Cyber security insurance

profileBfh
5.ChallengesofInsuringCyberRisk_EvolutionofCyberInsuranceMarket.pptx

Challenges of Insuring Cyber Risk & Evolution of Cyber Insurance Market

Session 4

September 29, 2022

Agenda

1 Assignment 2 – TPRM Clarification
2 Breakout 1 – 25 Years: Cyber Insurance Journey
3 The Evolution of Cyber Insurance
4 Breakout 2 – Cyber Insurance Has a Big Problem
6 Challenges of Insuring Cyber Risk

2

3

Third Party Risk Management (TPRM)

*Source: https://www.cisecurity.org/controls/cis-controls-navigator/ and https://www.optiv.com/cybersecurity-dictionary/tprm-third-party-risk-management

“Third-party risk management (TPRM) is the programmatic process of analyzing and controlling risks presented to an organization, its data, operations and finances by parties other than the organization itself.

 Business processes and supporting technology platforms are applied to manage, monitor and mitigate risks to the organization created by interdependencies with third-party business partners (such as suppliers, vendors, cloud technology providers, etc.), as well as their third- or nth-parties. 

 TPRM program is one critical component of a comprehensive integrated risk management (IRM) program supporting an organization’s governance, risk and compliance (GRC) strategy.”

- Optiv Cybersecurity Dictionary

3

4

Breakout #1 - 25 Years: The Journey of Cyber Insurance

Group 1: Managing General Agents (MGAs)are mentioned in the article. Why do you think these entities that were typically used for Construction Risks used for cyber insurance?

Group 2: Early cyber insurance required a vulnerability assessment and the insured to remediate “high vulnerabilities” in 30 days. This type of requirement did not last long, why do you think carriers moved away from strict requirements like this?

Group 3: By 2017 the cyber insurance market was booming and Private Equity firms were eager to invest in cyber insurance MGAs. By 2020 things started to change and the cyber insurance market started to “harden.” What are some factors that caused this shift in a few short years?

Group 4: In today’s cyber insurance market, the cost of coverage is up and organizations must have strong cybersecurity protections in place to even qualify for coverage. Do you think this will have a positive or negative long-term impact on the cyber insurance industry?

https://www.insurancejournal.com/news/national/2022/07/06/674709.htm

The Evolution of Cyber Insurance

Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.

5

6

Cyber Insurance key players

Insurer (Carrier/InsurTech)

Cyber Insurance Distribution Model

Broker

Insured

Broker/Agent

Owns relationship with insured

Maintains and provides access to cyber insurance markets

Represents Insured to cyber insurance carrier(s) – including assigning preferred vendors

Assists with coverage reviews, claim support as well as other risk management services

Insurer/Carrier

Establishes underwriting requirements

Develops policy language, terms and conditions

Controls appointment and approval of response vendors

Pays Claims

Determines coverage

Insured

Entity covered by the cyber insurance policy

Required to follow terms and conditions of policy in order to receive coverage

Responsible for requesting any post claim/incident response vendors that deviate from carrier panel

Breach Coach: Appointed by carrier or pre-selected by client; Responsible for hiring cyber forensics providers; Leads investigation; Communicates directly with client and incident response providers

6

7

Traditional Cyber Insurance Carriers

7

Common Attributes of Traditional Cyber Insurance Carriers

These carriers typically offer “Admitted” options

While they have a specialized cyber insurance business unit, they will write multiple lines of commercial insurance coverage

Often takes longer for these types of carriers to revise coverage forms and add endorsements

Often work through traditional insurance distribution channels (direct to retail agents and brokers)

Often household or known names in the insurance marketplace

7

8

MGAs, Specialist Underwriters & InsurTech Market

8

Common Attributes

Often start out as non-admitted options

Some may offer other lines of specialized coverage, but many offer cyber and tech insurance exclusively

Often backed by a large insurance market like Lloyd’s of London or a very large traditional insurance or reinsurance carrier

Specialized insurance entity that is vested with underwriting authority from a large insurance market like Lloyd’s of London or another large insurance or reinsurance carrier

Often work through non-traditional distribution channels or through Wholesalers

Often, but not always, more technology and cybersecurity focused especially with underwriting and loss control

8

9

Admitted vs. Non-Admitted Carriers

9

Non-Admitted Carriers

Are regulated entities just like Admitted carriers, but does not necessarily have to adhere to all laws and regulations of each individual state

Do not pay into the state guarantee fund so if the carrier or company becomes insolvent there is a risk claims will not be paid

Do not have to file policy forms, endorsements or rates so are able to adapt coverage more quickly

In order to place coverage, brokers and agents may have to follow due=diligent search requirements if carrier is not on an “exportable” list

Taxes and fees are collected separately

Often a market for non-traditional or risks that are more difficult

Admitted Carriers

Must adhere to laws and regulations of each individual state Insurance Commissioner

Pay into the state guaranteed fund administered by each state Insurance Commissioner

Must file all forms, endorsements and rates with the Insurance Commissioner of each state

Pay state taxes and fees on behalf of insured (already included in premiums)

Insureds in some states can appeal to the Insurance Commissioner for claim disputes

Generally the go-to option for traditional insurable risks

9

10

Cyber Insurance Coverage Origins

Third-Party Cyber Liability

Data and Network Restoration Expenses

Business Interruption and Extra Expense

Network Security and Data Privacy Liability

Media Liability

Regulatory proceedings, fines & penalties

Data restoration

Lost income during time of cyber incident-triggered technology disruption

Extra expenses to get back up and running

Network Extortion

10

11

Coverage Restrictions

Specified Incidents
SolarWinds Orion MS Exchange Server Vulnerability Log4j Kaseya Vulnerability Open Ports and Unpatched Attack Surface More to come?

12

Coverage Restrictions

Policy Language
Naming specific laws/regulations rather than blanket coverage Silent on investigation, containment & remediation due to network security failure Limiting restoration expenses to data & software, silent network restoration Narrow definition of computer system that does not address cloud, 3rd party or employee devices Restrictions related to vulnerabilities of 3rd party product

13

Coverage Restrictions

Sublimits and Waiting Periods
Reduced limits on individual coverages to cap the amount the carrier will pay out for a specific loss Increasing the waiting period of business interruption claims Adding “co-insurance” to ransom payments and other coverages claims Adding “co-insurance” and coverage limitations to claims resulting from unpatched or unsupported software

14

Ransomware Payment Restrictions

To help reinforce OFAC ransomware payment restrictions carriers are starting to add Endorsements to policies

Watch out for overly broad and confusing requirements that extend beyond OFAC to European and other foreign guidelines.

Typical OFAC Endorsement

15

Coverage for Cyber Terrorism Is Changing

Carriers can no longer be silent on cyber terrorism coverage. This may not always be a good thing.

16

Cyber Terrorism Exclusion/Carveback Example

War Exclusion/Carveback Example

Any war, warlike operation, popular or military uprising, hostilities, insurrection, rebellion, terrorism (certified or not) by an individual or group or action taken by governmental authorities in hindering or defending against any of these.

This exclusion will not apply to Cyber Terrorism.

Cyber Terrorism Cyber terrorism means any actual or threatened attack by individuals or a group against a computer system, to advance ideological, social, religious, or political objectives, with the intent, in whole or in part to: cause harm to a computer system; or threaten an entity or person to further objectives.

Lloyd’s 2021 Addition of Carveback for “Innocent Bystanders” “Paragraph 1.3 shall not apply to the direct or indirect effect of a cyber operation on a bystanding cyber asset.”

Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.

“1.1. war or a cyber operation that is carried out in the course of war; and/or 1.2. retaliatory cyber operations between any specified states leading to two or more specified states becoming impacted states; and/or 1.3. a cyber operation that has a major detrimental impact on: 1.3.1. the functioning of a state due to the direct or indirect effect of the cyber operation on the availability, integrity or delivery of an essential service…

16

17

Cyber insurance in the news

17

18

Underwriting Evolution

2015-2019: Short Form Applications

Today: Long Form Applications & Analytics

Challenges of Insuring Cyber Risk

Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.

19

20

Breakout #2 – Cybersecurity Insurance has a Big Problem

Group 1: The article points out that the cyber insurance industry lacks historical loss data. The industry has been around for 25 years, why do you think we don’t have the data required? How does a lack of data impact underwriting cyber insurance policies?

Group 2: The article briefly mentions that “4 reinsurers account for more than 60% of premium” in the cyber insurance market. Why do you think this is a potential problem?

Group 3: The author of this article uses a good analogy to describe what organizations should do in the current cyber insurance market. He says, “I’m an avid cyclist, and I have health insurance, but that doesn’t mean I don’t need a good helmet, too.” How does this apply to cyber insurance based on what we have been discussing in class so far?

Group 4: In today’s hard cyber insurance market many business may not be able to afford the cyber insurance coverage they need. Towards the end of the article (2nd to last paragraph) the author provides a strategy for achieving desired cyber insurance coverage limits over time. What does the author suggest and do you think this is realistic for most organizations?

https://hbr.org/2021/01/cybersecurity-insurance-has-a-big-problem

21

Cyber risk is different

The Ludic Fallacy “The attributes of the uncertainty in real life have little connection to the sterilized ones we encounter in [models] and games.” — Nassim Nicholas Talib

Sterilized Risk Assumptions

Cyber Risk Realities

Lack of shared historical data and difficult to effectively quantify cyber risk

Historical data and industry-accepted methodology to quantify risk

Law of large numbers is bad - more policies written leads to more claims and less profits

Law of large numbers is good – risk exposure and loss ratio decreases with more policies written

What we don’t know is more important in assessing risk, no effective strategy for carriers to segment book (why control-based discounts don’t work)

What we know is very helpful when assessing risk (why control-based discounts work)

Forecasting and predicting errors could make cyber risk uninsurable

Forecasting and models help predict losses, facilitating a profitable insurance industry

21

22

Insuring Cyber Risk Is Complicated

Without changes, the cyber insurance industry as we know it may not be sustainable at the time it is needed most.

Underwriting & Cybersecurity Alignment

Policy Cost & Industry Profitability

Cyber Advisory Gaps

Evolving Threat Landscape

22

23

Evolving Threat Landscape

Proofpoint reports that “66 percent of CISOs feel their organization is unprepared to cope with a targeted cyberattack in 2021”

The Council of Insurance Agents & Brokers reported an average increase of 34.3% in Q4 2021. Notably, an increase of this magnitude has not been reported since the market fluctuations that followed 9/11.

+

=

77% of businesses surveyed by Advisen in 2020 purchase cyber insurance.

Cyber insurers can’t do this alone.

A sustainable cyber insurance market requires a pool of insurable risk that maintains a commonly accepted cybersecurity maturity baseline with the ability to adapt to the dynamic threat landscape.

Maturity

23

24

Underwriting & Cybersecurity Alignment

Limited in-term loss control engagement

Claims & IR Plan not integrated; Renewals follow point in time approach

Business Integration

Technical Consulting + Integration

Operational Execution

Strategy | Design | Program

Develop | Validate |Implement| Operate

Incident Response | Remediate

Identify

Protect + Detect

Respond + Recover

Policy Admin & Loss Control

Underwriting & Applications

Claims & Renewals

Point in time underwriting, limited ability to validate controls

Establish acceptable insurability baseline and methodology for validation

Regular check points to identify changes to baseline, mitigating emerging threats & implement meaningful loss control strategies

Renewals based on in-term successes & threat landscape; IR & Recovery aligned with insurance

Underwriting & Cybersecurity

Current State

Desired State

Cyber risk is underwritten at a single point in time and is based on responses to questionnaires. Carriers write policies without owning the relationship or ability to test or validate controls. Carriers provide loss control solutions and underwriting requirements. Brokers are responsible for explaining underwriting requirements and assisting insured to implement services and requirements provided by carrier.

Underwriting based on questionnaire responses and some external data.

Minimal cyber risk visibility during policy term.

Limited ability to implement loss control in response to changing risk landscape and attack surface.

24

25

Cybersecurity Advisory Gap in Traditional Insurance Distribution Model

Establishes and enforces underwriting requirements & handles claims.

Insurer (Carrier/InsurTech)

De facto cybersecurity advisor, collect underwriting info, validate controls?

Cybersecurity Partner

Broker

Implementation, prioritization and execution of cyber strategies and coordination with broker/carrier.

Technology-independent cybersecurity support aligned with cyber insurance process.

Insured

Advisory Gap

Cyber insurance is becoming a cybersecurity solution.

Brokers are now required to become experts on technical insurance products, advise on cyber risk management best practices and provide incident response support.

Cyber insurance becoming as much a cybersecurity solution as it is an insurance product.

Underwriting is more technical, but carriers don’t always work directly with insureds to implement and validate controls. Brokers that are used to traditional business insurance are now required to become experts on technical insurance products and advise on cyber risk management best practices and provide incident response support.

The typical middle market insurance buyers (CFO/COO) often assumes CISO and CIO responsibilities but needs help sorting through the cybersecurity noise to make meaningful change.

25

26

Cyber insurance is challenging the law of large numbers

—Advisen Information Security and Cyber Risk Management Survey, 2020

2011-2020 Cyber Insurance Purchasing Trend

US Cyber Loss Ratio 2016–2020

More business than ever are purchasing cyber insurance to manage cyber risk.

Policies were initially priced to encourage adoption and carriers have been pushed by competition to drive premiums down while expanding coverage.

26

Series 1 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 35 44 52 52 61 65 65 75 78 79

Standalone

2016 2017 2018 2019 2020 45 35.4 34.4 47.1 72.8 Package 2016 2017 2018 2019 2020 53.3 28.8 36.799999999999997 42.3 58.6 Total 2016 2017 2018 2019 2020 47.6 32.4 35.4 44.9 67

27

Premiums Are Up, Yet Demand Is Increasing

Premium increases are necessary as cyber insurance was often underpriced as carriers were competing for market share. As the threat landscape volatility continues premium increases alone are not enough to create a long-term sustainable market.

Of the 72% of accounts in Q4 2021 with a pricing increase greater than 20%,  39% of the accounts had an increase of 50% or more.

27

28

Reinsurance & Capacity

Premium/Risk

Retention/Deductible

Premium/Risk

Insureds (Businesses)

Insurers (Carriers)

Reinsurers

Lloyd’s of London

Claims

Claims

Claim Payments

Claim Payments

“As cyber risk is growing, the cyber insurance market has stalled. Insurers are taking bigger losses, seeing tighter margins, and relying more heavily on reinsurance to cover their own risk. The result is that companies are getting less protection for more money.”

Source: https://hbr.org/2022/03/the-cyber-insurance-market-needs-more-money

More business than ever are purchasing cyber insurance to manage cyber risk.

Policies were initially priced to encourage adoption and carriers have been pushed by competition to drive premiums down while expanding coverage.

28

29

Ransomware Is Still Most Common Cause of Claims

—Netdiligence Cyber Claims Study 2021

Top 5 Numbers of Claims - SMEs

Average Costs of Ransomware

29

30

Cyber Insurance claims are expensive

Percentage of Annual Claims by Annual Revenue

- Chubb Cyber Index

SME’s drive claim frequency, claims from large organizations are more costly. Both SMEs and large organizations must continue to balance investments in cybersecurity protections and cyber insurance.

- NetDiligence Cyber Claims Study 2021

Average Costs for All Claims

Series 1

Under $25M $25.1M–$150M $151M–$500M Over $501M 0.34200000000000003 0.27300000000000002 0.19700000000000001 0.188

Questions & Discussion

31

image1.png

image2.png

image11.png

image5.png

image12.png

image13.svg

.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }

image14.png

image15.svg

.MsftOfcResponsive_Stroke_ffc000 { stroke:#FFC000; }

image16.png

image17.svg

.MsftOfcResponsive_Stroke_ffc000 { stroke:#FFC000; }

image25.png

image18.png

image19.png

image20.png

image21.png

image22.png

image23.png

image24.png

image33.png

image34.png

image35.png

image36.png

image26.png

image27.png

image28.png

image29.png

image30.png

image31.png

image32.png

image37.png

image38.svg

image39.png

image40.svg

image41.png

image42.svg

image43.png

image44.png

image45.png

image46.png

image47.png

image48.png

image49.png

image50.png

image51.png

image52.png

image53.png

image54.png

image62.svg

.MsftOfcThm_Accent5_Fill_v2 { fill:#FFB500; }

image55.png

image56.svg

.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }

image57.png

image58.svg

.MsftOfcThm_Accent1_Fill_v2 { fill:#005092; } .MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }

image59.png

image60.svg

.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }

image61.png

image69.svg

.MsftOfcResponsive_Stroke_ffc000 { stroke:#FFC000; }

image70.png

image71.svg

.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }

image72.png

image73.svg

.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }

image63.png

image64.png

image65.svg

.MsftOfcResponsive_Stroke_ffc000 { stroke:#FFC000; }

image66.png

image67.svg

.MsftOfcResponsive_Stroke_ffc000 { stroke:#FFC000; }

image68.png

image75.svg

.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }

image76.png

image77.svg

.MsftOfcThm_Accent1_lumMod_60_lumOff_40_Stroke_v2 { stroke:#259CFF; }

image78.png

image79.svg

.MsftOfcThm_Accent6_Stroke_v2 { stroke:#7BAFD4; } Plan Build Run

image74.png

image81.svg

.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }

image80.png

image82.png

image90.svg

.MsftOfcThm_Accent6_Fill_v2 { fill:#7BAFD4; }

image91.png

image92.svg

image93.png

image94.svg

image95.png

image96.svg

image83.png

image84.svg

.MsftOfcThm_Accent6_Fill_v2 { fill:#7BAFD4; }

image85.png

image86.svg

.MsftOfcThm_Accent6_Fill_v2 { fill:#7BAFD4; }

image87.png

image88.svg

.MsftOfcThm_Accent6_Fill_v2 { fill:#7BAFD4; }

image89.png

image97.png

image98.png

image99.png