How Cyber Insurance Is Reshaping Security

267 views
•
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How Cyber Insurance Is Reshaping Security

TL;DR

Cyber insurance is pushing businesses to strengthen security controls, demonstrate insurability, and continuously adapt as threats change. Rising premiums, reduced capacity, and non-renewals create hardships, but closer cooperation among insurers, security providers, brokers, and customers can improve security posture, support more accurate pricing, and expand access to appropriate coverage over time.

Transcript

Hi, everyone. Um, you are here at the enviable slot of the last session of the last day, so congratulations. Um, and thank you for being here and joining us for, um, what's known to be saving the best for last. Um, today's, um, talk is on cyber insurance is changing cybersecurity. Um, and I'd like to introduce myself and then the panel will introdu... Read More

Key Insights

  • Cyber insurance is becoming harder to obtain because insurers face high claims, rising payouts, shrinking capacity, and uncertainty about whether prospective customers are adequately protected. Businesses have consequently experienced higher premiums, stricter qualification requirements, and non-renewals instead of simply negotiating discounts.
  • Cyber insurance and cybersecurity providers share the goal of protecting insured businesses against cybercrime. Their partnership can connect risk transfer with practical security improvements, giving insurers greater confidence while helping customers become more resilient and better positioned to obtain suitable policies.
  • Insurability is a journey because a business's environment and the threats against it continually change. A risk that appears strong today may look different tomorrow as vulnerabilities emerge, companies grow, acquisitions occur, and attackers modify their methods.
  • Continuous monitoring is important because static questionnaires and one-time assessments cannot fully represent changing cyber risk. Cybersecurity professionals can monitor organizations over time, guide improvements, and help businesses maintain their security posture as threats and operational environments evolve.
  • Security evidence can influence insurance conversations by showing that a prospective customer is taking appropriate protective measures. When insurers gain confidence in those measures, customers may improve their security posture and eventually discuss premiums that better reflect their investments and progress.
  • Managed service providers and security companies face substantial insurability challenges because supply chain exposure can place them in a high-risk category even when they are already following strong practices. These organizations may need particularly creative insurance structures because their services make coverage especially important.
  • Creative risk transfer can include different deductibles, grouping similar organizations so they can share risks, or limiting protection to catastrophic events. Such structures may provide some coverage for organizations that cannot qualify for lower-deductible or broader insurance on favorable market terms.
  • Cyber hygiene standards must evolve because accepted practices and underwriting questions change alongside threats. The panel describes expanding lists of expected controls and deeper assessment methods, including information gathered beyond questionnaires and from both outside and inside an organization's defenses.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How is cyber insurance changing cybersecurity practices?

Cyber insurance is encouraging businesses to strengthen controls, document their security posture, and work more closely with cybersecurity providers. Insurers need confidence that prospective customers are sufficiently protected before offering coverage at acceptable terms. This creates a shared incentive for insurers, security companies, brokers, and customers to reduce exposure, improve resilience, and continuously adapt defenses as threats and business environments change.

Q: Why are cyber insurance premiums and qualification barriers rising?

Premiums and qualification barriers are rising because insurers have paid many claims, faced loss-making books of business, and become less certain about whether some organizations are adequately protected. Capacity has also been shrinking. Insurers have responded with stricter requirements, higher prices, and some non-renewals, although the panel acknowledges that these reactions have not always been as customer-focused or solution-oriented as desired.

Q: Should every business be eligible for cyber insurance?

Every business should ideally have an opportunity to become insurable, but coverage depends on its present risk, security maturity, and willingness to improve. Some organizations may struggle to obtain favorable terms immediately. The panel recommends viewing insurability as a journey in which cybersecurity professionals provide monitoring and guidance, helping higher-risk businesses progress toward stronger protection and more appropriate insurance options.

Q: How can a company improve its cyber insurance prospects?

A company can improve its prospects by implementing appropriate security controls, demonstrating that those controls work, and continuing to strengthen its posture over time. Evidence that the organization is taking necessary protective measures can reassure insurers. Continuous monitoring and professional guidance are especially valuable because threats, vulnerabilities, acquisitions, growth, and other environmental changes can alter the company's risk after an initial insurance assessment.

Q: Why is continuous monitoring relevant to cyber insurance?

Continuous monitoring helps businesses and insurers account for risk that changes after a questionnaire or initial review. A company that appears secure today may become more exposed tomorrow as threats evolve, vulnerabilities emerge, or its environment changes through investment, growth, or acquisitions. Ongoing monitoring allows cybersecurity professionals to identify changes, guide improvements, and help the organization remain prepared throughout its insurance and security journey.

Q: Why are managed service providers difficult to insure?

Managed service providers, managed security service providers, and security companies can be difficult to insure because their supply chain exposure places them in a particularly high-risk category. Even organizations doing the right things may remain challenging risks. The panel argues that these providers need creative solutions because they face serious coverage barriers while also being among the organizations for which insurance is especially important.

Q: What insurance options may exist for very high-risk businesses?

Very high-risk businesses may need alternative structures instead of broad coverage with lower deductibles. The panel suggests using different deductibles, placing comparable organizations into classes that share risk, or offering insurance focused only on catastrophic events. These approaches can preserve access to some risk transfer while avoiding economic pressures and coverage terms that would be unsustainable for either the customer or insurer.

Q: How can insurers and cybersecurity vendors work together?

Insurers and cybersecurity vendors can combine financial risk transfer with practical security operations. Vendors can help customers implement controls, monitor changing environments, and provide evidence that supports underwriting confidence. Insurers can then use that stronger understanding to offer suitable coverage and eventually discuss premiums in relation to demonstrated investments and progress. Their aligned interests can produce more resilient and insurable businesses.

Summary & Key Takeaways

  • Cyber insurance has reached a validating moment by paying substantial claims and responding to loss-making business. That response has included higher premiums, shrinking capacity, non-renewals, and stricter qualification requirements. Although these conditions burden customers, they also encourage organizations to improve controls and give insurers greater confidence about which businesses are insurable.

  • Insurers and cybersecurity providers increasingly share the goal of protecting businesses against cybercrime. Security organizations can help customers demonstrate that they have appropriate protections while supporting continuous improvement. Better evidence of security progress may eventually enable more meaningful conversations about premiums and align coverage terms with each organization's evolving risk posture.

  • Insurability should be treated as a continuing journey rather than a permanent classification. Threats, vulnerabilities, business environments, and accepted security practices change over time. Higher-risk organizations may require creative structures, shared-risk classifications, larger deductibles, or catastrophic-only protection while they work with security professionals toward broader and more affordable coverage.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚