Office of Chief Counsel | www.insurance.pa.gov
Cybersecurity, Insurers, and the Department: What You Need to Know
John J. Lacek IV, Esq. Department Counsel Chair – Cybersecurity Incident Response Task Force
Cybersecurity, Insurers, and the Department: What You Need to Know - - PowerPoint PPT Presentation
Cybersecurity, Insurers, and the Department: What You Need to Know John J. Lacek IV, Esq. Department Counsel Chair Cybersecurity Incident Response Task Force Office of Chief Counsel | www.insurance.pa.gov A Growing Threat and Growing
Office of Chief Counsel | www.insurance.pa.gov
John J. Lacek IV, Esq. Department Counsel Chair – Cybersecurity Incident Response Task Force
A Growing Threat and Growing Awareness
Office of Chief Counsel | www.insurance.pa.gov
corporations in the early part of the decade
exposed
and email accounts
Office of Chief Counsel | www.insurance.pa.gov
addresses, account numbers, tax documents, and driver licenses
Office of Chief Counsel | www.insurance.pa.gov
compromise a system
discover
Office of Chief Counsel | www.insurance.pa.gov
cybersecurity incident
The Internet of Things – A Dangerous Playground
Office of Chief Counsel | www.insurance.pa.gov
As IoT technology becomes more ubiquitous, so to do the cybersecurity implications
What Authority does the Department Have?
Office of Chief Counsel | www.insurance.pa.gov
31 Pa. Code Chapter 146c – Standard for Safeguarding Customer Information
security program
program
controls, systems and procedures
service providers and requires services providers to implement measures designed to meet the objectives of the security program
Office of Chief Counsel | www.insurance.pa.gov
Insurance Practice
provider is engaging in a patter of activity which violates this chapter, a licensee will be liable unless:
feasible, or
Department
Office of Chief Counsel | www.insurance.pa.gov
Incident Response Task Force
cybersecurity incident
Force
Office of Chief Counsel | www.insurance.pa.gov
areas
procedures to be used
ensuring confidentiality and restrictions on access to information
Office of Chief Counsel | www.insurance.pa.gov
The Task Force is currently comprised on numerous Department program areas
Office of Chief Counsel | www.insurance.pa.gov
experiencing a cybersecurity incident
consumer protections and licensee integrity
with and remediating a cybersecurity incident
communication regarding cybersecurity issues
licensees who have experienced a cybersecurity incident
Office of Chief Counsel | www.insurance.pa.gov
understanding of the incident
harm
Office of Chief Counsel | www.insurance.pa.gov
should guide this decision:
before the general public
surprise
Office of Chief Counsel | www.insurance.pa.gov
Pursuant to the Exam Law and Holding Company Act, all communications with the Task Force are held in strict confidence
employees with a need to know
Office of Chief Counsel | www.insurance.pa.gov
Office of Chief Counsel | www.insurance.pa.gov
Office of Chief Counsel | www.insurance.pa.gov
The Model contains four key components
Office of Chief Counsel | www.insurance.pa.gov
based on the risk assessment
cybersecurity program
and sophistication of the licensee
plan
Investigation of Cybersecurity Incident
Office of Chief Counsel | www.insurance.pa.gov
cybersecurity incident
be able to identify certain information
Office of Chief Counsel | www.insurance.pa.gov
within 72 hours of the discovery of a cybersecurity event
notification laws (73 P.S. § 2302 – “without reasonable delay”)
Office of Chief Counsel | www.insurance.pa.gov
licensee’s cybersecurity programs
investigate cybersecurity incidents
General Data Protection Regulation (GDPR)
Office of Chief Counsel | www.insurance.pa.gov
Office of Chief Counsel | www.insurance.pa.gov
subjects residing in the EU, regardless of the companies location
can no longer use long legal terms and conditions
data which is no longer relevant to the original collection purpose or which the subject has withdrawn consent for. Companies must judge the request for removal against the public interest in availability of the data
what data it maintains about the individual and request a copy of said data, free of charge
million, whichever is greater
Office of Chief Counsel | www.insurance.pa.gov