2018
DOI: 10.1111/lsi.12303
|View full text |Cite
|
Sign up to set email alerts
|

Data Breach, Privacy, and Cyber Insurance: How Insurance Companies Act as “Compliance Managers” for Businesses

Abstract: While data theft and cyber risk are major threats facing organizations, existing research suggests that most organizations do not have sufficient protection to prevent data breaches, deal with notification responsibilities, and comply with privacy laws. This article explores how insurance companies play a critical, yet unrecognized, role in assisting organizations in complying with privacy laws and dealing with cyber theft. My analysis draws from and contributes to two literatures on organizational compliance:… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
30
0
2

Year Published

2019
2019
2023
2023

Publication Types

Select...
5
4
1

Relationship

0
10

Authors

Journals

citations
Cited by 63 publications
(33 citation statements)
references
References 26 publications
0
30
0
2
Order By: Relevance
“…Organizations face difficult challenges in terms of complying with these laws. Although many organizations do have formal policies in place, the majority of organizations do not believe that they are sufficiently prepared for a data breach, do not devote adequate money, training, and resources toward protecting consumer's electronic information from data breaches, and fail to perform proper risk assessments (Talesh 2017a).…”
Section: Insurance Company Intermediation Of Privacy Law and Data Theftmentioning
confidence: 99%
“…Organizations face difficult challenges in terms of complying with these laws. Although many organizations do have formal policies in place, the majority of organizations do not believe that they are sufficiently prepared for a data breach, do not devote adequate money, training, and resources toward protecting consumer's electronic information from data breaches, and fail to perform proper risk assessments (Talesh 2017a).…”
Section: Insurance Company Intermediation Of Privacy Law and Data Theftmentioning
confidence: 99%
“…Young (2016) in his thesis presented a framework which incorporates the operating principles of the insurance industry in order to provide quantitative estimates of cyber risk. Talesh (2017a) wrote that insurance companies play a critical role in assisting companies to comply with privacy laws and deal with cyber theft. In the cyber context, the insurance industry tries to engage in loss prevention and does so in a manner that is focused on managing and averting the risks associated with data breaches.…”
Section: Literature Reviewmentioning
confidence: 99%
“…Privacy of customers is of primary importance in all phases of the lifecycle of insurance policies, spanning from the early product design to its provision and 'delivery' to the customer (Talesh, 2018). However, for the given application domain we address in the present article, there is also a need for a broader approach to the notion of ethics.…”
Section: Foundations Of Ethical Insurance Productsmentioning
confidence: 99%