In 2014, Cyber Insurance saw record growth. In fact, in a recent white paper from Advisen, their buyer penetration index showed a five-fold increase in insurance purchases from 2006 to 2013, demonstrating that many organizations have recognized the value in outsourcing corporate cyber risk. Naysayers, however, warn that this move does not make companies more secure and allows organizations to ignore the behaviors and issues that are creating security risks in the first place.
This argument reminds me of the health care debate here in the U.S. Because of the skyrocketing costs of health care, many people have argued that making health insurance more affordable for low-income individuals would create a healthier population and lower overall costs for everyone. Supporters believe that having access to affordable preventative care and diagnostics means that health issues will be detected earlier and treated before they become a major concern. Recent studies have shown that health insurance does in fact make people healthier (when looked at over the long term), though it's yet to be seen how it will impact costs.
True, it’s not the actual policy that makes people healthier, but having the policy helps people adopt the preventative behaviors and take steps that will, in the long run, make them healthier. The case is similar with cyber insurance; people have questioned whether having this insurance can make a company more secure. Below I have outlined three ways that cyber insurance can improve the security performance of organizations:
1) Underwriting assessment process = exposing risks, correcting behaviors
Before an insurance policy is underwritten, there is typically an assessment process to uncover any hidden risks associated with the organization. While health insurance might be the only case where this is not true (in the US you can’t be denied coverage for preexisting conditions), for cyber insurance underwriting, applicants complete questionnaires and assessments that are beneficial for uncovering practices that are exposing the organization to cyber risks. Many insurers are starting to use objective, data-driven assessments like Security Ratings for this process, and in so doing are able to see trends over time for potential insureds and highlight performance and configuration issues in the network. They then require remediation of issues and use this information in deciding how to structure policy(ies). Some insurers, like Liberty International Underwriters, are even using ratings to be able to provide ongoing monitoring and alerts to their insureds, while others are offering the service as a benefit to their policyholders themselves.