Cyber Risk Insurance

Former Member
Former Member $organization

I am assisting an arts consortium in Tennessee with the implementation of Tessitura. We have recently gone live with the product for subscription sales, and will enable all remaining ticket sales functionality in a few weeks.

Since we are storing credit card information in Tessitura (and holding this data on site for the first time), my client's CFO and I are interested in pursuing the acquisition of "cyber risk" insurance to cover the contingency of data breach and the cost of the subsequent necessary response.

Have any of you explored or purchased this type of product? If so, I have some more specific questions for you.

Thanks.

 

 

 

Parents
  • Look up PCI compliance.  If your organization becomes PCI compliant, your question will be answered.  This is an extensive process that covers PC security, both physical and network, as well as practices and procedures in handling private information like credit card account numbers, names, address, etc.  I will be presenting on this subject at the conference in San Antonio.

     

    Kindest regards,

    Allen Clark, MCSE +Security

    Manager of Information Systems

    The Music Center at Strathmore

    www.strathmore.org

     

     

     


    From: Tessitura Finance Forum [mailto:forums-finance@tessituranetwork.com] On Behalf Of John Levy
    Sent: Tuesday, May 12, 2009 7:16 PM
    To: Allen Clark
    Subject: [Tessitura Finance Forum] Cyber Risk Insurance

     

    I am assisting an arts consortium in Tennessee with the implementation of Tessitura. We have recently gone live with the product for subscription sales, and will enable all remaining ticket sales functionality in a few weeks.

    Since we are storing credit card information in Tessitura (and holding this data on site for the first time), my client's CFO and I are interested in pursuing the acquisition of "cyber risk" insurance to cover the contingency of data breach and the cost of the subsequent necessary response.

    Have any of you explored or purchased this type of product? If so, I have some more specific questions for you.

    Thanks.

     

     

     




    This message was sent automatically to you by www.tessituranetwork.com because you subscribed to the Tessitura Finance Forum. You may reply to this message to post to the Finance forum or visit the site to search, read and post to the forums. In the interest of keeping the forum posts from becoming cluttered, we encourage you to delete previous message text from your reply before sending. Thank you!

  • Former Member
    Former Member $organization in reply to Allen Clark

    Allen,

    Thanks for the response.

    I'm all over and very familiar with the content of PCI DSS and compliance with it. As I'm sure you know, PCI DSS doesn't mandate cyber risk insurance, doesn't speak to the types of insurance needed, and doesn't suggest relevant liability coverage amounts based on transaction volume.

    My question is: have you purchased or participated in decision-making around the purchase of this type of cyber risk insurance product?

Reply
  • Former Member
    Former Member $organization in reply to Allen Clark

    Allen,

    Thanks for the response.

    I'm all over and very familiar with the content of PCI DSS and compliance with it. As I'm sure you know, PCI DSS doesn't mandate cyber risk insurance, doesn't speak to the types of insurance needed, and doesn't suggest relevant liability coverage amounts based on transaction volume.

    My question is: have you purchased or participated in decision-making around the purchase of this type of cyber risk insurance product?

Children
No Data