Swiss Re wants government bail out as cybercrime insurance costs spike
- Reference: 1667939409
- News link: https://www.theregister.co.uk/2022/11/08/government_cyber_insurance/
- Source link:
Global cyber insurance premiums hit $10 billion in 2021, according to Swiss Re's estimates. In a [1]study published this week, the insurance giant forecasted 20 percent annual growth to 2025, with premiums rising to $23 billion over the next few years.
Meanwhile, annual cyberattack-related losses total about $945 billion globally
[2]PDF
, and about 90 of that risk remains uninsured, according to insurance researchers at the Geneva Association[3]PDF
.[4]
While Forrester estimates a typical data breach costs an average [5]$2.4 million for investigation and recovery , only 55 percent of companies currently have cyber insurance policies. Additionally, less than 20 percent have coverage limits in excess of $600,000, which the analyst firm cites as the median ransomware demand in 2021.
[6]
[7]
"The market needs to mature further to ensure enough insurance protection is available," John Coletti, head cyber reinsurance at Swiss Re, told The Register . "Our industry has a key role to play by addressing three issues: improving data and modeling, increasing contract consistency and clarity and identifying new sources of capital."
The Swiss Re Institute recommends all three of these points to help mitigate exposure to cyber risk — and keep the insurance industry profitable.
[8]
While the industry has typically quantified risks based on backward-looking data, that doesn't work for cyber risk because of a couple of reasons: a lack of standardized data, and the rapidly changing threat landscape.
"Introducing cybersecurity standards will improve data in terms of breadth and transparency to allow meaningful risk insights and enable more accurate pricing and modeling," according to the report.
[9]Ritz cracker giant settles bust-up with insurer over $100m+ NotPetya cleanup
[10]Unhappy about excluding nation-state attacks from cyberinsurance? Get ready to pay
[11]Lloyd's to exclude certain nation-state attacks from cyber insurance policies
[12]Higher risks and premiums are creating critical gap in cyber insurance
Swiss Re also recommends insurers update policy language around exclusion clauses, terms and conditions to help clarify the scope of coverage.
Other insurance firms and marketplaces are struggling with policy language as well. Lloyd's of London recently announced that its sellers' policies will [13]soon stop covering losses from certain nation-state cyber attacks and those that happen during wars, declared or not.
Lack of clarity around coverage also landed two other major insurers, ACE American Insurance Company and Zurich American Insurance Company, into legal trouble after the 2017 NotPetya cyberattack. In this case, the question was around [14]what constitutes an act of war — which even in cyberspace could invalidate an insurance claim – and whether insurance companies should pay damages caused by network intrusions supported or organized by nation states.
[15]
"Exposures to hard-to-insure systemic risk scenarios remain a barrier for industry capacity," the Swiss Re study noted. "Stakeholders have taken steps to fix some of these issues, but factors such as attribution of cyber events remain a core problem."
Swiss Re also called for "new sources of capital," and added that "public and private sector collaboration is key to mitigating cyber threats to critical infrastructure."
One way to do this would be a government-backed fund to address the cyber-insurance gap, according to the report. Along these lines, the US Treasury recently [16]published a request for comment on questions related to cyber-insurance and catastrophic cyber incidents.
Another option "would be to tap into the market for insurance-linked securities," Swiss Re said. ®
Get our [17]Tech Resources
[1] https://www.swissre.com/institute/research/topics-and-risk-dialogues/digital-business-model-and-cyber-risk/cyber-insurance-strengthening-resilience.html
[2] https://www.mcafee.com/enterprise/en-us/assets/reports/rp-hidden-costs-of-cybercrime.pdf
[3] https://www.genevaassociation.org/sites/default/files/research-topics-document-type/pdf_public/research_brief_-_global_insurance_protection_gaps.pdf
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y2rfiGwuGYxKs7SuGTy23AAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://www.forrester.com/blogs/breaches-by-the-numbers-adapting-to-regional-challenges-is-imperative/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2rfiGwuGYxKs7SuGTy23AAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2rfiGwuGYxKs7SuGTy23AAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2rfiGwuGYxKs7SuGTy23AAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2022/11/02/mondelez_zurich_notpetya_settlement/
[10] https://www.theregister.com/2022/09/06/lloyds_cyber_insurance_policy/
[11] https://www.theregister.com/2022/08/24/lloyds_cybersecurity_insurance/
[12] https://www.theregister.com/2022/08/11/insurance_ransomware_blackberry/
[13] https://www.theregister.com/2022/08/24/lloyds_cybersecurity_insurance/
[14] https://www.theregister.com/2022/11/02/mondelez_zurich_notpetya_settlement/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2rfiGwuGYxKs7SuGTy23AAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://www.federalregister.gov/documents/2022/09/29/2022-21133/potential-federal-insurance-response-to-catastrophic-cyber-incidents
[17] https://whitepapers.theregister.com/
Re: It's capitalism
Yep. The days of insurers covering a risk in order to, on average, secure a return are long gone. Everyone just wants a guaranteed return.
Re: It's capitalism
That is basically my point.
Insurers know (or should know) what they are insuring. If the risks are high (perhaps because a company does not keep its systems secure) then the premiums should be high. They have an option, which is not to insure that part of the business at all. Instead they seem to be wanting to take the money but pass on the bill for the clean up to the taxpayer. Guaranteed profits not risk.
Or we could just get rid of bitcoin…
Yes, if only we knew that doing that would prevent any kind of cyber incident back in 2009, we could have stopped it in its tracks. After all, there was no computer-based crime in 2008. Criminals also have no way of exchanging money except for cryptocurrency, so that's another ill of society that didn't exist back in 2008. I'm glad you're here to tell us the easy answers.
Cyber insurance covers (or claims to cover) a lot of things. Eliminating cryptocurrency wouldn't even stamp out ransomware, but if it did, there would still be problems.
Why?
It isn't the governments that are slashing security spending left, right and centre (governments likely never have budget anyway). It isn't the governments playing security kabuki (especially not if they're nation state actors).
Can I make a counter-offer: only insure (or re-insure the insurers) if you've verified that their security isn't just lip service. Also, introduce personal liability for the executive and the board.
You can all stop bitterly laughing now.
Re: Why?
Absolutely this. You don't insure a driver without them having a valid license (albeit it's not always a great guide to competence), so why would you insure a company against an electronic break-in without first checking they at least have doors on the property?
It's not the insurance industry
that needs to mature in this case.
Except for that bit about whining when a bet turns sour.
Bill Microsoft
It's their shite at the core of the problem.
It's capitalism
Privatise the profitable bits, socialise all the losses. There shall at no time be any risk to the private sector. It's a rule