Menu

Call us on 03450 21 21 51

Cyber insurance in a hard market: how to mitigate the risks
The SRM Blog

Cyber insurance in a hard market: how to mitigate the risks

Julia Wailes-Fairbairn

Written by Julia Wailes-Fairbairn

6th August 2021

Share this article

cyber insurance

Would you want to be the provider of insurance cover for a low-lying house in the middle of a flood plain during a period of heavy rain? How about a car you knew was going to be left unlocked and unguarded in a high-crime area for months on end? Wouldn’t you want to see that steps have been taken to reduce the risk before committing your financial backing? You would certainly have to ask yourself whether it made economic sense to insure something with such a high likelihood of a claim.

Put into that context, it would be easy to ask how anyone manages to make a model for cyber insurance work. After all, the most common saying in cybersecurity today is: “it’s not a case of if an attack will occur; it’s when it will occur.”

 

A hard market to navigate

To draw out the metaphor a little further, there is little doubt that the flood waters are rising in the cyber world today. Attacks have increased in both scale and frequency year on year, with ransomware attacks up 148% and email phishing attacks up by 64% in 2020. It is therefore not surprising that we find ourselves in a “hard” insurance market, characterised by higher premiums, stringent underwriting criteria and reduced capacity.

In the last twelve months cyber insurance premiums have risen by 32 per cent, reflecting the realities of the cyber security risk and the pressure on underwriting profitability.

Meanwhile global insurance giant AXA took a stand in May, now refusing to write cyber insurance policies in France which pay out for extortion payments and ransomware. This refusal to pay ransomware demands may turn out to be a trend that continues across other insurers, countries and risks.

A report by the Royal United Services Institute also found that some insurers are giving up writing cyber policies altogether, largely due to the impact of ransomware. Instead, these insurers are looking at ways to escape this unprofitable line of business. The result is that cyber risk will be increasingly difficult to obtain and those policies which are available will cost more – with more detailed underwriting processes. They will also have greater limitations and exclusions than ever before.

 

An even harder market for those who are not well-protected

Having been around for just twenty years, cyber insurance is a comparatively immature market. It is also extremely fast-moving with cybercriminals continually developing new tactics. The constant changes to the threat landscape make it a complex underwriting challenge.

One response is for insurers to change their approach. For example, there is “co-insurance”, introduced by insurer AIG in January for those with only average or below-level controls. With these policies, the client has to take on a proportion of the risk themselves, matching a proportion of the pay out with their own money. While this type of insurance is not yet widespread, it reflects the thought process of some insurers who are scaling back cover for risks that are not well-protected.

 

Cyber insurance is not a “catch all” solution

If you consider cyber insurance to be the solution that enables your organisation to bypass all information security protocols, then the reality may come as something as a shock. Because insurers are not prepared to shoulder the risk presented by lax controls, systems, processes or policies. They are also unlikely to repeat cover if a claim has been made, without stipulating future exclusions.

In the end, it is unlikely that insurance alone will provide the financial protection you are looking for. After all, the cost of a breach goes deeper than the value of the initial attack. There are fines and penalties imposed by statutory authorities to consider, which take account of the current level of security when the breach occurred. In addition, a breach can significantly undermine the reputation of a business, costing even more in the long term.

 

The best approach to mitigating risk

In many instances, cyber insurance is a valuable tool but it should be part of a multi-layered strategy for cyber resilience.

  1. Best practice

Achieving (and maintaining) compliance in recognised standards like the Payment Card Industry (PCI) Data Security Standard (DSS), Cyber Essentials (CE) or ISO 27001 has a two-fold benefit. Firstly, the standards provide frameworks for best practice in cyber and information security, giving clear guidance and direction. Secondly, compliance demonstrates to an insurance underwriter that you take the security of your systems and data very seriously indeed.

 

  1. Testing

Penetration testing is a requirement of PCI DSS and ISO 27001 and also for Cyber Essentials Plus. But the key is not to look for simple compliance, which may require only an annual test (or when changes are made), but to use testing as a proactive tool to enhance your security. This may include regularly scheduled automated pen tests, outside of the prescribed guidelines, and could extend to enhanced manual penetration testing. Here, experienced and highly qualified professionals delve into your system identifying potential vulnerabilities which may not be identified through automated tests. In this way you can take highly-targeted proactive measures to improve your risk posture.

 

  1. Engaging with experienced professional consultancy

When considering the cost of cyber security, it may sound counter-intuitive, but engaging with a professional consultancy can actually save you money. That is because they bring a wealth of experience, having worked across a range of sizes and sectors of business, using their skills to develop and deliver effective strategies which reduce your level of risk and promote business continuity. By scoping the exercise correctly at the outset, they will ensure you do not waste money or resource on unnecessary tools or services.