Is it worth taking out personal cyber insurance in case you are caught up in a data hack?

Experts say investing in identity theft protection may provide peace of mind, but won’t help recover lost information

The recent Optus and Medibank data breaches in which thousands of Australians had their personal information stolen have heightened public consciousness of the threat of identity fraud.

Information including names, dates of birth, addresses, phone numbers, passport and Medicare numbers, and even healthcare claims have been posted online in the past few months as a result of the high profile breaches.

If you’re worried about your personal information being stolen in a hack or data breach, should you consider investing in personal identity theft protection or is it a waste of money?

What is personal cyber insurance?

Cyber insurance for individuals is offered in products such as Norton Identity Advisor Plus, Aura’s Identity Guard, Experion Identity Protection and PrivacyGuard. Prices range from $99.99 for a year of Identity Advisor Plus to $75 (US$50) a month for Aura’s family coverage.

The products generally offer similar services with varying degrees of coverage.

Norton’s Identity Advisor Plus, for example, promises to monitor social media and the dark web for any data that identifies you, alert you if you are caught up in a breach and provide an “identity restoration support specialist” to guide you through the next steps, such as replacing identity documents and locking accounts. It also offers identity theft insurance up to $58,000 to cover legal expenses and lost income for time spent standing in queues to correct records.

Most products also offer credit monitoring to alert you of anyone trying to take out loans or open bank accounts in your name and will lock down your credit file to prevent such activity.

Will these products prevent me from being hacked?

Short answer: no. These products are designed to limit the damage in the event your personal information is leaked by finding it quickly, limiting ID fraud in your name and potentially to cover any financial losses you might suffer.

Aren’t I covered by the company’s cyber insurance?

If you’re a business, cyber insurance will cover everything from financial losses and cybersecurity support to legal advice and privacy breach management.

Large companies often have cyber insurance designed to cover the costs should they come under an attack, but this is not always applicable to the customers of the business.

Is personal cyber insurance necessary?

While it might be possible to undertake some of the monitoring and remediation offered by these services yourself – such a searching your own name on social media and engaging a credit monitoring service – you might prefer the peace of mind that comes with knowing someone else is doing it in a systematic way.

And, unless you work in tech, monitoring the dark web is probably beyond your expertise.

Josh Lemon, a digital forensics and cyber incident expert at SANS Institute, thinks the “appetite for individuals to actually take insurance out is probably pretty low”.

“If you have your driver’s licence exposed or your credit card exposed, the time it takes you to get those changed and renewed often isn’t compensated as part of those claims.”

In some cases, companies will pay out costs incurred by customers for credit monitoring and document replacement, as was the case for customers caught up in the recent Optus breach.

Lemon also said customers who have lost money from their bank accounts are often compensated by the banks.

“A lot of Australian banks have consumer protection rights that allows that money to be returned back to you,” he said.

However Prof Yang Xiang, Swinburne’s dean of digital research, pointed out companies are not obliged to pay for replacements for documents except out of brand reputation management efforts, so the insurance may offer some peace of mind.

“That could give the individual some protection in terms of money. It doesn’t protect the information at all, but it just gives you some protection in terms of if you lose any money, the insurance can cover some loss,” he said.

Consumer group Choice has not examined personal insurance for ID theft since 2014, but at the time labelled it as unnecessary insurance.

Lemon said cyber insurance for small businesses was still a good investment, and noted that insurance was getting much more expensive for larger companies, with increased carveouts including around ransomware attacks. Medibank told investors it had not taken out cyber insurance due to the cost involved.

Can software prevent cyber-attacks?

Xiang said consumers should be aware that software is unlikely to protect you from cyber-attacks, given most cyber-attacks have some level of human involvement through phishing campaigns or other methods to obtain people’s login details.

“We do have some automated ways to protect users’ information, for example by using AI to give some indication that your personal information might be compromised. But still, it needs human involvement.”

Guardian Australia sought comment from Norton.

Contributor

Josh Taylor

The GuardianTramp

Related Content

Article image
Home affairs cyber survey exposed personal data of participating firms
Shadow minister says leak of ‘sensitive’ information after research into the Optus and Medibank hacks was ‘deeply ironic’

Josh Taylor

24, Jul, 2023 @3:00 PM

Article image
Medibank hacker says ransom demand was US$10m as purported abortion health records posted
Post on blog linked to Russian ransomware group says it offered ‘discount’ ransom to health insurer of US$9.7m, or $1 for each customer’s data

Josh Taylor

09, Nov, 2022 @10:38 PM

Article image
Medibank hackers announce ‘case closed’ and dump huge data file on dark web
Medibank confirms it may be the full trove of hundreds of thousands of customers’ private records that were stolen from the health insurer

Josh Taylor

01, Dec, 2022 @1:51 AM

Article image
TPG reveals emails of 15,000 iiNet and Westnet customers exposed in hack
Telecommunications company says hacker searched for customers’ cryptocurrency and financial information

Josh Taylor

14, Dec, 2022 @3:05 AM

Article image
Cybercrime in Australia has been on the rise for years, but Optus and Medibank have been wake-up calls
Experts say the recent prominence of data breaches is just companies being more forthcoming and the media more focused on reporting them

Josh Taylor

28, Oct, 2022 @7:00 PM

Article image
I am a Medibank customer. Am I affected by the cyber-attack? What can I do to protect myself?
Experts suggest using multifactor authentication and telling your bank to put extra security checks in place

Josh Taylor

02, Dec, 2022 @3:08 AM

Article image
Medibank cyber-attack: should the health insurer pay a ransom for its customers’ data?
Speculation is rife about whether the insurer will pay a hacker who claims to have extracted 200GB of files

Josh Taylor

27, Oct, 2022 @3:00 PM

Article image
Medibank reveals hack could affect all of its 3.9 million customers
Medibank says it is in communication with the hacker, but declined to say whether it would pay any demands made

Josh Taylor

25, Oct, 2022 @6:02 AM

Article image
Medibank hack started with theft of company credentials, investigation suggests
View forming within Medibank that details were then sold on a Russian-language cybercrime forum

Josh Taylor

24, Oct, 2022 @9:01 AM

Article image
Customers’ personal data stolen as Optus suffers massive cyber-attack
Personal information of potentially millions of customers exposed, including names, dates of birth, addresses, and contact details

Ben Doherty

22, Sep, 2022 @5:14 AM