February 22, 2021
Sprinklered Buildings Still Burn
Kurtis Suhs
Founder and Managing Director, Cyber Special Ops, LLCMr. Suhs serves as the Founder and Managing Director for Cyber Special Ops, LLC, a cyber risk company that provides its clients with Concierge Cyber, a revolutionary new delivery solution for cyber risk services modeled on concierge medicine.
Many insurance professionals have compared cyber insurance to employment practices liability (EPL) insurance which took decades for organizations to adopt; however that is where the comparison ends. Cyber insurance is more analogous to catastrophic commercial property insurance, in which state-sponsored actors and sophisticated crime syndicates target and seek to burn down your building 24/7/365 days per year.
According to FM Global, the three main reasons sprinklered buildings burn are 1) design deficiencies, 2) system impairments before a fire, and 3) system impairments during a fire. Lets evaluate how each of these causes compare with cyber loss.
Design Deficiency
Sometimes due to design deficiency or system impairment, an automated sprinkler system fails to suppress a fire sufficiently and thus a building burns despite the system.
Water supply
Is the water source
a public water supply?
a fire pond?
Incident Response
Is the data breach team
an external third-party service provider?
an internal legal and infosec team?
System design
Is the system design adequate?
What is the system trying to protect?
Network Design
Is the network architecture adequate?
What is the system trying to protect?
Changes in occupancy
Changes in electronic assets
The building (organization) was devastated by fire (a cyberattack). The cause of the devastation was multifaced. The water supply (incident response plan) was limited because a single connection from the public water main (a few data breach firms) supplied the entire sprinkler system (cyber insurance market). However, the water supply (incident response plan) was limited and the water flow (insureds cyber insurance coverage and limit) to the automatic sprinklered system (network defense) was marginally adequate for the task. The sprinkler system (network defense) was designed for a facility (organization) that processed a specific amount and type of paper (electronic assets). The plant (organization) was changed to process a new and greater amount of hazardous coated paper (sensitive information). This change was made without reevaluating the sprinkler design (network design) or water supply (incident response plan).
The system (network) simply couldnt generate enough water (cyber insurance) to mitigate this type of fire (cyberattack) and suppress it because it wasnt designed for this use and didnt have enough water (cyber insurance coverage and limit) for this type of fire (cyberattack). Furthermore, the local fire department (cyber insurer) wasnt aware of the change in the amount and type of paper (the exposure basis) and thus didnt know they were responding to a hazardous chemical fire (state-sponsored actor), which requires a very different firefighting response (incident response) as compared to a traditional uncoated paper fire (simple malware).
System Impairments Before a Fire
A fire that would normally be adequately controlled or suppressed completely can instead rage out of control and destroy the building.
There are three type of impairments that can occur before a fire (cyberattack) as follows:
- renovation of building (network)
- inadequate maintenance of property (network)
- arson (state-sponsored actors and sophisticated crime syndicates).
Deliberate action by an arsonist (state-sponsored actor or sophisticated crime syndicate) can impair or disable an automatic sprinkler system (computer network) so the arsonists (threat actor) fire setting (cyberattack) actions will cause damage.
Arsonists (cyber attackers) learn how sprinkler systems (computer networks) work and find ways to defeat or overtax them. Limited only by their imagination, for example, they may close valves (software applications) or attempt to overtax the system (all computer servers) by setting multiple fires (cyberattacks) designed to circumvent, damage or destroy the building (organization).
System Impairments During a Fire
System impairments that can occur during a fire are often the result of human action that cause a protection breakdown.
The most common system impairment that can occur during a fire (cyberattack) is premature closure of a sprinkler systems control valve (network defenses).
Another common system impairment is the inadequate monitoring of the sprinkler control valve (network defenses).
Call to Action:
For most businesses, the five most important categories of risk are tied to 1) theft of intellectual property, 2) business interruption, 3) theft or corruption of personally identifiable information, protected healthcare information, 4) credit and debit card data and 5) diminished cash flow. But which of these is a priority, to what degree, and for which organization assets?
If we really want to make cybersecurity better, we first need to ask what do we need to protect within the organization? All of this is highly dependent on the business, the internal network structure, and the other security controls that are in place premised upon the zero-trust information security model.
Organizations will never outpace the sophisticated cyber threat actor. Remember, the cyber adversary only has to be right once while your organization has to be right 100% of the time.
News Type
PLUS Blog
Business Line
Cyber Liability
Topic
Professional Liability (PL) Insurance
Contribute to
PLUS Blog
Contribute your thoughts to the PLUS Membership consisting of 38,000+ Professional Liability Practitioners.
Related Podcasts
Demystifying AI: Episode 1
Welcome to Demystifying AI, your go-to podcast series dedicated to demystifying the…
Related Articles
Cyber University: Remarkable Event Rewind
Last week, PLUS celebrated another successful Cyber University program. This three-day virtual…
The Challenges and Opportunities of Insuring Artificial Intelligence Webinar Recap
This webinar, held on September 10th, explored how the risks posed by…
The Coverage Impacts of Recent Developments in Cyber Security Regulation for Financial Services
Insurers and their insureds continue to face a growing patchwork of laws…