Cyber Insurance: Good News & Bad News

Even though the cybersecurity insurance market is barely 20 years old, cybersecurity insurance companies have already collectively grossed more than $2 billion in premiums. 

This implies both good news and bad news. The bad news is the demand for cybersecurity insurance demonstrates that hackers and data thieves are stepping up their game. Businesses and industries of all sizes are being targeted. 

The good news is that large organisations and small businesses alike are taking proactive steps to protect themselves from cyber threats.

As the cybersecurity insurance market continues to expand, SMBs will want answers to questions before procuring this insurance for their operations. Below are a few common questions companies consider before selecting a provider.
How likely is it for an SMB to be targeted by a cyber attacker?

By one measure, more than half of all cyberattacks target SMBs. Sure, SMBs typically do not store or maintain the same volume of data that is held by larger companies. But that doesn’t mean they are out of the wood. Small businesses generally have fewer resources and defensive technologies as compared to their larger peers. In other words, SMBs hold less data, but that data is easier to steal.

What does cybersecurity insurance cover?
Cybersecurity insurance policies can cover multiple different losses and liabilities associated with a data breach. This includes business downtime, extortion, data recovery, and fines levied by regulatory bodies. 
Some policies go even further to provide against third-party liabilities. Prime examples include a failure to protect their confidential data and legal fees. Of course, exact coverage details will depend on your policy. So be sure to suss out the specifics during your initial conversations.

Do all cybersecurity insurance carriers cover the same types of losses and liabilities?
Coverages from different insurance carriers do overlap, but some carriers offer different services and underwriting policies than others. Many of the world’s top commercial general liability insurance carriers(including Liberty Mutual, Beazley Insurance Co., Chubb Ltd.) are now offering cybersecurity riders on their policies.

Other insurance entities have been formed by individuals that have more technical knowledge of cybersecurity threats. Companies like Root9B, RSA, IBM Security, Dell Secure Works, and Palo Alto Networks all boast top-notch technical cybersecurity expertise. 

Meanwhile, companies like CyberPolicy offer SMBs an opportunity to shop through cyber insurance companies according to specific needs. Carriers include Hiscox, Aspen Insurance, and Hanover.

How much should an SMB budget for cybersecurity insurance?
Cybersecurity insurance policy premium costs will vary as a function of each SMB’s network systems environment. Annual premiums for one  million dollars of coverage will generally be between $5,000 and $50,000. Given that an SMB incurs an average loss of $200,000 from a single data breach, these premiums are readily justified on a cost-benefit basis.

Will cybersecurity insurance companies offer cyber threat abatement consulting services?
Many cybersecurity insurance companies work closely with their clients to detect likely cyber penetration points and to make suggestions to close off those gaps. 

Root9B, for example, will pursue cyber attackers that have broken into a system and will expunge those attackers while closing off the gaps that let them in. Dell Secure Works audits client systems to identify weaknesses. Palo Alto Networks works to stop a security breach as it is happening with threat-intelligence and other protection tools. 

Cybersecurity insurers are as interested in ending data breaches as their clients are in preventing them, and good carriers will always work with their clients to reduce threat levels.

What is an SMB’s ultimate risk if it fails to procure cybersecurity insurance?
Believe it or not, the worst case scenario is bankruptcy. The costs associated with even a low-level data breach are often large enough to wipe out an SMB’s profits. 

Cybersecurity insurance is critical. Without this essential service, you could suffer a cyberattack that kills your SMB for good.

The Times T2

You Might Also Read: 

Companies Are Buying Cyber Insurance 'in mad panic':

Cybersecurity Tips For Smaller Businesses:

Cyber Insurance Report 2017 - 2018 (£):


 

 

« Employees Are Key To Cybersecurity
Russia Will Create Its Own Internet »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Nethemba

Nethemba

Nethemba provide pentesting and security audits for networks and web applications. Other services include digital forensics, training and consultancy.

French Expert Center Against Cybercrime (CECyF)

French Expert Center Against Cybercrime (CECyF)

CECyF is a centre of excellence for countering cybercrime in France.

ProPay

ProPay

ProPay provides secure payment solutions for organizations ranging from small businesses to large enterprises requiring complex payment solutions.

Huntsman Security

Huntsman Security

Huntsman Security provides technology to enable real-time security monitoring and immediate visibility of advanced threats and compliance issues.

Windscribe

Windscribe

Windscribe is a Virtual Private Network services provider offering secure encrypted access to the internet.

State e-Government Agency (SEGA) - Bulgaria

State e-Government Agency (SEGA) - Bulgaria

The State e-Government Agency (SEGA) is responsible for matters relating to electronic governance in Bulgaria.

CybExer Technologies

CybExer Technologies

CybExer provide an on-premise, easily deployable solution for complex technical cyber security exercises based on experience in military grade ranges.

Worldline

Worldline

Worldline IIoT solutions allow industrial companies to start their digital transformation journey with industrial level cyber security standards (IEC 62443 ready).

RFA

RFA

RFA is a unique IT, financial cloud and managed cyber-security provider to the financial services and alternative investment sectors.

Dutch Innovation Park

Dutch Innovation Park

Dutch Innovation Park in Zoetermeer is a breeding ground for applied IT solutions in the field of cyber security, e-health, smart mobility and big data.

Pacific Cyber Security Operational Network (PaCSON)

Pacific Cyber Security Operational Network (PaCSON)

PaCSON is an operational cyber security network of regional working-level cyber security experts in the Pacific.

CSIR Information & Cybersecurity Research Centre

CSIR Information & Cybersecurity Research Centre

The CSIR Information & Cybersecurity Research Centre focuses on research, development, and innovation of home-grown cyber and information security.

Zyber 365

Zyber 365

Zyber 365 are providing a robust, decentralized, and cyber-secured operating system which adheres to the fundamental principles of environmental sustainability.

Veza Technologies

Veza Technologies

Veza is the authorization platform for data. Built for hybrid, multi-cloud environments, Veza enables organizations to manage and control who can and should take what action on what data.

Acumenis

Acumenis

At Acumenis, we help organisations of all sizes to manage information security effectively. Our key services are penetration testing, ISO 27001 implementations, and security

Apex

Apex

We aspire to make the AI revolution run faster, securely, for the benefit of all. We are purposely built for the new AI era and are creating capabilities to safely enable AI.