Cyber Risk Insurance: A View From The Prudential Regulation Authority

Cyber risk is increasingly prevalent in insurers' thinking, both in considering new product lines and in assessing the risks to which they, and their insureds, are already exposed.

In recent years, the Prudential Regulation Authority (PRA) has made efforts to understand and guide the insurance industry in this space.

Its recently published conclusion however is that the exposure to cyber risk is currently being underrated by insurers.

The PRA's review

Between October 2015 and June 2016 the PRA worked with various organisations associated within the cyber risk insurance sector, including insurance and reinsurance firms, cyber security consultancies, technology firms and regulators to assess the potential exposure to cyber risk claims.

This resulted in the publication of its results in November 2016 along with a Consultation Paper. A final Supervisory Statement was published in July 2017.

The PRA's review focused not only on affirmative cyber insurance policies, but also on the exposure to risk which was presented by implicit cyber exposure, a subject which they referred to as the 'silent' cyber risk, or in less catchy terms, "non-affirmative" cyber risk.

Silent risk

The potential cyber risks associated with many policies are not always clear on first consideration. It may at first appear excessive to exclude cyber claims in, say, a casualty policy. Indeed, why would you need to protect an insured against a cyber risk when they are looking to insure themselves against injury claims by their employees or third parties?

However, an increasingly automated world is giving rise to instances where an IT failure could render essential equipment faulty, in turn, causing someone to be injured.

Silent risks also exist in other policies. Director and Officers (D&O) policies, in particular, are open to cyber threats given the impact of technology in effectively steering a business.

Should a business be hit by a cyber-attack, it may find itself vulnerable to a loss in revenue, ultimately leading to shareholders pursuing the directors if the business was not properly prepared, triggering a D&O claim.

Elsewhere, events stemming from a cyber-attack may give rise to complications for various professionals, leading to them being incapable of performing their role sufficiently, in turn leading to a potential professional indemnity claim. This threat extends to financial institutions and general liability claims.

Even where the link between cyber breaches and potential liabilities is clearer, the PRA is concerned that the risk has not been adequately dealt with. The aviation world, despite the continual automation of aviation electronics, appears to be taking the position that the risk of exposure to cyber risk is minimal.

Likewise, property underwriters, whilst accepting that cyber-attacks are becoming increasingly likely to impact upon developments in smart-home technology, are, according to the PRA, not fully accounting for such risks.

Issues in addressing silent risks also extend to reinsurance contracts. Whilst the PRA acknowledges that reinsurers are becoming increasingly aware of the potential exposure brought about by silent cyber risks, they also found that reinsurers have to date been reluctant to utilise methods to limit their exposure.

But the times they are a changing. The PRA's review provided evidence that reinsurers have developed wording to address the issue, albeit the wording in question was both bespoke and had only recently been introduced. Of greater concern is that the wordings remain untested, and have not been adopted universally, leading to uncertainty.

Governance requirements

Knowing which policies to focus on is only the first step. Insurers have been mandated with clearly assessing and monitoring both their affirmative and silent cyber risk policies. The PRA's Supervisory Statement asks insurers to produce clear strategies, along with risk appetite statements for the management of associated risks, to be owned by the boards of those firms.

Clarifying their recommendations, the PRA have recommended that a firm's strategy should make clear, amongst other things, the markets they wish to pursue, their intention for managing silent cyber risk, rules relating to line sizes, aggregate limits and splits between direct insurance and reinsurance.

Once formulated, strategies are to be maintained by the board, and reviewed on a regular basis, ensuring they remain relevant, assisted by an aggregate cyber underwriting exposure metric for both affirmative and silent risk. Such measures are designed with the intention of identifying the potential for loss aggregation, through a variety of exposures, over extreme return periods.

Greater knowledge needed

Where insurers do not invest in data breach resources they may find themselves exposed to challenges not faced in other policy types. The long tail impact of a cyber-attack on an insured may see repercussions lasting months, even years after the event, and bring about a range of losses which are likely to prove difficult to quantify.

The quantification of potential losses is made harder by the lack of past claims data in the UK to measure the losses against.

Internal dissemination of information also plays a part. In the absence of personnel with a cyber breach skillset, the PRA is concerned that firms will struggle to keep other relevant staff, including risk management teams, abreast of developments in this quickly evolving sector.

The consequences are risks being assessed on outdated information or principles, which may lead to a policy being ill-constructed to protect an insured against risks, or an insurer being blind to the level of liability it may be facing. The PRA is clearly encouraging greater investment in staff or external advisors who have experience of assessing and managing cyber risks.

Increasing risk in the future

Cyber risk will be front and centre in the thinking of many businesses in the months ahead, particularly with the implementation of the GDPR in May 2018. GDPR is likely to increase the exposure to cyber risk faced by insurers, primarily through affirmative cyber policies, but also the silent risks detailed above.

In the months ahead, businesses will be faced with a tougher European regulatory framework on personal data, leading to the need for an increasingly rigorous standard of data governance to be maintained.

Another, as yet untested, area is the potential for insurers to meet regulatory fines. These have trended upwards in recent years and are set to rise substantially following the introduction of the GDPR.

Accordingly, the insurance sector needs to be alive to the risks ahead, but also the opportunities presented. The PRA Supervisory Statements calls for underwriters to consider the implications of cyber risks when drafting all form of policies, either affirmatively including, or expressly excluding, any exposure to cyber breaches.

They are also asked to assess the potential for cyber-attacks to lead to aggregated risks in several different areas and with long tails.

The PRA has offered advice regarding steps firms can take to better equip themselves for cyber risk exposure. These include making adequate capital provision, adjusting premiums to reflect additional risks, offering explicit cover, introducing robust wording exclusions, or attaching specific limits of cover.

Implementation of these steps is intended to enhance the ability of insurers to monitor, manage and mitigate silent cyber risk and to increase contract certainty for policyholders as to the level and type of coverage they hold.

Despite the PRA's concerns, market trends indicate insurers are becoming increasing alive to the potential impact of cyber risk on the insurance landscape. The growing list of insurers and other professional advisors offering cyber breach experience is a sign things are moving in the right direction.

However, this remains a complex and fast moving field, where expertise is in high demand, but those with genuine practical cyber breach experience are short in supply.

The answer is likely to be found in a collaborative effort between insurers, experts and third party consultants to share their experiences and expertise to help better understand the risk landscape.

For free Cyber Insurance consultancy please email:  info@cybersecurityintelligence.com and we will give you advice and suggestions on who to contact for opinion/insurance

Lexology:

You Might Also Read: 

Cyber Insurance Report 2017 - 2018 (£):

Strategies For A Cyber Security Culture (£):

 

« AI Applied To Video Analytics
Artificial Intelligence Needs Regulation »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Vade Secure

Vade Secure

Vade Secure provides protection against the most sophisticated email scams such as phishing and spear phishing, malware and ransomware.

Cyber Security For Critical Assets (CS4CA)

Cyber Security For Critical Assets (CS4CA)

Cyber Security For Critical Assets is a global series of summits focusing on cyber security for critical infrastructure.

ComCode

ComCode

ComCode provides consulting services and solutions in the area of digitization and cyber security for mid-sized and big businesses.

IAC

IAC

IAC is a specialist Irecruitment consultancy covering Internal Audit, Risk, Controls, Governance, IT Audit, and Cyber Security roles.

CryptoTec

CryptoTec

CryptoTec is a provider of security concepts and encryption solutions for secure communication between decentralized computerized systems.

Centre for Multidisciplinary Research, Innovation & Collaboration (C-MRiC)

Centre for Multidisciplinary Research, Innovation & Collaboration (C-MRiC)

C-MRiC collaborates on initiatives, ranging from national cyber security, enterprise security, information assurance, protection strategy, climate control to health and life sciences.

Charities Security Forum (CSF)

Charities Security Forum (CSF)

The Charities Security Forum is the premier membership group for information security people working for charities and not-for-profits in the UK.

Meterian

Meterian

The Meterian Platform is a fuss-free solution to protect you against vulnerabilities in your app’s software supply chain.

Newtec Services

Newtec Services

IT should be responsive, adaptive, and smart. Now more than ever, you need a business that runs efficiently and can adapt to today's challenges. We can help with custom IT solutions.

KanREN

KanREN

KanREN is a member based consortium offering custom, world-class network services and support for researchers, educators, and public service institutions in the state of Kansas.

GitProtect.io

GitProtect.io

​GitProtect is a fully manageable, professional GitHub and Bitbucket backup and recovery software that protects repositories and metadata from any event of failure.

Triaxiom Security

Triaxiom Security

Triaxiom Security offers penetration testing, security audits, and strategic consulting customized to meet your needs.

CyberFOX

CyberFOX

CyberFOX is a global cybersecurity solutions provider focused on identity access management (IAM) for managed service providers (MSPs) and IT professionals.

Anatomy IT

Anatomy IT

Anatomy IT empowers healthcare providers to deliver exceptional patient care with cutting-edge technology and cybersecurity solutions.

Cyber and Fraud Centre – Scotland

Cyber and Fraud Centre – Scotland

The Cyber and Fraud Centre – Scotland exists to ensure Scottish organisations are as resilient as they can be against cyber and fraud crime.

Rebellion Defense

Rebellion Defense

Rebellion Defense is a technology company developing advanced software to ensure mission-critical organizations stay ahead of emerging threats.