Why cyber insurance?
While cybersecurity insurance is a relatively new line of service in the industry (it’s only been around for the last 10-15 years), it is currently the fastest-growing form of insurance. And it’s no wonder—today, a data breach at a large company could cost hundreds of millions of dollars. Spurred on by recent increases in breach activity that have resulted in direct consequences and major costs to companies in every industry, more and more organizations are looking to transfer some cyber risk to insurance companies.
What does cyber insurance cover?
Cyber insurance covers all kinds of data losses—from personally identifiable information (PII), to credit card data, to healthcare data, and much more. When a breach happens, there are both first-party and third-party costs that must be covered:
- First-party costs, including:
- Credit monitoring to the customers, patients, or employees affected by the breach.
- Cost of forensics teams to identify and remediate the issue.
- Notification costs, as a company must notify the attorney general in every state people are affected (47 states currently require this action).
- Third-party costs, including:
- Lawsuits from customers, employees, or patients suing because their information was not properly maintained.
The Cyber Insurance Underwriting Process
To understand how much to charge a company, underwriters need to get a sense of how secure the company is and how big of a risk it poses. If the underwriter determines the company is tightly run and secure, the underwriter may charge a lower premium—but if the company doesn’t have the right cybersecurity controls in place, the underwriter may consider a higher premium, or choose not to underwrite the company at all.
But how do cyber liability insurers properly assess a company’s security posture? This has been the primary issue in the cyber insurance industry.
Historically, underwriters have assessed risk through the use of questionnaires and interviews with the company regarding their security practices. (This is very similar to how many companies review third parties for vendor risk.) The questionnaire typically asks many questions on the procedures, policies, hardware, and software that govern IT and cybersecurity, such as: