Insuranceciooutlook

A featured contribution from Leadership Perspectives, a curated forum for finance technology leaders, nominated by our subscribers and vetted by the Insurance CIO Outlook Editorial Board.

Executive & Cyber Solutions at EPIC

Battling Cyber Threats: How Accounting Firms and Other Professional Service Providers Mitigate Risks with Technology, Best Practices, and Insurance

Natalia M. Greene

Through this article, Natalia Greene and Gregg Davis explore how professional service firms, particularly in sectors like accounting and law, are increasingly vulnerable to cyber threats. They discuss the importance of leveraging cutting-edge technology, best practices, and comprehensive insurance to mitigate cyber risks. The article also covers regulatory liabilities, data privacy challenges, and strategies to manage cyber-related risks effectively.

“Accounting Firm Hit With Data Breach” was added to the lengthy list of recent headlines featuring cyber threat actors targeting professional service firms, like the healthcare, financial, and legal service sectors, access, collect and store voluminous, valuable electronic data. Firms cannot afford to delay vigilant risk mitigation efforts because threat actors’ tactics and techniques are only becoming more sophisticated with the assistance of rapidly evolving technology like Generative AI (“GenAI”).

To address the risks posed by cyber-attacks and data breaches, it is essential to consider how legal and regulatory liability may present. In the case of a malicious attack upon professional service firms’ systems or devices, where the bad actor gains unauthorized access to stored data - clients’ and employees’ personally identifiable and financial information, firms face not only civil and class action lawsuits but also regulatory proceedings for violations of international, national, and state privacy regulations.

Professional service firms that contract to provide client advisory or management services on behalf of their clients (e.g., outside CFO, C-Suite, or Board member services) are likewise exposed to civil and regulatory actions brought against those clients. We see more indemnity and contribution claims against firms that expose themselves to additional, heightened risks through broad, contractual indemnification provisions by assuming responsibility for client and third-party losses resulting from cyber-attacks targeting client or third-party systems and networks, which are often uncovered under a firm’s cyber insurance policy.

Here are some things for firms to consider as part of their ongoing efforts to develop and enhance their evaluation of existing processes and implementation of necessary upgrades:

Technology

In the ever-evolving landscape of cyber threats, cutting-edge technology is a critical line of defense for professional service firms.

● Advanced threat detection systems powered by artificial intelligence and machine learning algorithms can identify and respond to potential breaches in real-time, often before human analysts can process the data.

● Robust encryption protocols, when properly implemented, can render stolen data useless to attackers. Multi-factor authentication and other advanced access controls significantly reduce the risk of unauthorized system entry.

● Automated patch management systems ensure that software vulnerabilities are addressed promptly, closing potential entry points for cybercriminals.

"Firms cannot afford to delay vigilant risk mitigation efforts because threat actors’ tactics and techniques are only becoming more sophisticated with the assistance of rapidly evolving technology like Generative AI."

By leveraging these technological advancements, firms can create a formidable barrier against increasingly sophisticated cyber attacks, buying precious time for human intervention and potentially preventing catastrophic data breaches before they occur.

Best Practices Policies and Procedures   

● Limitation on data collection, access, and storage: Firms must carefully consider and collect only the data necessary to perform the professional services for which they are engaged, anonymize the data being collected, limit access to only those people that require the information, comply with records retention policies to limit the records stored, and ensure mechanisms are in place to terminate access to personnel who no longer need the data or are no longer employed by the firm.

● Privacy Laws: The privacy regulatory landscape is in constant flux at the international, national, and state levels. Currently, nineteen states have enacted comprehensive privacy laws that impose obligations on organizations and firms far beyond simply providing notification post-data breach. Firms must know and track compliance with each state’s post-breach notification and other requirements or face additional legal and regulatory exposure under relevant privacy laws.

● Training: Ongoing personnel training with up-to-date information about cyber threats and tactics and how to respond to them remains crucial since firms’ personnel remain the principal target of cyber threat actors.

Risk Transfer

● Indemnification provisions: Firms should always consult with an attorney before agreeing to contractual indemnification provisions and push back on any requirements they have to defend, indemnify, and hold another party harmless for that party’s losses. Firms’ agreement to these provisions could preclude or significantly limit insurance coverage under their existing insurance policies.

● Insurance coverages: Given the nature of services provided by professional service firms, they should carefully and regularly evaluate the adequacy of the risk transfer provided within their entire insurance portfolio. This includes the adequacy of policy limits and the types of insurance products they have in their portfolio (e.g., cyber, E&O, D&O, crime, Technology E&O, etc.) to protect them in the event of a cyber-attack or data breach. In doing so, firms should consider some of the following: whether and to what extent their CIO/CISO is covered under the appropriate policy(ies), whether there is coverage for data privacy-related breaches, the extent to which relevant insurance coverage is appropriately coordinated, the adequacy of existing limits for direct losses and third-party civil and regulatory liability exposure, and the extent to which exposure posed by the firm’s subcontractors and vendors is covered.

Professional service firms should prioritize real-time awareness of cyber-related risks, implement innovative technology and best practices, and maintain appropriate insurance coverages to manage and mitigate cyber risks that threaten them effectively.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief