More than ever before, the market needs a set of trusted cybersecurity analytics on which to focus.
A new independent study by the world’s largest insurance broker, Marsh McLennan, found 14 Bitsight analytics to be significantly correlated with cybersecurity incidents, helping organizations prioritize initiatives to measurably reduce the risk of an incident. These cybersecurity analytics fill an important gap in the market, allowing cyber insurers, insureds, and brokers to make decisions more closely tied to tangible outcomes.
To dive deeper into the analysis and what it means for the cyber insurance industry, Bitsight’s Aaron Aanenson, senior director of cyber insurance thought leadership, sat down for an interview with Noah Stone, senior manager of thought leadership.
Stone: Aaron, I’m excited to discuss this important research with you. To kick us off, what’s the purpose of this study and how did Marsh McLennan’s Cyber Risk Analytics Center (Marsh McLennan) approach the logic behind it?
Aanenson: The primary objective of this study was to further enhance the value of Bitsight’s cyber risk data for both the cyber insurance community and the broader cybersecurity industry. First, this enables cyber insurance underwriters to more easily synthesize the significant amount of risk data they analyze when they underwrite accounts. Second, it empowers cybersecurity leaders and risk managers to have clear data to articulate and support their cybersecurity risk strategies and budgets.
The study makes this possible by correlating likelihood of breach with performance in the cybersecurity risk areas that Bitsight measures, thereby allowing leaders to prioritize which areas of cybersecurity should be optimized for the greatest return on investment.
Insurance customers are interested in this study for these purposes, especially in the current cyber insurance environment where cyber coverage is increasingly challenging to obtain and maintain at a cost that makes sense for risk transfer strategies. Marsh McLennan independently conducted this study by comparing Bitsight’s risk vector ratings and the topline Bitsight Security Rating to their proprietary exposure and loss database. Then, using a statistical technique called “rank biserial correlation,” they quantified the relationship between Bitsight analytics and their loss data to produce the output you see in our report.
Stone: What exactly did Marsh McLennan find in their independent analysis, and why do you think it’s relevant to the cyber insurance industry?
Aanenson: Marsh McLennan found a significant correlation between 14 Bitsight analytics (13 risk vectors and the Bitsight Security Rating) and cybersecurity incidents. This data is incredibly valuable for cyber insurers because it provides objective data that the industry currently lacks. Other lines of insurance rely on decades, if not centuries, of historical risk data to make fairly reliable predictions for the future.
Cyber insurance faces unique challenges because most cyber incident data is kept private. And, the short history of claims data available to carriers demonstrates that the cyber claims of the past are drastically different from the cyber claims we see today. Since cyber threats change so quickly, we don’t necessarily need decades of claims data to inform underwriting decisions but the underwriting still needs to rely on current, reliable datasets that can be tied to losses in order to produce a viable and valuable insurance product.
Overall, this data enhances confidence in the predictability of losses which is critical to support the capacity of providers, underpinning the ability of insurance carriers to issue cyber insurance coverage.