Cyber insurance continues to pick up steam, with both smaller and larger entities adopting it. There are several drivers, such as recent supply chain compromises, large ransomware attacks, and the need to limit liability. The immediate and latent effects of a data breach are massive, ranging from loss of business, to degraded brand reputation, and loss of sensitive customer data.
While many organizations look at cyber insurance as a way to transfer risk and mitigate financial losses, the assessment process used by cyber insurers can help shape your security program for the better by understanding how claims are driving the questions they are asking you.
Assessing your security program
Cyber insurance takes a multifaceted approach when it comes to writing and providing coverage to an organization. The criteria is no different than with auto insurance, where it’s not just your driving record that determines pricing and how much liability the insurer is willing to take on. Some of the aspects that impact cyber insurance underwriting include the scale and size of an organization, the number of employees, and annual revenue. Insurers look at how much Personal Identifiable Information (PII), including Protected Health Information (PHI), is held by the company, both for employees and customers. Is the business processing lots of financial data? How reliant is a company on third-party providers for business operations? What controls does the business have in place, and what are the effectiveness of these controls in reducing the risk of cyber attacks?
Cybersecurity controls are assessed through self-attestation and direct observation—trust but verify. Questionnaires, such as those used in a standard Third Party Risk Management (TPRM) program, help inform insurers about what policies, processes, and controls are currently in place, as well as get a sense of whether the company seeking insurance believes they're following the resultant procedures, globally and consistently. The questionnaires usually follow an accepted standard framework, such as the NIST Cybersecurity Framework (CSF) or ISO 27001 and can include controls such as Multi Factor Authentication (MFA) for employee login into company systems or anti-phishing training. Are backups performed consistently and adequately protected from ransomware attacks? What vulnerability management tools are used, how often are they run, how quickly are the most critical vulnerabilities remediated, and how often are exceptions reviewed?
To augment assessments, validating these responses is done via a risk performance measurement tool, which can confirm or invalidate some assessment responses and reveal that what should be a strength is actually a liability. An example of the above would be if a company states that they have strict policies in place for the security of data in transit, but it's found they have many instances of SSLv3 enabled on exposed systems.