Skip to main content
The Actuary: The magazine of the Institute and Faculty of Actuaries - return to the homepage Logo of The Actuary website
  • Search
  • Visit The Actuary Magazine on Facebook
  • Visit The Actuary Magazine on LinkedIn
  • Visit @TheActuaryMag on Twitter
Visit the website of the Institute and Faculty of Actuaries Logo of the Institute and Faculty of Actuaries

Main navigation

  • News
  • Features
    • General Features
    • Interviews
    • Students
    • Opinion
  • Topics
  • Knowledge
    • Business Skills
    • Careers
    • Events
    • Predictions by The Actuary
    • Whitepapers
    • Moody's - Climate Risk Insurers series
    • Webinars
    • Podcasts
  • Jobs
  • IFoA
    • CEO Comment
    • IFoA News
    • People & Social News
    • President Comment
  • Archive
Quick links:
  • Home
  • Sections
  • Predictions
Predictions Features

Brace yourselves: Global cyber insurance demand is coming

Open-access content Saturday 26th August 2017

While cyber liability insurance is one of the fastest growing type of products in the industry, the majority of growth has come from US, but that is about to change.

Web_CyberSecurity_shutterstock_346773854.jpg

The US – where the regulation resides

The most plausible explanation for the rapid rise of cyber liability insurance in the US — and not elsewhere — is that individual states (well, at least 48 of them) and the federal government have been at the forefront of privacy legislation by enacting strict data breach notification statutes.

The effect of this legislation is multi-faceted, but naturally involves business cost. First, because many of these laws follow the states of residence of the affected individuals as opposed to the location of the breach or the breached entity, an incident affecting a large enough population will likely require an analysis of each of these laws, many of which have different definitions as to what exactly constitutes a breach requiring notification, and varying requirements as to the method, timeliness, and wording of the notification. Second, to the extent legal counsel determines that notification is indeed required, the organisation will incur the cost of transmitting the notice (usually by regular mail), and often, depending on the type of information compromised, the notice will include credit/identity theft monitoring and fraud resolution services. Finally, to the extent any regulators take an interest in the incident, there is a risk of a fine or penalty being assessed. Recent examples include an $18.5m (£14.4m) settlement between a retailer and 47 states and the District of Columbia, and a $5.55m settlement between a health system and the Department of Health & Human Services Office for Civil Rights.

The new frontier

Outside the US, and without the regulation-driven costs, there has understandably been less of an interest and/or perceived need for cyber liability insurance. But that lack of demand appears to be dissipating rapidly. What’s changed? For starters, there has been an evolution in both the manner and purpose of cyber attacks, most notably ransomware. According to security firm SonicWall’s 2017 Annual Threat Report, ransomware use grew 167 times year over year, as the 3.8 million attack attempts in 2015 rose to 638 million in 2016. Hackers have concluded that instead of spending a great deal of time attempting to infiltrate a targeted organisation’s network through a backdoor security hole, it’s easier to trick one of the organisation’s employees into opening the front door. What’s more, according to Symantec’s 2017 Internet Security Threat Report, the average ransomware extortion demand rose to $1,077 in 2016, up from $294 in 2015, and those numbers are expected to rise as attackers shift their focus from individual consumers to businesses.

Source: WLTW

 

In June, a cloud services provider had 150 of its servers encrypted, resulting in outages to the sites of more than 3,400 of its business customers. The ransom demand was purportedly negotiated down from an initial demand of over $4m to approximately $1m (a record amount — for now — in terms of publicly reported ransomware payments). What is so noteworthy about this particular demand is not so much the amount, but the way in which it was derived; it has been reported that the hackers based their demand on a calculation of the cloud provider’s total annual payroll. Accordingly, it seems that attackers in the future are more likely to make demands that take into account the financial means of their victims. It remains to be seen just how high that number can go before an affected organisation decides it’s not worth recovering the encrypted data.

While the increase in ransom demand amounts may finally be tempting non-US organisations to purchase cyber liability insurance, it’s more likely that the consequences of not paying the ransom has them apprehensive. To the extent that: a) the affected organisation refuses to pay the ransom; b) the hacker does not live up to their end of the bargain and fails to provide the decryption key; or c) the decryption process fully or partially fails and causes corruption of the data at issue, the effect could very well be an extended period of business interruption. The inability to earn income due to a network disruption is something to which any modern day organisation can relate. Recent mass scale WannaCry and Not-Petya ransomware attacks have caused business interruptions of varying degrees to companies of all sizes. It is this system outage coverage that has served to convince many insurance buyers — even those with little to no risk of regulation-driven cost exposure — that there is still relevant and valuable protection available within a cyber liability insurance policy. Moreover, the number of organisations around the world with little regulatory exposure is decreasing.

Privacy regulation outside the US

We previously provided a comprehensive look into the EU’s GDPR, which is set to apply from May 25, 2018 following a two-year transition period. What has not received as much attention is China’s 79-article Cyber Security Law (“CSL”), which took effect on June 1, 2017, and is likely to impact companies with a presence in China and those doing business with China. As a basic law, the CSL is an important starting point for personal information protection and regulation of cyber security risks. It is expected that a series of rules and regulations will be released to work alongside the CSL. However, in the meantime, many businesses potentially affected by the CSL have criticized the law as being vague, and overly broad in scope.

The CSL applies to the construction, operation, maintenance and usage of networks, as well as the supervision and management of networks within the mainland territory of China. A heavy focus is placed on ‘network operators’, defined by the CSL as owners and administrators of networks. Because that definition is incredibly broad, organisations that provide services and conduct business activities through networks may unknowingly be considered network operators. In addition to traditional telecom operators and internet firms, the definition of network operators could possibly be construed to include banking institutions, insurance companies, IT security companies, and other enterprises that have websites and provide various network services.

Network operators must adopt measures to safeguard network security and stability, respond to network security incidents, prevent cybercrimes and unlawful activity, and protect online data. In addition, certain network operators providing critical information infrastructure services or support have more stringent requirements, including training employees, formulating emergency response plans, and conducting disaster recovery exercises.

Perhaps the most significant impact of the CSL from an operational and financial standpoint will be on foreign and multinational organizations. The CSL stipulates that critical information collected or generated in China must be stored domestically. The only way to transfer that information outside of China is to allow security assessments to be conducted by Chinese regulators.

For individuals, the protections around personal information are strong. Network operators are barred from disclosing, tampering with, or destroying the personal information they have collected, while individuals and organisations are forbidden from stealing or using other illegal means to obtain personal information.

Companies that violate the CSL risk the suspension of operations, cancellation of business permits, imprisonment, and the assessment of monetary penalties of up to 10 times the amount of unlawful gains (or up to 1 million Renminbi — approximately $150,000 USD).

Despite the concerns about the CSL being vague and/or overly broad in its scope and application, those organisations conducting business in and with China should thoroughly review the CSL in connection with their current policies and procedures governing network security and data privacy.

Going global

These developments in China illustrate that what has largely been a US market for cyber insurance so far may not remain that way for long. The ever-present risk of business interruption resulting from cyber attacks, such as ransomware, the global increase in data security and privacy regulation, and the potential fines and penalties exposure associated with non-compliance, are steadily fueling international demand for cyber liability insurance. When implemented as a risk protection solution along with assessment and recovery planning tools, cyber insurance provides organisations with a holistically sound approach to cyber risk management.

Dan Twersky is a claims advocate within the claims and legal group for the financial lines practice of the corporate cisk and broking segment of Willis Towers Watson

For any further enquiries please email [email protected]willistowerswatson.com

 

Picture Credit | Shutterstock

 

This article was published as part of Predictions, the future-gazing thought leadership sub-brand of The Actuary covering emerging trends within the insurance, finance and actuarial sectors - you can find out more on the Predictions homepage.

 


 

This article was published as part of Predictions, the future-gazing thought leadership sub-brand of The Actuary covering emerging trends within the insurance, finance and actuarial sectors - you can find out more on the Predictions homepage.

 

You may also be interested in...

Web_FinanceVirtual_iStock-645609968.jpg

Actuaries in the age of artificial intelligence

Ben Pring explains how artificial intelligence is likely to change every aspect of the insurance industry and what insurance firms can do to keep up
Monday 26th February 2018
Open-access content
Web_ITSpend_iStock-493887856.jpg

#Insurtech is a launch pad to unimagined possibilities

Insurtech is where the insurance industry’s future begins, a starting point that is unfathomable, challenging and yet well within reach.
Monday 26th June 2017
Open-access content
Web_RobotSurgery_iStock-511732538.jpg

Uptake of robotic-assisted surgery brings risk

Once considered a far-fetched science fiction notion, robotics is now being used in the medical arena, offering transformative potential in patient care, prostheses and surgery.
Saturday 1st April 2017
Open-access content
Managing-the-dynamic-nature-of-cyber-risk-©Shutterstock.jpg

How can we manage the dynamic nature of cyber-risk?

Integrating board governance, technology solutions, behavioural change and risk transfer solutions can help reduce risk to a manageable level.
Wednesday 1st February 2017
Open-access content
Analysts-expect-150-million-connected-cars-to-be-in-circulation-by-2020©Shutterstock.jpg

Powered by the IoT, auto insurance is poised for a revolution

Connected cars promise to make car insurance more precise, personalised and convenient.
Sunday 1st January 2017
Open-access content
p22-24_dec_insuretech.jpg

InsTech and the innovation boom

‘InsTech’ is growing at a rapid pace, says Paolo Cuomo, as he outlines what companies are doing to take advantage of the innovations in technology available in the industry
Thursday 1st December 2016
Open-access content

Latest from Predictions Features

web_p12-15_PPE_GettyImages-1215903729-blue.png

At a crossroads

Neil Cantle, Nancy Watkins and Peter Kingsley sat down with Chris Seekings to discuss the role actuaries and insurers can play in tackling climate change, following the coronavirus crisis.
Wednesday 2nd September 2020
Open-access content
web_p10-11_windmill_iStock-505412046b.png

Inventing the big hedge

Insurance and risk services must be bold and lead innovation as the world grapples with climate risk, says Peter Kingsley
Wednesday 2nd September 2020
Open-access content
web_p6-7_polluted-ocean_iStock-1255120096-b.png

Culture shock

Insurers must monitor cultural narratives on climate change in order to prepare for different scenarios, says Peter Kingsley
Wednesday 2nd September 2020
Open-access content
Share
  • Twitter
  • Facebook
  • Linked in
  • Mail
  • Print

Latest Jobs

Exposure Management Analyst

London, England
£40000 - £50000 per annum
Reference
148639

Pricing - Casualty Actuary

London (Central)
£128K + bonus + benefits
Reference
148638

Reporting Contractor

Negotiable
Reference
148636
See all jobs »
 
 
 
 

Sign up to our newsletter

News, jobs and updates

Sign up

Subscribe to The Actuary

Receive the print edition straight to your door

Subscribe
Spread-iPad-slantB-june.png

Topics

  • Data Science
  • Investment
  • Risk & ERM
  • Pensions
  • Environment
  • Soft skills
  • General Insurance
  • Regulation Standards
  • Health care
  • Technology
  • Reinsurance
  • Global
  • Life insurance
​
FOLLOW US
The Actuary on LinkedIn
@TheActuaryMag on Twitter
Facebook: The Actuary Magazine
CONTACT US
The Actuary
Tel: (+44) 020 7880 6200
​

IFoA

About IFoA
Become an actuary
IFoA Events
About membership

Information

Privacy Policy
Terms & Conditions
Cookie Policy
Think Green

Get in touch

Contact us
Advertise with us
Subscribe to The Actuary Magazine
Contribute

The Actuary Jobs

Actuarial job search
Pensions jobs
General insurance jobs
Solvency II jobs

© 2023 The Actuary. The Actuary is published on behalf of the Institute and Faculty of Actuaries by Redactive Publishing Limited. All rights reserved. Reproduction of any part is not allowed without written permission.

Redactive Media Group Ltd, 71-75 Shelton Street, London WC2H 9JQ