Ransomware & Municipalities – UpdateMay 22, 2019
By: Robert Sargent, Tennant Risk Services
Another major municipality is suffering from a crippling ransomware attack (see our prior post), although Cyber Risk Insurance (also called Data Breach, Privacy and Network Security insurance coverage) will help in this case.
According to reports, a ransomware attack shut down Baltimore’s computer systems on May 7, 2019 and hackers demanded 13 bitcoins (approx. $75,000) to obtain the encryption keys needed to release the data and systems access. All systems have been impacted, although the city is doing its best to provide services.
The situation has not been resolved as of the date of this article, nearly two weeks later, and the ransom demand is increasing by approximately $10,000 per day. The city continues to use manual processes and other workarounds to key systems in order to provide some level of service to its residents.
The city has indicated that it will not pay the ransom. Instead, it is relying on experts and its staff to rebuild and recover key data and systems. There is no easy answer on whether to pay the ransom or not, and no guarantee that the data and systems will be released once the payment is made, but some experts strongly recommend quick payment of the ransom demand.
The city has Cyber Risk Insurance in place with a $50,000 deductible, although the exact coverage is not public. Cyber Risk Insurance is an essential coverage for municipalities of all sizes for protection from both criminal attacks and employee error, including ransomware attacks. Not only does comprehensive Cyber Risk Insurance include coverage for the ransom demand, it also covers business interruption losses. Business interruption costs are typically many times greater than the ransom demand.
Tennant Risk Services, a division of Worldwide Facilities, is a specialty wholesale broker and underwriting manager, and delivers expertise, markets and exemplary services to our retail insurance agent clients in the placement of professional liability and specialty insurance (E&O, D&O, EPL, Cyber Risk, Specialty). We are experts in Cyber Risk Insurance and excel at hard to place accounts.