Cyber insurance, also known as cybersecurity insurance or cyber risk insurance, is a type of insurance coverage designed to protect businesses and individuals from financial losses and liabilities associated with cyber threats and incidents. These threats can include data breaches, hardware attacks, ransomware attacks, denial of service attacks, and other forms of cybercrime.
Cyber Insurance Risk Framework
Cyber insurance is a necessary element in managing and reducing cyber risk. Which is why the New York Cyber Insurance Risk Framework came just in time. As an insurance policy that helps protect organizations from cyber incidents, the insured benefits from minimized business disruption have some of the financial costs covered. Essentially, this type of cybersecurity insurance prices an organization’s cyber risks. And doing so creates a financial incentive to fill the gaps in cybersecurity as this will reduce the insured’s premiums.
New York Department of Financial Services (NYDFS) released its Cyber Insurance Risk Framework (CIRF), being the first state in the nation to do so. The framework came as a result of a rise in cyberattacks. With a example being the SolarWinds attack, whereby a Russian state-affiliated hacking group managed to infiltrate the computer systems of numerous US government agencies, including the US Treasury and Department of Commerce. With cybersecurity becoming increasingly necessary as cyberattacks proliferate, the cyber insurance market is expected to reach $20 billion by 2025, up from $3.15 billion in 2019.
The Framework applies to all property or casualty insurers that write cyber insurance. Includes a number of practices for managing cyber insurance risk under seven categories.
Establish a Formal Cyber Insurance Risk Strategy
Insurers need to have a clearly delineated strategy for measuring cyber insurance risk. Both qualitatively, and quantitatively. Such a strategy should be directed and approved by senior management and the board. The strategy should include the following components:
Manage and Eliminate Exposure to Silent Cyber Insurance Risk
Insurance carriers need to identify and evaluate their exposure to silent, or non-affirmative, cyber risks under non-cyber policies. Subsequently, reduce such exposure. Insurers can eliminate cyber risks by making clear, in any policy that could be subject to a cyber-related claim. Whether or not the policy provides, or excludes, coverage for cyber-related losses.
Evaluate Systemic Risk
This is a crucial step that will prevent insurers from facing significant, and possibly unsustainable, costs. Systemic risk has grown due to the increased dependency on third-party vendors. This is especially in highly concentrated areas, as a result of globalization. Hence, according to the Framework, insurers must “understand the critical third parties used by their insureds and model the effect of a catastrophic cyber event on such critical third parties that may cause simultaneous losses to many of their insureds”. The SolarWinds attack is an example of a systemic risk that could damage many insureds simultaneously.
To evaluate systemic risk, insurers should conduct internal cyber “stress tests” based on unlikely, but possible, catastrophic cyber events. Such tests should, crucially, account for both silent and affirmative cyber risks. Additionally, these tests should also measure potential impacts across various industries.
Rigorously Measure Insured Risk
The Framework highlights the need for insurers to do a better job of knowing the exposure risks of their insureds. The NYDFS suggests developing and implementing a “data-driven” comprehensive plan that assesses the cyber risks of each insured, and potentially insured, organization. Such a plan must be able to be analyzed against claims data to better evaluate the risks presented. Additionally, insurers must evaluate an insured’s, or potential insured’s, data privacy and security program as this is critical to accurately assess the risk. The data gathering must provide enough detail to “make a rigorous assessment of gaps and vulnerabilities in the insured’s cyber”. This includes evaluating the following:
- Corporate governance.
- Vulnerability management.
- Access controls.
- Endpoint monitoring.
- Boundary defenses.
- Incident response planning.
- Third-party risk management.
Educate Insured and Insurance Producers
Insureds, and insurance brokers, need to be educated regarding the benefits of a comprehensive and effective data privacy and security program. Insurers should also facilitate and offer incentives for the development and implementation of such programs through policy pricing and discounted access to cyber services and risk assessments.
Obtain Cyber Expertise
In order to evaluate cyber risks, insurers must have the appropriate level of expertise. Hence, this requires the recruitment of employees with cyber experience and skills (employees role in cybersecurity). Moreover, insurers should commit to training and developing personnel.
Require Notice to Law Enforcement
When sustaining a successful attack, insurance policies should require policy holders to notify law enforcement. In doing so, law enforcement can assist in recovering stolen data and funds, as well as enable the prosecution of attackers to deter future cybercrime.
With cyberattacks not only proliferating – tens of thousands occur every day – but also becoming more sophisticated and dangerous, a cyber insurance framework will assist in the attempt to improve resilience to the malicious activities taking place in the cyber world. An organization’s cyber team needs to ensure that every vulnerability is covered, while attackers only need to exploit one – and the latter are getting much better at their job. Hence, it is not a question of if you will get attacked, but rather, when. Importantly, malicious cyber actors are seeking innovative and sneaky ways to bypass security measures in place.
Hardware attacks, for example, are extremely challenging to mitigate due to their extremely covert nature. Network Implants can evade existing cyber software solutions by sitting on the physical layer, and Spoofed Peripherals impersonate legitimate HIDs and are therefore not detected as harmful (Hacked Device). With this, cyber insurance is a necessary tool, and a framework will provide a coherent resource for insurers to refer to when creating their policies.
New York might be the first state to introduce such a framework, but it certainly will not be the last. Hopefully, this New York Cyber Insurance Risk Framework will be the start of a global push to introduce cyber insurance risk frameworks. But for now, to quote Frank Sinatra, “it’s up to you, New York”.