Cyber security insurance
Cyber Insurance Need & Strategy
Session 4
September 22, 2022
Agenda
| 1 | Purpose of Cyber Insurance |
| 2 | Essential Cyber Insurance Coverage Elements |
| 3 | Cyber Insurance as a Risk Management Tool |
| 4 | Assignment 3 Introduction |
| 6 | Discussion |
2
3
Enables innovation and adoption of technology
Cyber Insurance policies start to emerge
Coverage for electronic business interruption introduced
First-Party coverage introduced in response to California Security Breach and Information Act
Standalone cyber insurance as we know it today begins to emerge as a specialty coverage
Cyber insurance is a standard coverage
1990’s
2000’s
2003
2010’s
Today
Abbreviated History of Cyber Insurance
CryptoLocker
The first “crypto” malware
First Patch Tuesday
First iPhone
9 million Americans work remotely in 2019*
27.6 million Americans work remotely today*
NIST Introduces Framework for Secure Software Development
*Source: https://www.census.gov/newsroom/press-releases/2022/people-working-from-home.html
3
4
Directly addresses cyber losses not covered elsewhere
Charlie
4
5
Option to transfer risk
Transfer
Residual risk the organization can’t accept, control or avoid is transferred. This is why cyber insurance exists.
Accept
All organizations must accept some risk. This requires the ability to identify, quantify and assess business cyber risks.
Control
Organizations can buy down their risk with effective controls. This helps balance risk acceptance vs risk transfer.
Avoid
Not always an option, but some risks can be avoided.
Unfortunately, this is really hard to figure out!
Humans are vulnerable, software is vulnerable and no matter what anyone tells you you cant model cyber risk perfectly. Cyber insurance is really important right now and it’s something we need to have around in the future.
5
Organizations can use Cyber Risk Quantification (CRQ) tools to help determine the value of residual risk to insure.
6
Cyber Risk Transfer (continued)
Source - https://chubbcyberindex.com/#/splash
7
Supports Contract Requirements
Cyber Insurance: The [contractor/subcontractor/vendor] shall maintain Cyber Liability and First Party Breach Response Coverage with limits not less than $TBD per occurrence and $TBD in the aggregate to be maintained for the duration of the term of this Agreement. Coverage should include at a minimum Privacy Liability for failure to protect personal private information, corporate confidential information, or any other non-public information of which the [contractor/subcontractor/vendor] is responsible for maintaining integrity, availability and confidentiality; Network Security liability for failure to prevent the spread of a cyber incident; First Party Data Breach Expense coverage for the [contractor/subcontractor/vendor] expenses to respond to a network security or privacy incident.
Essential Cyber Insurance Coverage Elements
Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.
8
9
Essential Cyber Insurance Coverage Elements
Third-Party Cyber Liability
First-Party Cyber Event Expenses
Data and Network Restoration Expenses
Business Interruption and Extra Expense
Cybercrime
9
10
Liability to Others
Third-Party Cyber Liability
Network Security and Data Privacy Liability
Media Liability
Regulatory proceedings, fines & penalties
Source: https://www.forbes.com/sites/edwardsegal/2022/02/05/ftc-announces-final-settlement-over-equifaxs-2017-data-breach/?sh=7504cc06565a
10
11
Direct expenses to respond to a cyber incident
First-Party Cyber Event Expenses
Legal guidance
IR/Forensics
Incident handling/containment
Notification & credit monitoring
PR & crisis communications
PCI-DSS fines & penalties
- NetDiligence Cyber Claims Study 2021
11
12
Restoring network and data after a cyber incident
Data and Network Restoration Expenses
Data restoration
Network restoration
Software & computer program restoration
12
13
Lost income during time of cyber incident disruption
Business Interruption and Extra Expense
Lost income during time of cyber incident-triggered technology disruption
Extra expenses to get back up and running
Lost income due to reputation damage
Source - https://portswigger.net/daily-swig/toyota-shuts-down-production-after-cyber-attack-on-supplier
13
Theft of insured’s funds by electronic/cyber means
Your Employees
The Fraudster
Your Vendors
Fraudster intercepts invoices from your vendors and changes payment instructions.
You think you are paying your vendor, but you are really paying the fraudster
Fraudster compromises your vendors email or impersonates one of your contacts.
Cybercrime
Electronic theft
Social engineering
Funds transfer fraud
Telecom theft
Ransom payments
14
Mike
14
Cyber Insurance as a Risk Management Tool
Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.
15
Cyber Insurance does more than pay claims
4
Provides a place to turn for help during a crisis event
Gently forces businesses to follow Cyber Incident Response best practices
Provides access to cybersecurity vendors that are pre-approved and vetted
Support for unknown or unanticipated cybersecurity events
Serves as a backstop behind good cybersecurity controls and policies
Ever expanding Pre-Breach resources to minimize losses and accelerate recovery
16
Cyber insurance is a place to turn for help
17
17
Supports cyber incident response best practices
Recover
Detect
Respond
Incident Classification | Claim Reporting | Incident Response Engagement
Planning & Testing | External IR Team | Provider Pre-Approvals| Coordination with Carrier | Documentation
Remediation & Improvements| Renewal Preparation | Claim Mitigation Strategy
18
The cyber insurance claim process follows cyber incident response best practices and most claims are led by a 3rd party data privacy attorney. This helps guide decision making and protect attorney client privilege.
Service providers, like incident handling, response and forensic investigation services are included in coverage and hired by the data privacy attorney on behalf of the client.
Engagement with external entities like law enforcement, government officials and even cyber criminals demanding ransom payment are handled and/or guided by trusted advisors recommended by the cyber insurance carrier.
18
Post-incident cybersecurity resources
19
19
Support for unknown and unanticipated cybersecurity events
20
Defenders need to succeed 100% of the time
Attackers only need to succeed once
Oh S!#*
20
Backstop behind controls
21
Cyber Insurance is not a replacement for cybersecurity this!
In today’s environment many foundational controls are required in order to qualify for cyber insurance.
However, no organization is 100% secure and it is not possible to ever fully implement a cybersecurity strategy. Good organizations have a 2-3 year roadmap. Cyber insurance provides a backstop behind controls and cybersecurity gaps.
Source - https://www.cisecurity.org/controls/implementation-groups
21
22
Pre-breach loss control resources
Source - https://control.coalitioninc.com/
Assignment 3 Overview
Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.
23
24
Instructions (Delete before submitting)
Pick the title slide that aligns with your organization (Healthcare, Manufacturing, Non-profit or Legal) and delete the others. Please also be sure to enter your name on the title slide.
In 3-5 slides please present how cyber insurance would help your organization by following these guidelines:
Slide 1: Identify a few (3-4 is fine) key cyber insurance coverage elements that you think might help your organization manage cyber risk. Use the risk profile you created in Assignment 2 as your guide. Try to align Gaps or Requirements you found with insurance coverage.
Slide(s) 2-3: On the next 1-2 slides justify your reasoning for selecting the cyber insurance coverage elements you identified in the previous section. Provide examples of gaps, requirements or other risk management needs, and briefly explain how the coverages you are considering align with these exposures.
Slide (s) 3-5: Cyber insurance does more than pay claims. What are a few elements over and above paying claims your organization may be able to use to further cybersecurity or risk management objectives?
Note: feel free to pick your own titles for each slide
Please do your best to make the slides compelling. Don’t just write a list of things. If you need more room to explain something and don’t want your slides to be overly cluttered, feel free to add additional text in the notes section.
Keep in mind you will NOT be presenting these so your slides will need to stand on their own. Again, feel free to use notes section to provide additional information that does not fit on your slides.
All final submissions should be a minimum of 3 slides and a maximum of 5-6 content slides (Title, section breaks and any placeholders at the end do not count as content slides).
Questions & Discussion
25
image1.png
image2.png
image5.png
image11.png
image19.svg
.MsftOfcThm_Background2_lumMod_25_Fill_v2 { fill:#3B3B34; }
image12.png
image13.svg
image14.png
image15.svg
image16.png
image17.svg
.MsftOfcThm_Accent4_Fill_v2 { fill:#51284F; }
image18.png
image27.png
image20.png
image21.png
image22.png
image23.png
image24.svg
.MsftOfcThm_Background1_Fill_v2 { fill:#FFFFFF; }
image25.png
image26.svg
.MsftOfcThm_Background1_Fill_v2 { fill:#FFFFFF; }
image35.svg
image28.png
image29.svg
image30.png
image31.svg
image32.png
image33.svg
image34.png
image36.png
image37.svg
.MsftOfcThm_Accent1_Stroke_v2 { stroke:#005092; }
image38.png
image39.png
image40.jpg
image41.png
image42.svg
.MsftOfcThm_Accent1_Stroke_v2 { stroke:#005092; }
image43.png
image44.png
image45.png
image46.svg
.MsftOfcThm_Accent1_Stroke_v2 { stroke:#005092; }
image47.jpg
image48.png
image49.svg
.MsftOfcThm_Accent1_Stroke_v2 { stroke:#005092; }
image50.png
image58.svg
image59.png
image60.svg
image61.png
image62.svg
image63.png
image64.svg
image65.png
image66.svg
image51.png
image52.svg
.MsftOfcThm_Text1_lumMod_65_lumOff_35_Fill { fill:#595959; }
image53.png
image54.svg
image55.png
image56.svg
.MsftOfcThm_Accent2_Fill { fill:#ED7D31; }
image57.png
image4.png
image67.png
image68.png
image69.png
image70.png
image71.png
image72.png
image73.png
image74.png
image75.png
image76.png
image84.png
image85.svg
image86.png
image87.svg
image77.jpeg
image78.png
image79.svg
image80.png
image81.svg
image82.png
image83.svg