ANACAM MAGAZINE - n. 3 luglio | settembre 2024

sono assicurabili (ne esistono alcuni ad alto rischio) e neppure tutte le aziende. Così com’è difficoltoso, o pressoché impossibile, assicurarsi per i danni da furto in edifici sprovvisti di cancelli, porte o finestre, è altrettanto difficoltoso riuscire a contrarre una “Polizza Cyber” se l’azienda è priva di dotazioni basilari sulla sicurezza informatica. Chi intende attivare una “Polizza Cyber” deve, quindi, preventivamente attenzionare il proprio livello di protezione, per poi presentare la propria azienda alle compagnie di assicurazione con un’impostazione atta a negoziare il target di copertura; il valore aggiunto alla negoziazione può essere dato dal supporto di un broker indipendente. Puntando maggiormente ai requisiti basilari che ogni azienda interessata ad una “Polizza Cyber” deve possedere, si riporta una breve check-list: • esistenza di procedure scritte e di misure di trattamento, protezione e riservatezza dei dati; • esistenza di Firewall con relativi aggiornamenti; • esistenza di Antivirus/Spyware/Anti-Spam con relativi aggiornamenti; • rimozione di utenze generiche o non nominative (tutti gli amministratori di sistema devono essere identificati e nominati); • patch management - rilascio automatico aggiornamenti critici; • backup settimanale degli archivi digitali e conservazione duplicato in luogo sicuro e/o su supporti remoti; • assenza di incidenti informatici negli ultimi 3 anni (in caso di incidenti pregressi sarà necessario uno screening di approfondimento). Se tali requisiti sono soddisfatti, l’azienda è classificata assicurabile e può scegliere le caratteristiche della propria copertura tra: • copertura protezione dati e responsabilità verso terzi per incidenti informatici; • copertura interruzione della rete; • copertura attacchi informatici a fini estorsivi; • perdite pecuniarie traenti origine da accertamento PCI-DSS; • pronto intervento; • responsabilità civile multimediale; • incidente riguardante i dati elettronici; • fornitori servizi esternalizzati (OSP); • disfunzione sistema informatico; • crime – trasferimento fraudolento fondi; • opzioni tailor made. Per affrontare in modo approfondito il processo di verifica dei requisiti richiesti per attivare una “Polizza Cyber”, può risultare utile ricorrere a società di consulenza specializzate in questo ambito. Gli aspetti economici della polizza variano in base al livello di protezione che l’azienda detiene e in base al tipo di implementazioni tecniche e proceprocedures to protect data, systems, and information that now form the core of the company’s assets. It is necessary to point out that not all business sectors are insurable (there are some high risk ones) and neither are all companies. Just as it is difficult, or almost impossible, to insure against theft in buildings without gates, doors or windows, it is equally difficult to take out a ‘Cyber Policy’ if the company lacks basic IT security equipment. Whoever intends to take out a ‘Cyber Policy’ must, therefore, first consider his or her level of protection, and then present his or her company to insurance companies with an approach to negotiate the coverage target; the added value to the negotiation can be provided by the support of an independent broker. Focusing more on the basic requirements that any company interested in a ‘Cyber Policy’ must have, here is a short check-list: • existence of written procedures and measures for data processing, protection and confidentiality; • existence of Firewall with relevant updates; • existence of Antivirus/Spyware/AntiSpam with relevant updates; • removal of generic or unnamed users (all system administrators must be identified and named); • patch management - automatic release of critical updates; • weekly backup of digital archives and duplicate storage in a secure location and/or on remote media; • absence of IT incidents in the last 3 years (in the case of previous incidents, in-depth screening will be required). If these requirements are met, the company is classified as insurable and can choose the features of its cover between: • data protection and third party liability cover for computer incidents; • network interruption coverage; • extortionate cyber attack coverage; • pecuniary losses arising from PCI-DSS assessment; • emergency response; • multimedia liability; • electronic data incident; • outsourced service providers (OSPs); • computer system failure; • crime - fraudulent transfer of funds; • tailor-made options. In order to deal in depth with the process of verifying the requirements for activating a ‘Cyber Policy’, it may be useful to turn to consultancy companies specialised in this area. The economic aspects of the policy vary according to the level of protection the company has, and according to the type of technical and procedural 54 SICUREZZA DEI SISTEMI INFORMATICI DI ANGELO NICOLOSI*

RkJQdWJsaXNoZXIy NDUyNTU=