The SolarWinds breach is already one of the most significant cybersecurity incidents ever. And as with any unprecedented cyber event, this will have long-term effects on the way businesses and government consider their security programs. While many questions remain unanswered, the SolarWinds impact on the insurance sector has become clearer after an analysis we’ve completed with one of our partners. So, what should we expect the financial impact of SolarWinds on cyber insurers? And how can cyber insurers quantify a breach of this scale in the future?
Today, Bitsight and Kovrr announced our new partnership and released a joint analysis of the financial impact of the SolarWinds hack to the insurance industry. We find that although the SolarWinds attack is a cyber catastrophe from a national security perspective, insurers may have narrowly avoided a catastrophic financial incident to their businesses. We estimate the insured losses to be $90,000,000, which includes incident response and forensic services for companies who were impacted by this incident and have cyber insurance coverage.
Quantifying the financial cost associated with the SolarWinds attack
Together, Bitsight and Kovrr are able to produce the cost associated with the breach by breaking down the different elements into cost components. Based on the specific organization location, industry, and size, we are able to determine the cost of forensics, incident response, regulatory fines, addressing the incidents, and using public relations services to communicate information about the attack. This information is mostly derived from claims and other data sources of prior incidents.
We estimate the insured losses from the SolarWinds attack to be $90,000,000, which includes incident response and forensic services for companies who were impacted by this incident and have cyber insurance coverage.
While the number of SolarWinds victims from the attack may grow in the following months, we do not expect the direct insured costs to change significantly. We note that many of the organizations affected by this incident include Federal government agencies, who typically do not buy insurance for most risks, including cyber.