Cyber insurers regularly get requests for new business and increased limits. How can they determine which organizations will be a risk worth taking? In my previous blog, I discussed how understanding an applicant’s cyber hygiene is the best indicator of whether they may experience a successful ransomware or other cyber attack. In this blog, I’ll walk through how to measure an applicant's cyber hygiene and which metrics are categorically proven to stand out.
How to measure an applicant's cyber hygiene
Despite the significant increase in cyber insurance premiums, there are still organizations that lean on their cyber policy in lieu of making larger investments in new and more effective security controls. Part of an underwriter’s job is to identify these cases and avoid insuring them.
A strong candidate for cyber insurance is typically an organization that performs the following tasks and then seeks insurance for risks that are unlikely to materialize (yet would be devastating if they did):
- Demonstrates that they have processes in place to identify cyber risk
- Mitigates high likelihood and high impact risks sufficiently
- Integrates backup controls and other layers of security to enforce a defense-in-depth strategy
- Monitors their security program for effectiveness
- Seeks incremental improvements over time
Armed with this information, underwriters can perform a more in-depth discovery with applicants so that the risk is qualitatively and quantitatively evaluated against specific underwriting criteria. The most common quantitative method to measure cyber hygiene is with a cybersecurity ratings tool. Modern IT environments are complex, and it’s hard to make and understand insureds’ claims about cybersecurity. Cybersecurity ratings solutions help underwriters verify the accuracy of the information they receive from applicants with an unbiased view of a cybersecurity program.
Start with an applicant's security rating
The best indicator for future performance is past performance. Underwriters can derive this from cybersecurity ratings because they are based on historical cybersecurity performance. Think of a security rating like a credit rating—if someone missed a payment by the due date, their credit score might be impacted and then need time to recover. When it comes to cyber insurance, the same principles apply so that applicants are incentivized to maintain strong cybersecurity throughout the policy period. Without that incentive, some insureds might treat cybersecurity as a once-a-year exercise, leaving insureds vulnerable throughout the policy period and their carriers on the hook for claims.