April 24, 2023 By Sue Poremba 4 min read

When cyber insurance first became available in the 1990s, there wasn’t much need for it — or at least, so people thought. The internet as we know it today was still in its infancy, and most organizations didn’t see the point of cyber insurance. The original policies were to cover liability around software and media concerns.

As we moved into the 21st century, the internet became entrenched in everyday business operations and blurred the boundaries between personal and corporate. As a result, the need for cyber insurance took on greater urgency. Data breaches, DDoS attacks, ransomware — virtually any cyber incident that compromised sensitive data or put an organization at risk for lost business made investing in cyber insurance policies look more appealing. But how has the rise of cyber insurance impacted cybersecurity as a whole?

Are you eligible for cyber insurance?

Normally you purchase insurance to protect yourself, your property or your business interests in case something bad happens. Car insurance, for example, is a requirement to own and operate a vehicle, but you don’t have to really do much more than purchase it to obtain coverage. A life insurance policy might require a physical, but for most people, that’s not an issue. Some policies, like flood insurance, do have contingencies before the purchase can be made, but those are predetermined — such as living in an area prone to flooding.

Cyber insurance is different. You can’t just call an agent and request cyber insurance to cover your losses if your network is breached. Being eligible for cyber insurance requires your cybersecurity program to meet certain standards. In addition, you must maintain those standards to continue coverage.

Attackers change tactics

These standards alone have been the push that some organizations needed to improve their overall cybersecurity posture. That in itself has impacted cybersecurity overall. But over time, as defense against attacks became more complicated, too many organizations have become lazy. Premiums are increasing, but at the same time, insurance providers are becoming more selective in what they will pay.

“While ransomware continues to be a dominant risk, we are seeing tactics change, including the rise of other forms of extortion as well as funds transfer fraud,” Jason Rebholz, chief information security officer at Corvus Insurance, said in a prepared statement.

Cybersecurity has become more fluid, Rebholz added, and attackers are shifting their methods. This makes it harder for organizations to put the best protections in place, which impacts cyber insurance in turn.

How cyber insurance improves your security systems

Cyber insurance was still relatively new in the early days of the Obama Administration. However, that didn’t stop members of the Department of Homeland Security from touting its value. One point that jumps out is cyber insurance’s advantage over governmental regulation as a means to improve your cybersecurity program.

“Governmental regulation results in an emphasis on meeting basic minimum standards, whereas insurance results in companies striving to adopt — and improve upon — best practices,” a government white paper declared.

“Fear of legal sanctions can force companies to maintain a set of minimum standards, as cyber insurance does, but unlike cyber insurance, it does not provide any incentive to do better,” the white paper also stated, adding that the widespread adoption of cyber insurance will produce better security.

Examine your risk levels

So the idea of using cyber insurance to improve your security posture has been out there for a long time. With almost two decades of hindsight, we can see that cyber insurance hasn’t replaced the need for government regulations. However, it did put the process into place.

Again, you can’t simply decide to purchase cyber insurance and sign a check to an agent. It is a process that will examine your organization’s risk levels and tolerance, looking in-depth at areas that include:

  • Your business industry. Industries like finance and banking will have different security issues to cover than healthcare or retail, for example.
  • The type of information your company stores and transmits.
  • Your formal cybersecurity program, controls and tools.
  • Auditing procedures.
  • Backup and data loss protection policies.
  • Compliance regulations and how well you meet them.
  • Security history, including data breaches and other cyber incidents, and the corporate response.

Because premium dollars can add up, organizations will be selective in the areas they decide to cover. Again, this benefits overall cybersecurity efforts because it forces organizations to be better aware of everything within their network. This especially applies to where they store sensitive data, how they use it and where they are most vulnerable to threats. A lack of visibility into systems has always been one of the biggest threats to data and networks. Cyber insurance forces organizations to have a better idea of their risk posture and the steps needed to improve.

Rethinking the approach to ransomware

Many organizations relied on cyber insurance to cover the costs of a ransomware attack, primarily reimbursing the ransom. That’s changed. According to the National Association of Insurance Commissioners (NAIC), the premiums for ransomware policies have increased substantially over the past few years, as have the number of claims for ransom and extortion. The FBI has advised against paying the ransom since that doesn’t guarantee the data will be released, and that has played into some cyber insurance companies’ decision to rethink their ransomware coverage.

With the increase in premium costs and the decrease in the number of insurance policies available, ransomware has taken on a new level of liability for organizations. This means companies need to revamp their internal approach to how their internal cybersecurity policies and programs address ransomware attacks. Policies may explicitly state if the company will pay a ransom and the investment in data loss prevention (DLP) and recovery tools.

Cyber insurance has been a godsend to many organizations that would have otherwise struggled to survive after a serious cyber incident. But no one wants to deal with insurance claims in the first place. Instead, cyber insurance has changed the way organizations should build and structure their cybersecurity programs. The more prepared you are to be approved for an insurance claim, the better prepared you are to avoid a cyber disaster overall.

More from Risk Management

Cybersecurity dominates concerns among the C-suite, small businesses and the nation

4 min read - Once relegated to the fringes of business operations, cybersecurity has evolved into a front-and-center concern for organizations worldwide. What was once considered a technical issue managed by IT departments has become a boardroom topic of utmost importance. With the rise of sophisticated cyberattacks, the growing use of generative AI by threat actors and massive data breach costs, it is no longer a question of whether cybersecurity matters but how deeply it affects every facet of modern operations.The 2024 Allianz Risk…

Adversarial advantage: Using nation-state threat analysis to strengthen U.S. cybersecurity

4 min read - Nation-state adversaries are changing their approach, pivoting from data destruction to prioritizing stealth and espionage. According to the Microsoft 2023 Digital Defense Report, "nation-state attackers are increasing their investments and launching more sophisticated cyberattacks to evade detection and achieve strategic priorities."These actors pose a critical threat to United States infrastructure and protected data, and compromising either resource could put citizens at risk.Thankfully, there's an upside to these malicious efforts: information. By analyzing nation-state tactics, government agencies and private enterprises are…

6 Principles of Operational Technology Cybersecurity released by joint NSA initiative

4 min read - Today’s critical infrastructure organizations rely on operational technology (OT) to help control and manage the systems and processes required to keep critical services to the public running. However, due to the highly integrated nature of OT deployments, cybersecurity has become a primary concern.On October 2, 2024, the NSA (National Security Agency) released a new CSI titled “Principles of Operational Technology Cybersecurity.” This new guide was created in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD SCSC) to…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today