Corvus Documents
Corvus Insurance
Smart Cyber Insurance
Corvus Insurance
Smart Cyber Overview
Corvus Insurance offers Smart Cyber Insurance®, a comprehensive solution designed to address the evolving landscape of cyber risks. This innovative product combines the financial strength of Travelers A++ paper with cutting-edge underwriting practices and proactive risk prevention services. Information is current as of the date of the document.
Coverage and Limits
- Primary and Excess Cyber risks for organizations with up to $5B in gross annual revenue
- Policy limits up to $10M
- Broad 1st Party & 3rd Party Insuring Agreements
Enhanced Protection
- Contingent Business Interruption with Full Policy Limits
- System Failure coverage
- Cyber Crime and Social Engineering Protection
- Bodily Injury and Media Liability coverage
- Online and Offline Coverage
- Reputational Loss Coverage
- Full Prior Acts
Eligible Risk Classes
Corvus caters to a wide range of industries, including:
- Healthcare
- Retail
- Manufacturing
- Financial Institutions
- Education
- Professional Services
Unique Selling Points
Comprehensive Risk Management
- Personalized cyber threat alerts for all policyholders
- On-call guidance from cybersecurity experts
- Prioritized security recommendations via the Policyholder Risk Dashboard
Flexible Underwriting
- Experienced underwriting team offering hands-on partnership
- Adaptable approach to accommodate complex risks
Claims Expertise
In-house claims team with decades of combined experience
Incentivized Risk Reduction
Retention reduction endorsement, offering a 25% reduction in self-insured retention (up to $25,000) for policyholders who engage with Corvus services
About Corvus
Corvus Insurance, a wholly owned subsidiary of Travelers Insurance, is committed to building a safer world through innovative insurance products. Their Smart Cyber Insurance® and Smart Tech E+O offerings combine broad coverage with proactive risk prevention services, including threat alerts and support from in-house cybersecurity experts.
By leveraging advanced underwriting techniques and providing comprehensive risk management tools, Corvus aims to insure against cyber risks and actively works to prevent cyberattacks. This approach offers policyholders a robust defense against the ever-evolving landscape of digital threats, making Corvus Smart Cyber Insurance® a compelling choice for organizations seeking comprehensive cyber risk protection.
Corvus Insurance
Corvus Signal
Corvus Insurance
Corvus Signal – Risk Prevention
Corvus Signal: Cutting-Edge Cyber Risk Prevention
Corvus Signal is a comprehensive risk prevention solution designed to help organizations stay ahead of emerging cyber threats. This innovative platform, available at no cost to Corvus policyholders, has been proven to reduce the impact of cyber incidents by 20%.
Key Features and Benefits
Risk Insights
- Personalized threat monitoring and alerting
- Dark web monitoring for early threat detection
- Cyber alerts are delivered directly to your inbox
- Third-party risk reports for vendors and partners upon request
Risk Dashboard
- Centralized access to the latest advice and security recommendations
- Visibility and control over security priorities
- Enables focused efforts on the most critical risks
Vendor Marketplace
- Database of pre-vetted security vendors
- Discounts available for some vendors to Corvus policyholders
Advisory Services
- Partnership-based approach with personalized risk insights
- Access to Corvus’ in-house team of cybersecurity experts
- Guidance available via email, call, or through the Risk Dashboard
Impressive Statistics
- 20% lower frequency and cost of cyber breaches
- 15.5 days average head start before alerted vulnerabilities are exploited
- 3x faster patching, with cyber alerts, sent the same day as the discovery
- Only 12% of researched threats result in alerts, of which 82% are later exploited
Policyholder Journey
1. Introductory Call: Deep dive into policy benefits and IT environment
2. Cyber Advice: On-demand guidance from cyber experts
3. Optimized Spend: Investment recommendations and access to pre-vetted vendors
4. Renewal Prep: Proactive preparation for policy renewal
Corvus Black Services:
- Incident Response Plan Review with Corvus Experts
- Virtual Incident Response Tabletop exercise (two hours)
Corvus Signal offers a robust, data-driven approach to cyber risk prevention. Combining personalized insights, expert guidance, and cutting-edge technology empowers organizations to effectively prioritize their cybersecurity efforts and reduce their vulnerability to emerging threats.
Corvus Insurance
Smart Tech E&O
Corvus Insurance
Smart Tech E&O
Corvus Insurance offers Smart Tech E+O® policies, combining Travelers A++-rated paper with expert underwriting and comprehensive risk prevention solutions. These policies cater to a wide range of organizations, from SMEs to those with $2B in annual revenue.
Smart Tech E&O Features
- Broad Coverage: The policies provide extensive third-party liability coverage for technology services and products and miscellaneous professional liability exposures.
- Cyber Protection: Comprehensive first and third-party cyber liability coverage is included, along with full policy limits for cyber extortion, ransomware, system failure, and contingent business interruption.
- Additional Protections: The policies also cover cybercrime, social engineering, invoice manipulation, and media liability (both online and offline).
Risk Prevention Services
Corvus offers several risk prevention services to all policyholders:
- Personalized cyber threat alerts
- On-call guidance from cybersecurity experts
- Prioritized security recommendations via a Policyholder Risk Dashboard
- A Retention Reduction Endorsement, which can reduce the retention by 25% (up to $25K) for engaged policyholders
Excess Coverage
Corvus also provides follow-form excess coverage, which includes access to their Risk Prevention Services. These services have been shown to reduce the frequency and cost of cyber breaches by 20% for engaged policyholders.
Underwriting and Claims
Corvus emphasizes its hands-on partnership approach, with a team of experienced underwriters and an in-house claims team with decades of combined experience.
Appetite and Eligibility
Corvus targets primary and excess risks, earning up to $2B in gross annual revenue and offering limits of up to $5M. Eligible classes include IT consultants, data analytics firms, IT staffing firms, telecommunication service providers, software developers, digital advertising agencies, and other technology-related businesses.
About Corvus
Corvus Insurance, a wholly owned subsidiary of Travelers Insurance, aims to build a safer world through insurance products that help reduce cyber risk. It offers products in the U.S., the Middle East, Europe, Canada, and Australia. The company operates under various names, including Corvus Insurance Agency, LLC, Corvus Agency Limited, and Corvus Underwriting GmbH.
Corvus Insurance’s Smart Tech E+O® policies offer comprehensive coverage tailored to technology businesses. They combine robust cyber protection with proactive risk prevention services to create a more secure digital environment for policyholders.
Corvus Insurance
Policyholder Guide
Corvus Insurance
Policyholder Guide
Corvus Insurance provides an overview of its cyber risk management services and policy benefits for its policyholders. Now part of Travelers, Corvus positions itself as a partner in cyber risk management, offering a comprehensive approach to helping businesses face the ever-evolving threat landscape.
Features and Benefits
Continuous Monitoring: Corvus employs a non-intrusive scan that continuously monitors the policyholder’s IT environment while their team of cybersecurity experts observes the threat landscape.
Proactive Alerts: The company sends alerts with remediation directions whenever there’s an imminent risk to the business.
Expert Support: Corvus provides access to cybersecurity professionals throughout the policy term for guidance and to answer questions.
Claims Expertise: In the event of a cyber incident, Corvus offers seasoned claims experts who are well-versed in handling complex situations such as ransomware attacks and data breaches.
Risk Prevention Services
Corvus offers Risk Prevention Services at no additional cost during the policy term, which includes:
- Threat alerts with remediation directions
- Access to Corvus experts for guidance
- Estimated value of services reaching tens of thousands of dollars for many policyholders annually
Policy Benefits
- Potential for up to 25% reduction in policy retention through completion of a security questionnaire
- Continuous monitoring for new vulnerabilities and dark web activity
- Tailored alerts based on the organization’s IT infrastructure
- Risk quantification and cyber risk assessment
- Action Center with security recommendations
- Vendor Marketplace with vetted providers and discounted rates
Claims and Breach Response Process
Corvus outlines a six-step process for handling cyber incidents:
1. Discovery of the incident
2. Notification to Corvus
3. Collaboration with the Claims Team
4. Investigation initiation
5. Notification to individuals and regulators (if required)
6. Notification to Corvus of any subsequent lawsuits or investigations
Corvus Insurance offers a comprehensive cyber risk management solution that combines continuous monitoring, expert guidance, and robust claims support. Their services aim to help businesses navigate the complex cyber threat landscape and mitigate potential risks effectively.
Corvus Insurance
Manufacturing Industry
Corvus Insurance
Manufacturing Industry
Corvus Insurance is partnering with manufacturers to address the growing cyber risk in the sector. In 2022, manufacturing became the most targeted industry for ransomware attacks, with a staggering 1177% increase in attack frequency between Q1 2021 and Q1 2023. Despite this challenging landscape, Corvus offers comprehensive coverage with competitive terms and manufacturer-specific endorsements.
Target Markets and Coverage
Corvus caters to a wide range of manufacturing sub-classes, including:
- Food Manufacturing
- Apparel Manufacturing
- Contract Manufacturing
- Electronics Manufacturing
- Wood Product Manufacturing
- Metal Product Manufacturing
- Petroleum and Chemical Manufacturing
Corvus’s appetite extends to primary and excess risks, earning up to $5B in gross annual revenue and having limits of up to $10M.
Enhanced Coverage for Manufacturers
Corvus has developed specialized coverage enhancements tailored to the manufacturing industry:
Manufacturing Industry-Specific System Coverage
This extension covers computer systems and software commonly used in manufacturing, such as MES, CMMS, SCADA, and WMS.
Contingent Business Interruption Coverage
Contingent Business Interruption Coverage includes coverage for losses from stalled raw materials if physical suppliers encounter a cyber incident, in addition to traditional contingent BI coverage.
Alternative Production Run Costs
To mitigate contractual penalties and maintain client satisfaction, Corvus covers the expense of contractors to continue production while the insured’s systems are offline.
Invoice Manipulation Protection
Coverage extends beyond typical unauthorized access scenarios, including the value of products wrongfully shipped due to socially engineered invoice manipulation.
Utility Fraud Coverage
Utility Fraud Coverage protects against utility overages resulting from unauthorized and illegal use of an organization’s utility services or resources.
About Corvus Insurance
Corvus Insurance, a subsidiary of The Travelers Companies, Inc., is committed to building a safer world through insurance products that reduce cyber risk for policyholders. Their Smart Cyber Insurance and Smart Tech E+O products offer broad coverage, in-house claims handling, and risk prevention services. These services include threat alerts for policyholders and support from in-house cybersecurity experts.
Corvus operates in various regions, including the United States, the Middle East, Europe, Canada, and Australia. The company markets its products under different names in different regions: Corvus Insurance Agency, LLC in the U.S., Corvus Agency Limited for Corvus London Markets, and Corvus Underwriting GmbH for Corvus Germany.
By offering tailored solutions and comprehensive coverage, Corvus aims to address the unique cyber risks manufacturers face in today’s increasingly digital and interconnected industrial landscape.
Corvus Insurance
Manufacturing Examples
Corvus Insurance
Smart Cyber – Manufacturing Examples
Corvus Insurance provides an overview of cyber risks and insurance solutions for the manufacturing industry. It highlights the increasing vulnerability of manufacturing companies to cyber attacks and the importance of adequate cyber liability coverage.
Industry Vulnerability
The manufacturing industry has become a prime target for cyber attacks due to its valuable data, including credit card information and health records. The frequency of ransomware attacks on this sector increased by 1177% between Q1 2021 and Q1 2023.
Emerging Challenges
Manufacturing companies face new challenges, including:
- Increasing reliance on IoT products
- Shift towards automation
- Need for comprehensive cyber liability coverage
Cyber Claims Examples
Corvus presents three case studies illustrating common cyber threats:
1. Phishing Email Scam: An employee opened a phishing email, compromising the personal and financial information of 5,000 customers.
2. Payment Card Data Breach: A clothing manufacturer’s online ordering system was hacked, exposing 500,000 customers’ credit card information.
3. Computer Virus: A manufacturing plant’s server was infected with malware, causing a multi-day shutdown and significant revenue loss.
Smart Cyber and Cyber Excess Policy Highlights
Key Coverage Features:
- Protection against privacy law violations and resulting fines/penalties
- Coverage for third-party risk, including data breaches at vendor locations
- Risk prevention services and tailored threat alerts
- In-house claims handling and incident response support
Corvus emphasizes the critical need for manufacturing companies to reassess their cyber risk exposure and invest in comprehensive cyber insurance coverage to protect against the evolving threat landscape.
Corvus Insurance
Healthcare Industry
Corvus Insurance
Healthcare Industry
Corvus Insurance, a subsidiary of The Travelers Companies, Inc., offers specialized cyber insurance solutions for healthcare entities. It aims to combat cyber risks in the healthcare sector by providing comprehensive coverage and risk prevention services.
Corvus focuses on a wide range of healthcare sub-classes, including:
- Clinics and hospitals
- Health practitioners (physicians, dentists)
- Health departments and services
- Healthcare consultants
- Long-term care and assisted living facilities
- Medical laboratories and imaging centers
- Pharmacies and surgery centers
Coverage Details:
- Primary and excess cyber risks
- Limits up to $10 million
- No revenue cap for potential clients
Enhanced Coverage
Corvus offers several coverage enhancements tailored to the healthcare industry:
1. HIPAA Corrective Action Plan: Covers costs for recertifying HIPAA compliance and implementing corrective action plans.
2. Expanded Definition of Computer Systems: Includes healthcare-specific systems such as:
– Internet-connected medical equipment
– Electronic Medical Record (EMR) systems
– Patient Customer Resource Management (CRM)
– Picture Archiving and Communication System (PACS)
3. Preventive Shutdown: Extends Business Interruption and Contingent Business Interruption coverage to situations where systems must be shut down to mitigate damage from computer crimes or attacks.
4. Outsourced Service Providers: Expands coverage to include Electronic Health Record (EHR) systems providers.
Corvus Insurance Overview
- Offers Smart Cyber Insurance and Smart Tech E+O products
- Provides broad coverage, in-house claims handling, and risk prevention services
- Operates in the U.S., Middle East, Europe, Canada, and Australia
- Utilizes marketing names: Corvus Insurance, Corvus London Markets, and Corvus Germany
Corvus Insurance aims to build a safer world through insurance products that help reduce cyber risk for policyholders. Their approach includes threat alerts and partnerships with in-house cybersecurity experts to prevent cyberattacks.
Additional Information
- Policy eligibility is determined during the application process
- Quotes, terms, conditions, and premiums adhere to Corvus Insurance’s underwriting guidelines
- The actual policy contract supersedes any general descriptions or informational material
- Coverage may not be available in all jurisdictions
Corvus provides an overview of its cyber insurance offerings for the healthcare sector, highlighting its specialized coverage enhancements and commitment to reducing cyber risks in this critical industry.
Corvus Insurance
Healthcare Examples
Corvus Insurance
Smart Cyber – Healthcare Examples
Corvus Insurance provides an overview of cyber risks and insurance solutions for the healthcare industry. It highlights the increasing frequency of ransomware attacks on healthcare entities and emphasizes the importance of adequate cyber liability coverage and risk management practices.
Cyber Threats in Healthcare
Healthcare is a highly targeted industry due to the sensitivity of Protected Health Information (PHI) and critical IT systems.
Ransomware attacks on healthcare entities increased by 141.66% between Q1 2021 and Q1 2023.
Q2 2023 saw ransomware rates 48% higher than any other quarter in the past two years.
Cyber Claims Examples
Corvus presents three scenarios illustrating common cyber risks in healthcare:
1. Phishing Email Scam: A medical group’s network was compromised through a phishing email, exposing PHI and resulting in HIPAA violations.
2. Vendor Exposure: An assisted living facility faced the consequences when its third-party medical billing vendor suffered a data breach, affecting 30,000 patients’ PII and PHI.
3. Lost Paper Records: An ambulatory surgical center left 10,000 patient medical files unattended, leading to potential HIPAA violations and negative publicity.
Smart Cyber and Cyber Excess Policy Highlights
- Coverage for ransomware remediation
- Coverage for privacy laws and fines/penalties
- Risk prevention services
- In-house claims handling
Given the increasing frequency and severity of cyber-attacks, Corvus emphasizes the critical need for cyber insurance in the healthcare sector. It showcases Corvus Insurance’s offerings, including Smart Cyber Insurance® and Smart Tech E+O®, which aim to reduce risk, increase transparency, and improve healthcare policyholders’ resilience.
Corvus Insurance
Financial Services Industry
Corvus Insurance
Financial Services Industry
Corvus Insurance is partnering with financial services organizations to address cyber risk challenges in the industry. Corvus highlights the increasing threat of cyber attacks, particularly ransomware, which saw a 231% rise in frequency from Q4 2022 to Q2 2023 in the financial sector.
Target Market
Corvus aims to serve various financial services sub-classes, including:
- Financial & Investment Advisors
- Wealth Managers
- Banks and Credit Unions
- Insurance-related entities (Carriers, MGUs, MGAs, Agents & Brokers)
- Investment firms (Mutual and Hedge Funds, Real Estate Investment & Private Equity)
- Financing and Lending Institutions
Appetite and Coverage
- Offers primary and excess cyber risks
- Provides limits up to $10M
- No revenue cap for potential clients
Coverage Enhancements
1. Payment Card Reissuance Costs: Covers expenses related to reissuing credit and debit cards following a cyber event.
2. Client Payment Fraud: Expands cyber crime coverage to include losses incurred by the insured’s clients or customers due to third-party deception. This coverage is not available for banks, credit unions, or mortgage lenders.
3. Financial Services Specific System Coverage: Extends protection to various computer systems and software commonly used in the financial industry, such as:
- Trade management and execution platforms
- Money management platforms
- Proprietary trading platforms
- Business intelligence software
- Bookkeeping software
- Payment gateways
- Tax management software
- Financial planning software
4. Financial Fraud Intermediary: Expands financial fraud coverage to include an Intermediary, either an Insured Representative or Seller Representative.
About Corvus Insurance
Corvus Insurance, a subsidiary of The Travelers Companies, Inc., focuses on creating a safer world through insurance products that help reduce cyber risk for policyholders. Their offerings include:
- Smart Cyber Insurance
- Smart Tech E+O products
These products feature broad coverage, in-house claims handling, and risk prevention services. Corvus provides threat alerts and partners with in-house cybersecurity experts to help prevent cyberattacks.
Corvus Insurance
Financial Services Examples
Corvus Insurance
Smart Cyber – Financial Services Examples
Corvus Insurance provides an overview of cyber risks and insurance solutions for the financial services industry.
Cyber Threats in Financial Services
Financial data is highly valuable to cybercriminals due to the personal information connected to customer accounts. Recent trends show a 231% increase in ransomware attacks on the financial sector from Q4 2022 to Q2 2023.
Cyber Claims Examples
1. Posting Information Online: A bank discovered customer personal information posted online, potentially exposing the names, Social Security numbers, and birth dates of some customers.
2. Distributed Denial-of-Service (DDoS) Attack: Hackers used a DDoS attack as a smokescreen to infiltrate a bank’s network, shutting down online banking for three days and exposing customer data.
3. Hacker Event: A bank’s computer system was hacked, compromising records containing personal information and customer messages with potentially confidential data.
#Smart Cyber and Cyber Excess Policy Highlights
- Coverage for Privacy Laws & Fines/Penalties: Protects against fines from non-compliance with privacy laws.
Coverage for Third-Party Risk: Covers breaches regardless of where data is stored or who caused the compromise.
Risk Prevention Services: Offers tailored threat alerts and partnerships with cyber experts.
In-house Claims Handling: Provides support throughout the breach response process.
Risk Management Solution
Financial institutions are advised to carry cyber liability insurance covering first—and third-party risks, including ransomware and social engineering attacks. In the event of a breach, companies may need to hire public relations firms, forensic service providers, and cyber breach coaches and cover expenses for customer notification and identity restoration services.
Corvus Insurance
Construction Industry
Corvus Insurance
Construction Industry
Corvus Insurance is partnering with the construction industry to address this sector’s growing cyber risks. The industry responsible for critical infrastructure is increasingly targeted by cyber threats, with ransomware attacks against it rising by 48% from 2022 to 2023. In response, Corvus is offering comprehensive cyber insurance solutions tailored to the unique needs of construction businesses.
Appetite:
- Primary and excess risks for companies with up to $5B in gross annual revenue
- Coverage limits up to $10M
Coverage Enhancements:
1. Property Damage Claims
- First and third-party coverage for damages arising from hacking attacks
- Up to $1M limit available
2. Bodily Injury Claims
- Third-party coverage for injuries resulting from security or privacy breaches
- Up to $1M limit available
3. Missed Bid Coverage
- Business income loss coverage for missed bids or RFPs due to system interruptions
4. Contractual Credits and Penalties
- Coverage for service credits or penalties imposed due to hacking-related failures
Additional Enhancements:
- Regulatory and Preventive Shutdown Coverage
- Vicarious Liability Coverage for property owners
- Protection against independent contractors’ failure to prevent malicious code transmission
- Expanded definition of Computer Systems to include drones, Building Information Management Software, and SCADA systems
About Corvus Insurance
Corvus Insurance, a subsidiary of The Travelers Companies, Inc., focuses on creating a safer world through insurance products that reduce cyber risk for policyholders. Their offerings include:
- Smart Cyber Insurance
- Smart Tech E+O products
These products feature broad coverage, in-house claims handling, and risk prevention services. Corvus provides threat alerts and partners with in-house cybersecurity experts to help prevent cyberattacks.
Corvus Insurance
Construction Examples
Corvus Insurance
Smart Cyber – Construction Examples
Corvus Insurance provides an overview of cybersecurity risks and insurance solutions for the construction industry. It highlights the increasing vulnerability of construction businesses to cyber threats due to the adoption of web-connected tools.
Cyber Threat Landscape
- Ransomware attacks in the construction industry increased 48% from 2022 to 2023.
- 80% of industry respondents in 2024 believe proper cybersecurity controls are critical.
Risk Management Solution
Cyber liability coverage and proactive risk management practices are now essential for construction companies. This includes insurance to cover cyberattack costs, such as ransomware and social engineering attacks.
Cyber Claims Examples
1. Phishing Email Scam: A large construction firm lost approximately $2,000,000 due to a fraudulent email impersonating a supplier’s billing representative. Corvus assisted in recovering most of the stolen funds.
2. Vendor Data Breach: A construction management firm suffered a data breach exposing subcontractors’ payment and personal information. The breach resulted in significant costs for legal fees, compliance requirements, and security infrastructure upgrades.
3. Ransomware Attack: A construction management company faced a $60,000 ransomware demand and incurred $100,000 in lost productivity, totaling $160,000 in losses.
Smart Cyber and Cyber Excess Policy Highlights
- Missed Bid Coverage: Expanded coverage for missed bids or RFPs due to system interruptions.
- Third-Party Risk Coverage: Responds to breaches regardless of where the data resides.
- Risk Prevention Services: Offers tailored threat alerts and partnerships with in-house cyber experts.
- In-house Claims Handling: Provides support throughout the entire breach response process.
Corvus emphasizes the importance of cyber insurance and risk management in the construction industry, highlighting the evolving threat landscape and providing practical examples of cyber incidents. It also outlines key features of Corvus’ Smart Cyber Insurance products and services designed to address these risks.
Corvus Insurance
2024 Q2 Cyber Threat Report
Corvus Insurance
Cyber Threat Report Q2 2024
The Q2 2024 Cyber Threat Report by Corvus Insurance highlights a significant increase in ransomware activity, setting new records for the year’s first half.
Ransomware Activity
Ransomware attacks reached unprecedented levels in Q2 2024, with 1,248 victims posted on leak sites. This represents a 16% increase from Q1 and an 8% year-over-year rise. The report suggests that ransomware activity may continue to escalate later in the year, potentially reaching new highs.
Ransomware Groups
LockBit, a major ransomware group, experienced a resurgence in May after facing law enforcement actions earlier in the year. However, their overall activity remains lower than pre-intervention levels. New groups like PLAY, Medusa, RansomHub, INC Ransom, and Blacksuit emerged to fill the void left by declining groups.
Ransom Demands and Payments
Q2 saw a significant ransom demand increase, reaching a nearly two-year high. Average ransom payments even exceeded the peaks observed in 2022. Organizations with robust backup strategies were 2.38 times less likely to pay ransoms and experienced 72% lower median claim costs.
Evolving Tactics
Ransomware operators have adapted their strategies, with 93% of incidents in 2024 involving data theft in addition to encryption. This “double-extortion” tactic pressures even well-prepared organizations to consider ransom payments.
Industry Impacts
Construction, manufacturing, and professional services were the most frequently targeted industries in Q2. The IT Services and Software Development sectors saw notable increases in ransomware incidents, raising concerns about potential systemic risks.
In Summary
Corvus emphasizes the need for organizations to implement robust, multi-layered security strategies to combat the evolving ransomware threat. It highlights the importance of proactive measures, including effective backup strategies and heightened vigilance, especially in high-risk sectors like IT services.
Corvus Insurance
2024 Q3 Cyber Threat Report
Corvus Insurance
Cyber Threat Report Q3 2024
The Q3 2024 Cyber Threat Report by Corvus Insurance highlights the evolving landscape of ransomware attacks and cybersecurity trends.
Ransomware Activity
- Ransomware attacks remained elevated in Q3 2024, slightly increasing to 1,257 victims posted on leak sites, up 0.7% from Q2.
- The ransomware ecosystem has become increasingly distributed, with 59 active groups, reflecting a more complex and competitive threat landscape.
- The Gini coefficient, measuring the distribution of attacks among groups, has been decreasing since late 2023, indicating a more even spread of activity.
Prominent Ransomware Groups
- RansomHub emerged as the most active group, with a 160% increase in victims compared to Q2, totaling 195 reported victims.
- PLAY maintained a strong presence with 93 victims, while LockBit 3.0’s activity decreased sharply from 208 to 91 victims.
- Medusa and Akira continued to impact the landscape, with 40-50 victims each.
Industry Targeting
- Construction remained the most targeted sector, with 83 victims, a 7.8% increase from Q2.
- Healthcare saw a 12.8% increase in attacks, with 53 victims in Q3.
- IT Services experienced a slight decline, with 49 victims compared to 54 in Q2.
Attack Vectors and Vulnerabilities
- VPNs were increasingly used for initial attack access, contributing to 28.7% of ransomware claims.
- Many incidents were traced to outdated software or VPN gateways with weak or default credentials.
- Approximately 75% of policyholders either did not use multi-factor authentication (MFA), implemented it partially, or had undetermined coverage.
Emerging Threats
- RansomHub, a new ransomware-as-a-service operation started in February 2024, has rapidly become one of the most prolific groups, claiming over 290 victims across various sectors.
- The group employs a double-extortion model and uses advanced tools like EDRKillShifter to evade detection.
Corvus emphasizes the persistently high level of ransomware activity, the increasing competitiveness of the ransomware ecosystem, and the continued targeting of vulnerable sectors. It highlights the importance of strengthening defenses, particularly in high-risk industries and addressing common vulnerabilities such as weak VPN credentials and lack of MFA.
Corvus Insurance
Unpatched Software
Corvus Insurance
Unpatched Software
The Case of the Unpatched Environment: A Cyber Insurance Success Story
Corvus Insurance details a case study involving Corvus, a cyber insurance provider, and their approach to assessing and mitigating cybersecurity risks for a national retail franchise seeking coverage.
Background
A national retail franchise approached Corvus for cyber coverage after receiving an exorbitant renewal premium from their current carrier. Despite being loss-free for several years, the client faced challenges in the hard market for cyber insurance.
The Corvus Scan Discovery
Corvus utilized its proprietary scanning technology to assess the client’s IT infrastructure. The scan revealed unpatched servers vulnerable to the Microsoft Exchange Server vulnerability, contradicting the client’s belief that their systems were fully updated.
Investigating the Discrepancy
- Initial Confusion: The client and their Managed Service Provider (MSP) were confident that all necessary patches had been applied.
- Deep Dive Analysis: Corvus’s Data Science team conducted a thorough investigation, pinpointing the exact issues and their locations.
- Root Cause: The investigation uncovered a miscommunication between the MSP and the client, compounded by an oversight in the system architecture.
The Underlying Issue
The problem stemmed from the client’s load balancer, routing traffic to multiple servers. While one server had been patched, others were overlooked due to a lack of comprehensive verification across all potential traffic destinations.
Resolution and Outcome
1. Vulnerability Patching: Once identified, the client and MSP patched the overlooked Microsoft Exchange servers promptly.
2. Improved Security Posture: The process revealed and addressed critical vulnerabilities, enhancing the client’s overall cybersecurity.
3. Successful Coverage: With the vulnerabilities addressed, Corvus was able to offer a competitive quote and bind the account.
Key Takeaways
1. Data-Driven Approach: The case demonstrates the value of using data-driven tools to verify cybersecurity measures.
2. Collaboration: Effective communication between the insurer, client, and MSP was crucial in resolving the issue.
3. Holistic Security: The incident highlighted the importance of comprehensive security checks, especially in complex network architectures.
4. Risk Management: Corvus’s approach provided insurance coverage and actively improved the client’s security posture.
Corvus illustrates its commitment to not just providing cyber insurance but also actively contributing to improving its clients’ cybersecurity. By identifying and addressing overlooked vulnerabilities, Corvus demonstrated the value of its data-driven approach in the current cyber insurance market.
Corvus Insurance
Incident Response
Corvus Insurance
Incident Response
Corvus Insurance provides a comprehensive guide on effectively working with a cyber insurer during an incident response. It outlines five key stages and offers practical tips for maximizing the partnership between an organization and its cyber insurance provider.
Stage 1: Before the Incident
The first step is incorporating your cyber insurer into your Incident Response Plan (IRP). This involves:
- Documenting who will contact the insurer, when to do so, and how
- Ensuring offline access to contact information
- Socializing the updated IRP among relevant staff
- Conducting response drills
Stage 2: Discovery of an Incident
When an incident is discovered, it’s crucial to notify your insurer promptly, even if it seems minor. The document emphasizes:
- Following the IRP instructions for contacting the carrier
- Not hesitating to reach out, as situations can escalate quickly
- Using secure communication methods if systems are compromised
Stage 3: Working with Your Insurer’s Team and Vendors
Once notified, your insurer will:
- Gather initial information about the incident
- Provide guidance on the next steps
- Help connect you with necessary vendors, such as:
- Legal counsel (breach coach)
- Digital forensics firm
These specialists will assist in protecting the investigation, navigating privacy laws, and determining the incident’s technical aspects.
Stage 4: Notifying Individuals and Regulatory Compliance
In this stage, the focus shifts to:
- Determining notification requirements with legal counsel
- Drafting appropriate communication for affected individuals
- Engaging notification and call center services if needed
- Offering credit monitoring services when necessary
- Ensuring compliance with varying state and local data breach laws
Stage 5: Aftermath and Reflection
The final stage involves:
- Conducting a post-incident review to identify areas for improvement
- Implementing a security roadmap based on lessons learned
- Preparing for potential regulatory investigations or lawsuits
- Demonstrating compliance and adequate preparation for regulators
Throughout the document, the importance of prompt communication with the insurer, adherence to the IRP, and leveraging the expertise of specialized vendors is consistently emphasized. The guide aims to help organizations navigate the complex incident response process while maximizing the benefits of their cyber insurance partnership.
Corvus Insurance
Multi-Factor Authentication
Corvus Insurance
Multi-Factor Authentication
Corvus Insurance provides a comprehensive overview of Multi-factor Authentication (MFA) and its importance in cybersecurity.
What is MFA?
MFA is an authentication method that requires users to provide two or more credentials to access an account.
These credentials can include:
- Something you know (e.g., password, PIN)
- Something you have (e.g., smartphone, debit card)
- Something you are (e.g., biometric data like facial recognition)
Importance in Cybersecurity
MFA is crucial for cybersecurity because:
- 81% of data breaches in recent years are attributed to password compromises
- It adds an additional layer of security beyond a single password
- It helps protect against unauthorized access, data breaches, and password-based cyber-attacks
Implementation
MFA should be implemented across:
- All remote access points (email, VPN, etc.)
- Cloud and on-premises applications
- Applications containing personally identifiable information (PII)
- Internal activity with privileged users
Strength of Different Factors
Not all MFA methods are equally secure:
- SMS-based authentication is considered less secure
- The US government stopped using SMS authentication in 2016
- MFA apps like Duo, Google Authenticator, or Microsoft Authenticator are recommended for smartphone-based MFA
Limitations of MFA
While important, MFA is not a complete security solution:
- It may not prevent malware spread if a personal computer is already compromised
- Additional external defenses are necessary for further risk mitigation
Implementation Process
The MFA roll-out process varies depending on factors such as:
- Organization size
- Email provider and technology platforms in use
- Introduction strategy to employees
It is recommended that implementation be prioritized based on risk level, starting with administrative and high-risk accounts.
Cost Considerations
MFA is generally an affordable security option:
- There are no additional costs for implementation through Microsoft O365 and Google Workspace
- The overall cost depends on the organization’s specific needs and existing infrastructure
Getting Started
For organizations seeking assistance with MFA implementation, Corvus offers vCISO Services, which include:
- A free, no-risk consultation call
- Exclusive discounted rates for further services
- Access to blue-chip vendors for hands-on help
MFA is critical to modern cybersecurity strategies, offering enhanced protection against unauthorized access and data breaches. While not infallible, its implementation across an organization’s systems can significantly reduce the risk of security incidents.
Corvus Insurance
Vendor Data Breach Response
Corvus Insurance
Responding to a Vendor Breach
Corvus Insurance provides comprehensive guidance for organizations dealing with data breaches at their vendors. Corvus highlights the increasing reliance on managed service providers and cloud-based solutions while warning against the assumption that these vendors are inherently secure.
Vendor Breach Risks
Attacks on IT Managed Service Providers increased by 185% in 2019
44% of companies reported experiencing a vendor-caused breach
Large vendors are attractive targets for criminals due to potential access to multiple organizations
Initial Response Steps
1. Remain calm and follow the incident response plan
2. Secure the organization’s environment
3. Notify the broker and cyber liability carrier
4. Retain experienced privacy counsel
5. Review the vendor contract for relevant provisions
Legal and Regulatory Considerations
- Various laws and regulations may apply based on data type and location
- Examples include state-specific laws, HIPAA, FERPA, NY DFS, GLBA, GDPR, and PIPEDA
- Each regulation has unique notification requirements and timelines
Information to Obtain from the Vendor
- Access to forensic reports or summaries
- Details about ransomware variants and containment measures
- Scope of compromised data and affected individuals
- Vendor’s plans for notification and associated costs
- Number of impacted customers
- Vendor’s cyber insurance status
- Plans for future security enhancements
Challenges in Vendor Breach Response
- Lack of control over the investigation and its pace
- Limited access to forensic findings and facts
- Potential delays in notification timelines
- Unfavorable contract terms regarding liability and indemnity
- Inconsistent approaches among affected organizations
Ideal Vendor Response
- Transparency in forensic investigation and findings
- Hiring experienced counsel and forensics experts
- Precise identification of compromised data
- Offer to handle notifications and provide support services
- Adequate assurances of containment and future prevention
Corvus emphasizes the importance of preparedness, clear communication with vendors, and understanding legal obligations in the event of a vendor data breach. It is a valuable resource in navigating the complexities of third-party cyber incidents.
Corvus Insurance
Coverage Overview
Corvus Insurance
Coverage Overview
Corvus Insurance provides an overview of Smart Cyber Insurance, detailing a comprehensive range of coverages designed to protect businesses from cyber-related risks and incidents. The policy is structured into three main categories: Third-Party Coverages, First-Party Coverages, and Additional Coverage Enhancements.
1. Third-Party Coverages
This section outlines protections for claims made against the insured:
- Network Security and Privacy Claims: Coverage for incidents such as denial of service attacks, malicious code, stolen laptops, or data breaches.
- Regulatory Investigations, Fines, and Penalties: Protection against civil fines and penalties imposed by governmental agencies due to privacy regulation breaches.
- Media Liability Claims: Coverage for claims arising from the release or display of media material, including copyright infringement, slander, libel, and defamation.
- PCI DSS Assessment Expenses: Coverage for costs related to non-compliance with Payment Card Industry Data Security Standards.
- Breach Management Expenses: Protection for breach response costs for which the insured has contractually indemnified a third party.
2. First-Party Coverages
This section covers direct losses and expenses incurred by the insured:
- Business Interruption: Compensation for business income loss and extra expenses during network outages.
- Contingent Business Interruption: Coverage for losses due to network outages at outsourced service providers.
- Digital Asset Destruction, Data Retrieval, and System Restoration: Protection for digital asset loss and related expenses resulting from security breaches, privacy breaches, or administrative errors.
- System Failure Coverage: Coverage for losses due to unintentional or unplanned outages.
- Social Engineering & Cyber Crime Coverage: Protection against financial fraud, phishing attacks, and telecommunications fraud.
- Reputational Loss Coverage: Compensation for business income loss related to media reports arising from privacy breaches, cyber extortion threats, or phishing attacks.
- Cyber Extortion and Ransomware Coverage: Coverage for expenses or payments to respond to cyber extortion demands or ransomware attacks.
- Breach Response and Remediation Expenses: Coverage for expenses related to data breach incidents, including legal services, forensics investigation, notification, credit monitoring, and public relations.
- Court Attendance Costs: Compensation for expenses incurred to attend court, adjudication, mediation, or other hearings related to covered claims.
3. Additional Coverage Enhancements
The policy offers several optional enhancements:
- Bricking Coverage
- Forensic Accounting Coverage
- Criminal Reward Expenses
- Invoice Manipulation
- Bodily Injury
- Preventative Shutdown
Each Corvus Smart Cyber Insurance policy includes a Dynamic Loss Prevention Report, which provides a detailed analysis of the client’s cybersecurity profile and risk-prioritized recommendations for addressing IT vulnerabilities. This comprehensive coverage aims to protect businesses from a wide array of cyber threats and their potential financial impacts.
Strengthen Your Digital Defense Strategy Today
Learn More about Corvus Coverage & Pricing
No Spam. Promise!
Corvus Insurance | Smart Cyber
Corvus Insurance is a specialized cyber insurance provider offering innovative cyber risk management solutions. As a subsidiary of Travelers Insurance, Corvus combines market-leading innovation with proven financial stability. The company’s core products, Smart Cyber Insurance® and Smart Tech E+O® are designed to address the complex and evolving landscape of cyber threats businesses face today.
What sets Corvus Insurance apart is its data-driven approach to cyber insurance. The company leverages proprietary intelligence, which includes millions of data points from claims, public web sources, and the latest cyber threat intel, to provide more accurate risk assessments. This approach enables Corvus to offer policyholders tailored coverage, real-time threat monitoring, and personalized alerts. Additionally, Corvus provides a comprehensive risk management platform called the Corvus Risk Dashboard, which gives policyholders visibility into their security posture, emerging threats, and cybersecurity recommendations. The company also stands out for its collaborative underwriting process, on-demand risk advisory services, and 24/7 incident response support, all of which contribute to a more holistic approach to cyber risk management.
What is Cyber Insurance
Cyber insurance is a specialized insurance product designed to protect businesses against the financial losses and disruptions that can arise from cyber-related incidents, such as data breaches, ransomware attacks, and other cyber threats. This type of insurance typically covers costs related to data recovery, legal fees, notification of affected parties, regulatory fines, and business interruption losses. Businesses need cyber insurance to mitigate the financial impact of cyber-attacks, ensuring they can quickly recover and continue operations while minimizing the potential damage to their reputation and customer trust.
What does cyber insurance cover?
Cyber insurance typically covers costs related to data breaches, including data recovery, legal fees, notification of affected parties, and regulatory fines. It may also cover business interruption losses and expenses related to restoring business operations.
Why is cyber insurance important for SMBs?
Small businesses, often with potentially weaker security measures, are prime targets for cyber attacks. Cyber insurance is a crucial tool in managing the financial burden of such attacks, ensuring they can recover quickly and sustain minimal operational disruption.
How is the cost of cyber insurance determined?
Factors such as the size of the business, the industry, the amount and type of data handled, and the company’s existing cybersecurity measures influence the cost of cyber insurance. Higher-risk businesses or those with poor security practices may face higher premiums.
What are the exclusions in a cyber insurance policy?
Standard exclusions in cyber insurance policies include claims related to pre-existing breaches, acts of war or terrorism, and the failure to maintain minimum security standards. It’s essential for businesses to review policy details to understand specific exclusions and limitations.