Showing posts with label Cyber Insurance. Show all posts
Showing posts with label Cyber Insurance. Show all posts
By: Shaahil Abraham, BCA 4th Sem, 1st Shift 

“There are only two types of companies those that have been hacked and those that will be.” said by Robert Mueller FBI director (2012).
Cyber insurance began catching on in 2005, with total value of premium forecast is to reach $7.5 billion by 2020 worldwide!
Technology, social media and transactions over the Internet play key roles in how most organizations conduct business and reach out to prospective customers today. Those vehicles also serve as gateways to cyber attacks.
Cyber attacks are likely to occur and can cause moderate to severe losses for organizations large and small. As part of a risk management plan, organizations routinely must decide which risks to avoid, accept, control or transfer.
What is cyber insurance?

Cyber insurance is an insurance product used to protect businesses and individual users from internet based risks. Cyber insurance can’t protect the organisations form the cyber crime but it can keep the business on stable financial footing.
The rise of cyber insurance:

Events such Year 2000 problem, 9/11, causes the demand for cyber policy. It was by the year 1990 that the first cyber policies start to appear in the market. The year 2000 has much exclusion related to cyber insurance such as Rogue Employee, Regulatory, and Fines & Penalties and there was no first party coverage which by mid of 2000 was granted.
By the year 2003, California Security Breach Information Act was implemented. The Act stipulates that if there's a security breach of a database containing personal data, the responsible organization must notify each individual for whom it maintained information.
The California Security Breach Information Act was implemented to stop the increasing incident of identity theft. According to the Federal Trade Commission, the organization received 214,905 complaints of identity theft in 2003.
The result of policy was that many states started to follow similar act and there was new first party and third party coverage which included IT Forensics, customer notification, penalties etc.
The current status of cyber insurance is that attacks to the information infrastructure in the cyber field on the one hand have become more and more complex and professional. On the other hand, there are large amount of companies’, states and population’s dependency on IT and thus accordingly providing protection to them was the main criteria of cyber insurance companies. Many experience of the events related to data loses have proven effective in developing an environment where provides best possible data protection.

Common recompense Expenses covered under cyber insurance:

Investigation: Forensics investigation is 
important to determine what has actually occurred, cause of damage and possible ways to prevent the same type of situation again.

Business losses: A cyber insurance policy may include errors that occurred due to negligence and other reasons, as well as monetary losses experience by network downtime etc.

Privacy and notification: This includes data breach notifications to the customer and other affected parties which are mandated by law in many jurisdictions.

Lawsuits and extortion: This includes legal expenses associated with the release of confidential information.

Advantages of cyber insurance:
1) Data security
The importance of data for a company is at an all-time high. In the current information era, many competitive advantages are strongly based on data, therefore the risk associated to losing control of this data also higher. Insurance offsets the expenses of a data breach.

2) Peace of mind
The jurisdiction regarding data breaches is getting tougher and tougher. Especially if one holds personal data (e.g., names, addresses, etc.) and even more so if one hold personal sensitive data (e.g., medical records). In this new legislative scenario being insured gives business owners’ peace of mind. 

3) Closing the gap between traditional coverage and current needs
Traditional policies don’t cover the first party breach notification cost it only cover liability arising of tangible property but cyber insurance provides coverage for liability for loss of data, regularity and legal fine and penalties.

Disadvantage of cyber insurance:

1) Lack of historical data
Pricing on the end of the insurer is difficult, since the risk is on intangible property and          there is very little historical data. This tends to drive prices up.

 2) Less helping situation
The biggest impact on one’s cyber security is prevention. And there is very little insurance will do about this. One has to know where the relevant data sits and how to protect it.

3) Policies have their limits
Cyber security is a highly technical space, and while choosing one policy versus another, it is important to see what each covers and what its limitations are (e.g., some cover the breach if it is due to third party provider and others don't). Some policies might also limit the way one can react to a breach (e.g., only allowing you to work with a determined law firm).

Top cyber insurance companies in today’s scenario:

Insurance companies are:

Rank
Company
Direct written premium
Policies in force claim made
Policies in force occurrence
1
American international group
215,563
16,418
____
2
Chubb limited


121,132
5,119
____
3
Xl group


113,462
1,301
121
4
AXIS capital holding


83,223
3,067
____
5
Beazley insurance company


68,954
13,324
____
6
Travellers company


65,026
32,887
____
7
CNA financial corporation


57,637
24,981
____
8
Allied world assurance company


29,938
1,002
____
9
Berkshire hatchway incorporations


20,467
72,909
8715
  

Stand alone package cyber coverage combined 2014-2015









































Experience thought the insurance companies that Cyber insurance has been a fast-evolving market as the risks change.
Industry estimates suggest that the global cyber insurance business could increase to $20 billion by 2020, but the lack of information on cyber insurance is a challenge for insurance companies, policyholders, regulators and investors to evaluate and price risk.
The latest sources states that AIG, Chubb, XL Group leads in U.S Cyber Coverage Market Share

Conclusion:
It is rightly said that “time growing old teaches all things”, lack of data security is still a question mark for many organisations and fear for many, but till now many example have been set up to make one realise the importance of data security and thus there are efficient ways to overcome the problem, one of it is cyber insurance.
Cyber risk is complex and constantly changing, which makes it very difficult to evaluate exposure, particularly when combined with the lack of historical data to properly underwrite and price policies. Additionally, there is an added concern with respect to risk aggregation, in that a single attack could potentially affect many companies at the same time, which further impairs the ability of insurers to assess the risk. However, as the demand for cyber insurance continues to grow, insurance carriers will continue gathering the data they need to set appropriate rates and developing new products and coverage options.



By: Minal Aggarwal, BCA 4th Sem, 1st Shift

Today in this world of fast growing technologies, social media and online transactions, Internet plays an important role in organizations to conduct their business. So, online transactions are prone to cyber-attacks and can cause huge losses to the organizations. As part of risk management plan for the organizations, cyber insurance comes in play, where there is transferring risks.
Cyber insurance does not actually protect the organizations from cyber-crimes, but it can keep the business on the stable financial footing.

The Cyber Insurance Policy, also referred as Cyber Risk Insurance, is designed to help the organizations mitigate risk exposure by offering costs involved with recovery after a cyber-related security breach or similar event.  Although cyber insurance policies have been around from past 10 years in the market, but recently market awareness has increased, because of the headline-grabbing cyber breaches that have hit almost every industry.

“The Verizon 2016 Data Breach Investigation Report confirms that companies large and small, across all industries, in all geographies, are at risk of being targeted by a cyber-attack. In fact, it is estimated that 62 percent of cyber breach victims are small to mid-sized businesses. The average total cost of a breach, according to the 2015 Cost of Data Breach Study: Global Analysis, is now at $3.79 million.”
So the demand for cyber insurance in the market is increasing, and also the government is also becoming more active in policing corporate responses to cyber-attacks. There are now many mandatory data breach notification laws in many countries. Lots of well-known insurance companies offer cyber policies, such as Allianz, Chubb Philadelphia and Travelers.
 But there is no standard for underwriting the cyber insurance policies. Most cyber policies in the market offer a combination of two types of insurance coverage. First party coverage covers losses of the organizations and third-party coverage which protect against the claims against the organizations by customers or the partners. Besides financial coverage, insurers also provide risk management and post-breach services, including loss-prevention measures and remediation tools
.
“THERE IS NO STANDARD FORM FOR A CYBER INSURANCE POLICY IN THE MARKET.”

Cyber insurance covers first-party losses and third-party claims, but general liability insurance covers only property damage. Like in the case “Sony was caught in that situation after the 2011 PlayStation hacker breach, with hard costs reaching $171M that could have been offset by cyber insurance had the company made certain that it was covered ahead of time. During a court case, Zurich American Insurance Company said that Sony’s policy only covered physical property damage, not cyber damages.”

Although some of the standard insurance policies, such as Business Owners Policy (BOP), provide coverage for cyber incidents. If we lost the data due to some hardware failure or computer virus, the insurance pay recovery and replacement costs. This type of cyber insurance policies includes various types of risks like:
·         Business interruption
·         Corruption of the data
·         Identity theft
·         Cyber extortion
·         Reputation Recovery
Many insurance companies also offer pre-breach and post-breach services, like monitoring, incident response and many more. So, insurance companies have started hiring more cybersecurity specialists and it bring many opportunities for cybersecurity startups also.

But certainly, the way we look at the risk, it is evolving and Cyber Insurance has a played a very important role in organization’s overall risk mitigation strategies. The extent to which it will enable us to better assess and ultimately combat the rising threat landscape we are facing is still to be seen.

By: Rony Roy, BCA 4th Sem, 1st Shift
Today, executives are acutely aware that their information is under constant attack as cyber threats become more pervasive, persistent and sophisticated. Cyber insurance to cover losses and liabilities from network or information security breaches can provide incentives for security investments that reduce risk. Although cyber insurance has evolved, industry has been slow to adopt it as a risk management tool. Individuals, businesses, and other organizations routinely use insurance to help manage risks. They buy insurance policies to cover potential losses from property damage, theft, and liability that they can’t or don’t want to bear alone. Insurance carriers’ offerings have evolved to address increased demand (such as directors’ and officers’ liability), new perils (such as loss of intellectual property), and previously uncovered risks (such as college students’ property losses).


IT security has traditionally referred to technical protective measures such as firewalls, authentication systems, and antivirus software to counter such attacks, and mitigation measures such as backup hardware and software systems to reduce losses should a security breach occur. In a networked IT environment, however, the economic incentives to invest in protective security measures can be perverse. My investments in IT security might do me little good if other systems connected to me remain insecure because an adversary can use any unprotected system to launch an attack on others. In economic terms, the private benefits of investment are less than the social benefits, making networked IT security a public good and susceptible to the free-rider problem. As a consequence, private individuals and organizations won’t invest sufficiently in IT security to provide an optimal (or even adequate) level of societal protection.

Benefits of Cyber Insurance

In other areas, such as fire protection, insurance has helped align private incentives with the overall public good. A building owner must have fire insurance to obtain a mortgage or a commercial business license. Obtaining insurance requires that the building meet local fire codes and underwriting standards, which can involve visits from local government and insurance company inspectors. Insurance investigators also follow up on serious incidents and claims, both to learn what went wrong and to guard against possible insurance abuses such as arson or fraud.


Insurance companies often sponsor research, offer training, and develop best-practice standards for fire prevention and mitigation. Most important, insurers offer lower premiums to building owners who keep their facilities clean, install sprinklers, test their control systems regularly, and take other protective measures. Fire insurance markets thus involve not only underwriters, agents, and clients, but also code writers, inspectors, and vendors of products and services for fire prevention and protection. Although government remains involved, well-functioning markets for fire insurance keep the responsibility for and cost of preventive and protective measures largely within the private sector. As with fire insurance, the prospective benefits of well-functioning markets for cyber insurance can accrue to stakeholders both individually and collectively.

They include:

  • A focus on market-based risk management for information security, with a mechanism for spreading risk among participating stakeholders.
  • Greater incentives for private investments in information security that reduce risk not only for the investing organization but also for the network as a whole.
  • Better alignment of private and public benefits from security investments.
  • Better quantitative tools and metrics for assessing security.
  • Data aggregation and promulgation of best practices.
  • Development of a robust institutional infrastructure that supports information security management. 


Thus cyber insurance can, in principle, be an important risk-management tool for strengthening IT security and reliability, both for individual stakeholders and for society at large.

But are these prospective benefits realistic and achievable?

It is likely, as security expert Bruce Schneier expects, that:
“[T]he insurance industry [is] going to move into
Cyber insurance in a big way. And when they do,
they’re going to drive the computer-security industry…
just like they drive the security industry in
the brick-and-mortar world”
By: Sonali Mehla, BCA 4th Sem, 1st Shift

Cyber insurance is an insurance product used to protect businesses and individual users from internet-based risks and more generally from risks related to information technology, infrastructure and activities. Risks of this nature are typically excluded from traditional commercial general liability policies or at least are not specifically defined in traditional insurance products. Cyber insurance typically covers expenses related to first parties as well as claims by third parties against losses such as data destruction, extortion, theft, lacking and denial of service attacks.

Virtually, every business relies on data and computer systems. When these systems experience a virus or other computer attack, a business is at real risk of losing critical information that is essential to the daily operation and potentially exposing itself to third party liability. Computer viruses are the growing problem and a cyber attack can significantly impact a business’s bottom line. Cyber risk insurance provides broad affordable cyber liability protection specially designed for small business to address the growing threat of information security exposures. The cyber liability insurance helps pay for the costs associated with computer restoration and data recovery and the coverage also protects against third party liabilities a business might have a failure of system security.

AN ASSESSMENT OF CYBER INSURANCE:

2014 marked an important milestone in the growth of cyber insurance with a significant jump in both the number of companies offering cyber insurance and the number of firms buying cyber insurance. Currently, over fifty major insurance providers now offer cyber liability insurance coverage. Demand for that insurance rose by 21% across all industries in 2014 as compared to 201, with financial institution representing the biggest increase of 29% in coverage buying.

Value and importance of cyber insurance – A cyber insurance marketplace is an important component of a strong cyber security program. It serves as an important risk transfer mechanism. Cyber insurance allows a company to share the cost of an incident amongst the pool of insured companies. It motivates customers wishing to be insured to follow god cyber security practices as eligibility for insurance or preferred rates, are likely to be based upon whether the insured passes recommended practices or pass certification audits.

Adding to challenges is the constant change and innovation being experienced in cyber space. In just the last few years we have seen the dramatic growth of social networks, mobile and the cloud, the emergence of the Internet-of-things, wearable, 3D printing and the sharing economy, and in the near-future we are likely to see drones and self-driving cars. These new products, services, business models, and interdependencies impact both the form and likelihood of a cyber-attack occurring and the nature and severity of the resulting loss. Cyber insurance will have to keep up with these changes, updating their risk and pricing models.

There are a number of factors driving the growth of a healthy cyber insurance marketplace, but there are still many unknowns and issues that will need to be addressed for the cyber insurance market if it is to continue to grow, prosper and add value. The financial services industry is uniquely positioned to play a key role in helping to identify, address and resolve these barriers and issues as it includes representatives of both large buyers of cyber insurance (example-banks), and the insurers who partnering with leading cyber security professionals can work together to find solutions satisfactory to both buyer and seller.

By: Vipul Aggarwal, BCA 6th Semester, 2nd Shift

With the increase in the use of technology, social media and online transactions by organizations for business and/or reaching out the prospective customers, the threat for cyberattack is increasing day by day. Cyberattacks, done by the hackers, criminals, insiders or even nation states, can cause moderate to severe losses for the organizations whether large or small. As a part of the risk management plan, organizations must decide which risks to avoid, accept, control or transfer. The transferring of the risks is where the cyber insurance comes into play.

Cyber insurance policy which is also known as cyber risk insurance or cyber liability insurance coverage (CLIC), is designed to help an organization mitigate risk exposure by offsetting costs involved with recovery after a cyber-related security breach or similar event. Concept of cyber insurance as a risk management plan was started in the 1990s. Although its roots were looking strong in the 80s, the market for it failed to thrive. It finally started catching on by 2005 with the worth $2.5 billion and it is expected that the total values of premiums will reach $7.5 billion by 2020. Cyber insurance typically covers expenses related to first party as well as third party claims. There are several reimbursable expenses that are involved in it like investigation, business losses, privacy and notification and lawsuits and extortion. Since the cyber insurance is still evolving, the underwriters have limited data to determine the financial impact of the attacks, so the true risk of cyberattacks is not completely understood.

Compared to the market in US and UK, the cyber insurance market is yet to evolve in India. Currently only HDFC Ergo, Tata AIG and ICICI Lombard offers insurance cover in India again cyber risks and threats. Also Reliance General Insurance and Bajaj Allianz are in the process of providing cyber insurance to cop up with the increasing demand for such products in India. Currently the maximum cover that is provided in India is Rs. 300 crores but the providers are saying that the cover can be raised to Rs. 600 crores based on the specific requirement of the customers. Since India is starting towards the Digitalization, it is expected that there will be a huge growth in the cyber liability insurance market and more companies will start taking benefit of it.


Despite the advantages of cyber insurance, one should understand that this is not a solution to the security threats or vulnerabilities. It just transfers the security cost risk from the insured to the insurer. We should also understand that cyber insurance is like any other insurance policy that helps us to cop up with the real life risks and can be used in the situations where the threats are really prevailing.