Connect with Our Team

Table of Contents

    Key takeaways

    • Treat the Christie’s hack as a warning that any internet-dependent business can lose revenue and trust when cyberattacks disrupt core systems
    • Strengthen your first line of defense by enforcing multi-factor authentication, training employees, reviewing vendors, and updating your business continuity plan
    • Back up your risk strategy with cyber liability insurance that helps cover expenses from breach response, business interruption, reputational harm, and third-party claims

    The ongoing hack of Christie’s auction house immediately ahead of a planned $840M art sale is an object lesson in the realities of cyber risk for today’s internet- and technology-dependent business world.

    ARTnews has a  nice overview of the situation. In short, Christie’s main site has been down for five days, and there is currently no indication from the company of when it may return. Christie's has pulled together a work-around, but it’s clear the hack has caused the venerable auction house to scramble. The implications for those selling and planning to buy art in the auction are unclear.

    So what happened? How did the hack occur?

    That’s not clear yet, either. Christie’s has not released detailed information on the breach. What is clear is that fine art is a consistent target for cyberattacks, and broad cyber liability coverage is vital in these instances. Why? Because fashioned properly, it’s a backstop that helps protect your business, and recover and rebuild from a cyber incident. A good cyber liability coverage program will hit all the key exposures of such an attack:

    • Business interruption, sometimes known as business income loss
    • Breach response
    • Reputational harm
    • Third-party liability coverage

    Additionally, your first line of defense is effective risk management. The fine art world is taking the Christie's incident as a reminder to revisit cyber risk management controls. These include:

    • Multi-factor authentication enabled on all systems
    • An up-to-date and vetted business continuity plan
    • Consistent cybersecurity training for all employees
    • Vendor cybersecurity reviews

    The cyber threat landscape continues to intensify. For questions or more information, you can reach a cyber insurance specialist through our secure contact form.

     

    About the author

    Allen Blount is a Cyber Liability leader at Brown & Brown, where he guides organizations on cyber insurance, cyber risk management, and analyzing incidents like the Change Healthcare cyberattack. Before his insurance career, he practiced law.