Cyber risk uncertainty is growing. Despite massive spending worldwide to the tune of $173 billion, cyber attacks keep occurring. Ransomware attacks—a type of cyberattack that encrypts an organization's network or locks users out of their devices and requires a ransom before restoring access—are costing companies 20 days of downtime on average. Within the next few years, nearly half of companies worldwide will experience cyber attacks on their software supply chains. And threats like malware and botnets (such as the recent Emotet re-emergence) are wreaking havoc on companies worldwide.
It comes as no surprise that cyber insurance claims are exploding. As companies worldwide scramble for coverage, insurers are experiencing significant losses and rethinking their underwriting decisions. The result? Stricter underwriting standards, which take longer to evaluate.
So how do cyber insurers determine which organizations are going to be a risk worth taking? It depends on an organization’s overall cyber hygiene and their ability to effectively respond to new attacks and vulnerabilities. It’s more important than ever to continue underwriting good and opportunistic risks, while not overcorrecting for the high loss ratios the industry is seeing. Insureds need to answer two questions: what is good cyber hygiene and how do you measure it? In this blog, I will tackle the first of these questions. Insurers have to first understand the current cyber insurance landscape and how it impacts cyber hygiene.
The link between ransomware and cyber insurance
Before unpacking cyber hygiene, first consider how ransomware is impacting the cyber insurance landscape. Traditional insurance, such as auto or home insurance, provides coverage for high impact, low frequency events. This type of insurance covers events that likely won’t happen, but could be very costly if they did. Organizations seek insurance coverage for these risks because it’s impractical to mitigate or avoid them. With the explosion of ransomware, companies suddenly experience high impact and high frequency incidents—making cyber insurance more expensive and harder to get, yet more necessary than ever.
Ransomware has been a threat for a long time. In 2016, Bitsight published an article to draw attention to the problem. Since then, ransomware and other similar threats are only continuing to explode. Nowadays, attackers use cryptocurrencies to monetize ransomware attacks in a way that’s easier to get payment and avoid tracking. Plus, the rapid speed of digital transformation in the last few years means that the attack surface has never been bigger for attackers to find areas of weakness.