Cyber Insurance Roller Coaster: Demand is increasing rapidly and some insurers are disembarking

 

Cyber Insurance Roller Coaster: Demand is increasing rapidly and some insurers are disembarking

Cyber insurance has had a quiet first half of 2021. Forrester has received a steady stream of inquiries from clients about the topic. These questions came in from both the private and public sectors. While some are trying to find the best way to acquire a cyber-insurance policy, others are having trouble with renewal decisions and rising premiums. Given the current market, it's not surprising.

Ransomware causes disruptions and ripple effects across providers and their customers

Cyberattacks can affect any business. Hiscox recently conducted a survey of small businesses and found that 23% had been attacked in the last 12 months. What is the average loss for small US businesses? The average loss for small businesses in the US is close to $26,000 Worse, many small businesses are forced to close within six months.

If this is the Roaring2020s then cyber insurance providers will be among the first to try their champagne. After their ransomware attacks and data breaches, cyber insurance providers such as AXA, Chubb and CNA have come under fire. Dmitry Smilyanets , a future threat intelligence analyst, interviewed a member of a ransomware as-a-service group that indicated that cyber-insurance companies are being targeted because they are "one the most delicious morsels." To hack insurers first, to get their customer base. Then work in a targeted manner from there. After you have sorted through the list, hit the insurer.

AXA France announced that it will no longer be selling cyber insurance policies in France with ransomware payment coverage. It will continue to help customers with damages and recovery costs. AXA's industry-first decision is unlikely to be the first to take drastic measures in order to remain solvent when policy claims tip into unprofitability. Cyber insurance policies are not able to draw on the years-old data that is used in traditional business insurance policies. Is it possible that there are many unknown variables, as well as a lack of cybersecurity expertise at the insurance level, that have led to a product that is underpriced.

Cyber-insurers are under additional pressure

All this business demand for cyber coverage occurs when the market is becoming less able and willing to cover it. Yes, there is more demand than supply. Fitch Ratings estimated that 2020 US Cyber Direct Loss Ratios were 73%. This is the highest level recorded in six years and a clear indication of the severity of cyber damage and claims. What was the result? In a market that is becoming more competitive, premiums for standalone cyber insurance are expected to rise by 30% in 2021 if they can still be purchased. Insurers are tightening their underwriting standards as well as excluding certain risks.

Insurance providers may have their own incentive to better understand risk in underwriting policies. However, external forces such as regulatory pressures from NY Division Financial Services (NY DFS), have created a Cyber Insurance Risk Framework that insurers can follow to manage risk. NY DFS also recommends that insurers refrain from making ransom payments to prevent economic incentives for such activity.

Moody's says cyber risk is a global concern that "increases in importance" in their financial sector credit analysis. We believe cyber risk is business risk.

Musings about the Future

Change is inevitable when forces collide and disruption builds. Four possible shifts are visible:

  1. Cyber insurance challenges rise.We'll see a decrease in cyber insurance coverage for some organizations. They will not be covered by the usual commercial channels. The FAIR plan (Fair Access to Insurance Requirements), which was created in 1960 to provide insurance in areas that are at high risk due to factors beyond their control, is a parallel in the US housing market. Following Hurricane Katrina,Insurance companies have reworked the modelsMillions of homeowners were dropped from their home/private property policies in high-risk flood areas. They sought coverage through state-backed FAIR plans. The government will be asked to support the cyber market in the same way it supported terrorism insurance. It can't do everything and will need to choose wisely.
  2. Risk management maturity is the qualifier and gauge.To improve its cybersecurity monitoring capabilities, an insurance company will purchase smart cyber startups. We already see partnerships between insurance carriers and managed security service provider (MSSPs). These partnerships are primarily designed to serve the small and medium-sized business market. They offer discounted premiums in exchange for using a particular MSSP partner's services. If insurers offer incentives to monitor, there is the potential for more innovation. Think of innovations such as dynamic premium pricing or burstable pricing based on severity, similar to what we see in DDoS protection. Or a credit score-like system that could be used to rate cyber risk. Insurers may become a type of alternative security service provider, which will allow for greater profits and lower risk.
  3. Cyber insurance is the price of admissionThe partner ecosystem. All third-party relationships will require cyber insurance, not just IT vendors. Cyber insurance is a requirement in IT service contracts. However, as more firms share PII, protected medical information and IP with suppliers, partners, and vendors, a cyber policy becomes a necessity rather than a nice-to have. Cyberattack claims are being denied by standard policies. Professional liability policies were traditionally used to cover cyberattack losses. Business liability policy providers are working to separate cyber claims from traditional business interruption claims.Invoke "failure-to-follow" exclusion languageThis basically means that the insured failed to uphold their responsibility by failing to maintain minimum/adequate security standards. Be prepared to produce a certificate of cyber liability insurance. Some customers may even request to be added to the policy.
  4. Digital business DNA can be used to test underwriting processes and underwriter skills.Different businesses may have a different digital profile. Healthcare providers can access sensitive financial and medical information of their customers. Even local artisans can have their own digital profiles. Cyber insurance underwriting inputs must capture more information about potential customers. This means that underwriters must be able and willing to accept a new launch path: rapidly developing digital competencies at all levels, even the microindustry level. Regulators must also be aware of the demand for digital skills.

Cyber insurance's future will be influenced by industry and outside forces. We will experience this change, with all its bumps as well as dips. Cyber insurance is not the protection umbrella that companies have been claiming it to be. It is a tool to manage risk. A better, maturer approach to managing risk should be the goal.


Comments

Popular posts from this blog

Payments, Payment Rails and Blockchains and the Metaverse

The Metaverse and the Potential of Blockchain

How to draw attention to your online store in a crowd-sourced marketplace 7 Ways to Stand Out Among the Sea of Competing Products