Cyber Insurance Will Reshape Cyber Security

Cyber security is broken as there is virtually no company that isn’t a potential target. From mom-and-pop storefronts to Fortune 500 companies, no business is immune to cyber risk. Even with the best possible cybersecurity posture, there is always a threat of a breach.
 
There are several factors driving the rise in cyber threats. They break down into a few core categories:  more areas of exposure, difficulty in law enforcement and more creative hackers.
 
Increased exposure. There is a lot of code out there, code that can be exploited for cyber-attacks. The sheer volume grows constantly as software companies write more lines of code for each solution. Further, there are more and more software offerings being implemented by all sizes of companies. In short, more software solutions with more lines of code for each. This presents many more opportunities for exploitation. Legacy code presents its own problem, as older code is hard to check adequately.
 
Hackers are hard to identify, harder to catch. Hackers don’t necessarily “phish where they live.” They often prefer to hack across borders, making it difficult to coordinate law enforcement efforts. Sophisticated hackers often work in groups, making traceability and accountability nearly impossible.
 
Hacking innovation. Since cybersecurity technologies adapt to threats after the fact, hackers improve their hacking techniques to be successful. Due to the cycle of hack-solution-new hack, cybersecurity providers primarily react to new attacks; they can’t predict them. Growing hacking opportunities, a lack of accountability and large financial rewards give hackers plenty of incentive to keep innovating their methods while more and more hackers join their ranks.
 
How it Affects the Market
 
There are two outcomes cropping out of this new era of cyber threats that affect businesses.
  • One is the inability of cybersecurity providers to guarantee the effectiveness of a cyber solution, or combination of products, to thwart a breach. 
  • Second, it is impossible to accurately quantify the cost/benefit of a cyber strategy since the likelihood and potential severity of cyber breaches is unknown.
Since the beginning of insurance, the industry has always sought ways to reduce risk, including incentivising clients to take preventative measures. Yet businesses need some form of cyber protection. How, then, can they determine an appropriate cyber budget and allocation plan, given the inherent uncertainties they face?
 
The solution: Cyber Insurance
The insurance industry is best poised to solve the cyber-security problem. There are three reasons: motivation, data and leverage.
 
Motivation. Cyber insurance carriers have the same end goal as the insured: not to get breached. The insured doesn’t want to experience a breach, and the carrier doesn’t want to pay out. The risk exposure for insurers is amplified, as risk understanding is less developed compared to more mature lines of insurance such as life, homeowners and auto.
When cyber-attacks are thwarted, it’s a “win-win” for both parties.
 
Data.Carriers have a lot of it, and they are only going to accumulate more. Large-scale breaches and widespread viruses make headlines, driving businesses of all sizes to demand cyber coverage. As the cyber insurance market grows, carriers will amass more data.
 
More than just volume, insurers are in the unique position of collecting proprietary information not accessible to other companies. Specifically, insurance providers collect four categories of data that can be analyzed for the purpose of minimising cyber threats.
  • Actual losses. Using accumulated claims data, carriers can identify the type and severity of breaches, and associate them with actual losses. Claims reports and breach investigations allow carriers to better understand the root causes of how an attack occurred and how to minimize future similar attacks.
  • Technology solutions and practices. Insurers know what technology products clients use by company and solution. Additionally, an increasing number of carriers are using technical solutions to assess the risk level of their insureds. This allows for deep analysis of which practices and solutions actually minimise losses, which don’t, and in which cases.
  • Company demographics. Cyber carriers know industry, company size, revenue and much more about their client base.
  • Company details. Carriers are in a unique position where they can require an applicant to provide additional qualitative and quantitative data to better understand the insured’s risk, including the type of data they store, their organisational processes and even governance. 
Some examples are number of credit card records housed, assessment of their incidence response plans to the type of regulations they follow. As carriers learn what information best drives ROI, they can adapt their questions to best serve their predictive models. These datasets help develop risk models that can better predict the likelihood of an attack, potential damage and the preventative steps necessary to minimise threats.
 
Leverage
 
Leveraging the above, cyber insurance can reshape cybersecurity. Once insurance carriers can understand and model cyber risk, they can drive adoption of best practices via financial incentives to the insureds. In time, cyber-security vendors will be measured on their ability to minimise cyber breaches, incentivising them to improve their offering. There is nothing new here. Since the beginning of insurance, the industry has always sought ways to reduce risk, including incentivizing clients to take preventative measures.
 
The US' first insurance company, The Philadelphia Contributionship  was founded in 1752 by none other than Benjamin Franklin, offering fire insurance in the city of Philadelphia. Before accepting a potential client, Franklin’s company would send a team of surveyors to inspect the property to assess risk of fire and set rates accordingly. As fire insurance evolved, several drivers helped reduce premiums and lower losses, including industry regulation, improved building standards, the creation of paid fire departments and financial incentives given to the customer based on taking recommended preventive actions. 
 
Take a more recent example: modern homeowners insurance. All other factors being equal, a homeowner who installs an alarm system and smoke detectors will see a lower premium than one who doesn’t.
 
Similarly, if cyber policyholders show they’ve adapted suggested actions, they will not only enjoy a maximised cyber posture but also savings on premiums. These actions will create demand for cyber products that adhere to insurance standards.
 
Cyber insurance carriers, armed with the best understanding and motivations, will spur businesses to take actions that allow for better cyber planning and budgeting, improved ability to withstand attacks, more accurate premiums on policies, and ultimately a stronger cybersecurity ecosystem. Cyber-security may be broken, but cyber insurance can help fix it.
 
Insurance Journal:       Carrier Management
 
You Might Also Read:
 
Effective Cybersecurity Requires Both Cyber Training & Insurance Cover:
 
« British Government Funds Chip Maker To Build Cyber Resilience
The Next Industrial Revolution »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

SafeCharge

SafeCharge

SafeCharge is a global provider of technology-based multi-channel payments services and risk management solutions for demanding businesses.

Information Network Security Agency (INSA) - Ethiopia

Information Network Security Agency (INSA) - Ethiopia

INSA's vision is to realize a globally competent National Cyber capability which plays a key role in protecting the national interests of Ethiopia.

SecureMetric Technology

SecureMetric Technology

SecureMetric is one of SE Asia’s leading players in the field of digital security with a focus on Software Licensing Protection, 2-Factor Authentication, Advanced Identity and Access Management, Publi

Snyk

Snyk

Snyk is the leader in developer security. We empower the world’s developers to build secure applications and equip security teams to meet the demands of the digital world.

DirectDefense

DirectDefense

DirectDefense is an information security services and managed services provider.

LMG Security

LMG Security

LMG Security is a cybersecurity consulting, research and training firm.

US Cyber Range

US Cyber Range

US Cyber Range is a scalable, cloud-hosted infrastructure providing students with virtual environments for realistic, hands-on cybersecurity labs and exercises.

LANCOM Systems

LANCOM Systems

LANCOM Systems is the leading European manufacturer of secure, reliable and future-proof networking (WAN, LAN, WLAN) and firewall solutions for the public and private sectors.

SecurIT360

SecurIT360

SecurIT360 is a full-service specialized Cyber Security and Compliance consulting firm.

Mr Backup (MRB)

Mr Backup (MRB)

MRB offers Data Protection as a Service for businesses looking to reduce the time, cost and complexity of securing your company data.

CERT.JE

CERT.JE

CERT.JE is responsible for promoting and improving the cyber resilience across the critical national infrastructure, business communities and citizens in Jersey.

Guardz

Guardz

Guardz helps small and growing businesses to go from zero or low cyber protection to having comprehensive security – in the quickest and most straightforward way.

Galvanick

Galvanick

Galvanick enables your operations and IT teams to protect your industrial systems and networks against digital threats.

PingSafe

PingSafe

PingSafe is creating the next-generation cloud security platform powered by attackers' intelligence, providing coverage for vulnerabilities that traditional security solutions would otherwise overlook

Silobreaker

Silobreaker

Silobreaker is a SaaS platform that enables threat intelligence teams to produce high-quality and relevant intelligence at a faster pace.

True Corporation

True Corporation

True Corporation is Thailand’s leading Telecom-Tech company, empowering people and businesses with connected solutions that advance society sustainably.