Lloyd's of London suggests insurers should not cover 'retaliatory cyber operations' between nation states
- Reference: 1638280930
- News link: https://www.theregister.co.uk/2021/11/30/lloyds_london_cyber_insurance_clauses/
- Source link:
The insurer's "Cyber War and Cyber Operation Exclusion Clauses", published late last week, include an alarming line suggesting policies should not cover "retaliatory cyber operations between any specified states" or cyber attacks that have "a major detrimental impact on… the functioning of a state."
"The insurer shall have the burden of proving that this exclusion applies," warn the exclusion policies [2]published by the Lloyd's Market Association.
[3]
Although the wordings in the four clauses are published as a suggestion for insurers in Lloyd's-underwritten policies and are not concrete rules, they provide a useful indicator for the direction of travel in the slow-moving cyber insurance world.
[4]
[5]
The policy clauses also raise the idea of insurance companies attributing cyber attacks to nation states in the absence of governments carrying out attribution for specific incidents, an idea that seems [6]extremely unlikely to survive contact with reality . All four of the clauses, available as PDFs from the [7]bulletin , contain this wording:
Pending attribution by the government of the state (including its intelligence and security services) in which the computer system affected by the cyber operation is physically located, the insurer may rely upon an inference which is objectively reasonable as to attribution of the cyber operation to another state or those acting on its behalf. It is agreed that during this period no loss shall be paid.
Some infosec figures expressed dismay over the new clauses, with Ciaran Martin, former chief of Britain's National Cyber Security Centre, tweeting:
The document is called “War, cyber war and cyber operations exclusions”. But👇it defines ‘war’ & ‘cyber operations’ but not ‘cyber war’.
Does para 9.2 exclude cover for any state sponsored hacking which happens all the time outside war? If so, that’s huge. Be clear about it 2/4 [8]pic.twitter.com/eI3G35rdhz — Ciaran Martin (@ciaranmartinoxf) [9]November 28, 2021
Matt Middleton-Leal, EMEA North MD for cloud security firm Qualys, said in a statement that it wasn't all doom and gloom, though he wasn't exactly upbeat either.
"Some of the guide policies include protection for 'bystander attacks' and some do not," he said. "Bystander attacks are a risk where a specific nation state attack affects IT systems used by other companies that have the same applications or IT setups in place, and they get hit in the blast radius. While they are not the specific target they may get hit in the same way."
"Petya in 2017 is a good example of this," continued Middleton-Leal. "The attack was aimed at Ukrainian companies, but other companies around the world were affected. This new guidance from Lloyd's is a positive move and one that I think will help – even if state actors do carry out attacks specifically targeting other nation states, the impact on other businesses should not be discounted."
[10]
Cyber intrusions tend to come from nation states' spy agencies; an insurance policy which refused to pay out if, say, Russia or China [11]broke into a company's servers to steal customer data would be of very low value in today's world. All Western businesses targeted by Russia's SVR spy agency in the SolarWinds hack, for example, would potentially see themselves left with legions of angry end users and no financial safety net to meet lawsuits and beef up their defences.
[12]Cyber insurance model is broken, consider banning ransomware payments, says think tank
[13]The cost of cyber insurance increased 32 per cent last year and shows no signs of easing
[14]Ransomware-hit law firm gets court order asking crooks not to publish the data they stole
[15]Google's VirusTotal reports that 95% of ransomware spotted targets Windows
One could also make a comparison with [16]the Irish health service ransomware attack . Though it wasn't from a state-sponsored crew (as far as is known at the time of writing), the effects on Ireland's largely state-owned healthcare sector was disastrous.
British government policy is that cyber insurance can be used to pay off ransomware criminals, though the RUSI defence think tank [17]suggested banning such payments earlier this year . In a research report, RUSI also found that insurers were selling policies with minimal due diligence, leading to (quelle horreur) insurance firms paying out when their clients suffered cyber attacks.
With [18]premiums rising , it's no surprise that cyber insurance firms are tightening their belts. ®
Get our [19]Tech Resources
[1] https://www.lloyds.com/conducting-business/requirements-and-standards/supplemental-requirements-and-guidance
[2] https://www.lmalloyds.com/LMA/News/LMA_bulletins/LMA_Bulletins/LMA21-042-PD.aspx
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YaZYu4FcWNN5MJw@vY7gyAAAAIA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YaZYu4FcWNN5MJw@vY7gyAAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YaZYu4FcWNN5MJw@vY7gyAAAAIA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2019/12/05/fooling_attribution_breadcrumbs/
[7] https://www.lmalloyds.com/LMA/News/LMA_bulletins/LMA_Bulletins/LMA21-042-PD.aspx
[8] https://t.co/eI3G35rdhz
[9] https://twitter.com/ciaranmartinoxf/status/1464875914936860674?ref_src=twsrc%5Etfw
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YaZYu4FcWNN5MJw@vY7gyAAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2021/04/15/solarwinds_hack_russia_apt29_positive_technologies_sanctions/
[12] https://www.theregister.com/2021/07/01/rusi_cyber_insurance_ransomware_report/
[13] https://www.theregister.com/2021/07/05/cyber_insurance_report/
[14] https://www.theregister.com/2021/07/06/ransomware_4_new_square_chambers/
[15] https://www.theregister.com/2021/10/14/googles_virustotal_malware/
[16] https://www.theregister.com/2021/05/14/ireland_hse_ransomware_hospital_conti_wizardspider/
[17] https://www.theregister.com/2021/07/01/rusi_cyber_insurance_ransomware_report/
[18] https://www.theregister.com/2021/07/05/cyber_insurance_report/
[19] https://whitepapers.theregister.com/
Culpability
I do wonder how the insurance companies would attribute 'cyber crime' to nation states and whether that would include actors geographically located in, say Russia, which are not an official part of the government, but which, at least in the hallowed walls of the Register, are often associated with the government. At least tolerated (while they do not attack Russia's interests) etc. The various groups known as 'Russian Business Network', 'Russian Bear' and other actors (Google them at your own risk) are often considered by Western media to be working with or for the Russian state, if not actually part of it.
Re: Culpability with Multiple Obvious Points of Abject Failure
Who here is going to say that the likes of a GCHQ/MI6/MI5 is not to be a vital hostile nation state hacker of note, especially as such organisations needs to be in order to be in any remote way effective in providing secret state security systems their relative protection from foreign harm or alien intrusion ..... Novel Smash and Grab, Crash and Trash Raiders and AIMarauders?
How on Earth can one defend against a friend or a foe if one is ignorant of their abilities and bereft of their facilities and utilities.
The Jolly Roger icon is very APT with regard to this post methinks.
As expected
Any excuse to avoid a payout for insurance companies, par for the course.
(caveat there are lots of insurance types vehicle, cycle, house, personal indemnity, insurance for specific high value items etc. these are just some broad points, may not apply to all insurance types)
.. Dig out any insurance policies you may have, look through the exceptions, you may be surprised at what's excluded.
.. Look for max payouts for various items (unless specifically named and given a value of part of policy setup) - your expensive kit may essentially be insured for peanuts.
.. if your insurance still has an act of god clause then its really bad.
.. See what "excess" you have to pay regardless, look at implications of losing any no claims bonuses etc.
.. If insurance is for something that may appreciate in value (e.g. house) - chances are the insurance value will stay the same, onus will be on you to reinsure if there's a house price boom & you can easily end up under insured.
.. Chances are you will find something, somewhere where you are getting stiffed (in a bad way) by an insurer.
Re: As expected
"Chances are you will find something, somewhere where you are getting stiffed (in a bad way) by an insurer."
And if you can't find it, they certainly can.... right there, at the bottom of page 79, in light grey 1pt Times Roman... no, no, written on top of the full stop at the end of para 23... try at x250 magnification
Re: As expected
Like many people, I have house & car insurance and that's about it.
Both state that "acts of war" are excluded from coverage.
Not a clever move.
>> insurance companies attributing cyber attacks to nation states <<<
Best case - Nation states who may well be able find out exactly how much the company knows before trotting down to their friendly UK libel lawyers!
Worst case - insurance companies bank accounts, IT and all backups become a train wreck overnight.
I'd have used Elbonia as a 'bad actor' example as well - just saying...