Wednesday, 24 June 2015

Cybersecurity ETF: Lessons From A Success (And Failures)

T wo misses and a middling success. That’s what it took for Andrew Chanin to launch a blockbuster new ETF.PureFunds ISE Cyber Security ( HACK ) recently crossed $1 billion in assets, roughly seven months after its debut.

The niche exchange traded fund partly lucked out — a high-profile security breach atSony (SNE) occurred not long after its Nov. 12 launch. Since then, a slew of online data thefts have kept hackers in the news and made cybersecurity stocks a hot pick for successful investing .

IBD Leaderboard stockPalo Alto Networks (PANW ) is up roughly 130% in the past year. Sector LeadersVasco Data Security ( VDSI ) andCyberArk Software ( CYBR ), an IPO , rocketed about 50% each in the past three months.

Chanin, CEO of PureFunds, says HACK filled an unmet need in the ETF marketplace.

“It spoke very loudly” to investors, he said, “whether they think there could be more cyberattacks in the short term or maybe own much broader technology exposure but want a tactical tilt towards cybersecurity or believe there’s going to be so much spending by corporates and government entities.”

HACK now holds $1.1 billion in assets, with almost half its assets in the top 10 of 31 stock holdings. It skews toward smaller caps valued at $2.68 billion on average.

That makes it a risky bet in a volatile industry segment. Its 0.75% expense ratio is relatively steep, but in line with peers focused on specific themes.

New Jersey-based PureFunds’ first two ETFs — targeting gemstone and mining stocks — failed to attract investors and shut down. Its third try,PureFunds ISE Junior Silver (SILJ), holds $4.9 million.

Launching A New ETF

One key lesson they taught Chanin was that “just because you launch an ETF doesn’t mean every investor is going to be able to invest in it.” He describes this as a common — but erroneous — assumption among rookies in the business.

Chanin, 29 years old, found major ETF platforms have gatekeepers who decide whether a product gets approved. Their rules or milestones for granting approval were murky to him as an outsider.

What’s the solution? None really, says Chanin: “Having a track record helps.” But that’s just what rookie ETF providers don’t have. So Chanin suggests “having clients and colleagues show that they are interested (in the ETF ) by reaching out to platform gatekeepers.”

Persistence paid off for Chanin: “Had we not been willing to take on risks, we would not be where we are today.”

He didn’t hesitate to shut down ETFs that weren’t gaining assets. “We saw that as a business decision,” he said. “So many people are scared it will show you don’t have what it takes to succeed.”

But he made sure to do right by stakeholders — by being transparent about the decision and process, as well as giving back as much of the investments’ net asset value as possible to them.

“Investors didn’t end up with zero” when the ETFs liquidated, Chanin said. “It didn’t hurt our brand or our reputation.”

HACK’s success, and its siblings’ failures, showed Chanin that “timing is very important to the success of an ETF.” How does one determine the opportune time? “You won’t know until you launch it,” Chanin conceded. But it can be critical to have a first-mover advantage: “I got into ETFs with the mindset of being first to market.”

HACK gained 0.3% on the stock market today. It’s up 27% year to date.

View the original content and more from this author here: http://ift.tt/1BAo2aO



from cyber security caucus http://ift.tt/1BAo0Q1
via IFTTT

DHS Secretary Calls for Cybersecurity Legislation

(WASHINGTON) — Department of Homeland Security Secretary Jeh Johnson told Senators on Tuesday he wants them to pass cybersecurity legislation – something he and President Obama have long pushed for but that Johnson said is all the more pressing in light of the most recent OPM hacks.

He talked to reporters after a closed briefing for Senators along with OPM Director Kathy Archuleta on the security breach.

“There’s a need for cyber legislation and I’m hoping that this congress will pass cyber legislation which will give us additional authorities to do the job that we need to do,” Johnson said. “I am concerned that we do everything possible as quickly as possible,” he added.

Sen. Tom Carper (D-DE) expanded a bit more about what Johnson asked for:  legislation providing liability protection for companies who share information with the government, ways to incentivize those companies to share information and to force the government to do a better job sharing information with the businesses that are reporting.

Carper also said it was time to implement “Einstein Three” technology in the OPM’s systems, and that the Senate must move on the nomination of an OPM deputy administrator which happened in the fall of last year.

On the scope of the problem, Sen. Susan Collins (R-ME) told reporters, “OPM is having a difficult time completing its forensic work to determine exactly how many records were compromised. We’re hearing conflicting numbers but I would be willing to wager that in the end, it’s going to be significantly more than the 4.2 million Americans that OPM has already admitted records more breached.”

View the original content and more from this author here: http://ift.tt/1fAiByL



from cyber security caucus http://ift.tt/1GHoCmb
via IFTTT

Washington, Beijing confront differences on cyber security and South China Sea

Washington: The United States and China vowed to avoid confrontation as they headed into a final day of key talks, confronting head-on differences on issues such as cyber security and freedom of the seas.

President Barack Obama was also preparing to meet key members of the Chinese delegation ahead of a visit in September by Chinese President Xi Jinping.

US Vice President Joe Biden sharply warned Beijing on Tuesday that the world’s waterways — which carry 80 percent of the planet’s commerce — must remain open.

“Responsible countries adhere to international law and work together to keep international sea lanes open for unimpaired commerce,” Biden said pointedly.

The two major trading partners remain at odds over China’s claims to much of the South China Sea and Washington has repeatedly urged Beijing to stop building artificial islands and resolve its numerous territorial claims peacefully.

“Nations that discard diplomacy and use coercion and intimidation to settle disputes, or turn a blind eye to aggression of others, only invite instability,” Biden warned.

In unusually frank comments, Chinese Vice Premier Wang Yang agreed Beijing and Washington do not agree on everything, admitting “on some issues, perhaps, consensus still eludes us.”

But he insisted “neither of us could afford the cost of noncooperation or even all-out confrontation.”

“Decision-makers of both countries must always remember that confrontation is a negative sum game in which both sides will pay heavy prices and the world will suffer too,” Wang said.

New rules needed

Welcoming the top delegation of some 400 officials also led by China’s State Councilor Yang Jiechi for the seventh round of annual talks, Biden insisted Beijing must be at the table to help set up a new “rules-based system” in a rapidly changing world.

“There will be intense competition, we will have intense disagreements. That’s the nature of international relations,” Biden said.

“There are important issues where we don’t see eye-to-eye, but it doesn’t mean we should stop working hand-in-hand,” he said.

US Secretary of State John Kerry insisted: “No nations agree on every issue. But we do not accept that a narrowing of the differences is beyond our reach.”

“Our relationship is dynamic and it has grown and matured steadily in the past decades.”

Jiechi vowed China would work with the United States “in a spirit of openness, to properly address the relevant issues.”

High on the agenda is cyber hacking, with Treasury Secretary Jacob Lew insisting both nations must “abide by certain standards of behavior within cyberspace.”

“We remain deeply concerned about Chinese government-sponsored cyber-enabled theft of confidential business information and proprietary technology from US companies,” Lew told the delegations.

“Such activity falls outside of the bounds of acceptable state behavior in cyberspace.”

But in a sign of China’s discontent, Chinese Finance Minister Lou Jiwei called on the US to boost its domestic savings and investment to strengthen growth, including spending to improve infrastructure.

“The United States should have a proper mechanism to mobilize more savings to direct to investment,” he said, pointing out that China’s contribution to global growth is 30 percent, while the US, the largest economy in the world, added only 10 percent.

Ties have strained over US accusations of cyber espionage and a bilateral cyber working group was suspended by Beijing last year after Washington indicted five Chinese military officers for hacking into US computers.

This week’s talks come after revelations of huge breaches of US government computer networks at the Office of Personnel Management — an issue US officials said they would raise directly with their Chinese guests.

Kerry said the two countries, the world’s two largest economies but also biggest emitters of greenhouse gases, were working “effectively” to try to reduce emissions ahead of a key UN-led Paris conference on setting new targets in December.

“The idea is that you are creating a critical mass of countries that are setting these targets and everyone feels compelled to join,” Kerry said.

View the original content and more from this author here: http://ift.tt/1BzQ3iM



from cyber security caucus http://ift.tt/1GHkpPu
via IFTTT

Tuesday, 23 June 2015

Cybersecurity Coverage Litigation: Learning to Survive After the Second Wave Hits

It’s a familiar pattern.  First, new risks inspire legislation and regulations that impose new penalties.  Next, insurers and policyholders fight over whether the new liabilities are covered under traditional liability policies.  Finally, insurers craft new coverages to define their obligations in the changed environment.  See, e.g., DeMeo, Eldred, Utiger & Scruggs, “Insuring Against Environmental Unknowns,” 23 J. Land Use & Envtl. L. 61, 62-65 (2007).  In this respect (if not in any others), the unprecedented growth of both cybersecurity exposure and the demand for cybersecurity insurance have unfolded in a predictable way.  In 2015, some of the most closely-watched suits over traditional CGL policies wound down or settled, while litigation under early cyber endorsements has begun to spring up.  Last Fall, the Insurance Services Office (ISO) amended its standard CGL coverage form specifically to exclude data breach liability; then, in a March 2015 press release, it unveiled a standardized cyber-liability coverage form.

The First Wave Recedes: Square Peg Litigation

The first wave of coverage litigation over claims related to cybersecurity tested the limits of policies that had been issued without specific underwriting of cybersecurity risks.  Insureds typically sought coverage under GL and E&O/D&O/professional liability coverages.  In many cases, the policies were written before the privacy laws and regulations that imposed the policyholder’s loss had been enacted.  This first wave of litigation thus consisted of “square peg” cases—courts struggled to fit a square peg of liability into a round hole of coverage.

  • In 2013, for example, in First Bank of Delaware v. Fidelity and Deposit Co. of Maryland, No. N11C-08-221 (Del. Super. Ct. Oct. 30, 2013), VISA claimed a bank was liable for a data breach, after a subcontractor that processed the bank’s credit and debit transactions was hacked, and customers’ personal identification numbers were compromised. The breach resulted in millions of dollars in unauthorized withdrawals, and it also triggered contractual indemnification issues by and among the bank, the subcontractor and VISA.  Under one of the relevant contracts, VISA charged the Bank $1.5 million in cost reimbursement assessments.

The bank looked to its D&O carrier to defend and indemnify.  Its policy included an “electronic risk liability’ coverage that insured against “unauthorized use of, or unauthorized access to electronic data or software with a computer system.”  Coverage under that provision depended, in part on whether the hacked computer system, which belonged to the subcontractor, was “used to transact business on behalf of the [bank].” The Delaware court found that it was (at least arguably), and so that coverage was available.

Then things got complicated.  The court examined whether a fraud exclusion applied, and it held that the insurer had met its burden of proving that it did.  But it went on to hold that the exclusion, when applied to a data breach, would render the entire coverage grant for electronic risk liabilityillusory, and it therefore declined to apply the exclusion.  After reargument was denied, the insurer did not pursue an appeal.

  • The coverage saga of Recall Total Information Management, Inc. v. Federal Ins. Co., 317 Conn. 46 (Conn. May 26, 2015), finally came to an end this year. In that case, the insured was an information management contractor for IBM.  On a trip from one IBM facility to another, a van belonging to a subcontractor inadvertently dropped 130 computer tapes—containing HR data about 500,000 current and former IBM employees—onto a highway.  The contractor sought coverage under the theory that the associated losses—such as the costs of notification and credit—came within the personal injury coverage of its GL policy, which applied to “injury. . . caused by an offense of . . . electronic, oral, written or other publication of material that. . . violates a person’s right of privacy.”

An intermediate appellate court found there was no coverage, but the Connecticut Supreme Court granted certiorari to review the decision.  At oral argument, the Justices openly struggled with the insured’s square peg argument that the employee information had been “published” within the meaning of the policy, because the record contained no evidence that the data on the tapes had actually been accessed—which would have required special equipment.  (The only evidence of what happened to the tapes was a report that a motorist had been seen loading them into his car.)  One of the Justices asked whether a hacker who gains access to a “closed architecture system” has thereby “published” the information in that system; he also suggested that the theft at issue had involved only the medium on which the information was stored, rather than the information itself.  Shortly after argument, the Court ruled in favor of the insurers, holding that this peg did not fit into an advertising injury hole.

  • 2015 also saw the resolution of another much-watched cybersecurity coverage case, pitting Sony Corporation against its insurers in a dispute over coverage for Sony’s much-publicized Playstation data breach.  In 2014, a New  York trial court dismissed the insurers from a declaratory judgment action.  Sony appealed, and industry watchers eagerly awaited an appellate ruling—especially because the trial court decision was a short bench ruling, blunting its usefulness as precedent.  They were disappointed:  the case settled before the appeal was heard.

The underlying bench ruling may be of little precedential value, but it might also have been the catalyst for the explosive increase in demand for dedicated cybersecurity coverage that followed it.  Whatever the cause, the purchase of cyber- specific coverage has sky-rocketed.

A New Regime Emerges

So what do these new cyber policies look like?  How do they fit into an overall coverage program?  What are the limits and contours of coverage under these policies?  These questions will drive the second wave of cybersecurity coverage litigation.

According to recent industry data, the coverage is not cheap.  This is due in large part to the growth of the liability exposure.  As noted by one analyst, “the average costs for a breached company total $9.4 million over a 24-month period.”  Those costs include both first- and third-party losses, including regulatory penalties and fines, credit monitoring, public relations costs to address reputational harm, costs associated with the lost data itself, business interruption and, of course, litigation expense. Annual premiums can range from $7,000 – $15,000 for smaller companies to as high as $50,000 for larger ones, depending on variety of factors.

One important factor that can help keep premium costs down will be loss services associated with the new insurance regime.  In scoring the risk, underwriters will look to the level of the cybersecurity measures employed. Industry organizations have developed standards and best practices (see e.g.ISO/IEC 27001:2013), and insurers may require or offer incentives to insureds to adhere to such standards in maintaining an Information Security Management System (ISMS).  Prevention-driven loss services of this kind can create a “virtuous cycle” of reducing losses, and thus reducing premiums costs over time.  This cycle creates additional benefits to the consuming public, whose data is being vacuumed up at astonishing rates and in often surprising ways.

 

View the original content and more from this author here: http://ift.tt/1LxEl8E



from cyber security caucus http://ift.tt/1e1hcjD
via IFTTT

US, China to Hold ‘Very Direct’ Talks

U.S. officials are promising a “very direct” conversation with Chinese officials during a high-level, annual dialogue that continues Tuesday in Washington.

Cyber security, China’s disputed maritime claims, and bilateral efforts to combat climate change are among the main topics expected to be raised during the meetings.

The talks opened Monday with a series of wide-ranging Strategic Security Dialogue meetings, which a senior State Department official described as frank.

“They’ve been candid and to the point in dealing with issues where we disagree and are very good for trying to find ways to narrow our differences on these most sensitive issues in the relationship,” the official said.

China’s official Xinhua news agency said the two sides held an “in-depth exchange of views on issues of common concern” and said they agreed to continue working to promote trust and improve relations.

U.S. Secretary of State John Kerry and Treasury Secretary Jacob Lew will join Chinese Vice Premier Wang Yang and State Councilor Yang Jiechi at Tuesday’s broader U.S.-China Strategic and Economic Dialogue.

Cyber Concerns

One source of recent U.S.-China tensions is cyber security, an issue the State Department official said “will certainly be talked about in very direct terms.”

The U.S. is investigating a massive cyberattack that targeted the private records of about 4 million current and former federal government employees.

Investigators say it appears the attack began last year, although it was not detected until two months ago.

The U.S. government has not openly accused China of being behind the hack. However, officials have said an investigation is underway to determine if there is a China link.

A senior State Department official said the U.S. and China have had ongoing discussions about “all of the various aspects of cyber security.”

“The issue will be addressed in pretty direct terms with the Chinese,” the official said.

The U.S. and China do not always agree on the approach to cyber security and cyber defense, said State Department spokesman John Kirby.

“It is certainly one of those areas where there is room for better cooperation, better dialogue and more transparency,” he said.

Climate Initiatives

On Monday, Energy Secretary Ernest Moniz outlined a series of collaborative efforts between the U.S. and China on climate change, including a Carbon Capture Utilization and Storage project.

The renewable energy project involves capturing carbon dioxide emissions from sources such as coal plants with a goal of either reusing the emissions or storing them so that they do not enter the atmosphere.

“The United States and China continue to lead the drive to press our clean energy ambition further, both in our countries and globally,” said Moniz.

At the same session on Monday, China’s Special Representative for Climate Change, Xie Zhenhua, said the U.S. and China could have a significant impact on climate change at the bilateral and multilateral levels.

South China Sea Building

One of the thornier issues the U.S. will raise with China is Beijing’s construction activity in disputed regions of the South China Sea.

The U.S. voiced concern that China’s construction on islands and reefs may restrict movement of foreign vessels and planes. China has said its construction is “lawful.”

“It is not about accepting the status quo,” said Kirby.

Kirby said the U.S. had made clear its concerns about the land reclamation activities and the militarization of at least some of the islands.

On Tuesday, Vice President Joe Biden will deliver remarks at the opening of the Strategic and Economic Dialogue, which will include additional sessions on climate change as well as a women’s leadership dialogue.

Officials say the three-day dialogue will also help set the stage for Chinese President Xi Jinping’s September visit to Washington.

View the original content and more from this author here: http://ift.tt/1TJf8xx



from cyber security caucus http://ift.tt/1Lr9yNR
via IFTTT

U.S. to Raise Cybersecurity with China in ‘Pretty Direct Terms’

Meetings between top U.S. and Chinese officials began under a cloud of mistrust and acrimony arising from tension over security in cyberspace and at sea. As the WSJ’s Felicia Schwartz and Ian Talley report:

The Obama administration, reeling from a massive computer attack and data theft at the government’s Office of Personnel Management, pledged to raise the issue of cybersecurity with Chinese counterparts at every level during the annual talks, including in security and economic sessions.

U.S. officials haven’t formally accused China of the cyber-intrusion, which resulted in the theft of millions of personnel records and the likely loss of sensitive security-clearance information. But a senior State Department official said Monday that the issue “will be addressed in pretty direct terms with the Chinese.”

View the original content and more from this author here: http://ift.tt/1SF5CKv



from cyber security caucus http://ift.tt/1CqoseT
via IFTTT

S’pore ‘will need more cyber defenders’

As Singapore grows increasingly wired, more manpower will be needed to keep its online infrastructure safe from malicious attacks- and the Defence Science and Technology Agency (DSTA) is reaching out to young talents to ensure that the nation’s cyber security is kept up to speed

We will need more and more cyber-security engineers in Singapore, going forward,” said DSTA cyber-security director Tan Ah Tuan.

He was speaking at the award ceremony of the third Cyber Defenders Discovery Camp held at the Singapore University of Technology and Design yesterday.

These camps for pre-university and tertiary students aim to raise awareness of cyber security and to interest them in a career within the field.

Twenty-two teams from junior colleges, polytechnics and universities took part in the three-day camp, which saw a record turnout of 323 students this year – three times that of the previous years.

Participants went for a two-day crash course on how cyber attacks are launched and how to defend against these attacks through firewalls and patching up server vulnerabilities.

They applied their skills at a competition yesterday, where each team had to defend its own servers and network while attacking the other teams’ systems at the same time.

Minister of State for Defence Mohamad Maliki Osman, who was the guest of honour, said the camp was to search for “the best and brightest to be Singapore’s future cyber defenders”.

The nation’s cyber-defence workforce and its skill sets must increase, said Dr Maliki, in order to stay ahead of cyber attackers.

Undergraduate Erickson Tjoa, 24, who was in the winning team in the university/polytechnic category, said the experience had made him more interested in cyber security. “I originally wanted to go into academia, but this field is more creative and exciting,” said Mr Tjoa.

According to Mr Tan, agencies will require innovative and creative cyber defenders to fight the ever-growing threat of cyber attacks.

“We do offer internships to the teams who display aptitude in this area,” said Mr Tan.

That was the route Mr Elvin Poh took. The 27-year-old was a participant at the inaugural camp in 2012, and is now a cyber-defence engineer at DSTA’s Cybersecurity Programme Centre.

“The camp was my first glimpse into the cyber-security world, where I developed my interest in learning how to protect systems,” said Mr Poh.

View the original content and more from this author here: http://ift.tt/1fwdK1A



from cyber security caucus http://ift.tt/1TKh3lA
via IFTTT