Before leaving on an extended (and expensive) vacation, I bought travel insurance. I wanted to protect myself in case I or my traveling partner tested positive for COVID-19. I had to answer a number of questions about my eligibility for such insurance before they would approve me. Nor did the insurance come cheap, but I wanted to protect myself and recover most of my expenses if my trip was canceled. 

Insurance is a necessary expense if you want to protect your assets. But, to purchase the insurance you need to meet certain criteria. This is mandatory for health, vehicle, life, business insurance and so on. 

As organizations face increasing numbers of cyber threats, cyber insurance is becoming a vital need. It’s a good way to protect against financial loss if there is a data breach or ransomware attack. However, just as you would have to pass a physical and meet certain requirements for life or health insurance, your cybersecurity system will have to undergo its own physical of sorts. Cyber insurers require businesses to meet certain standards and practices before approving a policy. 

What Cyber Insurers Want to See

Most insurance rules fall into basic cybersecurity measures, Jack Kudale, founder and CEO of Cowbell Cyber, an AI-powered cyber insurance company for small and medium-sized businesses, explained in an email interview. What insurers want to see are fairly standard best practices, such as multi-factor authentication (MFA), incident response plans and patching processes.

“We are seeing a significant shift where companies are now using cyber insurance requirements to build a compelling business case for higher priority and investment in cybersecurity,” Kudale said. “This can really become a win-win for all, as companies will easily become more secure and resilient to cyberattacks.”

There are specific types of attacks and threats that cyber insurers want to see addressed. According to Risk Strategies’ State of the Market 2022 Report, cyber insurance carriers are looking more closely at cyber risks caused by ransomware attacks, stricter government and industry regulations, weaknesses in the cloud and disruptions to the supply chain.  

The pandemic increased cyber risk, the report warned, because of the greater reliance on technology to keep business running smoothly across a remote workforce. This increased risk led to higher insurance payouts, so cyber insurers need to protect their own interests. This is why they have set a higher standard for organizations to meet to be eligible for cyber insurance. 

“It is important for businesses to use proprietary assessment tools to identify risk management controls that are deficient to their peer group,” Rob Rosenzweig, National Cyber Risk Practice for Risk Strategies, wrote in the report. Businesses should work closely with insurance brokers, Rosenzweig added, to ensure risk control standards are followed.

Best Practices for Cyber Insurance 

Companies that have a mature cybersecurity system should be ready to meet the requirements set by cyber insurers. Others with less mature systems or that have struggled to meet risk assessment goals during the pandemic will need to be more proactive. However, any company can benefit from conducting a risk assessment when applying for or updating cyber insurance contracts. 

“One benefit of a risk assessment conducted for cyber insurance is that it covers all facets of risk exposures: technology, processes and people,” said Kudale. 

Consider checking the following before you look for cyber insurance:

  • Conducting an intensive data inventory to know where data lives, where you store it and how you use it
  • Ensuring you have MFA set up
  • Taking a closer look at how you conduct backups. Are they done daily? Are they segmented from the network? Will you be able to put the backup into place quickly if a ransomware attack or other outage causes downtime?
  • Setting up a patching schedule and controls to make sure patches and updates aren’t ignored
  • Updating the incident response plan
  • Deploying regular security awareness training for employees
  • Setting up a least-privileged access model to prevent unauthorized users from causing cyber incidents and data breaches
  • Updating encryption processes.

The Good News

According to NetDiligence’s Cyber Claims Study 2021 Report, an interruption in business due to a cyber incident can cost a company hundreds of thousands of dollars, including recovery expenses. Fines and fees surrounding exposed records cost companies close to $1 million. As the number of cyber incidents increases, so will the cost to insure the business losses. It’s no wonder cyber insurance companies are looking to protect themselves.

There’s good news. The more your organization does to meet the requirements set up by cyber insurance companies, the more protection you’ll have. And that means your insurance will be a small expense toward protecting your assets.

More from Data Protection

Data never dies: The immortal battle of data privacy

4 min read - More than two hundred years ago, Benjamin Franklin said there is nothing certain but death and taxes. If Franklin were alive today, he would add one more certainty to his list: your digital profile. Between the data compiled and stored by employers, private businesses, government agencies and social media sites, the personal information of nearly every single individual is anywhere and everywhere. When someone dies, that data becomes the responsibility of the estate; but what happens to the privacy rights…

Vulnerability resolution enhanced by integrations

2 min read - Why speed is of the essence in today's cybersecurity landscape? How are you quickly achieving vulnerability resolution? Identifying vulnerabilities should be part of the daily process within an organization. It's an important piece of maintaining an organization’s security posture. However, the complicated nature of modern technologies — and the pace of change — often make vulnerability management a challenging task. In the past, many organizations had to support manual integration work to get different security systems to ‘talk’ to each…

Cost of a data breach 2023: Geographical breakdowns

4 min read - Data breaches can occur anywhere in the world, but they are historically more common in specific countries. Typically, countries with high internet usage and digital services are more prone to data breaches. To that end, IBM’s Cost of a Data Breach Report 2023 looked at 553 organizations of various sizes across 16 countries and geographic regions, and 17 industries. In the report, the top five costs of a data breach by country or region (measured in USD millions) for 2023…

Cost of a data breach 2023: Pharmaceutical industry impacts

3 min read - Data breaches are both commonplace and costly in the medical industry.  Two industry verticals that fall under the medical umbrella — healthcare and pharmaceuticals — sit at the top of the list of the highest average cost of a data breach, according to IBM’s Cost of a Data Breach Report 2023. The health industry’s place at the top spot of most costly data breaches is probably not a surprise. With its sensitive and valuable data assets, it is one of…