Here’s what your organization needs to know about cyber insurance

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum./

Author: Anna Sarnek, Senior Director, Risk Solutions, SecurityScorecard, Larry Slusser, Vice President, Global Head of Professional Services, SecurityScorecard


Currently, 4.7 million experts worldwide work in the cybersecurity field trying to limit the global costs of cybercrime. Losses from cybercrime are expected to surge in the next five years, rising from $8.44 trillion in 2022 to approximately $11 trillion in 2023 and potentially reaching approximately $24 trillion by 2027.Insurers provide cybersecurity recommendations and the insured look to insurers to understand the insurance needs. As such, it is critical to close the gap in both the insurers’ technical cybersecurity knowledge and their knowledge of how the insured’s organization is structured digitally to understand what is already deployed and what else is needed to increase security.

Incidence response (IR) is the process by which an organization handles a data breach or cyberattack. As insurers partner with technology and service providers, often to minimize costs, customers are losing the power to choose which IR firms they can work with and what technology providers they can implement.

In addition, how these recommended technologies are implemented is often not monitored in an ongoing way, which means the security of critical assets may not be continuous. Many insurance company claims teams are utilizing high volume digital forensic firms that, as a result, aren’t necessarily imaging all of the evidence in a case. The ramifications of the gaps created by this high volume digital forensics scheme have yet to be seen in this rapidly changing space. Cybercrime has continued to rapidly increase in 2023 and cyber insurance cost increases have kept pace. According to a recent study of 3,000 cybersecurity and IT professionals, 95% of organizations that purchased a cyber insurance policy in the last year reported a direct impact of this trend on their cyber coverage:

  • 60% said it impacted their ability to get coverage;62% said it impacted the cost of their coverage;and 28% said it impacted the terms of their policy.

While cyber insurance is a critical component of a risk-loss management strategy, the cost benefit is becoming more difficult to analyse owing to continued cyberattacks and increasing premiums. As the cost of premiums increase and organizations learn to implement better system backups, some have opted to invest more heavily in system recovery procedures over cyber insurance.

Losses from cybercrime are expected to surge in the next five years Image: Statista

In addition to rising rates, insurers have introduced exclusion clauses into policies in an effort to minimize risk exposure. In the past two years, many cyber insurers have focused on potentially catastrophic cyber risk, including fallout from geopolitical conflicts and corresponding nation state activity. For example, Lloyd’s of London mandated new war exclusion wording, while Marsh continues to question insurers on clients’ behalf regarding their approach to war and cyber catastrophic risk.The challenge facing insurance companies is quantifying the risk and complexity of measuring the cascading impact of a cyber attack. This monumental task is complicated by a rapidly evolving threat landscape. Without continuous monitoring and reassessments to analyse the insured’s internal environment, the risk quantification is considered static and difficult to predictably rely on.Several IR cases point to Fortune 1000 organizations with eight-figure cybersecurity budgets that get compromised owing to poor implementation of tools and the lack of a critical asset inventory. Furthermore, appropriate internal and third-party access control continues to be a challenge for all organizations and something that cannot be surfaced by questionnaires and control checklists.

Cyber risk management is being driven by advances in predictive aggregation models, improved cyber hygiene, ways to prioritize investments, greater information sharing between private and public entities, and increased government actions and regulations in support of a cyber resilient society.

While these advances can improve internal risk management, they rely on detailed, reliable and continuous data. There is often a gap between the quality and quantity of information available to the insurers and the insured. Consequently, questionnaires are becoming more lengthy and complicated for potential insureds to fill out, often muddling the understanding of the final cyber coverage for the insured.

Organizations can minimize and even simplify risk assessments by focusing on four core areas. These can be summarized in four core questions that will be asked by the IR team in the event of a breach:

What type of firewall is being used?

  • It is absolutely essential that a firewall be in place in any cyber defence structure. It is the drawbridge and fortified door guarding the castle.Equally as critical is the need for at least 60 days of firewall logs, six months if possible. Just like security camera footage, firewall logs are vital evidence in a potential cyber incident.
  • How is the environment backed up?
  • Spending the money for quality back-ups is as important as cyber insurance premiums.Ensure your back-ups are configured to be immune to any possible network intrusion or infectionBack-up length needs to be industry appropriate for the timeline and budget that your industry demands
  • Is there a multifactor authentication (MFA) in place for all users?
  • An MFA requirement for access to any company system is not optional and needs to be implemented so that it cannot be compromised without gross negligence.This needs to apply to all departments and levels of employees throughout the company with a zero-exception policy.
  • Do you regularly verify who has access to your systems?
  • Having a system of changing passwords is not enough; you need to verify who has access to what systems and software at least quarterly.The lowest level of access policies must be mandatory to ensure proper risk mitigation.The principle of least privilege (POLP) model is mandatory to ensure proper risk mitigation. POLP is a concept that limits users’ access rights to only what are strictly required to do their jobs.Having a tool that sends alerts when new accounts are created is a necessary cost to ensure unauthorized users can be identified immediately within the environment.
  • Despite the increasing complexity in cyber insurance and rapidly emerging and changing cyber threats, addressing these questions can help security leaders and cyber insurance providers alike bridge the knowledge gap

    between insurers and insured.

    Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

    Subscribe to get the latest posts sent to your email.

    Interesting reads

    UN News A popular market in Khan Younis, southern Gaza Strip.

    Economic collapse pushes highly educated Gazans into the ‘survival economy’

    This article is published in association with United Nations. Young Palestinians in Gaza with university-level educations are setting aside dreams of putting their hard-won skills into practice and doing whatever they can to survive.  Abdullah al-Khawaja, an electrical engineering graduate displaced from Rafah to Khan Younis, now stands behind a small spice stall, having lost the […]
    MONUSCO/Didier Vignon Dossou-Gbakon MONUSCO peacekeepers protect civilians in Ituri, eastern DRC.

    World News in Brief: AI diagnostics, humanitarian deal for DR Congo, rights abuse allegations in Belarus, Ukraine children bear heaviest burden

    This article is published in association with United Nations. New data shows that nearly three in four countries in Europe now use Artificial Intelligence in their health services to make a diagnosis. According to the UN World Health Organization (WHO) joint report with the European Union, 74% of countries in the bloc use AI tools in medical […]
    © WFP The conflict in the Middle East is impacting the cost of food in many parts of the world.

    Time running out on development goals as finance dries up, UN warns

    This article is published in association with United Nations. Rising conflicts, the climate crisis and shrinking development finance are putting growing pressure on the poorest and most vulnerable countries – pushing development goals further off track. The warning comes in the Financing for Sustainable Development Report 2026 (FSDR), a new UN report launched on Monday, which finds […]
    Ukraine’s women at breaking point after four years of war as attacks on energy, healthcare continue – UN humanitarians

    World News in Brief: Myanmar amnesty, rising needs in Afghanistan, another power loss at Ukraine nuclear plant

    This article is published in association with United Nations. Authorities in Myanmar released the country’s ousted president from prison on Friday, along with some 4,000 other people, as part of an amnesty to mark the traditional New Year festival. President Win Myint had been in jail since February 2021 when the military overthrew Myanmar’s democratically elected […]
    UN Photo/Eskinder Debebe Siobhán Mullally, Special Rapporteur on Trafficking in Persons, especially women and children, one of the UN independent human rights experts calling for more accountability for the alleged trafficking victims in the Epstein files.

    The Epstein files: Rights experts demand accountability, call for probe into trafficking allegations

    This article is published in association with United Nations. UN independent human rights experts called on Thursday for justice and accountability for young women and girls who were trafficked systematically as part of allegations contained in the so-called Epstein files. The Human Rights Council-appointed experts also issued a general warning over the “continuing violence of patriarchal power systems” revealed […]
    © World Bank A ship offloads its cargo at the port in Nuku'alofa, Tonga.

    Middle East conflict chokes end of supply chain as lights go out in the Pacific

    This article is published in association with United Nations. For Pacific Island countries, the Middle East crisis is not a distant geopolitical event. It is already showing up in higher fuel prices, electricity uncertainty and fears that communities sitting at the far end of global supply chains could be pushed into deeper economic insecurity. “We are […]
    © UNICEF/Fouad Choufany The Basta neighbourhood in Beirut, Lebanon, lies in ruins.

    ‘Time for diplomacy over escalation’ in Middle East war: Guterres

    This article is published in association with United Nations. As the war in the Middle East continues, the United Nations Secretary-General issued a passionate call for “serious negotiations” between the US and Iran to resume, warning that respect for international law “is being trampled” underfoot.  Addressing journalists at UN Headquarters in New York outside the Security […]
    © IFAD/GMB Akash Prolonged disruptions to fuel and natural gas supplies could affect the global availability of fertilizers and impact crop yields. (file photo)

    ‘Clock is ticking’: Hormuz disruption raises fears of global food crisis

    This article is published in association with United Nations. The clock is ticking for global food systems as disruptions in the Strait of Hormuz threaten to choke off the flow of fuel and crucial fertilizers needed for the next planting season – also raising the risk of higher food prices and a new wave of inflation.  […]
    This article is published in association with United Nations.

    Lebanon airstrike casualties ‘still under the rubble’ as ambulances, hospitals face new threats

    This article is published in association with United Nations. With Lebanon still reeling from Israel’s devastating airstrikes on 8 April, UN humanitarians reported new fears of attacks on ambulances and looming food shortages in the south of the country on Friday. Speaking from Beirut, where he witnessed Wednesday’s attacks first-hand, the World Health Organization (WHO)’s representative […]
    This article is published in association with United Nations.

    Lebanon: Health system overwhelmed following a ‘horrific’ day of Israeli strikes

    This article is published in association with United Nations. The scale and speed of destruction from the wave of airstrikes in Lebanon which began just hours after the US-Iran ceasefire announcement, has left the country’s already strained health system struggling to cope, according to the World Health Organization (WHO). WHO Representative in Lebanon Dr. Abdinasir Abubakar […]
    © NASA/Jeff Schmaltz A satellite image shows the Strait of Hormuz. (far right)

    Iran ceasefire raises hopes for reopening key Strait of Hormuz

    This article is published in association with United Nations. The announcement of a shaky two-week ceasefire between the US and Iran, will it is hoped, lead to the opening of the strategically important Strait of Hormuz, a vital waterway through which one fifth of the world’s oil and gas passes. The strait has become a global […]
    Fokah Wembe Darrell Dupray is a 4th-year medical student at Université des Montagnes, Bangangté Cameroon and a student leader within the Cameroon Medical Students’ Association (CAMSA).

    Global Health Priorities for the Year Ahead: Why the Next Generation Must Lead

    This article was exclusively written for The European Sting by Mr. Sharif Mohammed Sadat, a medical student from Bangladesh and serves as the Regional Director for Asia-Pacific of the International Federation of Medical Students’ Associations (IFMSA). He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this […]
    © IOM Families returning to Khartoum face the mounting task of rebuilding their lives and livelihoods amid damaged homes and limited access to basic services (file).

    World News in Brief: ‘Skyrocketing’ needs outpace Sudan funding, Ukraine strikes update, global water security

    This article is published in association with United Nations. The UN is significantly scaling up its presence in the Sudanese capital, Khartoum, to expand life-saving operations as the conflict between rival militaries approaches its third year. UN Resident and Humanitarian Coordinator Denise Brown has returned to the city with a core team, marking a renewed commitment […]
    © UNHCR Smoke and debris from a building in the Bashura neighbourhood of Beirut, Lebanon, after an airstrike.

    MIDDLE EAST LIVE 6 April: Strikes persist across region as humanitarian needs rise

    This article is published in association with United Nations. Strikes and counter-strikes continue across the Middle East, with dozens of casualties reported over the weekend in Lebanon following Israeli strikes targeting the south and the capital, Beirut. Meanwhile, humanitarian needs are rising, critical infrastructure remains under strain, and the wider economic and global impacts of the […]
    This article is published in association with United Nations.

    UN nuclear agency chief ‘deeply concerned’ by reports of latest attack on Iran power plant

    This article is published in association with United Nations. Reports of yet another projectile strike near the Bushehr nuclear power plant prompted Rafael Grossi, head of the International Atomic Energy Agency (IAEA), to register his deep concern on Saturday. The IAEA was informed of the strike – the fourth such incident in recent weeks – by […]
    This article is published in association with United Nations.

    Guterres warns of ‘wider war’ as Middle East conflict enters second month

    The Middle East crisis has lurched into its second month, prompting UN Secretary-General António Guterres to issue a stark warning on Thursday morning that the world is “on the edge of a wider war” with catastrophic global implications. Speaking to the press outside the Security Council in New York, the UN chief painted a grim picture of the rapidly […]
    This article is published in association with United Nations.

    Middle East war: Energy crunch hits vulnerable nations

    The war in the Middle East and the near halt to shipping in the Strait of Hormuz has amplified the energy crunch facing developing nations in Africa and South Asia that rely heavily on imported liquid gas, food and fertilizers.  And with Brent Crude still trading at more than $100 per barrel, many workers and households have reverted to […]
    © WHO UN officials in Cyprus oversee the loading of emergency humanitarian supplies for Gaza.

    Breaking the Gaza aid bottleneck: 106-tonne delivery arrives via new sea route

    This article is published in association with United Nations. The World Health Organization (WHO) has facilitated the delivery of some 106 metric tonnes of lifesaving nutrition supplies to the Gaza Strip – the first shipment via a mechanism to deliver aid by sea, in line with a UN Security Council resolution and amid the ongoing war […]
    © IMO Crew members take a break on a ship. (file)

    ‘No precedent’ for seafarers caught in war zone in post-WW2 era

    This article is published in association with United Nations. Some 20,000 seafarers remain stranded on ships in the Strait of Hormuz as the war in the Middle East continues, a situation which has been described as unprecedented in the post-Second World War era. The seafarers are working on some 2,000 ships including oil and gas tankers, […]

    Trackbacks

    1. […] Author: Anna Sarnek, Senior Director, Risk Solutions, SecurityScorecard, Larry Slusser, Vice President, Global Head of Professional Services,… Source: europeansting.com – Read more […]

    2. […] Author: Anna Sarnek, Senior Director, Risk Solutions, SecurityScorecard, Larry Slusser, Vice President, Global Head of Professional Services,… Source: europeansting.com – Read more […]

    Why don't you drop your comment here?

    Go back up

    Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com