How Cyber Insurance Underwriting Has Evolved
As cyber attacks have become more commonplace and the frequency of claims has grown, the process of cyber insurance underwriting has evolved significantly.
To reduce risk and potential losses, insurers are becoming more diligent about risk assessment during the application process and throughout the life of the policy. They want to know what measures your organization is taking to protect against cyber attacks and mitigate their impact—and they are turning to technology for answers.
In addition to relying on traditional methods such as risk assessment questionnaires, which are often subjective and hard to verify, today’s sophisticated underwriting technology can shine a light on your security posture in a non-invasive and data-driven way. These tools can help underwriters evaluate the financial impact of a cyber attack on your business, compare your security performance to others in your sector, and assess cyber risk in your supply chain.
Once a policy is secured, insurers can continuously monitor your organization's cybersecurity health and keep a pulse on emerging risk throughout the period of coverage.
What Risks Do Cyber Insurance Underwriters Look For?
Many hackers rely on network and system vulnerabilities such as open ports, unpatched software, and misconfigured systems for their attacks. Insurers want to know that your organization is taking steps to understand and act on these risks. A failure to do so may result in a higher premium or declined coverage.
Other elements of a mature and established security management program that underwriters look for are a robust data management strategy, multi-factor authentication, network segmentation, and endpoint protection.
To ensure you can procure the right policy at the right cost, use a tool like Bitsight Security Ratings. Bitsight provides a complete view of hidden risk in your network and across your integrated supply chain, so that you can remediate it before it becomes an issue and help reduce potential cyber risk insurance claims in the future. Additionally, 50% of global cyber insurance gross written premiums are underwritten by Bitsight customers including AIG, Chubb, and Hartford.
Prepare For Your Cyber Insurance Application
When applying for cyber insurance or renewing a policy, preparation can ensure the best outcome. Engage multiple teams including security, IT, compliance, and legal—each has a role to play in providing timely input.
Next, begin gathering the information that potential insurance companies will need. Your list should include relevant data points that prove your organization’s commitment to sound cybersecurity.
Bitsight Security Ratings are a great way to prove your digital risk protection efforts to a cyber risk insurance provider. Presenting an external, objective view of your network’s cybersecurity posture will give your potential insurance provider a trusted view into what your organization does to protect from threats, and will make securing a cyber risk insurance policy smoother.
Ensure Your Policy Covers Relevant Risks
Before you sign on the dotted line, study your insurer’s contractual wording to avoid any misunderstanding of what is covered and what’s excluded. For example, if your organization is hit by ransomware and chooses to pay the ransom, verify that your organization is protected against those financial losses. Another common exclusion are state-sponsored cyber-attacks. If you’re in a high-risk sector, such as critical infrastructure, technology, or finance, this form of coverage is crucial.
Read more about cyber insurance, what is and isn’t covered, and other things to look for in an insurer.