1 Quantifying e-Commerce Risk David Fishbaum, FSA Chuck McClenahan, FCAS MMC ENTERPRISE RISK CAS Seminar on Ratemaking - March, 2001.

Slides:



Advertisements
Similar presentations
Copyright 2006 Mid-City Offices Systems. Busy people… How would your business be affected, if you suddenly lost all of your computer data? Rush through.
Advertisements

Copyright, 1996 © Dale Carnegie & Associates, Inc. BANK ON IT Money Smart Course Indiana Department of Financial Institutions.
Chapter 1 Business Driven Technology
AFM INTERNAL AUDIT NETWORK MEETING MUTUAL ONE GROVE PARK, LEICESTER Current ‘Hot Topics’ in Information Security Governance Auditing David Tattersall 03.
Crime and Security in the Networked Economy Part 4.
DISASTER CENTER Study Case DEMIRBANK ROMANIA “Piata Financiara” ConferenceJanuary 29, 2002 C 2002.
VIRTUAL BUSINESS RETAILING Lesson 5 Financing. MAIN IDEA  Many people want to own their own business  Before opening a business, there are several steps.
“This workforce solution was funded by a grant awarded under Workforce Innovation in Regional Economic Development (WIRED) as implemented by the U.S. Department.
E-Commerce Security Issues. General E-Business Security Issues Any E-Business needs to be concerned about network security. The Internet is a “ public.
Lockton Companies International Limited. Authorised and regulated by the Financial Services Authority. A Lloyd’s Broker. Protecting Your Business from.
Forensic and Investigative Accounting Chapter 16 Cybercrime Loss Valuations © 2011 CCH. All Rights Reserved W. Peterson Ave. Chicago, IL
Financial Institutions – Cyber Risk Managing Cyber Risks In An Interconnected World State Compensation Insurance Fund Audit Committee Meeting – February.
Security, Privacy, and Ethics Online Computer Crimes.
Lecture 2 Page 1 CS 236, Spring 2008 Security Principles and Policies CS 236 On-Line MS Program Networks and Systems Security Peter Reiher Spring, 2008.
Client/Server Computing Model of computing in which very powerful personal computers (clients) are connected in a network with one or more server computers.
Risks, Controls and Security Measures
CSE 4482, 2009 Session 21 Personal Information Protection and Electronic Documents Act Payment Card Industry standard Web Trust Sys Trust.
BACKGROUND  Hawkes Bay Holdings/Aquila Underwriting LLP  Established 2009 utilising Lloyd’s capacity: Canopius % Hiscox 33 50% to May 2010, replaced.
Alter – Information Systems 4th ed. © 2002 Prentice Hall 1 E-Business Security.
Information Systems Today, 2/C/e ©2008 Pearson Education Canada 2-1 Lecture Outline 9 1. Using Information Systems for Competitive Advantage (p )
Protection Detail: Insurance Coverage in 2012 Presented By: Nezih Hasanoglu and Kim Singleton M3 Insurance Solutions for Business.
Overview of Cybercrime
Defining Security Issues
Computers Are Your Future Tenth Edition Spotlight 2: E-Commerce Copyright © 2009 Pearson Education, Inc. Publishing as Prentice Hall1.
Information Systems Today, 2/C/e ©2008 Pearson Education Canada Lecture Outline eCommerce Highlights of Electronic Business 2-1.
Bluff Numbers Day Two
WHAT EVERY RISK MANAGER NEEDS TO KNOW ABOUT DATA SECURITY RIMS Rocky Mountain Chapter Meeting Thursday, July 25, :30 am – 12:30 pm.
Invitation to Computer Science 5th Edition
Prepared by: Dinesh Bajracharya Nepal Security and Control.
RISK MANAGEMENT. RISK IS INEVITABLE  From your research of local businesses, what Risk was unavoidable and why?  Speculative Vs. Pure Risk  Speculative=
PATCH MANAGEMENT: Issues and Practical Solutions Presented by: ISSA Vancouver Chapter March 4, 2004.
E-Commerce Security Professor: Morteza Anvari Student: Xiaoli Li Student ID: March 10, 2001.
Trojan Horses on the Web. Definition: A Trojan horse a piece of software that allows the user think that it does a certain task, while actually does an.
CHAPTER 8 Selecting Your Business. Listen to your market!
Chapter 7: E-Commerce Security and Payment system
OCTAVE-S on TradeSolution Inc.. Introduction Phase 1: Critical Assets and threats Phase 2: Critical IT Components Phase 3: Changes Required in current.
Entrepreneurship Mr. Bernstein Identifying Business Risks, pp , and Dealing with Risks, pp January 8-9, 2015.
Deloitte Forensic Forensic Technology Conference of Regulatory Officers - CORO November 2012.
1 e-Commerce Risk A Case Study CAS 2000 Annual Meeting David Fishbaum Enterprise Risk.
CPS ® and CAP ® Examination Review OFFICE SYTEMS AND TECHNOLOGY, Fifth Edition By Schroeder and Graf ©2005 Pearson Education, Inc. Pearson Prentice Hall.
Forensic and Investigative Accounting Chapter 16 Cybercrime Loss Valuations © 2013 CCH Incorporated. All Rights Reserved W. Peterson Ave. Chicago,
1999 CAS RATEMAKING SEMINAR PRODUCT DEVELOPMENT (MIS - 32) BETH FITZGERALD, FCAS, MAAA.
Mgmt.101 ~ Introduction to Business Risk Management & Insurance.
Cybercrime What is it, what does it cost, & how is it regulated?
2004 CAS RATEMAKING SEMINAR PRODUCT DEVELOPMENT (COM - 4) BETH FITZGERALD, FCAS, MAAA.
Advice, Information, and Transactions. Focus Questions 1.How can people learn more about investing? 2.Where can investors find written information about.
Computer Security By Duncan Hall.
Virus Assignment JESS D. How viruses affect people and businesses  What is a virus? A computer virus is a code or a program that is loaded onto your.
The Pitfalls of the Small Business Owner Protect Your Assets!
Security Mindset Lesson Introduction Why is cyber security important?
1 Law, Ethical Impacts, and Internet Security. 2 Legal Issues vs. Ethical Issues Ethics — the branch of philosophy that deals with what is considered.
Online Banking. Learning Objectives To learn how society has been affected by online banking.
Managing Your Money Saving Investing Insurance CHAPTER 12.
Chapter Saving 2. Commercial Bank 3. Savings Bank 4. Credit Union 5. Savings Account 6. Certificate of Deposit 7. Money Market Account 8. Annual.
Module #4: Insurance. Risks O Risks come with every decision made in life. O Risks can be preventable, avoidable or completely unforeseeable. O Risks.
Risk Assessment and Risk Management James Taylor COSC 316 Spring 2008.
Online Shopping. Learning Objectives To learn how society has been affected by online shopping (e-Commerce)
Ratio Analysis…. Types of ratios…  Performance Ratios: Return on capital employed. (Income Statement and Balance Sheet) Gross profit margin (Income Statement)
Welcome to the ICT Department Unit 3_5 Security Policies.
Cyber Insurance Overview July 30, 2016 Wesley Griffiths, FCAS International Association of Black Actuaries.
Personal Finance Home and Auto Insurance
E&O Risk Management: Meeting the Challenge of Change
Current ‘Hot Topics’ in Information Security Governance Auditing
Identifying Business Risks, pp , and
Cyber Insurance Overview
Cyber Issues Facing Medical Practice Managers
Cyber Trends and Market Update
INFORMATION SYSTEMS SECURITY and CONTROL
Protect Your Ecommerce Site From Hacking and Fraud
Forensic and Investigative Accounting
Presentation transcript:

1 Quantifying e-Commerce Risk David Fishbaum, FSA Chuck McClenahan, FCAS MMC ENTERPRISE RISK CAS Seminar on Ratemaking - March, 2001

2 The Problem l You’re the risk manager of a financial institution with a new web site l Your insurance broker has provided you a quote for new e-commerce risk insurance coverage: $350,000 - $450,000 with low limits l Your not exactly sure what the risks of the web site are l What to do?

3 Background l The financial institution provides community banks with a product portfolio of ancillary products such as: u investments (mutual funds and stock trading) u insurance u other banking services l You provide web sites for these community banks for investments, insurance and lending

4 What are the risks? l Failure of the web site u problems with the surroundings, power failure, fire or flooding u failure of the hardware u failure of the software u attack through virus or computer hacker

5 Resultant damages are also varied l Delay in performing a service l Loss of brand value due to unreliability of service or transmission of computer virus l loss of value through failure to deliver u for example, an uncompleted stock trade

6 Background: E-commerce insurance coverage l There is an intensive application u the problem is that you can’t figure out how complex or risky a web site you are running l A system audit is part of the insurance coverage u there is a bias to find fault

7 How do you insure the high P/E ratio l Its 1999 and the price/earnings ratio of the e- commerce function seems to have broken down l The unspoken issue is how do you insure the value lost if something happens to the web site? l Not sure this is an issue today

8 Why bring in Actuaries? l Looking for someone to quantify the risk l We brought a multidisciplinary team of actuaries, economists and policy expert l The actuaries provided the quantification and modeling skill sets

9 Methodology l Model the web site l Stochastic testing l Scenario testing

10 Model l MMC ER developed a computer program to model the economic performance of the e- commerce infrastructure l Used company’s performance statistics l Used a Monte Carlo simulation to produce expected revenue and branding values l Based on this quantification, valued the potential losses of a series of scenarios

11 Application Server/Firewall/Proxy Layer ISP Provider In our estimation of the probability of failure at the application host level, elements such as software outage, hardware outage, data base performance etc were considered. Flow of Information and quantification of failure probabilities

12 Assumptions l Visits per week l Usage over the week l Revenue l Customer value l Application acceptance l Downtime

13 Results-Base Case

14 The Scenarios l Denial of service l Physical damage to hardware location l New virus brings down complete system l Malicious employee l Threats/extortion l Theft of credit card numbers

15 The Scenarios l Attack causes a degradation of performance or loss of service to web site l Not covered under current coverage l Modeling assumption: site down for 3 hours l Income loss/Customer value loss Denial of service

16 The Scenarios l Location of where hardware is kept is disabled l Covered under current insurance l Modeling assumption: site down for 10 days l Income loss/Customer value loss l Client bank’s lost revenue Physical damage to hardware location

17 The Scenarios l Not covered under current coverage l Model assumption: system down for 2 days l Income loss/Customer loss New virus brings down complete system

18 The Scenarios l Destruction of important data or programs l Cost of recovery process covered under current coverage l Not modeled l Theft of policyholder info or other intangible property l Not covered under current coverage Malicious Employee

19 The Scenarios l Threat to commit a computer crime or to use information gained from a computer crime in exchange for money, personal gain or to embarrass the company l Would be covered under current kidnap and ransom policies Threats/extortion

20 The Scenarios l CD universe and Salesgate (e-mall) l No credit card numbers are stored Theft of credit card numbers

21 Results of analysis l Biggest risk business interruption l Third party loss is minimal at this time though in time the Internet will affect its client relationship

22 Conclusions l Better quantification of risks l Better able to make a purchase decision l Other risk management decisions l What isn’t at risk is also important

23 Postscript l The website is still in operation l Strategy has been proven successful

24 e-Commerce Risk l Bruce Schneier - Secrets and Lies (Wiley Computer Publishing, 2000) u “The insurance industry does this kind of thing all the time; it’s how they calculate premiums. They figure out the annual loss expectancy for a given risk, tack on some extra for their operational costs plus some profit and use the result”

25 e-Commerce Risk l Bruce Schneier - Secrets and Lies (Wiley Computer Publishing, 2000) u “Of course there’s going to be a lot of guesswork in any of these; the particular risks we’re talking about are just too new and too poorly understood to be better quantized (sic).”

26 e-Commerce Risk l Pricing e-Commerce Risk u Determine Strategy u Identify the Risks u Collect Available Data u Develop Model u Price According to Strategy

27 e-Commerce Risk l Determine Strategy u “Guess and Confess” u Loss Leader u Self-Supporting u Franklin Approach

28 e-Commerce Risk l Determine Strategy - “Guess and Confess” u Insurer uses best available judgment (usually discovered deep in the bowels of the marketing department) as to the proper rate u Alternatively, rely on advice of career agents

29 e-Commerce Risk l Determine Strategy - Loss Leader u Aptly named, this strategy is based upon the assumption that the best way to develop experience and expertise is to write a lot of exposure

30 e-Commerce Risk l Determine Strategy - Self-Supporting u Goal is to cover losses and expenses, including start-up expenses, over some reasonable period of time. This is a radical strategy and has rarely been adopted in the property-casualty industry.

31 e-Commerce Risk l Determine Strategy - Franklin Approach u Focuses on loss avoidance u Underwrites against “undesirable” hazards, e.g. n large user base n large asset base n high public profile

32 e-Commerce Risk l Identify the Risks u We have a good track record here n Medical Malpractice n Computer Leasing n Asbestos and Environmental

33 e-Commerce Risk l How many do you recognize? u Daemon u Data mining u Digital wallet u Extranet u Luhn formula u Smart card u Thin client

34 e-Commerce Risk l How many do you recognize? u Daemon - a structured background process

35 e-Commerce Risk l How many do you recognize? u Daemon - a structured background process u Data mining - looking for hidden data patterns

36 e-Commerce Risk l How many do you recognize? u Daemon - a structured background process u Data mining - looking for hidden data patterns u Digital wallet - encryption software, user ID

37 e-Commerce Risk l How many do you recognize? u Daemon - a structured background process u Data mining - looking for hidden data patterns u Digital wallet - encryption software, user ID u Extranet - authorized outsider-available intranet

38 e-Commerce Risk l How many do you recognize? u Daemon - a structured background process u Data mining - looking for hidden data patterns u Digital wallet - encryption software, user ID u Extranet - authorized outsider-available intranet u Luhn formula - credit card verifying algorithm

39 e-Commerce Risk l Luhn formula (1) Start with penultimate digit and, moving left, double the value of each alternating digit. If you get a two digit number, add the two digits. (2) Add up all digits. Result must be zero mod 10

40 e-Commerce Risk l Luhn formula u u u =70

41 e-Commerce Risk l How many do you recognize? u Daemon - a structured background process u Data mining - looking for hidden data patterns u Digital wallet - encryption software, user ID u Extranet - authorized outsider-available intranet u Luhn formula - credit card verifying algorithm u Smart card - personal electronic memory card

42 e-Commerce Risk l How many do you recognize? u Daemon - a structured background process u Data mining - looking for hidden data patterns u Digital wallet - encryption software, user ID u Extranet - authorized outsider-available intranet u Luhn formula - credit card verifying algorithm u Smart card - personal electronic memory card u Thin client - network computer w/o hard drive

43 e-Commerce Risk l Ingram Micro Inc. vs. American Guarantee & Liability Insurance Company u “The court finds that ‘physical damage’ is not restricted to the physical destruction or harm of computer circuitry, but includes loss of access, loss of use and loss of functionality.”

44 e-Commerce Risk l Ingram Micro Inc. vs. American Guarantee & Liability Insurance Company u “Restricting the policy’s language to that proposed by American [i.e.that contained in the policy] would be archaic.”

45 e-Commerce Risk l TD Waterhouse fined $225,000 for repeated outages which left customers unable to trade l 11 online brokers reported 88 outages for 1st 9 months 1999 (12th firm reported so many outages it didn’t keep track).

46 e-Commerce Risk l Collect Available Data u Exposure base not well-defined u Economic costs of losses not disclosed u Industry is young and evolving u Threat base is also evolving

47 e-Commerce Risk l Collect Available Data u Remember, “Lloyd’s List” was started in 1696 but it wasn’t until 75 years later that the Society of Lloyd’s was formed

48 e-Commerce Risk l Develop Model u Identify major processes u Identify major threats u Relate threats to processes u Determine (or guess at) parameters

49 e-Commerce Risk l Example - Distributed Denial of Service (DDoS)

50 e-Commerce Risk u “Attack of the Zombies” - February,2000 n Monday, February 7 -Yahoo! portal rendered inaccessible for 3 hours n Tuesday, February 8 -Buy.com 90% inaccessible -eBay incapacitated -CNN 95% inaccessible -Amazon.com slowed to 5 minute access time n Wednesday, February 9 -ZDNet.com unreachable -E*Trade slowed “to a crawl” -Excite 60% inaccessible

51 e-Commerce Risk l How DDoS Works u Goal is to render system inoperable u One attacker controls multiple servers u Method: Break into numerous sites, install “attack script” and orchestrate coordinated attack

52 e-Commerce Risk USER PCs HACKER UNWITTING HOST “ZOMBIE” OTHER NETWORK COMPUTERS VICTIM’S SERVER

53

54

55 e-Commerce Risk l Price According to Strategy u Frequency will vary with n Popularity n Profile n Potential

56 e-Commerce Risk l Price According to Strategy u Severity will vary n eToys v. E*Trade

57 e-Commerce Risk l “You gotta be careful if you don’t know where you’re going ‘cause you might not get there.” - Yogi Berra