposure correlation to other enterprise risks. This cyber index could be created from the data patterns of the cyber catastrophe models and other data and then used as a threshold to trigger a data breach claims process following notification of a data breach. Special-purpose vehicles (SPVs). This risk transfer approach is used in conjunction with capital market investors and sponsors, and it is similar to the catastrophe bond investments that protect countries from earthquake risk. It creates a bond shared by government and private industry to pay and share claims by loss bands in the event of a large or black-swan event. While these partnerships are very effective, such bonds often have a 10-year span, and a shorter life-span vehicle will be more suitable to cyber. Sidecars. For natural catastrophes, these two-year vehicles have been referred to as sidecars, an SPV derivative of a captive where investors invest in a risk via A-rated hedge funds. If the event has not taken place within a given time frame, investors receive their money back with interest. This makes cyber risk part of an uncorrelated portfolio investment for chief investment officers. They can also base investment on the severity level of the attack, so investments are not lost on all events. It will take time for this SPV approach to evolve over reinsurance and captives, but with good data quality, proper event models, ratings and adoption of KSI and other standards in the IT space, the capability to use capital markets to risk-transfer cyber risks will emerge. Data integrity standards would increase investor confidence in such SPVs. For the full report on which this article is based, click here.

Shaun Crawford

Profile picture for user ShaunCrawford

Shaun Crawford

Shaun Crawford leads Ernst & Young's $1.4 billion global insurance business. He has been in the financial services industry for 27 years, having worked both in consulting or line management with the majority of European life assurers and U.K. retail banks at some point.

Has OSHA Become a Friend to Insurers?

A little-known regulation may provide a powerful tool outside of workers' comp law that can reduce fraud and lost work time.

It may be possible for employers to take a whole new approach to workers' comp cost containment based on an OSHA regulation that allows an employer to require injured workers to undergo a prompt medical exam outside of the workers' comp system and to obtain the release of prior medical records.

Most employers are unaware that they can utilize this little-known and virtually untried regulation that allows for employers to pay for second medical opinions under OSHA recordkeeping requirements and regulations.  The regulation can be found in §§ 1904.7(b)(3)(ii) and (b) (4)(viii).

There are two major facets to this statute. First, employers must pay 100% of the medical exam costs outside of the workers' comp system. Second, insurance companies and third-party administrators (TPA)s cannot schedule such exams or pay for such exams because they cannot work outside the state workers' comp system.

The costs of such exams are not included in an employers' overall workers' comp claim costs, nor are they included in experience modification calculations. The costs for such a program would have to come out of another budget, like risk management or safety.

Of major significance is that, while the regulation states such exams are outside workers' comp regulations, with proper procedure they and the related medical records are discoverable. They may be released and used in workers' comp claim adjudication.

This approach would not necessarily require any change in how medical professionals provide exams for injured workers. What would change is how these exams would be scheduled and paid for, outside workers comp.

A key issue is that these employer-directed exams would have to be "contemporaneous." OSHA defines this as, "no change in workers' condition" between the medical exams.

There would be a very short window, in my opinion, to utilize this OSHA prompt medical exam. These exams would need to be scheduled at the same time as the initial injury reporting.

The intent of OSHA is to allow employers to choose between two conflicting medical opinions (employee medical provider vs. employer medical provider) as to whether an injury or illness is "recordable" under OSHA regulations based on "authoritative" medical opinion.

OSHA regulations are silent on two fronts:  1) the actual timelines beyond "contemporaneous" and 2) whether these medical exams and prior medical records can be used through subpoena to question the need for continuing medical treatment and lost time under state workers' comp.

But I see no reason why the results of such an exam could not be used even after a claim is determined to be "recordable" under OSHA regulation, because the prompt medical exam and second medical opinions and reports are "discoverable" under proper procedure in state work comp systems, according to OSHA.

The employer can simply say, "We paid for a prompt medical exam under OSHA regulations, and this is what we found out." The employer would then have the right to share this information with its insurance company or TPA because the injured worker must agree to the exam and release of prior medical records.

This approach would be a great tool for employers in states such as Illinois whose workers' comp laws allow the employee to select the medical provider.

The recent federal court case in Illinois decided against Fed Ex may well have had a different outcome if the company had used federal OSHA regulations to support its policy of requiring employees to promptly report medical care.

Illinois state workers' comp law, among many others, clearly gives the employee the right to select the treating medical provider. Most people in the industry would say, "case closed!" But OSHA regulations (federal law) clearly also give employers the right to schedule a prompt medical exam and to choose between two conflicting medical opinions to determine the "most authoritative." OSHA also refers to Department of Transportation exams as an example of intermediary exams available to employers. Those exam records and results are not part of the comp record, but, with proper procedure and use of subpoena, records may become discoverable in work comp cases.

Employers have always felt powerless in states that allow the injured worker to select the treating medical provider, such as Illinois and New York. By using OSHA regulations, employers may very well have a powerful management tool in their arsenal that they didn't even know about to address potential fraud, abuse and inappropriate medical care and lost-work time.

Hence, I believe a little-known, rarely utilized outside of state workers' comp is available to employers under OSHA and could be very powerful.

Stay tuned.

9 Technologies That Will Change Insurance

If driverless cars end personal auto insurance, how will that affect other products? How do we assess the risk of a 3D-printed structure?

"We're at maybe 1% of what is possible. Despite the faster change, we're still moving slow relative to the opportunities we have." This compelling statement from Larry Page, CEO and co-founder of Google epitomizes the power and potential of emerging technologies. Yet most insurers have difficult comprehending how fast emerging technologies are being introduced. And the pace is gathering speed, having a profound impact on our lives, our businesses and our industry. Moore's Law tells us that computing power doubles every 18 - 24 months, but even that seems to be irrelevant compared with the power of emerging technologies, because they are coming faster, and they are more formidable than ever before. This rapidly accelerating pace comes at a time when the convergence of advancing technologies, increasing customer expectations and access to capital for new technology start-ups are magnifying the extremes, and the impact to the insurance industry is more game-changing than ever before. Never before has technology advancement had as much influence as what we are experiencing now. Technologies promise breakthroughs that will challenge long-held business assumptions and shift the boundaries between business and industry – creating completely new businesses and industries. SMA is actively tracking nine emerging technologies: 3D printing, the Internet of Things (IoT), drones/aerial imagery, driverless vehicles, wearable devices, "gamification," artificial intelligence, semantic technologies and biotechnology. We are following them from a perspective inside the industry as well as taking an "outside-the-industry" view.  Not surprisingly, adoption is being led by the Internet of Things (IoT). The IoT is followed by artificial intelligence (AI), drones/aerial imagery and then gamification. The insurance industry's rapid adoption is impressive. Five of the nine technologies are projected to arrive at or go well beyond the tipping point within three years. All nine are projected to surpass the tipping point within five years. Adding to the momentum, individuals and companies that are a part of SMA's Innovation Ecosystem and represent outside-the-industry perspectives see an even faster rate of adoption and greater potential for the transformation of insurance. This underscores that the insurance industry is on the crest of a massive wave of change. Over the next five years, these emerging technologies, just like the Internet, smartphones and social media before them, are expected to drive new business models and foster the formation of companies from unexpected combinations of companies and industries — capturing the customer relationship and revenue. The astounding influence of these technologies -- over a relatively short period -- will begin to delineate a new generation of market leaders within and outside the insurance industry. Who will be the next Facebook, Uber or eBay? So how should insurers respond to this rapid adoption? Insurers must quickly begin to develop strategies and experiment with and invest in these technologies today. If not, many insurers will be placed at significant risk, because there is typically a minimum two-year lag time between leaders and the mainstream and a minimum four- to five-year lag time between leaders and laggards. And given the pace of adoption of these technologies by insurance customers, the lag time carries more potential for damage than it did in the past. Consider that Apple introduced the iPhone just seven years ago, in June 2007. The result has been massive destruction and transformation that has created new leaders while forcing others into increasing irrelevance. While it may be difficult to grasp the sheer magnitude of the change coming from the emerging technologies, remember that Larry Page of Google says we are only seeing 1% of the potential. Insurers must aggressively find a way to engage these technologies and uncover the potential, first to stay in the game, and then to win it. To do so, insurers must have modern core systems as a foundation to integrate the use of these technologies. Consider these questions: How will product liability need to be redefined for driverless vehicles? If individuals or businesses no longer need auto insurance, what is the impact on other products? Multi-policy discounts? Will the driverless car encourage shopping for alternative options? Will it drive commoditization into other products? How will insurers assess the value and risk of a 3D-printed structure, body organs or vehicle parts? How will biotechnology-based agriculture change risk factors? How will drones help underwriting and claims? Can drones also provide resources needed during catastrophes, creating new services and value? Could gamification be a new channel to help drive increased market penetration through engagement and education about life insurance, health, medical, liability, home, umbrella and more? These are but a few of the implications for insurance. They are inter-related and complex. They stress the significant disruption that is coming, and coming fast, as represented by the five out of nine emerging technologies that will reach the tipping point within three years … and some much sooner. Insurers that have not begun to pilot these technologies are already lagging behind and will struggle to keep up with this accelerated pace of adoption, not just from today's competitors, but also from tomorrow's competitors, as well as their customers. That poses a question: Will you remain relevant, or become the next Kodak, Blockbuster Video, Borders or CNN of insurance – the iconic brand that dies? The coming years hold unparalleled opportunities for innovation and matchless potential for becoming market leaders that leverage emerging technologies to increase customer value, engagement and loyalty to insurers. As Steve Jobs stated, "Everyone here has the sense that right now is one of those moments when we are influencing the future." The question to you is: Will you influence the future or be a remnant of the past? This article is adapted from a new research report, Emerging Technologies: Reshaping the Next-Gen Insurer.

Denise Garth

Profile picture for user DeniseGarth

Denise Garth

Denise Garth is senior vice president, strategic marketing, responsible for leading marketing, industry relations and innovation in support of Majesco's client-centric strategy.

What the Apple Watch Says About Innovation

The watch is designed to bolster the iPhone -- but innovators must be willing to move beyond old products and business models.

|
Now that the dust has settled on the long-anticipated unveiling of the Apple Watch, a major obstacle to its success is coming into view: the iPhone. The Apple Watch has been the subject of breathless anticipation for years because, as Tim Cook said at its introduction, it represents “the next chapter in Apple’s story.” Conceived three years ago, shortly after Steve Jobs’ passing, the Watch is the embodiment of multiple dramatic arcs and aspirations. It is the first major product developed under Tim Cook and Jony Ive outside of Jobs’ shadow—and thus has huge personal and legacy implications for both men. The Watch is also Apple’s attempt to catalyze and dominate the wearables category. Given the intense competition in the smartphone market and the widespread view that new killer products, platforms and ecosystems will emerge somewhere at the intersection of the Internet of Things and wearable computing, the Watch is central to Apple’s post-iPhone strategy. It might seem that the iPhone should be the Apple Watch’s greatest asset. Apple is positioning the Watch as a jaw-dropping, must-have peripheral to the iPhone. Millions of iPhone-toting Apple fans are sure to queue up upon the Watch’s 2015 launch to buy it. But do not mistake early adopters for market validation. For billions of other potential customers, the Watch’s close linkage and tethering to the iPhone could be a fundamental weakness. In the short term, Apple must convince existing customers that they need a Watch in addition to their iPhone. Apple, however, has yet to offer a convincing case for this. Long-rumored groundbreaking health apps built on Watch-mounted sensors have not materialized—disappointing many healthcare watchers (including me). That leaves Apple competing against more narrowly focused wearable devices like the Fitbit and Pebble—but at multiple times the price and fractions of the battery life. Apple is also touting Apple Pay as a killer app that will attract consumers to the Watch. But, while Apple Pay is an intriguing service-oriented strategy for Apple, there is no need for consumers to buy an Apple Watch to use it. Apple Pay will work fine with just the iPhone. For now, it seems that Apple has higher hopes for the Watch as a fashion accessory than as a category-defining killer app. But even that highbrow aspiration has ample skeptics who question the Watch’s fashion chops and business potential. In the long term, when and if compelling apps emerge for the Watch, Apple will have to convince Watch enthusiasts that they need an iPhone in addition to the Watch. This might not seem like a limiting factor given that there are more than 300 million active iPhone users. But imagine if the iPhone were just a peripheral to the Mac, thereby limiting its addressable market to Mac owners. Or imagine if the iPhone had to be tethered to the iPod. Do not such scenarios, in retrospect, sound implausibly shortsighted? Both the Mac and the iPod were great products with loyal followings at the iPhone’s introduction. Apple, however, did not limit the iPhone to its predecessors’ market niches. As shown in Figure 1, the result was a blockbuster that lifted Apple far beyond those earlier products. The iPhone has grown to represent more than half of Apple’s revenues and perhaps even more of its profits. chunkagraph1 Figure 1 — Apple Device Sales Now the iPhone has a loyal following but a small share of the smartphone market. Will Tim Cook limit the Apple Watch’s success to iPhone owners, or will Cook free it to dominate the potentially larger wearable devices space? Freeing the Watch is a strategic imperative. History tells us that market-leading technology products like the iPhone inevitably fade. The companies that depend on them must innovate into the succeeding categories or fade as well. Kodak, Polaroid, IBM, DEC, Nokia, Motorola, Blackberry, Intel, Sony, Dell and Microsoft are among those fading or faded companies. All of those other companies underutilized disruptive advances in information technology for (at best) incremental enhancements to their dominant products. By doing so, they missed out on new killer products, business models and industries that coalesced around the new platforms enabled by those technology advances. Thus, Kodak wasted decades trying to deploy digital photography (which it invented) as an enhancer to its dominant film-driven businesses. Microsoft was slow to the web and the cloud and killed its early e-reader and tablet devices because of internecine struggles over how those new categories related to its Windows and Office businesses. The list goes on: IBM did not lead in minicomputers. DEC and every other leading minicomputer maker missed out on personal computers. Motorola and Nokia were killed by smartphones, and Blackberry is near death. Limiting the Watch to a peripheral role in the iPhone-centric ecosystem would repeat the same mistake made by those earlier market-leading technology companies. That’s not to say there is not a lot of money to be made in the defend-the-cash-cow approach. Just look at the more than $650 billion in revenue and nearly $250 billion in earnings that Steve Ballmer delivered in his tenure as Microsoft CEO. Ballmer achieved those impressive numbers by defending and milking Microsoft’s dominant Office and Windows products. Ballmer, Microsoft and its investors missed out, however, on the market value created by Google, Apple, Facebook, Twitter and others that capitalized on search, big data, cloud computing, mobile devices and social media. Ballmer’s inability to grow beyond the core products that he inherited stagnated Microsoft’s market value for a decade. Likewise, Tim Cook could nurse Apple’s iPhone-driven revenue stream for a long time. I doubt, however, that Tim Cook would be satisfied with a value-creation legacy comparable to Steve Ballmer’s. It is too early to dismiss the Apple Watch’s potential to transcend the iPhone. We’ll get a measure of Apple’s foresight when it releases the software development kit (SDK) for the Watch. That will show how fundamentally tethered the Watch is to the iPhone and whether Apple has laid the groundwork for the Watch to be standalone at some point. The real gut check for Tim Cook is further out in time, when technology and creativity enables wearable devices like the Watch to not only stand alone from the iPhone but also to replace it. Will Tim Cook allow the Watch to cannibalize iPhone sales—as Apple previously allowed the iPhone to eat away at the iPod and risked the iPad's doing the same to the Mac? Or will Apple stagnate as competitors and new entrants out-innovate it? Will Apple fade away as the riches from new killer apps, devices, ecosystems and business models that coalesce around emerging wearables-centric platforms flow to others?