• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
  • Advertise
  • About Craft Brewing Business

Craft Brewing Business

Professional Insight, Unfiltered

Craft Brewing Business Craft Brewing Business
  • News
  • Business & Marketing
  • Packaging & Distribution
  • Equipment & Systems
  • Ingredients & Supplies
  • Webinars & White Papers
  • News
  • Business & Marketing
  • Ingredients & Supplies
  • Packaging & Distribution
  • Equipment
  • Webinars & White Papers
  • COVID-19

Cyber security for breweries: We assess the risks and how to stay protected

May 22, 2017Chris Crowell

cyber security brewery
Step 1: Download some lock clip art to put over your o’s and 1’s.

One day, a payroll accounting employee at Scotty’s Brewhouse in Indianapolis received an email from the company’s CEO. The email requested the employee send all 4,000 of the company’s employee W-2 forms in PDF format. The employee did.

Turns out that email did not come from the CEO. It was a scam. Those 4,000 W-2s were sent to god knows who for god knows what. This style of scam — phishing or social engineering — is a little more sophisticated than all of those Nigerian princes out there who just need your bank account routing number to send you their riches. These emails come claiming to be from the IRS or Fed-Ex or a company’s CEO.

With W-2s, hackers then immediately file false tax returns to obtain refunds, which is tax fraud. Since the W-2 contains personally identifiable information, a brewery in Scotty’s situation must notify all victims of this hack, provide and pay for credit monitoring and indemnify victims who may suffer financial loss due to tax fraud. Then of course there is the negative stigma and possible loss in reputation that comes with such a headline, which may require additional public relations expenses to overcome.

Here are your cyber security risks

Web-application attacks are the most common risks, accounting for 40 percent of all data breaches. They’re usually the result of employees on the internet visiting a site with a virus or malware. When they click on a certain program, it ends up infecting the entire insured system, causing a breach. Employees can also be responsible for other miscellaneous errors that cause a breach, such as losing paper files that contain personal information, leaving personal information visible online and mailing personal information to others by mistake.

How and when craft breweries can use unpaid help

Breweries need to be careful, not just to avoid these email tricks, but also in how they handle credit card payments — POS intrusion is the second-leading cause of data breaches. Then there are online sales and transactions that can be denied by hacks that disrupt operations, leading to a loss of business. In certain situations, cyber-attackers will infect the brewery’s computer system with ransomware and encrypt data. The hackers then demand a ransom for the encryption keys. Without this information, the brewery will no longer have access to that data and will either have to pay the ransom or other companies a large sum of money to resolve the issue.

How to protect yourself

We asked Larry Chasin, insurance program manager at BreweryPak, what his firm recommends for breweries in need of stepping up cyber security protection.

“Considering POS intrusion is the second leading cause of a breach, merchants must become more compliant in accepting credit cards with chip technology,” he said. “In fact, as of October 1, 2015, all merchants should have the proper processing technology for accepting chip cards. However, most merchants in the U.S. do not, as the estimated number in compliance sits below 50 percent.”

Merchants without this chip card processing technology are more vulnerable to a data breach and won’t be reimbursed by the payment card industry for fraudulent credit card transactions. For example: Purchases made from a stolen credit card will not be compensated if the merchant isn’t following the “standards” for credit card processing technology. On top of that, they are subject to fines from the payment card industry which are typically covered under Cyber Risk coverage.

Cyber Risk coverage typically addresses third-party liability of insureds, as well as wrongful acts including infringement of copyright or trademark and defamation. These are typically associated with content posted to a website. Breaches that may reveal personally identifiable information of others or cause transmission of a virus to a third party should also be covered. The first-party expenses breweries should think about include extortion threats, business income, public relations, legal fees and credit monitoring.

Note that these exposures are not covered under the typical property and liability policy. In order to address these risks, specialized endorsements and policies must be made. We’d suggest finding an insurer that specializes in breweries and wineries and understands their unique risk exposures is best-suited to provide brewery owners with the cyber coverage options that are right for you.

“From a risk management perspective, breweries should make Cyber Risk prevention a high priority for all levels of leadership,” Chasin said. “Cyber Risk prevention is no longer just an IT issue but a responsibility to be shared by all employees no matter their position. It’s important to have policies and procedures in place regarding the handling of personal information and social media use. An organization’s security is only as strong as its weakest link, making employee training and awareness a priority. Limit data access to only authorized personnel and properly train employees on cyber security issues to keep your company protected.”

Lessons learned from a $90K beer heist: Do you have the proper theft controls in place?

brewery risk management
How 2020 has (and hasn’t) changed craft brewery risk management
insurance-risk-exposure
7 crazy insurance claims ─ could your brewery fall victim?
cyber security brewery
Pandemic or not, cyber risk still a big threat for breweries
cyber-attack
Drizly’s customer data was stolen, here’s some cyber security advice for the beverage industry

Reader Interactions

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Latest News

  • State of California Craft Beer: Covid recovery challenged by competition, consolidation
  • MicroStar Logistics launches Network Services Division to manage reusable plastic pallets for the beer Industry
  • Analyst speculates on Heineken acquiring Boston Beer, stock jumps
  • United States Bartenders’ Guild now has access to WOTVS Hospitality Assistance Program

Sign up for our newsletter

unsubscribe from list

Most Popular Today

Recent Features

  • CCBA California Craft Beer SummitState of California Craft Beer: Covid recovery challenged by competition, consolidation
    March 23, 2023
  • Koga-brothers-karben4Karben4 Brewing to relaunch Ale Asylum brand
    March 20, 2023
  • 4 steps to understanding the filtration process in craft beer
    March 20, 2023
  • newbelgium_2023_wildnectar-shopping-basket_family_IMG_2Beyond beer: Examples of craft breweries exploring canned cocktails
    March 16, 2023
  • brooklyn 35 featureBrooklyn Lager turns 35 and more beers to know this week
    March 14, 2023
  • Backwoods Brewing to open a 19-acre resort called Party Acres in the Columbia River gorge this May
    March 13, 2023

Footer

  • Email Newsletter Sign Up
  • About Craft Brewing Business
  • Contact Us
  • Advertise on Craft Brewing Business
  • Media Kit Download
  • Privacy and Terms

© 2023 · CBB Media LLC