Trisura Cyber Policy Ranked Among the Best in Canada

Trisura Cyber Policy Ranked Among the Best in Canada

By Sara Ametrano

 

Comprehensive cyber coverage is proving more and more crucial each year as hackers continue to become increasingly sophisticated and successful in their attacks. Insurance Business Canada recently surveyed brokers across the nation to uncover the best cyber policies on the market. The publication revealed the top 17 carriers, which included Trisura Guarantee Insurance Company.

Smiling woman with brown hair and blazer in front of buildings backdrop.

Angela Feudo, manager of professional solutions, Trisura.

Trisura’s manager of professional solutions, Angela Feudo, believes the organization’s cyber policy win is a testament to its customization ability. “At Trisura, we really listen to the insured and broker to ensure we understand what they are looking for,” she explains. “Working closely together allows us in to find the right solutions for their unique needs.”

In an ever-changing market, cyber insurance policies have had to adapt. There was a pressing need for policy structures to sustain future losses. With many individuals and companies working remotely for nearly two years, risks were greater, as was the need for education and training. “There is a greater awareness among organizations about cyber threats and, as a result, there have been improvements made around cyber security controls,” Feudo says.

As for what comes next, Trisura’s resident cyber expert anticipates there will be further market growth due to reliance on technology through process automation and internet connectivity. “The exposure for these businesses will grow and evolve and so must the insurance products that protect them. There will also be continued focus on not only cyber security controls, but also the use of cyber experts to aid in risk selection.”

Past cyber struggles and future challenges for the Canadian market are not necessarily unique. The global market must also be prepared to adapt, as Feudo notes, “cyber risk doesn’t have borders.”

About the 5-Star Cyber Awards:

Over the course of 15 weeks, Insurance Business Canada conducted one-on-one interviews with brokers and surveyed thousands more within the publication’s network. Brokers shared their thoughts on current cyber offerings and the most important policy features.

The top carriers were determined based on how they were rated in the following categories:

  • Relationships with brokers
  • Claim-handling abilities
  • Underwriting expertise
  • Product strength

For the official 2021 5-Star Cyber Awards report, click here.

Cyber 2021: Unpacking the Industry’s Trends and Threats

Cyber 2021: Unpacking the Industry’s Trends and Threats

In a recent panel discussion, Trisura’s manager of professional solutions, Angela Feudo, shared insight about the cyber trends and issues the industry is facing today.

This interview is part of a special report published by Insurance Business Canada. You can read the full report here.

IB | How would you describe the state of the Canadian cyber insurance market? (Rates, capacity, coverage limitations, new buyers etc.)


Smiling woman with brown hair and blazer in front of buildings backdrop.AF | The cyber insurance market has, for the most part, continued to tighten over the last year. There have been numerous carriers who are reducing their capacity, increasing rates, restricting terms and implementing tighter underwriting controls. While capacity contractions generally are becoming more common, there has been a focus on limiting network extortion. There continues to be an increased number of ransomware events, which has led to this response from the market. As both the frequency and severity of claims have increased, the rates have also increased significantly to compensate. There has been a greater focus from insurers on their clients’ cyber risk management and security awareness.  An increase in cyber security awareness and risk management will ultimately be beneficial for everyone. The awareness in cyber attacks has also brought an increased interest in cyber insurance. We are seeing more requests for cyber insurance from first-time buyers as ransomware attacks are no longer viewed as just a large organization concern. Smaller companies have become acutely aware that they too can be targeted.

IB | Ransomware is arguably the hottest topic in cyber insurance today. How have you seen the ransomware threat evolve in recent years, and where do you see this challenging risk headed?
AF |
Ransomware has increased in the number of companies and type of companies being compromised. Ransomware as a service has allowed for an increase in the number of individuals that can launch a ransomware attack. Threat actors no longer necessarily need to be a technically skilled hacker to deploy ransomware because it is now more accessible than ever to utilize. Individuals and organizations have become more cyber savvy in their defences against cyber criminals, and many have concentrated efforts and resources in creating, maintaining and encrypting backups, as well as focusing on their restoration processes. Due to these efforts and, in the event that files were corrupted, companies didn’t necessarily have to pay the ransom. Threat actors have moved to engaging in double extortion, meaning that the hackers would threaten to release private information if the organization doesn’t pay. Threat actors are also using distribution denial of service [“DDoS”] attacks as well on their victims to put pressure on them to pay the ransom. Hackers have expanded ransomware into a business model will use the best method against the victim. This can include encryption, DDoS or releasing of private information to cause the most disruption.

IB | Which industries are most exposed to cyber risk, and are these industries buying cyber insurance?
AF |
Any individual and organization that uses the Internet is exposed! Some industries and businesses, however, may be at a higher risk. Historically, the focus has been on healthcare, government, utility companies, schools and financial institutions. This has not changed; today, these industries continue to be at a higher risk, for different reasons. The health care industry has many older legacy systems that go unpatched. That, coupled with holding patient records, makes them an attractive target. Government, financial institutions and universities also hold a lot of confidential information. The larger organizations in these industry groups have been buying cyber insurance for years. Now, the smaller companies are also purchasing cyber insurance more regularly. We have also seen an increase in claims in the manufacturing, professional services and construction spaces. While there has been an increase in cyber purchases in these additional spaces, there are still a lot of companies who still do not purchase cyber insurance.

IB | How does the hardening market impact insurance brokers? What must they do in order to navigate this market successfully and secure the best solutions for their clients?
AF |
The hardening cyber market has created additional challenges for brokers. With markets reducing capacity, it has left brokers looking for replacement markets for those towers. It is now even more important for underwriters to clearly communicate their appetite to brokers, so they know who might be a viable option for their clients. Cyber is no longer just privacy based; for example, the exposure that a manufacturer has versus that of a law firm is very different. It is critical that insurers understand their client’s exposure in order to develop a trusted advisor relationship with their client. It is important for brokers to stay on top of emerging cyber threats, as this will enable them to educate their clients on where the exposures are. A lot of markets are asking for more underwriting information; understanding where potential exposures lie allows markets to get ahead of risks and be proactive in preparing the necessary increased security measures. The better controls a company has in place, the more likely they will be able to obtain better terms. Better controls are beneficial for the client, as their systems will be better protected from exposure. With the evolving digital landscape, it can be difficult to stay on top of the market, particularly if you are not a cyber specialist. Finding a specialist you can trust to help navigate the market will help.

IB | What are the most common cybersecurity attack vectors and breach methods?
AF |
We are still seeing a lot of losses arising from either weak or compromised credentials. Usernames and passwords continue to be exposed in data leaks and phishing scams. When this type of information is stolen or lost, the cybercriminals can easily access the company’s systems. If an employee uses the same password for both personal and business systems and the individual’s password gets compromised on their personal device, the hacker can use this opportunity to hack into the company’s system. Having good password hygiene, using multi-factor authentication or even biometrics can help combat this risk. Phishing continues to be a common method used by hackers, likely because it works. Cybercriminals are expanding on the methods they use in phishing; for example, during the pandemic, we’ve seen phishing scams where criminals are imitating health organizations or use the guise of providing relief money. Continued employee training, phishing tests and employing the principle of least privilege for access in systems can help with combat this risk.

It is important to also note that not all threats come from humans. Unpatched applications and servers are also a common vulnerability that can leave systems open to attacks. A good example of this is the January 2021 Microsoft Exchange Server attacks, which affected over 200,000 servers. Although patches were released by Microsoft in March, they did not retroactively remove any backdoors that might have been installed by hackers. Implementing software updates and installing patches as soon as they are available can help mitigate these vulnerabilities.

IB | In the growing threat landscape, what are some best practice cyber risk mitigation tactics that all companies (large and small) should implement?
AF |
Cyber risk for both individuals and businesses has continued to increase since the inception of the internet. This will only continue to increase over time as we become more connected to the internet and cybercriminals find new ways to take advantage of vulnerabilities. Companies of all sizes are vulnerable to cyber attacks and they should be taking steps to help mitigate those exposures. Human error still remains one of the top factors in cyber breaches, and so, employee awareness training is key to help combat this risk. Multi-factor authentication is becoming a standard security measure that all companies should implement because it improves a company’s security by adding an additional step that a cyber criminal would have to breach to gain access to a company’s system. Employing a patch management process allows you to keep your software functioning properly and maintain good security posture. Being up to date with the most current security fixes to combat any known vulnerabilities in the software. Businesses should also have a current record management system, keeping only records the company needs and getting rid of old data that is no longer useful. If you hold the record, you will need to protect it. If all else fails, it will be useful to have current back ups of important data. Back-up strategies will be different for each company, but the data in the back ups should be current, encrypted and stored securely off-site.

IB | How has the COVID-19 pandemic impacted the cyber risk landscape?
AF |
Since the COVID-19 pandemic started we have seen cyber criminals take advantage of people working from home. A lot of businesses did not have systems or the security designed to accommodate the majority of their staff in a work-from-home scenario. As a result, there has been an increase in phishing attacks and malware. Typically, devices at home are less secure, so multi-factor authentication, a focus on employee training and remote incident response plans are critical. COVID-19 has broadened out the cyber attack surface for cyber criminals to take advantage of due the increase in employees working from home. Many businesses realized the increase in exposure and invested in IT and additional cyber controls to help manage this risk. It is also important to look to the future of post-pandemic business models. It is expected that more businesses will allow for a more flexible workplace; whether that be a full work from home model or a hybrid that could include desk sharing. Technology, security and employee awareness training plans will need to be updated to ensure the best cyber security hygiene is in place for an organization. It will also be important to refresh the organization’s incident response plan to include how the company is currently conducting their business and where their employees are located.

IB | What cyber risks are lurking on the horizon?
AF |
Cybersecurity staffing shortages is a concern for businesses and the insurance industry. As the number of attacks grow and the demand for cybersecurity professional increases, there has been a continued decrease of cybersecurity staff. According to an article from CNN, there is approximately 3.12 million unfulfilled positions globally. With unfulfilled cybersecurity positions, businesses are more vulnerable to breaches. Cybersecurity is a global concern not only because hackers can reside anywhere in the world, but also because they can use other companies’ systems to breach yours by utilizing DDoS, MITM (man-in-the-middle attacks) and cryptojacking techniques. Cybersecurity should be a group effort against cybercriminals. Additionally, as 5G continues to expand (it is faster and can support more devices than traditional networks), it will increase the cybersecurity risk, as there is much more software being used in the network and, therefore, the attack surface has expanded. The increased speed of 5G, while beneficial to users, can prove to be a challenge for cybersecurity professionals. With its ability to support more devices, 5G will allow for more IoT devices. Not all IoT devices are manufactured with security in mind. With billions of IoT devices connected—all with mixed security levels—there could be potentially billions of breach points.

Return to Business: Preparing and Updating a Business Cash Flow Plan

Return to Business: Preparing and Updating a Business Cash Flow Plan

By Sara Ametrano and Victor Bandiera

 

 

Four stacks of coins increasing in height from left to right, with a jar full of coins at the end. A green upward-pointing arrow is on top of the piles.

Example image of financial increase.

To alleviate individual financial struggles due to COVID-19, the Federal government implemented the Canada Emergency Response Benefit (CERB) program. This initiative (currently in place until October 23, 2021) provides financial relief for eligible employers to cover a portion of their employees’ wages if their business was impacted directly by the pandemic. Now, as the country moves toward a sense of normalcy, resuming regular business operations and repairing the economy, the CERB program is ending.

 

 

What can you do to be ready?

If you’ve received financial support through CERB, putting a plan in place to resume business operations and generating profits is key. Part of your plan should include determining and updating your cash flow forecasts. Keep in mind there is a difference between cash flow forecasts and financial forecasts; where a financial forecast projects expected income over 12 months, a cash flow forecast is the actual cash activity (in and out) on a monthly or weekly basis.

 

Are cash flow forecasts necessary?

Yes. As you create a cash flow forecast, you must understand why the forecast is needed in the first place. History is littered with companies that were growing and making money but ran out of cash when they needed it the most. As your business shifts to growth mode, you will likely have a delay between doing work and getting paid, which could stress your balance sheet. Your cash flow plans are crucial for funding growth, so keeping your plan up to date and as accurate as possible rather than revisiting it on a reactionary basis is crucial. A surety and/or bank may also require this information, so having the figures and plan updated regularly allows you to easily provide any requested, relevant data.

 

Getting started:

To implement a cash flow plan, you need a clean starting point for your tracking period. Consider starting at a month-end, as you should have a good understanding of the current business financial state, including sub-ledgers for accounts receivables and liabilities such as accounts payable, held cheques after reconciling your bank accounts, contract bookings and other payments made.  The starting position gives something to balance to as well, which is very important. The cash flow forecast is usually 12 weeks at first, and then perhaps every month thereafter for a year.

Being organized is crucial for your plan. For example, revenue can be categorized by signed contracts, items still under negotiation or small fill-in work. Using these silos can help to identify various payment term differences, as well as separate any special payment terms like holdback receivables withheld monthly and released after contract completion, which usually results in large cash infusions.

Creating a chart in a spreadsheet could be useful to visualize projected and ongoing expenses and payments as well as any changes. Some things to highlight are sales assumptions:

  • Billing and collection assumptions for each contract
    • Separate the collection of accounts receivable and accounts receivable holdbacks
  • Cost of sales for each contract
  • The subcontractors who get paid when the business is paid by the client
  • Labour costs that are dependent on actual work performed and terms of collective bargaining agreements (if union) or employment/contract terms
  • Equipment costs (third-party rentals) or leases
  • Materials (some suppliers may permit deduction of holdbacks) and prompt payment discounts for early payment if cash flow permits

Many businesses require a bank operating line to help finance operations until payments from clients are received. The ability to access funds from the operating line will be based on the bank’s margining terms usually a percentage of current accounts receivables due within 90 days.

It will also be useful to identify items that cannot be deferred until the business is paid by the client. This list can include:

  • Payroll
  • Fuel
  • Equipment finance payments (interest and principal) or lease payments
  • Canada Revenue Agency payroll tax remittances
  • Workers compensation premiums and insurance premiums
  • Rent or mortgage payments

Cost items should be further broken down based on whether they are variable, fixed or discretionary. Variable items do not follow a set pattern but are dependent on production or sales such as sub-contractor costs or fuel. Fixed items, on the other hand, follow a regulated payment structure, such as rent and financing. Lastly, the discretionary category features costs that are a little “softer” and not directly associated with a specific contract but are still connected to its success, such as marketing.

Once you have completed your cash flow plan, remember to show the residual amount monthly and at end of the period. This is calculated by adding the starting cash balance to your receipts and payments allocated over the term. This might be a buffer over the period and can aid in considering a sensitivity analysis if things go better or worse than expected.

 

Determine workload:

Part of your preparations for resuming normal business operations should include taking inventory of current contracts. Is there an adequate backlog of work? What are the reasonable forecasted profits from the current contracts and estimated completion dates? Are there any current negotiations that may result in contracts being added to the backlog?

Highlight each contract and implement status checks weekly or monthly. Include the following information for each significant contract:

  • Re-forecasts of profitability (projected revenue and costs at completion)
  • Accounts receivable and accounts payable with segregated holdback
  • Any held cheques
  • The amount of remaining unbilled and unpaid work for each supplier/subcontractor
  • Resources required to complete work and their projected costs
  • Start and anticipated substantial performance dates, and therefore, holdback release date
  • Present aging of monthly accounts receivable to give you an idea of collection and payment schedules
  • Overhead: items not included in costs of sale or contract cost estimates; indirect operational costs (communications technology, supervisors, project managers, etc.); preventative maintenance costs and capital repairs versus running repairs of equipment
  • Internal equipment rental expense and true costs including fuel, wearing parts (for example, tires), running repairs (oil changes, radiator flushing, hydraulic oil, etc.), insurance, capital and depreciation including major overhaul costs (engine and undercarriage rebuilds, etc.) and expected return on capital
  • Information regarding debt service and split principal/interest on debt

CERB relief should be shown separately. Do not reduce your payroll costs, as this will just artificially reduce total amounts rather than show a true reflection of cash impact. All associated costs (paid and received) should be precisely accounted for to avoid any breach of trust obligations (if applicable), as per the statutory provincial Construction Act or Lien Act requirements. Items with a past-due status should be included as well. Deferred revenue and any work in progress do not need to be considered when it comes to the cash flow plan, as they are accrual-based calculations.

Having a strong understanding of your business’s cash flow forecast will give you confidence when making decisions around staffing, equipment purchases and when bidding on projects. Also, being able to present and articulate your cash flow plan will provide your lenders and surety with confidence to support the goals you have for your business, which should lead to more leverage and better terms.

If you have questions or would like someone to review your cash flow plan, please reach out to one of the surety underwriting experts at Trisura Guarantee Insurance Company.

 

The views expressed in this article are exclusively those of the authors; they do not necessarily reflect the views of Trisura Guarantee Insurance Company, its affiliates or partners.

A Message from Trisura’s Chief Operating Officer

A Message from Trisura’s Chief Operating Officer

Hello friends,

Man in blazer standing in front of marble wall.With the first quarter of 2021 coming to a close, I wanted to take the time to thank you for your continued support and valued partnership. Last year came with unique challenges and we hope we succeeded in helping make your brokerage run smoothly through it all. At Trisura, we take pride in helping our brokers be successful. In 2020 we conducted an extensive broker survey to give us insight into how we could continue to improve your experience with us. We appreciate all of the feedback received, and are in the midst of reviewing the results. We appreciate the tremendous role and responsibility that the broker community has and are honoured to support your efforts and the efforts of the Insurance Brokers Association of Canada. With this is mind, Trisura is pleased to continue our support as a Full Partner of the Insurance Brokers Association of Canada’s Broker Identity Program.

We are optimistic that we will be able to get together again in person later this year, and until then, we will do everything we can to bring you service that remains a step above.

 

Richard Grant
Chief Operating Officer, Trisura Guarantee Insurance Company

And the Excellence in Professional Liability Award Goes To…

And the Excellence in Professional Liability Award Goes To…

By Sara Ametrano

 

Over the last several months, Insurance Business Canada has been on a mission to determine the leading carriers for professional liability coverage in the country. Trisura is happy to report that we have made the inaugural list!

“We are thrilled to be recognized as a Five-Star Carrier for professional liability,” Marilyn vanGansewinkel, Trisura’s senior vice president of specialty insurance solutions says. “Trisura always strives to create positive experiences for our broker partners, providing tailored solutions to meet their unique needs.”

To determine the winners, the magazine conducted extensive research, surveys and one-on-one interviews with brokers to determine the nation’s leading professional liability providers. Information was gathered for a variety of categories, and Trisura is one of just two organizations to be selected as a top carrier for all of the categories:

  • Private E&O
  • Private EPLI
  • Private D&O
  • E&O Lawyers
  • E&O Design
  • E&O Accountants
  • E&O Medical
  • E&O Construction
  • E&O Non- profit
  • Public E&O
  • Public EPLI
  • Public D&O
  • Claims
  • Underwriting

What is professional liability insurance?

Professional liability insurance protects against allegations of negligence in the performance of a business’ professional services. The client may seek financial compensation if they believe the organization failed in their professional services that caused a financial loss.

What Trisura can do:

As we do with our other products, Trisura can tailor the professional liability coverage to fit each specific class of professional that we insure. Trisura takes a unique approach to all claims and provides expertise and solutions so organizations and individuals can quickly return to their business.

About the Insurance Business Canada Five-Star Carrier in Professional Liability Awards:

Over the span of 15 weeks, Insurance Business Canada conducted research, surveys and interviews with thousands of brokers to determine the country’s top carriers. The criteria used for scoring carriers included: relationships between parties, ability to handle claims, underwriting expertise and the products provided. Access the complete list of winners and more information on the awards here.

To learn more about Trisura’s professional liability coverage, click here. Or, talk to one of our experts today! Contact us.

Executive Outlook 2021: Chris Sekine, Trisura

Executive Outlook 2021: Chris Sekine, Trisura

Originally Published by Canadian Underwriter, December 23, 2020.

President and CEO, Chris SekineChris Sekine, President, CEO, Trisura Guarantee Insurance Company

COVID-19 has affected most businesses, and the insurance industry is no exception. Businesses are operating in a more uncertain environment than ever before. Insurers and reinsurers have adjusted underwriting appetites, which has influenced portfolios, available capacity, and pricing. Given current hardening conditions, we expect industry results to gradually improve. For many businesses, near-term results will be contingent on government support in response to the pandemic and the potential for further lockdowns.

Insureds are navigating challenging industry dynamics. The pandemic, combined with the hard market, amplified the need for brokers and their value. This is true for both insureds and insurers, and especially those with complex commercial risks. Trisura is a broker-driven company and we are working closely with our broker partners to navigate these turbulent times.

We expect the risk tolerance of businesses/insureds to evolve. Cyber risk is a good example of an exposure that businesses may not have appreciated. As cyber attacks have increased through COVID-19, businesses are looking to the insurance industry to help manage this risk.

We expect many business trends established before COVID-19 to return and business operations will resume much as they were pre-pandemic. For example, we anticipate a return to working in-office and in-person interactions with our brokers and partners. Although most companies successfully transitioned to working remotely, we don’t believe that is sustainable in the long run. Businesses rely on personal relationships. Virtual meetings are a great temporary measure, but they simply can’t replace in-person meetings.

That being said, the success of remote working arrangements will provide a broader tool set to employers and employees. For those with appropriate job functions, employers should offer flexible working arrangements.

Embracing technology will enhance productivity and collaboration of established operating norms. What hasn’t changed is that good people are the very core of a successful business.