Skip to main content

SafeKey and Cyber Insurance Alignment

cyberinsurance.jpgWhyCyber-Insurance Password Management MattersProviders

Cyber-insurance policiesproviders in New Zealand areincreasingly becomingassess morewhether specifican aboutinsured business has implemented basicreasonable cybersecurityand hygieneappropriate security controls. ProvidersOrganisations such as IAG expectplace businessesparticular emphasis on access control and credential management, as these are commonly exploited during cyber incidents.

Failure to takemaintain reasonableadequate stepscontrols toin protectthese accessareas tomay theiraffect systems,the andoutcome password handling isof a key focus area.claim.

WhyPassword management as an insurability consideration

In the event of a cyber incident, insurers carewill abouttypically passwordsreview

Fromwhether anbasic insurer’s perspective, passwords are the front door to your business systems. Poorsecurity practices were followed. Practices such as:

  • Writing passwords on paper or in notebooks

  • Storing thempasswords in unencrypted text files or spreadsheets

  • Sharing loginscredentials between staff

  • Reusing the same passwordpasswords across multiple servicessystems

are seenwidely regarded as avoidable risksweaknesses.

If asuch cyberpractices incidentare occursidentified andduring an investigationinvestigation, showsan that passwords were written down or poorly managed, insurersinsurer may determineconclude that minimum security standards were not met. This can result in a claim beingreductions declinedor denial of cover, evenregardless ifof the breachoriginal itselfcause wasof external.the breach.

How SafeKey supports expectationsreasonable security controls

SafeKey is a New Zealand–hosted password management service designed to help New Zealand businesses alignmeet withcommonly theexpected typescyber-insurance of controls insurers like IAG expect to see in place.controls.

SafeKey helpsassists by:

  • RemovingEliminating thewritten needand toinsecurely write downstored passwords
    UsersCredentials canare access systemsstored securely and accessed without everbeing seeingdisclosed orto recording the actual password.users.

  • Enforcing strong, unique passwordscredentials
    Each system can haveuse itsa ownunique, complex password without increasing staffoperational effort.burden.

  • ControllingProviding centralised access centrallymanagement
    When someone leaves the business,User access can be removedmodified immediately,or reducingrevoked ongoingimmediately risk.when employment or roles change.

  • Reducing informaluncontrolled passwordcredential sharing
    Access is grantedmanaged through securestructured sharing,permissions notrather emails,than notes,informal orsharing memory.methods.

Stronger

Supporting evidence in the event of a claim

IfFollowing youra businesscyber needsincident, insurers may require evidence that appropriate controls were in place prior to makethe aevent. cyber-insurance claim, being able to show that youThe use of a managed password systemsolution, likesuch SafeKeyas SafeKey, demonstrates that the business took reasonable steps to protect access to systems and recogniseddata, securityaligning controlswith wereinsurer inexpectations place.for Thisrisk puts you in a far stronger position during an insurer’s assessment.management.

AReducing simplerisk stepto withboth serioussystems impactand insurance cover

WritingPoor downpassword passwordspractices isremain one of the easiestmost wayscommon factors identified during cyber-incident reviews. By eliminating the need to unintentionallywrite underminedown, yourreuse, or share passwords informally, SafeKey helps reduce operational risk and strengthens a stronger position when engaging with insurers.

SafeKey provides a practical, locally supported control that helps protect business systems — and helps ensure cyber-insurance cover.remains SafeKey replaces that risk with a simple, controlled, and NZ-supported solution, helping protect both your systems and your ability to rely on your insuranceeffective when it mattersis most.most needed.