Lloyd's to exclude certain nation-state attacks from cyber insurance policies
- Reference: 1661322487
- News link: https://www.theregister.co.uk/2022/08/24/lloyds_cybersecurity_insurance/
- Source link:
In a memo sent to the company's 76-plus insurance syndicates, underwriting director Tony Chaudhry said Lloyd's remains "strongly supportive" of cyber attack coverage. However, as these threats continue to grow, they may "expose the market to systemic risks that syndicates could struggle to manage," [1]he added [PDF], noting that nation-state-sponsored attacks are particularly costly to cover.
Because of this, all standalone cyber attack policies must include "a suitable clause excluding liability for losses arising from any state-backed cyberattack," Chaudhry wrote. These changes will take effect beginning March 31, 2023 at the inception or renewal of each policy.
[2]
At a minimum – key word: minimum – these policies must exclude [3]losses arising from a war , whether declared or not, if the policy doesn't already have a separate war exclusion. They must also at least exclude losses from nation-state cyber attacks that "significantly impair the ability of a state to function or that significantly impair the security capabilities of a state."
[4]
[5]
Policies must also "set out a robust basis" on which to attribute state-sponsored cyber attacks, according to Chaudhry – and therein lies the rub.
Attribution is 'absolutely hard'
Attributing a cyber attack to a particular crime group or nation-state with 100 percent confidence "is absolutely hard," NSA director of cybersecurity [6]Rob Joyce said at this year's RSA Conference. More recently he emphasized this point with a meme on Twitter:
HOW CAN NSA REALLY BE SURE OF THE ATTRIBUTION? I MEAN ANYONE CAN THROW RUSSIAN MALWARE! [7]pic.twitter.com/Nv8ASBdbD8 — Rob Joyce (@NSA_CSDirector) [8]August 19, 2022
Threat analysts typically attribute an attack to a nation-state from its level of sophistication, Jim Richberg, public sector field CISO Fortinet, told The Register .
But as advanced persistent crime groups become more sophisticated – and have more resources at their disposal to buy zero-day exploits and employ specialists for each stage of an attack – differentiating between nation-states and cybercrime gangs becomes increasingly difficult, he explained.
[9]
"There are times when nation-states will act like criminals, using their tools and infrastructure, and sometimes vice versa," Richberg said. "The clear line of sophistication and stealth that many have used as a common sense delineation has blurred. Yet, If you are going to pay out money you are likely going to look for something that is more ironclad and likely related to forensic evidence."
State sponsored? Or sympathetic?
Plus, as many security researchers have pointed out, there's a [10]fine line between cybercriminals who are directly associated with a government agency – such as Russia's GRU – and those that simply enjoy government protections from prosecution or are [11]sympathetic to particular governments.
"Attacks aren't just nation-state or not," Google Threat Analysis Group senior director Shane Huntley told The Register .
"We have [12]hack-for-hire operators with both government and non-government customers," he added. "We have volunteer [13]hacktivists operating on behalf of government causes, and cybercriminals operating with the tacit approval of states. Without clarity on where thresholds are, no insurance policyholder has any type of certainty of what risk they are mitigating."
Ultimately, Huntley said, these policy changes mean attribution will become even more important with insurance payouts at stake. But it also provides incentives for victim organizations to downplay any evidence linked to a nation-state.
Bring in the lawyers
Because insurance policies are legally binding contracts, the question of attribution will likely be a legal question as opposed to a real-world one, according to Peter Hawley, director of insurance solutions in Europe for SecurityScorecard.
"The muddying of waters is the language surrounding 'state-backed,' which can be interpreted in a multitude of ways and therefore leaves an insurer open to either running the risk of paying money on an unsanctioned event, or facing an unenticing trip to court when the claim is declined and the insured then sues them in order to try to gain coverage," he told The Register .
[14]
"I see this being an important connection point between those in the threat intelligence community and the cyber insurance arena, as insurance customers will ultimately benefit from contract certainty and clarity around decisions that are made in the event of a claim," Hawley said.
[15]Don't panic about cyber insurers pulling up the drawbridge, says Lloyd's
[16]Higher risks and premiums are creating critical gap in cyber insurance
[17]Russian invasion has dangerously destabilized cyber security norms
[18]US, Europe formally blame Russia for data wiper attacks against Ukraine, Viasat
But as the [19]cost of cyber attacks continues to climb, insurers are being forced to find ways [20]to limit their risk or else go out of business, which is a scenario that Lloyd's [21]faced down in the late 1980s and early 1990s.
"Insurers, by and large, aren't worried about non-catastrophic nation-state attacks, and the intent isn't to decline claims where a nation-state is responsible," according to Coalition CEO Joshua Motta, whose company provides cyber insurance and security software.
In a series of [22]tweets , Motta argued this isn't an attempt to limit coverage "for the now everyday occurrences of nation-state hacking."
Instead, he noted, "what insurers worry about are catastrophic acts of (cyber) warfare that aren't quantifiable by the insurance industry, lead to astronomical damages, and ultimately bankrupt the industry." ®
Get our [23]Tech Resources
[1] https://assets.lloyds.com/media/35926dc8-c885-497b-aed8-6d2f87c1415d/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YwX2vbGzo0k2w6H68s1esgAAAIo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/12/09/lloyds_lma_cyber_insurance_clauses/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YwX2vbGzo0k2w6H68s1esgAAAIo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YwX2vbGzo0k2w6H68s1esgAAAIo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2022/05/07/false_flag_attacks/
[7] https://t.co/Nv8ASBdbD8
[8] https://twitter.com/NSA_CSDirector/status/1560513073743507456?ref_src=twsrc%5Etfw
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YwX2vbGzo0k2w6H68s1esgAAAIo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://blog.talosintelligence.com/2021/05/privateer-groups.html
[11] https://www.theregister.com/2022/03/15/cyberciminals_russia_ukraine/
[12] https://www.theregister.com/2022/07/25/aig-unique-cybercrime-business/
[13] https://www.theregister.com/2022/08/11/black_hat_hacktivists/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YwX2vbGzo0k2w6H68s1esgAAAIo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://www.theregister.com/2021/12/09/lloyds_lma_cyber_insurance_clauses/
[16] https://www.theregister.com/2022/08/11/insurance_ransomware_blackberry/
[17] https://www.theregister.com/2022/08/11/black_hat_hacktivists/
[18] https://www.theregister.com/2022/05/10/us_eu_russia/
[19] https://www.paloaltonetworks.com/blog/2022/06/average-ransomware-payment-update/
[20] https://www.theregister.com/2022/08/11/insurance_ransomware_blackberry/
[21] https://www.theguardian.com/money/2000/nov/04/business.personalfinancenews1
[22] https://twitter.com/joshuamotta/status/1562107166298779648
[23] https://whitepapers.theregister.com/
Re: Value of In-House Talent
Yeah.
I'm guessing not many.
"But don't worry, we'll still accept your premiums... provided you pay on time"
"You had a 'Third Party, Fire and Theft' policy... bad luck... a nation state organised the theft, so that just leaves 'Fire'... oh, they hacked your boiler and alarm system, causing it to burn down the building... as I said, really bad luck there... can I interest you in our new 'Comprehensive' policy?"
So by extension:
If I'm retained as an InfoSec bod and my client is popped by a Nation state, I'm not on the hook for my failings and my PI cover isn't needed?
And there's no need for the CISO / InfoSec team to fall on their swords either (Tangent: has anyone ever known either to do so ?)
Maybe this reflects the inevitable case where a cyber attack does take out some major infrastructure. Nobody can afford for that to happen. So where’s the commensurate budget to go and deal with those obsolete PLCs and their electromechanical predecessors?
There are secondary issues like figuring out how to work on such systems without disrupting other work that needs to happen, but that can all be done.
At a minimum – key word: minimum – these policies must exclude losses arising from a war,
That sort of clause is fairly standard in insurance policies. Fun fact: that's why some wars that the UK has been involved with were not classified as wars. For example in Malaya (not a "war", it was an "emergency") and the Falklands (not a "war", it was a "conflict") there we many British subjects/dependents who suffered losses or damages, but because these weren't technically wars they could still claim on their insurance policies.
A Stitch in Time Saves Nine/Proper Preparation and Planning Prevents Piss Poor Performance
However, as these threats continue to grow, they may "expose the market to systemic risks that syndicates could struggle to manage," [1]he added [PDF], noting that nation-state-sponsored attacks are particularly costly to cover.
In other, more fulsome words, ... their, and systemic markets exposure to being found out as, and widely recognised and popularly accepted as, and therefore easily able to be found guilty in the first degree and convicted of, being a state enabler complicit in ensuring a simple means to encourage and continue egregiously repressive and oppressively punitive inequitable status quo operations against command and controlling human resources/global assets/earthly treasures/heavenly pleasures/diabolical liberties/universal rights.
And yes, that would be disastrous for them to be involved in, in any way, and thus is gravely to be regarded ...... with much as was publicly revealed and earnestly advised on about the power of ever present money over 60 years ago [on January 17, 1961] surprisingly easily made applicable to them also ...... [2]President Dwight D. Eisenhower's Farewell Address (1961)
Sound earlier advice which quite obviously fell on deaf ears and now results in all manner of totally new formerly unimaginable unexpected consequences.
[1] https://assets.lloyds.com/media/35926dc8-c885-497b-aed8-6d2f87c1415d/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf
[2] https://www.archives.gov/milestone-documents/president-dwight-d-eisenhowers-farewell-address
Re: A Stitch in Time Saves Nine/Proper Preparation and Planning Prevents Piss Poor Performance
Do you write contracts for insurance companies in your spare time?
The more things change, the more they stay the same ‽ ‽
:-) In your dreams, maybe, but not nowadays in 0days
That [1]Lloyd's Market Bulletin Ref: Y5381 is a bold admission that some attack vectors are indefensible .... and therefore more valuable than ever can be priced for and bought for exclusive use/abuse/misuse.
That in its turn makes those attack vector agents enabled to be rich beyond even the craziest of dreams ...... and that is another mother of a brand spanking new market for status quo systems to consider requires their regulation with novel invented rules which affords them a remote proxy control facility. Such is their default modus operandi/vivendi.
Take care though stepping into that market for it does not accept the folly and counsel of useful fools who be useless tools.
[1] https://assets.lloyds.com/media/35926dc8-c885-497b-aed8-6d2f87c1415d/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf
Acts of war
On the face of it this ought to be a sensible move; insurers habitually exclude acts of war, and cyberwarfare is an obvious thing to lump in with that.
But how do you define cyberwarfare? Lloyds have plumped for action by a foreign State agency. Again, that might seem fair enough, except, how do you establish who perpetrated the attack, and even if you do pin it down to some black-hat organisation, how do you decide whether they are criminal freelancers or under state control or some unholy mix of the two?
"cyber attack coverage"
This is an abomination in principle.
It allows companies to not do the required effort to secure their systems, and instead get compensated for their lack of effort when disaster strikes.
This should not be allowed. We're not talking about a building ruined by an earthquake. Hacking is not an unforseeable event. It is ongoing and constant.
There should not be insurance on that. Do your job and secure your servers.
Re: "cyber attack coverage"
Home insurance is an abomination. Most houses are insecure since a brick through the window allows thieves into the house. House insurance just allows home-owners to not bother with properly securing their homes and instead just get compensated when they are robbed.
Home insurance should not be allowed......, etc.
Re: "cyber attack coverage"
Actually, there has always been a range of policy types in principle, from, at one end, low cost policies with negligible obligation on the insured that offer minimal cover that's hard to claim, and at the other end robust quite expensive policies that pay out fairly but demand specific security obligations to be fulfilled. If the insurer in the latter case finds out that those obligations have not been fulfilled they are unlikely to pay out. As the industry has matured, the latter type has actually come to dominate the market, so there's much less opportunity to be slack and rely on insurance as a fallback than there was in the early days of the industry.
Insurance is just one (but a necessary one) of the tools used to protect against the cyber threat (just as fire insurance is one of the tools to protect against that threat, in which case sloppy fire precautions will tend to result in non-settlement too)
"those that happen during wars, beginning in seven months' time"
So are they anticipating that the war in Ukraine will be over in 7 months time?
The thing I don't get is, why do they think that the "really sophisticated" attacks can only be carried out by governments?
Have they ever seen a government IT project? Plenty of examples elsewhere on this site. The only thing that is sophisticated about them is the ability of the same useless contractors to get massive contracts again and again despite their complete incompetence.
Value of In-House Talent
It'll be interesting to see how many companies these circumstances shift into hiring computer security staff who are not simply scapegoats, but whose input managements heeds, and who are properly supported with training and HW/SW budgets.