Strengthening Cybersecurity to Meet Insurance Demands and Support Growth
A multi-state senior living provider’s cybersecurity program was under pressure, and the organization was feeling the heat from multiple angles. Evolving threats and expansion plans both caused security worries, but the demands of the provider’s cyber insurance carrier were a persistent concern.
Each year, the carrier’s tightening cybersecurity requirements raised the bar for coverage. The organization needed a partner who could implement a cybersecurity program that would meet the insurer’s requirements and act as leverage for a better premium.
The provider turned to GuideIT for help.
The Challenge: Intensifying Cyber Insurance Criteria in the Face of Growth
The organization handles sensitive resident data across a growing footprint, so it faced several security predicaments:
- Deepening insurance demands: The carrier’s annual questionnaire increasingly required more of the organization, especially around documenting evidence of specific tools, processes, and procedures. Carriers no longer accept self-reporting assurances.
- A legacy security gap. The organization’s previous managed services provider had secured desktops and infrastructure but hadn’t kept pace with what carriers now expect of healthcare businesses.
- Financing exposure. The organization’s cycle of expanding locations and refinancing meant lenders wanted the same assurance insurers did: that a ransomware event wouldn’t derail its ability to pay its debts.
- A growing data footprint. A planned new line of business meant the organization would manage more protected health information (PHI), personally identifiable information (PII), and payment card data requiring adherence to PCI compliance. Leadership needed a future-looking security program that would keep the organization insurable as it grew.
The Solution:
Aligning Security With Carrier Requirements
GuideIT designed a security offering for the organization that would directly meet the carrier’s demands. From there, GuideIT:
- Encouraged leadership to validate the plan with the carrier. The organization shared GuideIT’s proposed security program with the carrier, who affirmed the plan’s direction.
- Reframed security as leverage for a better premium and business growth. The security investment will serve to reduce the organization’s premium and keep it insurable and financeable in the eyes of lenders.
- Set a timeline that minimizes disruption to residents and staff. GuideIT experts evaluated how and when to roll out security services that would have the most impact with the least disruption.
- Took on the insurance questionnaire. GuideIT now helps the organization complete renewal questionnaires.
- Planned for growth. As the organization expands into services involving more sensitive data, GuideIT will scale the security program accordingly, including securing the unified communications that connects medical providers, staff, families, and residents.
The Outcome:
Confidence in the Road Ahead
As the senior living provider embraces GuideIT’s security program, it expects to see:
- Lower cyber insurance costs over time. GuideIT will implement the measures that will help the organization see better premiums at renewal.
- Improved insurability and finance-ability. The security program will support the organization’s ongoing cycle of refinancing across its communities.
- A security posture built to scale. With an expanding business plan, the organization has peace of mind that its security program will evolve as it grows into new lines of business.