Blog Layout

Ask a School Insurance Underwriting Expert: What Does a Cyber Policy Cover?

Kevin Beer, President, Wright Specialty Insurance • Feb 16, 2023
Kevin Beer, President, Wright Specialty Insurance

Ask a School Insurance Underwriting Expert is a quarterly column addressing insurance and risk management related questions for ABACC members. 

If you have a question for Kevin Beer, please submit it via email

Question: In Layman’s Terms, What Does a Cyber Insurance Policy Cover?

Great question! It’s important to understand your policy coverage as schools are a target for bad cyber actors who may cause operational delays and potentially expose the school’s personal identifiable information or PII.

Not all cyber policies are equal. Many changes have occurred in the marketplace including high rate increases, reduced limits, higher deductibles and narrower coverage terms. Depending on your individual policy and exposure makeup, coverages may differ, but typical coverages you should look for in your cyber insurance policy include:

  • Incident response costs. Coverage for costs to notify those affected by a cyber breach at a school such as parents, students and teachers. This coverage also handles fines and penalties levied by government entities, which put the cyber exposure cleanup responsibility on schools (some of which are due to lax security).
  • Information technology security and forensics costs. Coverage for costs to secure a breached network or asset and investigating the incident.
  • Cybercrime. Coverage for damage costs related to thefts of funds and records. This coverage usually responds to ransom demands which is controversial. Governmental authorities often discourage schools and other cyber victims from paying any ransoms. There’s certainly an argument that such coverage is morally questionable, and over time it’s becoming less common to meet ransom demands.
  • Systems damage and business interruption. Coverage for costs to restore an out-of-operation computer system due to an attack as well as lost productivity.

Since underwriting cyber policies has become more complex, there are additional issues that could affect the availability of coverage including:

Multifactor Authentication (MFA)

This is the security practice of restricting access to systems until a secondary means of confirmation has been approved. Unfortunately, the multifactor authentication tool doesn’t work fully in the education sphere with its diverse users and divergence of their concerns. To illustrate, schools must have open system access to multiple types of users—teachers, administrators, students, alumni, parents and service providers. This range of users and the varied information they need to access, creates a risk to school systems. With a large number of records containing personally identifiable information (including medical records and Social Security numbers), schools have become a target for cybercriminals who see value in stealing this information. Many insurers won’t issue coverage to schools without MFA security tools in place. The only concession seems to be that a few insurers are allowing schools 60 days to implement MFA after the beginning of the policy year.

Legacy System Issues

It’s not uncommon for educational institutions to have antiquated systems and security measures needing upgrades. For this reason, schools of all types are viewed as soft targets by the cyber security community.

Risk Management Practices

Educational institutions that successfully manage cyber risk without security breaches are usually treated more favorably by insurers during quoting and renewal periods in a market that has become increasingly difficult.

The most important risk management tool is annual cyber risk awareness training. This instruction educates users who have access to PII, how to identify and address the various cyber threats including phishing, malware attack and ransomware. According to a recent IBM “Cyber Security Intelligence Index Report,” human error was a contributing factor in 95% of all cyber breaches, making user awareness training a top priority. As expected, the most common interface between systems and users is email which is key to any systems’ defense.

Additional good risk management practices are adding firewalls, updating technologies and replacement of legacy systems, and discarding old email servers.

Checklist items for school cyber risk management include:

  • Store critical data backups off premises and test them regularly. If a cyber criminal destroys or holds data ransom, backups are a lifeline. With regular backups, a school may only lose hours or a day of data rather than losing all its data. While the data records might be stolen, when the regular backups retrieved, the school should be able to get back to some level of normal operations relatively quickly.
  • Test for phishing by sending out system user emails to monitor responses. Check for system weaknesses by utilizing vulnerability or network penetration testing (hire a consultant or use internal IT experts if financial resources are available). Some schools do no testing, while others may do sophisticated testing as a private corporation might do.
  • Employ End-to-End encryption to stop cyber criminals from extracting data. Monitor the IT environment on a regular basis to identify signs of suspicious or inappropriate activity. Detecting an attack as early as possible is key to stopping the attack and minimizing damage.

About the Author: Kevin Beer is president of Wright Specialty Insurance, an underwriting manager of specialty insurance and risk management solutions for public and private universities, colleges and K-12 schools. Visit their website or call (877) 976-2111.

The use of meal plans and availability of certain foods can have a significant impact on performance
15 Apr, 2024
Campus dining services are only helpful if students participate in them! Here are some questions to ask when addressing the lack of student meal plan buy-in.
Don’t be fooled into thinking that simply belonging is enough.
By Michael G. Steger 27 Mar, 2024
Professional organizations are like food for the professional body; we require the nourishment that interaction with others in our field provides.
What if they screw up our data? How do I know it’ll work as promised?
By Brendan at Populi 13 Mar, 2024
Buying college software can be a nightmare. Sometimes it seems that the devil you know—your old system—is better than the devil you don’t.
Spend 10 minutes each week reaching out to a colleague you value but haven’t talked with in a while.
By Cheryl Hyatt, Hyatt-Fennell Executive Search 13 Feb, 2024
It is human nature to form connections…and to lose touch. The good news is that you can build a stronger relationship by just investing 10 minutes each week.
The long hours with a different pay scale from the for-profit world and how to level that field
05 Jan, 2024
Experienced members of ABACC were asked, “What do you wish you had known when you started working in Christian higher education?”
Read the most recent accreditation reviews and recommendations.
20 Dec, 2023
Are you just starting a position as a chief business officer in higher ed? Or, perhaps you’ve been promoted to a leadership role? What do you need to do first?
Heavenly Father, show me Your hand in my life and how You are providing for me to live abundantly.
By Dr. Mark Sooy 20 Dec, 2023
We were created for abundance and goodness. Deep down we know this to be true. In Genesis 1:28, God describes our purpose and calling as human beings.
Professional development must stay in the budget and may even need to be increased and prioritized.
By Dr. Duane Kilty 20 Dec, 2023
Our future depends on innovation, and our ability to innovate depends on our people. Investing in our people is investing in the well-being of the institution.
One of the most unique characteristics of higher ed is an inherent willingness to collaborate.
12 Dec, 2023
Given the financial pressure today’s higher ed institutions are facing, collaborative purchasing efforts are more important than ever before.
In 2022, sustained freezing temps led to frozen and burst pipes and water damage as far south as GA.
By Kevin Beer, President, Wright Specialty Insurance 13 Nov, 2023
Weather patterns have been changing in recent years, leading to unexpected and sometimes costly damage to facilities across the country.
More Posts
Share by: