Lynn,
I am really curious about this insurance. Is it only for breaches that lead to an MPN as these, I assume, are the ones that will require the additional work for which insurance will be necessary?
In regard to the policy, would the insurer be uninterested in low level or minor ones that might be picked up within the council. For example, someone sends an email to the wrong officer inside the council. Hardly going to require a report to the ICO and highly unlikely to warrant a MPN. If it does not cover those, would the insurer need to know those breaches to assess the risk to which they are insuring against?
For example, an organisation may have lots of small breaches, which indicate that they have a weak data protection culture, but never get an MPN. By contrast, there can be organisations which have a great data protection culture and suffer a breach that leads to an MPN. The insurer is going to look at each differently.
I suppose I am asking that if one has a robust data protection culture then insurance is less likely to be needed, but if one has a weak data protection culture then insurance is unlikely to be available, or only available at a very high cost. Moreover, an organisation may not be self-aware enough to understand its own risk. Thus, the central question is how one determines the risk associated with a potential data breach.
I would be grateful, if it is possible to share, to know how your organisation assessed its risk of a data breach requiring the insurance you have mentioned. Or is this simply a one off use sort of like subsidence insurance. Good to have but you can only use it once because it is difficult to sell your home after you have used it.
Thanks
Lawrence
Principal Information Management Officer
Durham County Council
Room 4/143-148
County Hall
County Durham
DH1 5UF
03000 268038
-----Original Message-----
From: This list is for those interested in Data Protection issues [mailto:[log in to unmask]] On Behalf Of Lynn Wyeth
Sent: 13 January 2014 14:38
To: [log in to unmask]
Subject: Re: Insurance for data breaches
Thanks all,.
Our insurer, Zurich insures us. Clearly not for fines as people have pointed out, you can't insure against them, but Zurich insure us against all other costs that we may incur as a result of a breach.
Some of our suppliers are finding it difficult to get anyone to insure them though. I just wondered if anyone had any names of companies other than Zurich that do offer it.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask] All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
________________________________
Help protect our environment by only printing this email if absolutely necessary. The information it contains and any files transmitted with it are confidential and are only intended for the person or organisation to whom it is addressed. It may be unlawful for you to use, share or copy the information, if you are not authorised to do so. If you receive this email by mistake, please inform the person who sent it at the above address and then delete the email from your system. Durham County Council takes reasonable precautions to ensure that its emails are virus free. However, we do not accept responsibility for any losses incurred as a result of viruses we might transmit and recommend that you should use your own virus checking procedures.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|