How Does Cyber Insurance Cover Ransomware Risk?

541 views
β€’
July 22, 2021
by
RSAC Cybersecurity
YouTube video player
How Does Cyber Insurance Cover Ransomware Risk?

TL;DR

Cyber insurance can cover incident response, data recovery, business interruption, cyber extortion, online media disputes, and liabilities arising from breaches or privacy violations. Ransomware has increased the speed and severity of losses, prompting insurers to raise prices and examine security controls more closely, but organizations with mature infrastructure, support capabilities, and risk awareness can still obtain meaningful coverage.

Transcript

Hello, everyone. Listeners, thank you for joining in. Hopefully, you've had time to listen to our recent podcast in which we hosted today's guests for an in-depth conversation on ransomware paradigm change. And today, we're following up with this live conversation on our social channels, where we have Ben Demarco, Christina Turplin, and Marcello An... Read More

Key Insights

  • Cyber insurance is broader than its name suggests because it combines several first-party and third-party protections. Its scope can extend from immediate breach investigation and operational recovery to lawsuits, regulatory investigations, privacy violations, and specified disputes involving a company’s online media.
  • First-party cyber coverage is designed to support direct organizational losses and response costs. Covered areas may include forensic specialists, privacy counsel, notifications, call centers, credit monitoring, data restoration, business interruption, increased working costs, theft of funds, cyber extortion, and ransomware response.
  • Third-party cyber coverage is intended to address claims brought against an insured organization. It may provide defense and indemnity for lawsuits and regulatory investigations arising from data breaches or privacy violations, while media coverage may address matters such as online copyright infringement or defamation.
  • Ransomware is a major shift for cyber insurers because losses can arrive quickly and with substantial severity. Ransom payments, business interruption, and related recovery costs are front-loaded, changing the amount insurers need to charge when offering cyber coverage.
  • Cyber insurance prices have risen globally from what was historically a low base. The discussion notes that cyber insurance had often been considerably cheaper than other financial-risk products, including professional indemnity, directors and officers coverage, and statutory liability insurance.
  • Insurance-market adjustments are a normal part of product maturation. Insurers introduce coverage, observe how claims develop, collect information about loss patterns, and then revise pricing as their understanding of the risk and the resulting claim flows improves.
  • Cyber maturity is increasingly central to insurance availability and pricing. Insurers now examine whether applicants have suitable infrastructure, adequate support capabilities, a clear understanding of their risks, meaningful security controls, and credible incident response and business continuity arrangements.
  • Cyber insurance is not disappearing for organizations that can demonstrate strong risk management. Companies that satisfy insurers on infrastructure, support, and risk understanding can still access coverage and reduce premium pressure, while less-prepared applicants face a more difficult market.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What does cyber insurance typically cover?

Cyber insurance can combine first-party and third-party coverage. First-party protection may address forensic investigation, privacy counsel, notifications, call centers, credit monitoring, data recovery, business interruption, increased working costs, theft of funds, and cyber extortion. Third-party protection may cover defense and indemnity for lawsuits, regulatory investigations, privacy violations, and certain online media disputes.

Q: How does cyber insurance help after a data breach?

After a suspected cyber or privacy event, coverage may help an organization engage forensic specialists and privacy counsel to determine what happened and receive legal advice. It can also support public and regulatory notifications, a response call center, and credit monitoring. These services form part of the broader incident-response protection available under many cyber policies discussed by the panel.

Q: How can cyber insurance respond to a ransomware attack?

Cyber insurance may respond to several consequences of ransomware. It can cover costs associated with cyber extortion, restoring or rebuilding encrypted or otherwise unrecoverable data, and business interruption when the organization cannot operate. It may also address increased working costs and professional incident-response services needed to investigate the attack and guide the organization’s response.

Q: Why have cyber insurance premiums increased?

Cyber insurance premiums have increased because ransomware has produced losses that can be severe and arrive quickly. Ransomware payments and business interruption costs may be incurred early in an incident, affecting how much insurers need to charge for coverage. The increase also reflects a maturing insurance market using actual claim patterns to refine its pricing.

Q: Is the cyber insurance market really in crisis?

The discussion characterizes the crisis narrative as partly a matter of perception moving ahead of reality. Prices have increased, but they rose from a historically low base, and insurance markets commonly adjust after products are tested by claims. Coverage remains available, particularly for organizations that can demonstrate cyber maturity, adequate infrastructure, effective support, and a sound understanding of risk.

Q: Can organizations still obtain cyber insurance?

Organizations can still obtain cyber insurance, especially when they demonstrate mature cybersecurity practices. Insurers increasingly assess the quality of infrastructure, available support capabilities, understanding of cyber risk, and the substance of security controls. Organizations that satisfy these expectations may retain good coverage and limit premium increases, while applicants with weaker answers can face a harder placement process.

Q: What cybersecurity information do insurers evaluate?

Insurers increasingly look beyond whether an applicant merely has business continuity and incident response plans. They examine the practical security controls behind those plans, whether the organization has appropriate infrastructure and support capabilities, and whether leaders understand their cyber risks. These factors help insurers distinguish organizations that manage risk effectively from those that are less prepared.

Q: Why is ransomware considered a paradigm shift for cyber insurance?

Ransomware is considered a paradigm shift because it activates parts of cyber policies that were previously used less often, particularly cyber extortion, business interruption, and data recovery. The related losses can be substantial and front-loaded, arriving through ransom demands, operational disruption, and restoration work. This pattern has materially affected claims experience, underwriting scrutiny, and premium requirements.

Summary & Key Takeaways

  • Cyber insurance combines first-party and third-party protection. First-party coverage may fund forensic investigations, privacy counsel, public and regulatory notifications, call centers, credit monitoring, data restoration, business interruption, theft-related losses, and ransomware response. Third-party coverage may address legal defense, indemnity, regulatory investigations, privacy violations, and certain online media claims.

  • Ransomware changed the cyber insurance market because related losses can be both severe and immediate. Payments, business interruption, and recovery expenses may arise quickly, requiring insurers to reconsider how much premium they charge and how they structure coverage. The resulting adjustments reflect a market responding to observed claim patterns and maturing risk data.

  • Cyber insurance remains available, but insurers now distinguish more carefully between organizations with strong cyber maturity and those unable to demonstrate effective controls. Applicants are increasingly assessed on their infrastructure, support capabilities, risk understanding, incident response readiness, and business continuity planning. Mature organizations can limit premium increases and continue securing useful coverage.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š