Here’s what your organization needs to know about cyber insurance

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum./

Author: Anna Sarnek, Senior Director, Risk Solutions, SecurityScorecard, Larry Slusser, Vice President, Global Head of Professional Services, SecurityScorecard


Currently, 4.7 million experts worldwide work in the cybersecurity field trying to limit the global costs of cybercrime. Losses from cybercrime are expected to surge in the next five years, rising from $8.44 trillion in 2022 to approximately $11 trillion in 2023 and potentially reaching approximately $24 trillion by 2027.Insurers provide cybersecurity recommendations and the insured look to insurers to understand the insurance needs. As such, it is critical to close the gap in both the insurers’ technical cybersecurity knowledge and their knowledge of how the insured’s organization is structured digitally to understand what is already deployed and what else is needed to increase security.

Incidence response (IR) is the process by which an organization handles a data breach or cyberattack. As insurers partner with technology and service providers, often to minimize costs, customers are losing the power to choose which IR firms they can work with and what technology providers they can implement.

In addition, how these recommended technologies are implemented is often not monitored in an ongoing way, which means the security of critical assets may not be continuous. Many insurance company claims teams are utilizing high volume digital forensic firms that, as a result, aren’t necessarily imaging all of the evidence in a case. The ramifications of the gaps created by this high volume digital forensics scheme have yet to be seen in this rapidly changing space. Cybercrime has continued to rapidly increase in 2023 and cyber insurance cost increases have kept pace. According to a recent study of 3,000 cybersecurity and IT professionals, 95% of organizations that purchased a cyber insurance policy in the last year reported a direct impact of this trend on their cyber coverage:

  • 60% said it impacted their ability to get coverage;62% said it impacted the cost of their coverage;and 28% said it impacted the terms of their policy.

While cyber insurance is a critical component of a risk-loss management strategy, the cost benefit is becoming more difficult to analyse owing to continued cyberattacks and increasing premiums. As the cost of premiums increase and organizations learn to implement better system backups, some have opted to invest more heavily in system recovery procedures over cyber insurance.

Losses from cybercrime are expected to surge in the next five years Image: Statista

In addition to rising rates, insurers have introduced exclusion clauses into policies in an effort to minimize risk exposure. In the past two years, many cyber insurers have focused on potentially catastrophic cyber risk, including fallout from geopolitical conflicts and corresponding nation state activity. For example, Lloyd’s of London mandated new war exclusion wording, while Marsh continues to question insurers on clients’ behalf regarding their approach to war and cyber catastrophic risk.The challenge facing insurance companies is quantifying the risk and complexity of measuring the cascading impact of a cyber attack. This monumental task is complicated by a rapidly evolving threat landscape. Without continuous monitoring and reassessments to analyse the insured’s internal environment, the risk quantification is considered static and difficult to predictably rely on.Several IR cases point to Fortune 1000 organizations with eight-figure cybersecurity budgets that get compromised owing to poor implementation of tools and the lack of a critical asset inventory. Furthermore, appropriate internal and third-party access control continues to be a challenge for all organizations and something that cannot be surfaced by questionnaires and control checklists.

Cyber risk management is being driven by advances in predictive aggregation models, improved cyber hygiene, ways to prioritize investments, greater information sharing between private and public entities, and increased government actions and regulations in support of a cyber resilient society.

While these advances can improve internal risk management, they rely on detailed, reliable and continuous data. There is often a gap between the quality and quantity of information available to the insurers and the insured. Consequently, questionnaires are becoming more lengthy and complicated for potential insureds to fill out, often muddling the understanding of the final cyber coverage for the insured.

Organizations can minimize and even simplify risk assessments by focusing on four core areas. These can be summarized in four core questions that will be asked by the IR team in the event of a breach:

What type of firewall is being used?

  • It is absolutely essential that a firewall be in place in any cyber defence structure. It is the drawbridge and fortified door guarding the castle.Equally as critical is the need for at least 60 days of firewall logs, six months if possible. Just like security camera footage, firewall logs are vital evidence in a potential cyber incident.
  • How is the environment backed up?
  • Spending the money for quality back-ups is as important as cyber insurance premiums.Ensure your back-ups are configured to be immune to any possible network intrusion or infectionBack-up length needs to be industry appropriate for the timeline and budget that your industry demands
  • Is there a multifactor authentication (MFA) in place for all users?
  • An MFA requirement for access to any company system is not optional and needs to be implemented so that it cannot be compromised without gross negligence.This needs to apply to all departments and levels of employees throughout the company with a zero-exception policy.
  • Do you regularly verify who has access to your systems?
  • Having a system of changing passwords is not enough; you need to verify who has access to what systems and software at least quarterly.The lowest level of access policies must be mandatory to ensure proper risk mitigation.The principle of least privilege (POLP) model is mandatory to ensure proper risk mitigation. POLP is a concept that limits users’ access rights to only what are strictly required to do their jobs.Having a tool that sends alerts when new accounts are created is a necessary cost to ensure unauthorized users can be identified immediately within the environment.
  • Despite the increasing complexity in cyber insurance and rapidly emerging and changing cyber threats, addressing these questions can help security leaders and cyber insurance providers alike bridge the knowledge gap

    between insurers and insured.

    Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

    Subscribe to get the latest posts sent to your email.

    Interesting reads

    © WHO/Hanan Balkhy Displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services.

    World News in Brief: Mounting waste in Gaza, drone attacks in Sudan, aid truck struck in Ukraine

    This article is published in association with United Nations. Mounting waste and limited access to sanitation sites are deepening health risks for families across Gaza, as humanitarian workers warn that overcrowded dumping areas and worsening living conditions threaten vulnerable communities. Ramiz Alakbarov, UN’s top aid official in Occupied Palestinian Territory visited a dumping site in Gaza […]
    This article was exclusively written for The European Sting by Mr. Franco Miguel Nodado, a 4th-year medical student from the Philippines. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on the topic, nor The European Sting’s one.

    Autism Spectrum Disorders in Global Health: Bridging the Gap in  Awareness, Early Diagnosis, and Inclusive Care 

    This article was exclusively written for The European Sting by Ms. Georgia Maria Vardalachaki, a medical student from the Medical University of Crete, Greece. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s […]
    © WHO/Hedinn Halldorsson WHO Director-General Tedros and a health expert during operations involving the MV Hondius off Tenerife amid the hantavirus response.

    Hantavirus-hit ship evacuation completed as quarantines begin

    This article is published in association with United Nations. The passengers and crew have disembarked from the hantavirus-hit cruise ship MV Hondius in Tenerife and many have returned to their home countries, as the UN World Health Organization (WHO) said the operation demonstrated a “triumph of solidarity”. The repatriation effort, coordinated by Spanish authorities with support […]
    © NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

    Strait of Hormuz de-escalation is urgent, says UN chief

    This article is published in association with United Nations. As the Strait of Hormuz crisis deepens and tensions between Iran and the United States remain unresolved, oil prices rose again early Monday, prompting the UN Secretary-General to call for a peaceful resolution and warn of the widening fallout across Africa and beyond. “My strong appeal is […]
    This article is published in association with United Nations.

    Ukraine: Over 3,000 attacks on healthcare since full-scale Russian invasion

    This article is published in association with United Nations. The World Health Organization (WHO) has verified more than 3,000 attacks on healthcare in Ukraine since Russia launched its full-scale invasion in February 2022, the UN agency reported on Friday. “During 1,534 days of war, Ukraine’s healthcare system has experienced repeated attacks,” it said.  Every aspect of the system has been […]
    WHO Passengers from MV Hondius assisted by Spanish and WHO health teams after disembarking.

    Passengers leave hantavirus-hit cruise ship in Tenerife as WHO says outbreak ‘not another COVID’

    This article is published in association with United Nations. Passengers and crew from the cruise ship MV Hondius began disembarking in Tenerife on Sunday under a tightly coordinated international health operation led by Spanish authorities and the World Health Organization (WHO), as officials sought to reassure the public that the outbreak “is not another COVID.” The […]
    Nuclear energy in the Middle East: A realistic choice or a risk?

    Nuclear energy in the Middle East: A realistic choice or a risk?

    This article is published in association with United Nations. As global electricity demand grows, so does the popularity of nuclear energy. In the Middle East, several countries are evaluating or advancing nuclear power projects, balancing weighty issues such as regional security, climatic conditions and international cooperation. “Nuclear energy is at the intersection of energy demands, technological […]
    © NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

    Bahrain and US float Security Council resolution on the Strait of Hormuz

    This article is published in association with United Nations. Bahrain and the United States have circulated a draft Security Council resolution calling for Iran to cease attacks in the Strait of Hormuz, their ambassadors outlined to journalists at UN Headquarters in New York on Thursday. The text is supported by Kuwait, Qatar, Saudi Arabia and the […]
    © CDC An enhanced microscopic image shows the Hantavirus.

    Hantavirus outbreak: Another passenger contracts disease

    This article is published in association with United Nations. It’s been confirmed that another passenger from the cruise liner linked to the outbreak of hantavirus has contracted the disease, which has claimed the lives of three people on board and sparked an international alert coordinated by the UN World Health Organization (WHO). The individual, who is […]
    This article is published in association with United Nations.

    UN warns of worsening human rights crisis in Mali after deadly attacks

    This article is published in association with United Nations. The human rights situation in Mali is rapidly deteriorating following coordinated attacks by armed groups across the country, with civilians killed, displaced and cut off from food and aid, UN rights office OHCHR said on Tuesday. The violence, which erupted on 25 and 26 April, saw large-scale […]
    © UNICEF A damaged ambulance in Tebnine in southern Lebanon.

    In Lebanon, the same fears and dangers persist despite ceasefire: UNHCR

    This article is published in association with United Nations. Death and destruction have continued unabated in Lebanon while communities are still unable to return to their homes despite a ceasefire that began on 17 April, humanitarians said on Tuesday. “Civilians in the south of Lebanon and parts of the Bekaa [Valley] are really living with the […]
    © Unsplash/Planet Volumes A computer-generated image shows the Strait of Hormuz.

    Uncertainty continues over safety in the Strait of Hormuz

    This article is published in association with United Nations. Amid claims and counter-claims of strikes and confrontations in the crucial Strait of Hormuz between Iran and the United States, UN maritime officials continue to urge vessels to exercise “maximum caution”. “We are aware of the reports but do not have further details. We continue to urge […]
    © ADB/Ariel Javellana Women farmers in India sell wheat grain and buy fertilizer with the proceeds.

    Middle East crisis puts aid, food, fuel further out of reach for millions already struggling – UN agencies

    This article is published in association with United Nations. As the Middle East crisis continues the humanitarian fallout is worsening, with aid route disruptions and food and fuel price hikes wrecking the lives and the rights of the most vulnerable people worldwide, UN agencies warned on Friday. Heightened insecurity and instability around key Gulf routes, including […]
    © Unsplash/Angus Gray Ship transits through the Strait of Hormuz have dropped by over 90 per cent since the crisis escalated in late February 2026.

    Hormuz crisis strangling global economy, Guterres warns, demanding solutions to end stalemate

    This article is published in association with United Nations. The escalating crisis in the Strait of Hormuz could push tens of millions into poverty, trigger a surge in global hunger and even tip the world towards recession, the UN Secretary-General warned on Thursday. António Guterres decried the restrictions on free passage through the crucial chokepoint which […]
    This article is published in association with United Nations.

    AI in advertising risks fuelling information crisis, UN warns

    This article is published in association with United Nations. With spending on advertising topping $1 trillion a year worldwide, the United Nations on Wednesday highlighted the untapped power of major brands to shape the future of Artificial Intelligence, warning that a failure to act could deepen a global information integrity crisis. In a new brief titled […]
    This article is published in association with United Nations.

    2015 nuclear deal ‘no basis’ for any new agreement with Iran

    This article is published in association with United Nations. The 2015 nuclear accord with Iran cannot be the starting point for a new agreement with the country, the head of the International Atomic Energy Agency (IAEA) said on Wednesday in New York.  Rafael Mariano Grossi was speaking during a press conference at UN Headquarters held on […]
    Credit:Unsplash)

    From Hormuz to Lebanon, crisis reverberates through trade routes, upending humanitarian networks

    © WHO/Hanan Balkhy In Gaza displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services. This article is published in association with United Nations. Disruptions in the Strait of Hormuz continue to send shockwaves through global food systems, the UN Food and Agriculture […]
    © UNICEF/Mohamed Zakaria A displacement centre in El Fasher, North Darfur (file).

    World News in Brief: Sudan drone attacks condemned, South Sudan violence, airstrikes in Ukraine, South Africa Freedom Day

    This article is published in association with United Nations. The United Nations has condemned two recent drone attacks in Sudan, one of which left seven dead, Spokesperson Stéphane Dujarric said on Monday during his regular media briefing in New York. An aid truck from the UN refugee agency (UNHCR) that was carrying emergency shelter kits came under attack by […]
    © IMO/Cihancan Tunay A ship makes its way across an ocean.

    Chokepoints and conflict: How the Hormuz crisis is exposing global shipping vulnerabilities

    This article is published in association with United Nations. The blockading of ships in the Strait of Hormuz as a result of the conflict between the United States and Iran has demonstrated how ships and seafarers have become “leverage in geopolitical disputes,” according to the head of the UN’s International Maritime Organization (IMO). Since conflict began […]

    Trackbacks

    1. […] Author: Anna Sarnek, Senior Director, Risk Solutions, SecurityScorecard, Larry Slusser, Vice President, Global Head of Professional Services,… Source: europeansting.com – Read more […]

    2. […] Author: Anna Sarnek, Senior Director, Risk Solutions, SecurityScorecard, Larry Slusser, Vice President, Global Head of Professional Services,… Source: europeansting.com – Read more […]

    Why don't you drop your comment here?

    Go back up

    Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com