Unhappy about excluding nation-state attacks from cyberinsurance? Get ready to pay
- Reference: 1662471010
- News link: https://www.theregister.co.uk/2022/09/06/lloyds_cyber_insurance_policy/
- Source link:
Based in the UK, Lloyd's is a marketplace of insurance buyers and sellers, rather than a company, and has [1]77 cyber risk insurers under its wing for which it sets the rules. Collectively, it has more than 200 lines of business and wrote $41.2 billion (£35.5 billion) of gross premiums last year. North America is the source of over half of its premiums.
How big is Lloyd's?
Altogether, as of [2]mid-2022 , Lloyd's has 76 syndicates (companies and individual insurers who work together to offer a specific type of insurance contract, thereby spreading the risk among themselves); over 380 brokers (go-betweens for the buyers and sellers); and more than 4,030 coverholders in over 200 countries and territories (coverholders transact insurance business in countries beyond the reach of the syndicates).
Lloyd's chief of markets Patrick Tiernan was speaking to the [3]Financial Times after a backlash against an August memo
[4]PDF
, penned by Lloyd's underwriting director Tony Chaudhry [5]last month , saying the market will require all of its insurance groups to exclude any liability for losses resulting from state-backed cyberattacks from their insurance policies from March 31 2023.Tiernan told the FT that not including these cyberwar exclusions would "drive up insurers' capital requirements" – a cost they would in turn pass on to customers.
Companies looking for risk protection against cyberattacks have complained the move limits and potentially excludes a lot of the cover they believe they've paid for, while legal experts have pointed at increasing dispute over whether or not a particular attack has state support.
Why should I care about acts of war clauses? They won't affect your auto insurance much, but they will impact cyberspace
As Lloyd's has pointed out, acts of war clauses are really "common" in insurance contracts generally. However, for the most part, there's only a very slim chance that, say, your car gets hit by a missile from another country attacking yours. Most of the time, you are looking at insuring against damage from someone ignoring a red light.
In cybersecurity, however, there's a much more real risk of the person or people behind the attack, or the malware, [6]being linked to all those murky groups . In addition to nations in conflict who pit their cyberteams against each other, cyberattacks could be launched by groups affiliated with them, or even independent groups sympathetic to one of them.
[7]
For example, Russia's infamous APT 29, aka [8]Cozy Bear , has been fingered by both the US and UK governments as being behind the SolarWinds Orion attack. That attack could [9]potentially have affected up to 18,000 public and private orgs, including governments, who used the Orion network management system to manage their IT resources.
[10]
[11]
SolarWinds said in an SEC filing last year that the number was "under 100" – hardly reassuring.
Costs of doing business
Premium rates taken by Lloyd's stakeholders already rose by 10.9 percent in 2021, a year which marked a return to profitability for the marketplace, it said in its latest annual report. Meanwhile, international insurance broker Howden found last year that across the globe, cyber insurance pricing had increased by an average of 32 percent in the year before its assessment.
Tiernan told the paper the move was a way of being "responsible to our customers and acting with the market," claiming: "Very often in the past, these sort of corrections or evolutions to policy language happen post-event... after everything has gone wrong."
Lloyd's Market Association (LMA), a trade body for Lloyd's-affiliated syndicates, first started floating [12]model clauses excluding acts of "cyberwar" for insurers and underwriters in September last year, stating in at least one of them that when it came to deciding whether a state actor was behind the cyberattack, "the insurer may rely upon an inference which is objectively reasonable as to attribution of the cyber operation to another state or those acting on its behalf."
[13]
At the time, Patrick Davison, the LMA's underwriting director, told The Reg that insurance companies themselves would need to prove an exclusion clause applies – that's if no government openly declared an attack was the fault of some other rogue state.
[14]Lloyd's to exclude certain nation-state attacks from cyber insurance policies
[15]Cyber insurance model is broken, consider banning ransomware payments, says think tank
[16]The cost of cyber insurance increased 32% last year and shows no signs of easing
[17]FedEx execs: We had no idea cyberattack would be so bad. Investors: Is that why you sold $40m+ of your own shares?
[18]Cyberlaw wonks squint at NotPetya insurance smackdown: Should 'war exclusion' clauses apply to network hacks?
[19]How do we stamp out the ransomware business model? Ban insurance payouts for one, says ex-GCHQ director
According to Lloyd's [20]2021 annual report , it took in £39.2 billion ($45.37 billion) in gross written premiums and took in £2.3 billion ($2.66 million) in profit before tax.
It hasn't come out of the greatest year, though – in 2020, it reported a loss before tax of £887 million ($1.02 billion), with an underwriting loss of £2.676 billion ($3.1 billion), including COVID-19 losses.
More than one cyber insurance company has claimed losses by the companies it has insured should fall under war or "hostile acts" exclusions. Pharma giant Merck recently received a $1.4 billion payout from its insurer, ACE American Insurance Company, after the Superior Court of New Jersey [21]ruled an exclusion on damage caused by the NotPetya ransomware was "inapplicable."
The [22]file-scrambling ransomware infected computers all over the world, hitting hospitals, courier FedEx, TNT, and others, and causing an estimated $1 billion in damages. Altogether, [23]the UK , US, and [24]Ukrainian governments have all attributed the attack to Russia's state-sponsored hackers.
[25]
However, in the Merck case, the court sided with the pharma giant's argument that the exclusion contained language that limited it to the use of armed force, and that "the exclusion applied only to traditional forms of warfare" involving "de jure or de facto" sovereigns – which shows why Lloyd's and other insurers are very keen to tighten up those cyberwar clauses and avoid losing these kinds of cases.
Mondelez International Inc also [26]sued its insurer , Zurich American Insurance Company, over an act of war exclusion for the NotPetya attack. The case, currently in the circuit court for Cook County Illinois, was filed in 2018 – with the outcome pending.
We've asked Lloyd's for comment. ®
Get our [27]Tech Resources
[1] https://www.lloyds.com/about-lloyds/our-market/what-we-insure/cyber/cyber-products
[2] https://www.lloyds.com/about-lloyds/media-centre/key-facts-and-figures
[3] https://www.ft.com/content/e865a3d1-5652-41aa-990a-bb5ad57288c6
[4] https://assets.lloyds.com/media/35926dc8-c885-497b-aed8-6d2f87c1415d/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf
[5] https://www.theregister.com/2022/08/24/lloyds_cybersecurity_insurance/
[6] https://www.theregister.com/2021/11/30/lloyds_london_cyber_insurance_clauses/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YxdulwXtlgD7TZvklq-5ZAAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://www.theregister.com/2020/12/18/solarwinds_nnsa_microsoft_cisa/
[9] https://www.sec.gov/ix?doc=/Archives/edgar/data/1739942/000173994221000076/swi-20210507.htm
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YxdulwXtlgD7TZvklq-5ZAAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YxdulwXtlgD7TZvklq-5ZAAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://www.theregister.com/2021/12/09/lloyds_lma_cyber_insurance_clauses/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YxdulwXtlgD7TZvklq-5ZAAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://www.theregister.com/2022/08/24/lloyds_cybersecurity_insurance/
[15] https://www.theregister.com/2021/07/01/rusi_cyber_insurance_ransomware_report/
[16] https://www.theregister.com/2021/07/05/cyber_insurance_report/
[17] https://www.theregister.com/2019/09/19/fedex_execs_sued/
[18] https://www.theregister.com/2019/07/26/do_insurance_war_exclusion_clauses_apply_to_cyberattacks/
[19] https://www.theregister.com/2021/04/09/ban_cyber_insurance_payouts/
[20] https://www.lloyds.com/about-lloyds/investor-relations/financial-performance/financial-results/full-year-results-2021
[21] https://www.bloomberglaw.com/public/desktop/document/MerckCoIncvsAceAmericanInsuranCeDocketNoL00268218NJSuperCtLawDivA?1642788257
[22] https://www.theregister.com/2017/06/28/petya_notpetya_ransomware/
[23] https://www.theregister.com/2018/10/04/russian_military_intelligence_blamed_for_reckless_cyberattacks/
[24] https://www.theregister.com/2017/07/04/sbu_claims_russia_was_behind_notpetya/
[25] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YxdulwXtlgD7TZvklq-5ZAAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[26] https://www.theregister.com/2019/01/11/notpetya_insurance_claim/
[27] https://whitepapers.theregister.com/
Re: Excluding them makes it worthless
I agree. If the product doesn't provide the support that you need or expect, stop buying / supporting the product.
Let's see how far that gets Lloyds.
The problem lies with the cyber world, not Lloyds
In the IT world, cyber by extension, it has been shown that supposed "best practices" are not actually that good against a determined attacker. This is a different kettle of fish compared to measuring the tread on a set of tyres.
How many of us have done the equivalent of a "#include" or "import" of whatever package or module, and NOT done ANY due diligence on it? The great mantra of the Linux world is "the community maintains/monitors it". The term "community" is a misnomer when it turns out one of two people are actually doing the maintaining. Then when a flaw comes along, e.g. log4j, some people jump up and down waving their fists and beating their chests that it was vulnerable and nobody noticed until now. Despite being used by huge numbers of people, none of them did the due diligence. None. I bet the same people could measure their tyre tread or even make a reasonably good guess that it's time for new tyres. The "problem" with software is that it is complicated, and to understand it takes time and money from people who are clever enough to understand it. The fact that open source software means the source is available does not mean it is being looked at by competent programmers. It's fair to say that it MAY be being looked at in some cases, and in far fewer cases it IS being actively looked at.
The Lloyds register graded ships on build quality and materials used. They also inspected the ships to make sure the standards were not being fudged. We have no such equivalent in the IT world - it's an uncoordinated and endless list of best practices from different people and organisation which turn out to be actually not very good. We are at times barely ahead of the bad guys, and at other times we don't even know we've been compromised. Small companies are in general unable to find the right staff (meaning sufficiently competent) to ensure security, large companies regularly get compromised and come out with their "we take security very seriously" slogans.
SolarWinds is the example of the fire station chief telling everyone to install fire detectors while its own station burned down. A company selling computer security products could not keep itself secure.
Lloyds is right but for the wrong stated reasons. Computer security is in general a bad joke.
Who's the hacker?
How do you know if your hacker is a nation state? How would you prove that?
Do they leave a calling card? "Regards, the North Korean government".
If there is no proof left behind that shows it was a nation state, does that mean the insurance will pay out or are they going to argue the opposite?
"it has been shown that supposed "best practices" are not actually that good..."
The basic problem is that "best practice" (even according to ISO standards) turns out to be merely most common practice. Its absolute quality is generally assumed until (by very slow drift) experience tweaks it, but the update cycle is typically several years, whereas the adversary commonly operates on a weeks to months cycle.. So the guidance on defence is always running behind an evolving threat.
The only way to correct this situation for any organisation is to define their own defence in depth using observation, research and rational thinking. Unfortunately, that can be a quite expensive continuous activity if it's going to work unless it's based on sound current intelligence and agility.
Consequently, insurance can be a contributor to defence, but paying increasing premiums as the threat landscape hots up may not be the best option, as the money is a throw away while no incident has occurred. It's quite likely you will have paid out in premiums a significant proportion of the insurance payout when an incident finally occurs.
There is an alternative though. Self insurance (investment in a fallback fund) can work well, not least because while not called upon it's attracting interest and therefore increasing in value.
Excluding them makes it worthless
As it immediately means the vast majority of claims will not pay out.
You can't have it both ways, Lloyds.