Cyber Should Be Standalone Insurance

Treating cyber risk as a standalone insurance market holds the promise of unlocking the potential for meaningful coverage for both insurers and buyers. That is according to a new report by JLT Re and JLT Specialty Limited.

According to the report released at the 2017 annual Risk Management RIMS Conference, buyers are clamoring for better cyber products to address the growing and complex risks of cyber, while underwriters are being cautious over concerns around “unquantified cyber exposures potentially buried in traditional policies.”

JLT said it believes considering cyber as a standalone line of business rather than a peril will result in more resilience to cyber risk in the re-insurance market and this shift will benefit insurance buyers in the form of “greater certainty, expertise, capacity and stability from the re-insurance market in a complex and growing risk area.”

“Cyber exposures have grown considerably for companies of all sizes and domiciles in recent years, causing business costs to rise sharply,” said David Flandro, global head of Analytics, JLT Re.

“Companies face challenges in understanding their exposures and the type of insurance cover needed as the underlying drivers of cyber risks frequently change, requiring insurers and brokers to explain and quantify these exposures as clearly as possible. Increased coordination and collaboration between key markets will be crucial in meeting evolving demands and unlocking the huge potential associated with cyber for the benefit of companies and carriers alike.”

Standalone policies would help eliminate the risk of silent exposures and, ultimately, make the market more resilient.

JLT notes that insurance approaches for cyber risk can differ considerably from one company to the next, a reflection of the view that cyber can either be considered a peril that falls within traditional property/casualty products or a line of coverage in its own right.

JLT views a standalone cyber market as a way to address both buyers’ changing needs and insurers’ uncertainty.

“As more premiums flow into the standalone market, carriers will be able to evaluate and price risks more accurately as good-quality claims data and sophisticated modelling tools become increasingly accessible,” said Sarah Stephens, head of Cyber, Technology and Media E&O for JLT.

“This, in turn, will help ensure the market is better placed to trade through future systemic losses by encouraging innovative reinsurance and insurance-linked securities (ILS) structures.”

Stephens said governmental support is also likely to be needed in back-stopping some of the more catastrophic loss scenarios.

She said a more robust cyber market, with comprehensive, standalone policies at its core, would also help “eliminate the risk of silent exposures and, ultimately, make the market more resilient to future catastrophic cyber losses.”

She said given the strong likelihood of a major cyber event in future, the market needs to prevent a situation where (re)insurance buyers are faced with a dearth of capacity as happened in the aftermath of the 9/11 attacks.

Given the complexity of cyber risks, access to reinsurance capital is essential in alleviating the primary market’s aggregation burden and supporting the innovative cover needed for future cyber risks, according to JLT.

“There is sufficient reinsurance capacity for the current cyber insurance market and increased reinsurer appetite for cyber risk bodes well for long-term growth prospects,” according to Chris Bennett, partner, London Market and International Non-Marine, Cyber Treaty for JLT Re. “New approaches have emerged in recent years as competition between reinsurance companies has stiffened, making non-proportional structures such as excess-of-loss, stop-loss and aggregate covers as commonplace today as the more traditional quota share arrangements.”

The report notes that cyber risk has changed since the first policy was underwritten around the turn of the century and it claims the market now needs to respond decisively to the changing scale and scope of cyber risk. For example, data breaches have become more frequent in the last five years, with the number of reported data breaches globally rising by more than 300 percent.


 
Number of Global Reported Data Breaches and Records Lost – 2011 to 2016
(Source: Risk Based Security/Cyber Risk Analytics)
 
The report also cites considerable concern over the scalability of the risk, where one cyber event is capable of triggering multiple claims under different policies at national, or even global, levels. As technologies become further embedded in the operations and strategies of organisations across all geographies and sectors, malicious actors will increasingly look to exploit the vulnerabilities associated with innovations such as the Internet of Things, cloud computing, autonomous vehicles, machine automation and connected devices.

“Market participants have begun to explore how catastrophic cyber risks such as systemic cloud service provider failures or targeted cyber-attacks on power grids could impact businesses and risk carriers,” said Flandro.

“These efforts have highlighted the real potential for multi-billion dollar (re)insured pay-outs. Products designed to mitigate such systemic cyber risk accumulations are less readily available, but considerable progress can be achieved by drawing on the expertise that exists in the standalone cyber market.”

Insurance Journal:

You Might Also Read:

Cybercrime Cost The Global Economy $450Billion In 2016:

Insurers Get Much More Cautious About Cyber Risk:

Cyber Insurance: 7 Questions To Ask:

UK Parliamentary Committee Wish To Penalise CEOs for Cyber Breaches (£):

Why SMEs Need Cyber Insurance:

 

 

 

« Intelligence Agency Backs Start-Up Spy Apps
US vs. North Korea Cyberwar Underway »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

eSentire

eSentire

eSentire is the authority in Managed Detection and Response Services, protecting the critical data and applications of organizations from known and unknown cyber threats.

SI-CERT

SI-CERT

SI-CERT (Slovenian Computer Emergency Response Team) is the national cyber scurity incident response center for Slovenia.

Cyber Security Academy - University of Southampton

Cyber Security Academy - University of Southampton

An industry/University partnership established to advance cyber security through world class research, teaching excellence, industrial expertise and training capacity.

Jumpsec

Jumpsec

Jumpsec provides penetration testing, security assessments, social engineering testing, cyber incident response, training and consultancy services.

General Dynamics Information Technology (GDIT)

General Dynamics Information Technology (GDIT)

General Dynamics IT delivers cyber security services to defend critical information and infrastructure.

SentryBay

SentryBay

SentryBay is the global leader in preventative endpoint isolation protection. We protect remote, BYOD and corporate endpoints so they can safely and securely connect with your corporate network.

Avertium

Avertium

Avertium is the managed security and consulting provider that companies turn to when they want more than check-the-box cybersecurity.

WebOrion

WebOrion

WebOrion is an All-in-One Web Security & Performance Suite. Fortify, accelerate and monitor your website today.

Center for Infrastructure Assurance and Security (CIAS)

Center for Infrastructure Assurance and Security (CIAS)

CIAS is developing the world's foremost center for multidisciplinary education and development of operational capabilities in the areas of infrastructure assurance and security.

BAE Systems

BAE Systems

BAE Systems develop, engineer, manufacture, and support products and systems to deliver military capability, protect national security, and keep critical information and infrastructure secure.

TrafficGuard

TrafficGuard

TrafficGuard is an award-winning digital ad verification and fraud prevention platform.

ZAG Technical Services

ZAG Technical Services

ZAG Technical Services is an award-winning information technology consulting firm delivering digital transformation solutions, IT assessments, managed services, security, and support.

Arista Middle East

Arista Middle East

Arista Middle East is part of Global Arista Technologies specializing in OT Cybersecurity.

Staley Technologies

Staley Technologies

Staley Technologies is a US nationwide structured cabling, technology integrator, and Managed IT & Cyber Security provider.

HTX (Home Team Science & Technology Agency)

HTX (Home Team Science & Technology Agency)

HTX brings together science and engineering capabilities to transform the homeland security landscape and keep Singapore safe.

Applaudo

Applaudo

Applaudo specializes in helping the world’s most admired brands optimize their IT solutions, reduce delivery costs, and accelerate their digital transformation.