Cyber security insurance
Challenges of Insuring Cyber Risk & Evolution of Cyber Insurance Market
Session 4
September 29, 2022
Agenda
| 1 | Assignment 2 – TPRM Clarification |
| 2 | Breakout 1 – 25 Years: Cyber Insurance Journey |
| 3 | The Evolution of Cyber Insurance |
| 4 | Breakout 2 – Cyber Insurance Has a Big Problem |
| 6 | Challenges of Insuring Cyber Risk |
2
3
Third Party Risk Management (TPRM)
*Source: https://www.cisecurity.org/controls/cis-controls-navigator/ and https://www.optiv.com/cybersecurity-dictionary/tprm-third-party-risk-management
“Third-party risk management (TPRM) is the programmatic process of analyzing and controlling risks presented to an organization, its data, operations and finances by parties other than the organization itself.
Business processes and supporting technology platforms are applied to manage, monitor and mitigate risks to the organization created by interdependencies with third-party business partners (such as suppliers, vendors, cloud technology providers, etc.), as well as their third- or nth-parties.
TPRM program is one critical component of a comprehensive integrated risk management (IRM) program supporting an organization’s governance, risk and compliance (GRC) strategy.”
- Optiv Cybersecurity Dictionary
3
4
Breakout #1 - 25 Years: The Journey of Cyber Insurance
Group 1: Managing General Agents (MGAs)are mentioned in the article. Why do you think these entities that were typically used for Construction Risks used for cyber insurance?
Group 2: Early cyber insurance required a vulnerability assessment and the insured to remediate “high vulnerabilities” in 30 days. This type of requirement did not last long, why do you think carriers moved away from strict requirements like this?
Group 3: By 2017 the cyber insurance market was booming and Private Equity firms were eager to invest in cyber insurance MGAs. By 2020 things started to change and the cyber insurance market started to “harden.” What are some factors that caused this shift in a few short years?
Group 4: In today’s cyber insurance market, the cost of coverage is up and organizations must have strong cybersecurity protections in place to even qualify for coverage. Do you think this will have a positive or negative long-term impact on the cyber insurance industry?
https://www.insurancejournal.com/news/national/2022/07/06/674709.htm
The Evolution of Cyber Insurance
Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.
5
6
Cyber Insurance key players
Insurer (Carrier/InsurTech)
Cyber Insurance Distribution Model
Broker
Insured
Broker/Agent
Owns relationship with insured
Maintains and provides access to cyber insurance markets
Represents Insured to cyber insurance carrier(s) – including assigning preferred vendors
Assists with coverage reviews, claim support as well as other risk management services
Insurer/Carrier
Establishes underwriting requirements
Develops policy language, terms and conditions
Controls appointment and approval of response vendors
Pays Claims
Determines coverage
Insured
Entity covered by the cyber insurance policy
Required to follow terms and conditions of policy in order to receive coverage
Responsible for requesting any post claim/incident response vendors that deviate from carrier panel
Breach Coach: Appointed by carrier or pre-selected by client; Responsible for hiring cyber forensics providers; Leads investigation; Communicates directly with client and incident response providers
6
7
Traditional Cyber Insurance Carriers
7
Common Attributes of Traditional Cyber Insurance Carriers
These carriers typically offer “Admitted” options
While they have a specialized cyber insurance business unit, they will write multiple lines of commercial insurance coverage
Often takes longer for these types of carriers to revise coverage forms and add endorsements
Often work through traditional insurance distribution channels (direct to retail agents and brokers)
Often household or known names in the insurance marketplace
7
8
MGAs, Specialist Underwriters & InsurTech Market
8
Common Attributes
Often start out as non-admitted options
Some may offer other lines of specialized coverage, but many offer cyber and tech insurance exclusively
Often backed by a large insurance market like Lloyd’s of London or a very large traditional insurance or reinsurance carrier
Specialized insurance entity that is vested with underwriting authority from a large insurance market like Lloyd’s of London or another large insurance or reinsurance carrier
Often work through non-traditional distribution channels or through Wholesalers
Often, but not always, more technology and cybersecurity focused especially with underwriting and loss control
8
9
Admitted vs. Non-Admitted Carriers
9
Non-Admitted Carriers
Are regulated entities just like Admitted carriers, but does not necessarily have to adhere to all laws and regulations of each individual state
Do not pay into the state guarantee fund so if the carrier or company becomes insolvent there is a risk claims will not be paid
Do not have to file policy forms, endorsements or rates so are able to adapt coverage more quickly
In order to place coverage, brokers and agents may have to follow due=diligent search requirements if carrier is not on an “exportable” list
Taxes and fees are collected separately
Often a market for non-traditional or risks that are more difficult
Admitted Carriers
Must adhere to laws and regulations of each individual state Insurance Commissioner
Pay into the state guaranteed fund administered by each state Insurance Commissioner
Must file all forms, endorsements and rates with the Insurance Commissioner of each state
Pay state taxes and fees on behalf of insured (already included in premiums)
Insureds in some states can appeal to the Insurance Commissioner for claim disputes
Generally the go-to option for traditional insurable risks
9
10
Cyber Insurance Coverage Origins
Third-Party Cyber Liability
Data and Network Restoration Expenses
Business Interruption and Extra Expense
Network Security and Data Privacy Liability
Media Liability
Regulatory proceedings, fines & penalties
Data restoration
Lost income during time of cyber incident-triggered technology disruption
Extra expenses to get back up and running
Network Extortion
10
11
Coverage Restrictions
| Specified Incidents |
| SolarWinds Orion MS Exchange Server Vulnerability Log4j Kaseya Vulnerability Open Ports and Unpatched Attack Surface More to come? |
12
Coverage Restrictions
| Policy Language |
| Naming specific laws/regulations rather than blanket coverage Silent on investigation, containment & remediation due to network security failure Limiting restoration expenses to data & software, silent network restoration Narrow definition of computer system that does not address cloud, 3rd party or employee devices Restrictions related to vulnerabilities of 3rd party product |
13
Coverage Restrictions
| Sublimits and Waiting Periods |
| Reduced limits on individual coverages to cap the amount the carrier will pay out for a specific loss Increasing the waiting period of business interruption claims Adding “co-insurance” to ransom payments and other coverages claims Adding “co-insurance” and coverage limitations to claims resulting from unpatched or unsupported software |
14
Ransomware Payment Restrictions
To help reinforce OFAC ransomware payment restrictions carriers are starting to add Endorsements to policies
Watch out for overly broad and confusing requirements that extend beyond OFAC to European and other foreign guidelines.
Typical OFAC Endorsement
15
Coverage for Cyber Terrorism Is Changing
Carriers can no longer be silent on cyber terrorism coverage. This may not always be a good thing.
16
Cyber Terrorism Exclusion/Carveback Example
War Exclusion/Carveback Example
Any war, warlike operation, popular or military uprising, hostilities, insurrection, rebellion, terrorism (certified or not) by an individual or group or action taken by governmental authorities in hindering or defending against any of these.
This exclusion will not apply to Cyber Terrorism.
Cyber Terrorism Cyber terrorism means any actual or threatened attack by individuals or a group against a computer system, to advance ideological, social, religious, or political objectives, with the intent, in whole or in part to: cause harm to a computer system; or threaten an entity or person to further objectives.
Lloyd’s 2021 Addition of Carveback for “Innocent Bystanders” “Paragraph 1.3 shall not apply to the direct or indirect effect of a cyber operation on a bystanding cyber asset.”
Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.
“1.1. war or a cyber operation that is carried out in the course of war; and/or 1.2. retaliatory cyber operations between any specified states leading to two or more specified states becoming impacted states; and/or 1.3. a cyber operation that has a major detrimental impact on: 1.3.1. the functioning of a state due to the direct or indirect effect of the cyber operation on the availability, integrity or delivery of an essential service…
16
17
Cyber insurance in the news
17
18
Underwriting Evolution
2015-2019: Short Form Applications
Today: Long Form Applications & Analytics
Challenges of Insuring Cyber Risk
Proprietary and CONFIDENTIAL. Do Not Distribute. © 2022 Optiv Security Inc. All Rights Reserved.
19
20
Breakout #2 – Cybersecurity Insurance has a Big Problem
Group 1: The article points out that the cyber insurance industry lacks historical loss data. The industry has been around for 25 years, why do you think we don’t have the data required? How does a lack of data impact underwriting cyber insurance policies?
Group 2: The article briefly mentions that “4 reinsurers account for more than 60% of premium” in the cyber insurance market. Why do you think this is a potential problem?
Group 3: The author of this article uses a good analogy to describe what organizations should do in the current cyber insurance market. He says, “I’m an avid cyclist, and I have health insurance, but that doesn’t mean I don’t need a good helmet, too.” How does this apply to cyber insurance based on what we have been discussing in class so far?
Group 4: In today’s hard cyber insurance market many business may not be able to afford the cyber insurance coverage they need. Towards the end of the article (2nd to last paragraph) the author provides a strategy for achieving desired cyber insurance coverage limits over time. What does the author suggest and do you think this is realistic for most organizations?
https://hbr.org/2021/01/cybersecurity-insurance-has-a-big-problem
21
Cyber risk is different
The Ludic Fallacy “The attributes of the uncertainty in real life have little connection to the sterilized ones we encounter in [models] and games.” — Nassim Nicholas Talib
Sterilized Risk Assumptions
Cyber Risk Realities
Lack of shared historical data and difficult to effectively quantify cyber risk
Historical data and industry-accepted methodology to quantify risk
Law of large numbers is bad - more policies written leads to more claims and less profits
Law of large numbers is good – risk exposure and loss ratio decreases with more policies written
What we don’t know is more important in assessing risk, no effective strategy for carriers to segment book (why control-based discounts don’t work)
What we know is very helpful when assessing risk (why control-based discounts work)
Forecasting and predicting errors could make cyber risk uninsurable
Forecasting and models help predict losses, facilitating a profitable insurance industry
21
22
Insuring Cyber Risk Is Complicated
Without changes, the cyber insurance industry as we know it may not be sustainable at the time it is needed most.
Underwriting & Cybersecurity Alignment
Policy Cost & Industry Profitability
Cyber Advisory Gaps
Evolving Threat Landscape
22
23
Evolving Threat Landscape
Proofpoint reports that “66 percent of CISOs feel their organization is unprepared to cope with a targeted cyberattack in 2021”
The Council of Insurance Agents & Brokers reported an average increase of 34.3% in Q4 2021. Notably, an increase of this magnitude has not been reported since the market fluctuations that followed 9/11.
+
=
77% of businesses surveyed by Advisen in 2020 purchase cyber insurance.
Cyber insurers can’t do this alone.
A sustainable cyber insurance market requires a pool of insurable risk that maintains a commonly accepted cybersecurity maturity baseline with the ability to adapt to the dynamic threat landscape.
Maturity
23
24
Underwriting & Cybersecurity Alignment
Limited in-term loss control engagement
Claims & IR Plan not integrated; Renewals follow point in time approach
Business Integration
Technical Consulting + Integration
Operational Execution
Strategy | Design | Program
Develop | Validate |Implement| Operate
Incident Response | Remediate
Identify
Protect + Detect
Respond + Recover
Policy Admin & Loss Control
Underwriting & Applications
Claims & Renewals
Point in time underwriting, limited ability to validate controls
Establish acceptable insurability baseline and methodology for validation
Regular check points to identify changes to baseline, mitigating emerging threats & implement meaningful loss control strategies
Renewals based on in-term successes & threat landscape; IR & Recovery aligned with insurance
Underwriting & Cybersecurity
Current State
Desired State
Cyber risk is underwritten at a single point in time and is based on responses to questionnaires. Carriers write policies without owning the relationship or ability to test or validate controls. Carriers provide loss control solutions and underwriting requirements. Brokers are responsible for explaining underwriting requirements and assisting insured to implement services and requirements provided by carrier.
Underwriting based on questionnaire responses and some external data.
Minimal cyber risk visibility during policy term.
Limited ability to implement loss control in response to changing risk landscape and attack surface.
24
25
Cybersecurity Advisory Gap in Traditional Insurance Distribution Model
Establishes and enforces underwriting requirements & handles claims.
Insurer (Carrier/InsurTech)
De facto cybersecurity advisor, collect underwriting info, validate controls?
Cybersecurity Partner
Broker
Implementation, prioritization and execution of cyber strategies and coordination with broker/carrier.
Technology-independent cybersecurity support aligned with cyber insurance process.
Insured
Advisory Gap
Cyber insurance is becoming a cybersecurity solution.
Brokers are now required to become experts on technical insurance products, advise on cyber risk management best practices and provide incident response support.
Cyber insurance becoming as much a cybersecurity solution as it is an insurance product.
Underwriting is more technical, but carriers don’t always work directly with insureds to implement and validate controls. Brokers that are used to traditional business insurance are now required to become experts on technical insurance products and advise on cyber risk management best practices and provide incident response support.
The typical middle market insurance buyers (CFO/COO) often assumes CISO and CIO responsibilities but needs help sorting through the cybersecurity noise to make meaningful change.
25
26
Cyber insurance is challenging the law of large numbers
—Advisen Information Security and Cyber Risk Management Survey, 2020
2011-2020 Cyber Insurance Purchasing Trend
US Cyber Loss Ratio 2016–2020
More business than ever are purchasing cyber insurance to manage cyber risk.
Policies were initially priced to encourage adoption and carriers have been pushed by competition to drive premiums down while expanding coverage.
26
Standalone
2016 2017 2018 2019 2020 45 35.4 34.4 47.1 72.8 Package 2016 2017 2018 2019 2020 53.3 28.8 36.799999999999997 42.3 58.6 Total 2016 2017 2018 2019 2020 47.6 32.4 35.4 44.9 67
27
Premiums Are Up, Yet Demand Is Increasing
Premium increases are necessary as cyber insurance was often underpriced as carriers were competing for market share. As the threat landscape volatility continues premium increases alone are not enough to create a long-term sustainable market.
Of the 72% of accounts in Q4 2021 with a pricing increase greater than 20%, 39% of the accounts had an increase of 50% or more.
27
28
Reinsurance & Capacity
Premium/Risk
Retention/Deductible
Premium/Risk
Insureds (Businesses)
Insurers (Carriers)
Reinsurers
Lloyd’s of London
Claims
Claims
Claim Payments
Claim Payments
“As cyber risk is growing, the cyber insurance market has stalled. Insurers are taking bigger losses, seeing tighter margins, and relying more heavily on reinsurance to cover their own risk. The result is that companies are getting less protection for more money.”
Source: https://hbr.org/2022/03/the-cyber-insurance-market-needs-more-money
More business than ever are purchasing cyber insurance to manage cyber risk.
Policies were initially priced to encourage adoption and carriers have been pushed by competition to drive premiums down while expanding coverage.
28
29
Ransomware Is Still Most Common Cause of Claims
—Netdiligence Cyber Claims Study 2021
Top 5 Numbers of Claims - SMEs
Average Costs of Ransomware
29
30
Cyber Insurance claims are expensive
Percentage of Annual Claims by Annual Revenue
- Chubb Cyber Index
SME’s drive claim frequency, claims from large organizations are more costly. Both SMEs and large organizations must continue to balance investments in cybersecurity protections and cyber insurance.
- NetDiligence Cyber Claims Study 2021
Average Costs for All Claims
Under $25M $25.1M–$150M $151M–$500M Over $501M 0.34200000000000003 0.27300000000000002 0.19700000000000001 0.188
Questions & Discussion
31
image1.png
image2.png
image11.png
image5.png
image12.png
image13.svg
.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }
image14.png
image15.svg
.MsftOfcResponsive_Stroke_ffc000 { stroke:#FFC000; }
image16.png
image17.svg
.MsftOfcResponsive_Stroke_ffc000 { stroke:#FFC000; }
image25.png
image18.png
image19.png
image20.png
image21.png
image22.png
image23.png
image24.png
image33.png
image34.png
image35.png
image36.png
image26.png
image27.png
image28.png
image29.png
image30.png
image31.png
image32.png
image37.png
image38.svg
image39.png
image40.svg
image41.png
image42.svg
image43.png
image44.png
image45.png
image46.png
image47.png
image48.png
image49.png
image50.png
image51.png
image52.png
image53.png
image54.png
image62.svg
.MsftOfcThm_Accent5_Fill_v2 { fill:#FFB500; }
image55.png
image56.svg
.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }
image57.png
image58.svg
.MsftOfcThm_Accent1_Fill_v2 { fill:#005092; } .MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }
image59.png
image60.svg
.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }
image61.png
image69.svg
.MsftOfcResponsive_Stroke_ffc000 { stroke:#FFC000; }
image70.png
image71.svg
.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }
image72.png
image73.svg
.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }
image63.png
image64.png
image65.svg
.MsftOfcResponsive_Stroke_ffc000 { stroke:#FFC000; }
image66.png
image67.svg
.MsftOfcResponsive_Stroke_ffc000 { stroke:#FFC000; }
image68.png
image75.svg
.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }
image76.png
image77.svg
.MsftOfcThm_Accent1_lumMod_60_lumOff_40_Stroke_v2 { stroke:#259CFF; }
image78.png
image79.svg
.MsftOfcThm_Accent6_Stroke_v2 { stroke:#7BAFD4; } Plan Build Run
image74.png
image81.svg
.MsftOfcThm_Accent5_Stroke_v2 { stroke:#FFB500; }
image80.png
image82.png
image90.svg
.MsftOfcThm_Accent6_Fill_v2 { fill:#7BAFD4; }
image91.png
image92.svg
image93.png
image94.svg
image95.png
image96.svg
image83.png
image84.svg
.MsftOfcThm_Accent6_Fill_v2 { fill:#7BAFD4; }
image85.png
image86.svg
.MsftOfcThm_Accent6_Fill_v2 { fill:#7BAFD4; }
image87.png
image88.svg
.MsftOfcThm_Accent6_Fill_v2 { fill:#7BAFD4; }