SlideShare a Scribd company logo
Loopholes and
Vulnerabilities in Data
Security
Are you ready to accept your cyber
liability?
Laird Rixford / @lrixford
President
My Previous Job
Network nerd
Trusted Advisor
What do you have to lose?
Sorry to Scare You…
• In case of a security breach you could be
• Subject to $1,000 to $100,000 per incident
• Qualify each piece of breached data as a separate
incident
• Required to notify individuals and media of
breach
• Required to provide monitoring or
remuneration to affected parties
• Applies to all agents. Not just health.
What is Your Data Worth?
• Financial data is $5/record
• Health data is worth $50/record
• Identity theft data is worth $188/record
Security and Confidentiality
Laws
• Health Insurance Portability and Accountability
Act (HIPAA)
• Health Information Technology for Economic
and Clinical Health (HITECH)
• Payment Card Industry Data Security Standard
(PCI DSS)
• Sarbanes–Oxley Act of 2002 (SOX)
• Gramm–Leach–Bliley Act (GLBA)
• State and Federal Laws
• Cyber Liability, Professional Liability, Errors and
Omissions Policies
• Carrier Contracts
What is Considered PII?
• Name
• Address
• Birthday
• Social security number
• Drivers license number
• Financial information
• Email
• Health information
Ease of Access = Less
Security
More difficult to access, more security
Points of Entry
• Physical
• Technology infrastructure
• Remote access
• Phone system
• Cloud and vendor products and services
• Employees
Mitigating the Threat
Mitigate, not prevent
Physical Access
Physical access is full access
Physical Access
• Limit access to critical areas
• Anywhere with a computer or access to
security infrastructure is critical
• Secure servers in a locked cabinet
• Security cameras
• Security system
• Even alarm inner doors during business hours
Technology
Infrastructure
An easy target
Technology Infrastructure
• New machines are cheap
• Update and patch
• Operating systems
• Software
• Firewalls
• Run supported software
• Encrypt mobile devices
• Use high security Wi-Fi (WPA2-PSK or Enterprise
RADIUS)
• System policies
• Disable USB storage
• Force password change
• Force screen saver lock
• Install prevention
Remote Access
Remote Desktop, Thermostats, VPN, Oh MY!
Remote Access
• Do you or your employees really need it?
• How often do you use it?
• Turn it on only when you need it
• Use two-factor authentication
• DUO
• RSA Key
Phone System
The oldest hack
Phone System
• Prevent remote access
• Change password often
• Enable remote extensions only as needed
Cloud & Vendor
Services
Their security is your security
Cloud & Vendor Services
• Request security audit results
• Use offerings meant to increase security
• Change password
• Two-factor authentication
• Remove unused users
• Leave vendors who do not comply
• Ask for Business Associate Agreement
Employees
The best hack
Employees
• Users do not like security
• Train users as to importance of security and
how to recognize social engineering
• Security begins and end with them; include
them in the conversation
Security Costs Money,
A Hack Costs More
You are a target. Act accordingly.
More Security = Less
Threat
The harder you make it, the less you are a target.
Suggestions
• Create a security program
• Longer passwords are better
• Change passwords often
• Use authentication that changes
• Hire an IT professional to secure your
network
• Keep all software patched and up to date
• Lower your attack profile
• Encrypt everything
Cyberliability Policy
• Do you need one?
• What coverage should you get?
Thank You
Don’t forget to fill out your surveys!
Laird Rixford / @lrixford
President

More Related Content

More from Insurance Technologies Corporation (ITC)

SEO in 2019...and Beyond!
SEO in 2019...and Beyond!SEO in 2019...and Beyond!
SEO in 2019...and Beyond!
Insurance Technologies Corporation (ITC)
 
Email Service Quirks and How to Get Around Them
Email Service Quirks and How to Get Around ThemEmail Service Quirks and How to Get Around Them
Email Service Quirks and How to Get Around Them
Insurance Technologies Corporation (ITC)
 
ITC AgencyBuzz
ITC AgencyBuzzITC AgencyBuzz
Answering Your Top 10 FAQs About Insurance Website Design
Answering Your Top 10 FAQs About Insurance Website DesignAnswering Your Top 10 FAQs About Insurance Website Design
Answering Your Top 10 FAQs About Insurance Website Design
Insurance Technologies Corporation (ITC)
 
How to Write the Perfect Insurance Email
How to Write the Perfect Insurance EmailHow to Write the Perfect Insurance Email
How to Write the Perfect Insurance Email
Insurance Technologies Corporation (ITC)
 
Blogging Your Way to Local SEO Success
Blogging Your Way to Local SEO SuccessBlogging Your Way to Local SEO Success
Blogging Your Way to Local SEO Success
Insurance Technologies Corporation (ITC)
 
Common Misconceptions About Email Marketing
Common Misconceptions About Email MarketingCommon Misconceptions About Email Marketing
Common Misconceptions About Email Marketing
Insurance Technologies Corporation (ITC)
 
Search Marketing For The Short And Long Term
Search Marketing For The Short And Long TermSearch Marketing For The Short And Long Term
Search Marketing For The Short And Long Term
Insurance Technologies Corporation (ITC)
 
Using the 5 Ws to Create a Successful Email Marketing Strategy
Using the 5 Ws to Create a Successful Email Marketing StrategyUsing the 5 Ws to Create a Successful Email Marketing Strategy
Using the 5 Ws to Create a Successful Email Marketing Strategy
Insurance Technologies Corporation (ITC)
 
Crawl, Walk, Run: Using Your Agency’s Branding to Reach Online Prospects
Crawl, Walk, Run: Using Your Agency’s Branding to Reach Online Prospects Crawl, Walk, Run: Using Your Agency’s Branding to Reach Online Prospects
Crawl, Walk, Run: Using Your Agency’s Branding to Reach Online Prospects
Insurance Technologies Corporation (ITC)
 
All Sky, No Net: How Agencies Can Survive Automation
All Sky, No Net: How Agencies Can Survive AutomationAll Sky, No Net: How Agencies Can Survive Automation
All Sky, No Net: How Agencies Can Survive Automation
Insurance Technologies Corporation (ITC)
 
How to Turn Your Website into a Lead Generator
How to Turn Your Website into a Lead GeneratorHow to Turn Your Website into a Lead Generator
How to Turn Your Website into a Lead Generator
Insurance Technologies Corporation (ITC)
 
10 Email Marketing Feaux Pas You're Probably Making
10 Email Marketing Feaux Pas You're Probably Making10 Email Marketing Feaux Pas You're Probably Making
10 Email Marketing Feaux Pas You're Probably Making
Insurance Technologies Corporation (ITC)
 
Think Like a Marketer: Marketing Ideation for Insurance Agents
Think Like a Marketer: Marketing Ideation for Insurance AgentsThink Like a Marketer: Marketing Ideation for Insurance Agents
Think Like a Marketer: Marketing Ideation for Insurance Agents
Insurance Technologies Corporation (ITC)
 
How Do You Know if Your Website Needs to be Updated?
How Do You Know if Your Website Needs to be Updated?How Do You Know if Your Website Needs to be Updated?
How Do You Know if Your Website Needs to be Updated?
Insurance Technologies Corporation (ITC)
 
Email Marketing: The Agency Newsletter and Beyond
Email Marketing: The Agency Newsletter and BeyondEmail Marketing: The Agency Newsletter and Beyond
Email Marketing: The Agency Newsletter and Beyond
Insurance Technologies Corporation (ITC)
 
Are You Missing the Mark? Email Marketing Opportunities You May Be Missing Ou...
Are You Missing the Mark? Email Marketing Opportunities You May Be Missing Ou...Are You Missing the Mark? Email Marketing Opportunities You May Be Missing Ou...
Are You Missing the Mark? Email Marketing Opportunities You May Be Missing Ou...
Insurance Technologies Corporation (ITC)
 
Band For Your Buck: Underused Features of Your Insurance Website
Band For Your Buck: Underused Features of Your Insurance WebsiteBand For Your Buck: Underused Features of Your Insurance Website
Band For Your Buck: Underused Features of Your Insurance Website
Insurance Technologies Corporation (ITC)
 
Ask Me Anything: Bob Ingram of Peachstate Insurance
Ask Me Anything: Bob Ingram of Peachstate InsuranceAsk Me Anything: Bob Ingram of Peachstate Insurance
Ask Me Anything: Bob Ingram of Peachstate Insurance
Insurance Technologies Corporation (ITC)
 
The Bare Necessities: Your Homepage Checklist
The Bare Necessities: Your Homepage ChecklistThe Bare Necessities: Your Homepage Checklist
The Bare Necessities: Your Homepage Checklist
Insurance Technologies Corporation (ITC)
 

More from Insurance Technologies Corporation (ITC) (20)

SEO in 2019...and Beyond!
SEO in 2019...and Beyond!SEO in 2019...and Beyond!
SEO in 2019...and Beyond!
 
Email Service Quirks and How to Get Around Them
Email Service Quirks and How to Get Around ThemEmail Service Quirks and How to Get Around Them
Email Service Quirks and How to Get Around Them
 
ITC AgencyBuzz
ITC AgencyBuzzITC AgencyBuzz
ITC AgencyBuzz
 
Answering Your Top 10 FAQs About Insurance Website Design
Answering Your Top 10 FAQs About Insurance Website DesignAnswering Your Top 10 FAQs About Insurance Website Design
Answering Your Top 10 FAQs About Insurance Website Design
 
How to Write the Perfect Insurance Email
How to Write the Perfect Insurance EmailHow to Write the Perfect Insurance Email
How to Write the Perfect Insurance Email
 
Blogging Your Way to Local SEO Success
Blogging Your Way to Local SEO SuccessBlogging Your Way to Local SEO Success
Blogging Your Way to Local SEO Success
 
Common Misconceptions About Email Marketing
Common Misconceptions About Email MarketingCommon Misconceptions About Email Marketing
Common Misconceptions About Email Marketing
 
Search Marketing For The Short And Long Term
Search Marketing For The Short And Long TermSearch Marketing For The Short And Long Term
Search Marketing For The Short And Long Term
 
Using the 5 Ws to Create a Successful Email Marketing Strategy
Using the 5 Ws to Create a Successful Email Marketing StrategyUsing the 5 Ws to Create a Successful Email Marketing Strategy
Using the 5 Ws to Create a Successful Email Marketing Strategy
 
Crawl, Walk, Run: Using Your Agency’s Branding to Reach Online Prospects
Crawl, Walk, Run: Using Your Agency’s Branding to Reach Online Prospects Crawl, Walk, Run: Using Your Agency’s Branding to Reach Online Prospects
Crawl, Walk, Run: Using Your Agency’s Branding to Reach Online Prospects
 
All Sky, No Net: How Agencies Can Survive Automation
All Sky, No Net: How Agencies Can Survive AutomationAll Sky, No Net: How Agencies Can Survive Automation
All Sky, No Net: How Agencies Can Survive Automation
 
How to Turn Your Website into a Lead Generator
How to Turn Your Website into a Lead GeneratorHow to Turn Your Website into a Lead Generator
How to Turn Your Website into a Lead Generator
 
10 Email Marketing Feaux Pas You're Probably Making
10 Email Marketing Feaux Pas You're Probably Making10 Email Marketing Feaux Pas You're Probably Making
10 Email Marketing Feaux Pas You're Probably Making
 
Think Like a Marketer: Marketing Ideation for Insurance Agents
Think Like a Marketer: Marketing Ideation for Insurance AgentsThink Like a Marketer: Marketing Ideation for Insurance Agents
Think Like a Marketer: Marketing Ideation for Insurance Agents
 
How Do You Know if Your Website Needs to be Updated?
How Do You Know if Your Website Needs to be Updated?How Do You Know if Your Website Needs to be Updated?
How Do You Know if Your Website Needs to be Updated?
 
Email Marketing: The Agency Newsletter and Beyond
Email Marketing: The Agency Newsletter and BeyondEmail Marketing: The Agency Newsletter and Beyond
Email Marketing: The Agency Newsletter and Beyond
 
Are You Missing the Mark? Email Marketing Opportunities You May Be Missing Ou...
Are You Missing the Mark? Email Marketing Opportunities You May Be Missing Ou...Are You Missing the Mark? Email Marketing Opportunities You May Be Missing Ou...
Are You Missing the Mark? Email Marketing Opportunities You May Be Missing Ou...
 
Band For Your Buck: Underused Features of Your Insurance Website
Band For Your Buck: Underused Features of Your Insurance WebsiteBand For Your Buck: Underused Features of Your Insurance Website
Band For Your Buck: Underused Features of Your Insurance Website
 
Ask Me Anything: Bob Ingram of Peachstate Insurance
Ask Me Anything: Bob Ingram of Peachstate InsuranceAsk Me Anything: Bob Ingram of Peachstate Insurance
Ask Me Anything: Bob Ingram of Peachstate Insurance
 
The Bare Necessities: Your Homepage Checklist
The Bare Necessities: Your Homepage ChecklistThe Bare Necessities: Your Homepage Checklist
The Bare Necessities: Your Homepage Checklist
 

Recently uploaded

Authentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto RicoAuthentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto Rico
Corey Perlman, Social Media Speaker and Consultant
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
SabaaSudozai
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
Adnet Communications
 
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
Neil Horowitz
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
JeremyPeirce1
 
HOW TO START UP A COMPANY A STEP-BY-STEP GUIDE.pdf
HOW TO START UP A COMPANY A STEP-BY-STEP GUIDE.pdfHOW TO START UP A COMPANY A STEP-BY-STEP GUIDE.pdf
HOW TO START UP A COMPANY A STEP-BY-STEP GUIDE.pdf
46adnanshahzad
 
How MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdfHow MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdf
MJ Global
 
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
❼❷⓿❺❻❷❽❷❼❽ Dpboss Kalyan Satta Matka Guessing Matka Result Main Bazar chart
 
BeMetals Investor Presentation_June 1, 2024.pdf
BeMetals Investor Presentation_June 1, 2024.pdfBeMetals Investor Presentation_June 1, 2024.pdf
BeMetals Investor Presentation_June 1, 2024.pdf
DerekIwanaka1
 
Creative Web Design Company in Singapore
Creative Web Design Company in SingaporeCreative Web Design Company in Singapore
Creative Web Design Company in Singapore
techboxsqauremedia
 
amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05
marketing317746
 
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
bosssp10
 
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
my Pandit
 
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
SOFTTECHHUB
 
Mastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnapMastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnap
Norma Mushkat Gaffin
 
Digital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital ExcellenceDigital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital Excellence
Operational Excellence Consulting
 
Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024
Kirill Klimov
 
Digital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on SustainabilityDigital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on Sustainability
sssourabhsharma
 
2022 Vintage Roman Numerals Men Rings
2022 Vintage Roman  Numerals  Men  Rings2022 Vintage Roman  Numerals  Men  Rings
2022 Vintage Roman Numerals Men Rings
aragme
 
Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024
Top Forex Brokers Review
 

Recently uploaded (20)

Authentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto RicoAuthentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto Rico
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
 
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
Brian Fitzsimmons on the Business Strategy and Content Flywheel of Barstool S...
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
 
HOW TO START UP A COMPANY A STEP-BY-STEP GUIDE.pdf
HOW TO START UP A COMPANY A STEP-BY-STEP GUIDE.pdfHOW TO START UP A COMPANY A STEP-BY-STEP GUIDE.pdf
HOW TO START UP A COMPANY A STEP-BY-STEP GUIDE.pdf
 
How MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdfHow MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdf
 
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
 
BeMetals Investor Presentation_June 1, 2024.pdf
BeMetals Investor Presentation_June 1, 2024.pdfBeMetals Investor Presentation_June 1, 2024.pdf
BeMetals Investor Presentation_June 1, 2024.pdf
 
Creative Web Design Company in Singapore
Creative Web Design Company in SingaporeCreative Web Design Company in Singapore
Creative Web Design Company in Singapore
 
amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05
 
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
 
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
 
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
 
Mastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnapMastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnap
 
Digital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital ExcellenceDigital Transformation Frameworks: Driving Digital Excellence
Digital Transformation Frameworks: Driving Digital Excellence
 
Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024Organizational Change Leadership Agile Tour Geneve 2024
Organizational Change Leadership Agile Tour Geneve 2024
 
Digital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on SustainabilityDigital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on Sustainability
 
2022 Vintage Roman Numerals Men Rings
2022 Vintage Roman  Numerals  Men  Rings2022 Vintage Roman  Numerals  Men  Rings
2022 Vintage Roman Numerals Men Rings
 
Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024
 

Cyberliability, Loopholes and Vulnerabilities in Data Security - Laird Rixford, ITC

  • 1. Loopholes and Vulnerabilities in Data Security Are you ready to accept your cyber liability? Laird Rixford / @lrixford President
  • 3. Trusted Advisor What do you have to lose?
  • 4. Sorry to Scare You… • In case of a security breach you could be • Subject to $1,000 to $100,000 per incident • Qualify each piece of breached data as a separate incident • Required to notify individuals and media of breach • Required to provide monitoring or remuneration to affected parties • Applies to all agents. Not just health.
  • 5. What is Your Data Worth? • Financial data is $5/record • Health data is worth $50/record • Identity theft data is worth $188/record
  • 6. Security and Confidentiality Laws • Health Insurance Portability and Accountability Act (HIPAA) • Health Information Technology for Economic and Clinical Health (HITECH) • Payment Card Industry Data Security Standard (PCI DSS) • Sarbanes–Oxley Act of 2002 (SOX) • Gramm–Leach–Bliley Act (GLBA) • State and Federal Laws • Cyber Liability, Professional Liability, Errors and Omissions Policies • Carrier Contracts
  • 7. What is Considered PII? • Name • Address • Birthday • Social security number • Drivers license number • Financial information • Email • Health information
  • 8. Ease of Access = Less Security More difficult to access, more security
  • 9. Points of Entry • Physical • Technology infrastructure • Remote access • Phone system • Cloud and vendor products and services • Employees
  • 12. Physical Access • Limit access to critical areas • Anywhere with a computer or access to security infrastructure is critical • Secure servers in a locked cabinet • Security cameras • Security system • Even alarm inner doors during business hours
  • 14. Technology Infrastructure • New machines are cheap • Update and patch • Operating systems • Software • Firewalls • Run supported software • Encrypt mobile devices • Use high security Wi-Fi (WPA2-PSK or Enterprise RADIUS) • System policies • Disable USB storage • Force password change • Force screen saver lock • Install prevention
  • 15. Remote Access Remote Desktop, Thermostats, VPN, Oh MY!
  • 16. Remote Access • Do you or your employees really need it? • How often do you use it? • Turn it on only when you need it • Use two-factor authentication • DUO • RSA Key
  • 18. Phone System • Prevent remote access • Change password often • Enable remote extensions only as needed
  • 19. Cloud & Vendor Services Their security is your security
  • 20. Cloud & Vendor Services • Request security audit results • Use offerings meant to increase security • Change password • Two-factor authentication • Remove unused users • Leave vendors who do not comply • Ask for Business Associate Agreement
  • 22. Employees • Users do not like security • Train users as to importance of security and how to recognize social engineering • Security begins and end with them; include them in the conversation
  • 23. Security Costs Money, A Hack Costs More You are a target. Act accordingly.
  • 24. More Security = Less Threat The harder you make it, the less you are a target.
  • 25. Suggestions • Create a security program • Longer passwords are better • Change passwords often • Use authentication that changes • Hire an IT professional to secure your network • Keep all software patched and up to date • Lower your attack profile • Encrypt everything
  • 26. Cyberliability Policy • Do you need one? • What coverage should you get?
  • 27. Thank You Don’t forget to fill out your surveys! Laird Rixford / @lrixford President

Editor's Notes

  1. Ask questions…77% say their company is safe from cyber threats 66% say they are not concerned with hackers, cyber-criminals, or even employees stealing data 47% believe a data breach would have no impact on their business https://www.staysafeonline.org/business-safe-online/resources/
  2. 71% of data breaches target small businesses 96% of data breaches target payment card data
  3. Do any of these required fields look familiar to an agent?
  4. Doors, Server Room, Desktops
  5. Using cameras to socially engineer or steal passords.
  6. Wi-Fi (hide SSID, MAC, limiting pools), Operating Systems, Software, Firewalls, Mobile Devices (Laptops, Tablets, Phones), Crack windows login. XBOX/PS DDOS of Firewall. Dont allow you to be a point of contact either.
  7. Updates to OS, Software, Firewalls. Mobile devices encrypted storage. Crack windows login.
  8. Remote Desktop GoToMyPC VPN
  9. Two factor. Access = security hole.
  10. VOIP, Conference Bridges, Long Distance Calling, Paging
  11. Someone could just take a phone home and call from home.
  12. Focus on security? Security audits? Save password is bad. Require local install of data.
  13. Save password is bad. Require local install of data.
  14. Disgruntled Employee, Unethical Employee, What is social engineering? Other vulnerabilities can be exploited to leverage social engineering.
  15. 60% of small businesses close within six months of experiencing a data breach
  16. SMB Security Program Status:87% do not have a formal written security policy 59% do not have a security incident response plan for a data breach 50% of users still use poor passwords 83% do not have a system to require employees to periodically change passwords