Opens in a new tab
vmblog logo 2024 wht (updated)

Cyber Insurance: Premiums, coverage gaps, and the thick gray space of who is responsible

Share: 

David Marshall | Published: October 12, 2023

By Brett Helm and Bob Ackerman

Intro

Cyber insurance is one of the fastest-growing segments of the insurance market. Given the rapidly changing cyber regulations and the unique needs of each policyholder, carriers understandably need help to accurately assess risk. Insurance companies have yet to develop effective systems and processes to apply actuarial rigor to cyber-insurance underwriting.

Cyber-attacks continue to increase in sophistication and number. The impact of these attacks is also rising. According to IBM’s Cost of a Data Breach Report, the cost of a data breach for healthcare organizations reached $10M per incident in 2022. Healthcare is not alone, as cyberattacks impact every major industry.

With the growing number and scale of attacks, cyber insurance carriers face heavy loss ratios, generally higher than for other lines of insurance. In some cases, companies are losing money.  Insurance companies are making changes to combat these losses. Policyholders face increased premiums, lower coverage limits, additional exclusions, and higher rates of denied claims. Cyber-insurance companies are also requiring companies to attest to a nine-point cybersecurity plan.

cyberinsurance-mandates-chart 

These mandates are designed to minimize exposure for cyber-insurance companies by providing higher levels of security for organizations purchasing cyber-insurance.

Despite these mandates, the current approach to cyber-insurance underwriting fails both insurance carriers and policyholders. Cyber-insurance companies need a better exposure view to enable a sustainable cyber-insurance business with reasonable profits and premiums. Policyholders need reasonable, fair premiums and assurance that they will be covered in the event of a loss.

Mismatched Expectations

When an application for cyber insurance is received, the insurance carrier expects to obtain an accurate disclosure. Cyber-insurance carriers are using questionnaires submitted as part of the insurance application process for underwriting.

The use of manual processes to gather data on an applicant’s computing infrastructure is a flawed approach – it will never work.  Not only are questionnaires tedious and challenging to fill out, but a manual process cannot accurately represent the state of a company’s computing infrastructure. Computing infrastructure is complex, varied, and dynamic. Questionnaires are not sophisticated enough to provide an accurate view of cyber risk. Even if the questionnaire is accurately filled out, it will be out of date soon after submission. In most cases, there is no validation on the part of the insurance company to ensure the accuracy of these questionnaires.

On the other hand, companies buying cyber insurance are expecting to be able to get cyber insurance at an affordable rate. Policyholders desire a policy with clearly defined coverages and exemptions. They hope to be covered in the event of a loss; however, they find this is only sometimes the case.

Shortcomings in insurance coverage

Companies are finding it more challenging to get cyber insurance and insurance rates are climbing rapidly. According to the Delinea State of Cyber Insurance Report, it took more than 6 months to get cyber insurance for 7% of companies, and 67% of companies reported increases in cyber insurance rates of 50% to 100%. Additionally, 28% of small companies were denied coverage and were unable to even obtain cyber insurance. For those with insurance, the number of exclusions continues to grow.

Insurance policies are written with exclusions to manage their exposure. Often, these exclusions concern gray areas where carriers cannot accurately predict risk. Unfortunately, what is excluded is often where policyholders most need protection. 

According to the Delinea report, cyber insurance coverage could be void because of:

  • Lack of security protocols
  • Internal bad actors
  • Human error including misconfiguration or lost cell phone/laptop
  • Acts of war
  • Companies failing to follow compliance procedures
  • Acts of terrorism
  • Not reporting incidents to insurance companies first

These exclusions would result in companies not receiving a payout, or only receiving a partial payout on a claim.

Cyber insurance won’t pay the for all costs, should an organization be hit with a cyber-attack. Policies often allow the insurance companies to make the decision on paying a ransom in the case of ransomware attacks, despite a company’s preference.  Additionally, many policies won’t pay for incident response, communication costs for public relations or crisis response.

Incident response could result in denied claims   

claim-denied  

When a cyber-incident occurs and a company files an insurance claim, the insurance company will bring outside security experts as part of the incident response process. The goal of the incident response team is to determine the cause of the cyber incident.

This is a standard cyber-security practice to help the organization improve its cyber posture. By finding the root cause, the problem can be mitigated to ensure hackers cannot exploit the same weakness in the future.

This root cause analysis also allows the insurance company to determine if cyber-insurance mandates are being followed. If mandates are not followed, insurance companies may deny the claim or provide only a partial payout.

Ultimately, through the process of investigating the claim, the carriers can find the insured failed to maintain secure practices and mitigate their own exposure. At this point, the claim is often denied. 

Automated monitoring

Automation with continuous monitoring is the solution to cyber-insurance risk management. Unlike traditional insurance categories, corporate computing infrastructure is dynamic. New applications are installed and updated, devices are added or moved, and new services are enabled on a regular basis. Any of these changes can dramatically impact the organization’s risk profile.

Automated cyber-risk management provides significant benefits to cyber insurance providers and policyholders alike, including:

  • Ensuring precise premiums based on actual cyber-risk data
  • Eliminating the need to fill out and process questionnaires, which have grown to as much as 50 pages
  • Ensuring accurate data is provided to insurance companies
  • Improving the security of their infrastructure by providing actionable information on vulnerabilities discovered

Conclusion

Cyber-insurance claims may be denied if your network is not in compliance with insurance company mandates when an attack occurs. Maintaining compliance is challenging. Corporate networks are highly dynamic. Devices are continuously added or moved, new applications are installed, software is patched, users change passwords and configurations, and other changes occur almost constantly.

Without continuous monitoring and assessment of security against cyber-insurance requirements, organizations remain at risk, and cyber-insurance providers need real data on their exposure. Tools to automate this process are critical to the viability of the cyber-insurance industry. 

##

ABOUT THE AUTHORS

Brett-Helm 

Brett Helm is the Co-Founder and Chairman of Dragonfly Cyber, provider of Internal Risk measurement for Cyber Insurance compliance. This solution is available now.  Previously, Brett held CEO roles at DB Networks and Coradiant as well as senior management roles at Intel.

Bob Ackerman 

Robert R. Ackerman Jr. founded AllegisCyber Capital – the world’s first dedicated cyber venture firm – to be “for cyber entrepreneurs by cyber entrepreneurs.”  Bob is also the Co-founder of cybersecurity and data science foundry DataTribe, Co-founder of CyberGRX, and Chairman of the annual Global Cyber Innovation Summit – the “Davos of Cybersecurity” – for leading Global 2000 CISOs, cyber innovators, and policy leaders.

With a 20+ year history in early-stage cybersecurity investing, Bob is titled as one of “Cyber’s Money Men” by major business publications for his experience and leadership in cybersecurity VC investing, named one of “Technology’s Top 100 Investors” by Forbes and featured on Forbes Midas List, and recognized as one of two leading cyber investors in the word by Cyber Defense magazine.

  1. IBM Cost of Data Breach Report 2023 was published in August 2023
  2. Global Insurance Market Report was published April 9, 2023
  3. Delinea State of Cyber Insurance Report was published Sept 5, 2023