How organizations can defend themselves against cyber risk - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading From the Field: Expert Insights
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
From the Field: Expert Insights
From the Field: Expert Insights RSS Get our newsletter
Order Prints
July 21, 2023 From the Field: Expert Insights
Share
Share
Post
Email

How organizations can defend themselves against cyber risk

By Joseph Carson

Cyber insurance, once viewed as a desirable security accessory, has evolved into an incident response and business resilience lifeline. As cybercrime continues to leave mass financial and operational destruction in its wake, protecting the bottom line and ensuring business continuity following such events has captivated the attention of executive leadership, and propelled the demand for cyber insurance.

Cyber
Joseph Carson

Regulatory compliance and increased scrutiny from customers have also forced this level of urgency. Not only has there been an influx of applications for cyber insurance but also a tidal wave of organizations actively using their coverage. Research from Delinea found that 80% of organizations have leveraged their coverage at least once, and more than half of that group has used it on more than one occasion.

With the average cost of a data breach reaching astronomical amounts ($4.35 million according to IBM), insurers are not only raising rates but also tightening requirements. Many organizations are now facing significant delays and upfronts costs to satisfy the more rigorous coverage qualification criteria. As cyber insurance is still a relativity new phenomenon for many organizations despite having been around for many years, many organizations lack prior knowledge of the application process itself and can be unprepared for the questions and risk assessments from carriers.

Although each insurer has its own methodology to assess organizational risk, many reference the five key functions of the National Institute of Standards and Technology’s cybersecurity framework to evaluate companies: Identify, Protect, Detect, Respond and Recover. Understanding the core questions that insurers may ask under each of these components can help streamline the process of obtaining coverage and minimizing costs.  Let’s explore how organizations can prepare for each of these five components.

Identifying risks 

A prospective insurer first will want to understand the specific risks which pertain to your organization and the current risk management processes in place. Organizations can evaluate their risks by conducting a cybersecurity risk assessment to identify where vulnerabilities prevail. This activity also helps gauge a company’s cyber risk tolerance.

For example, insurance carriers will want a deep dive into how organizations conduct security awareness training initiatives for employees. Insurers want to see organizations conducting frequent security training that extends beyond simple online tests.  Insurers will also want a portrayal of an organization's inventory of hardware, software and privileged accounts.  Maintaining a list of all devices, applications and privileged accounts that could be a possible entry point for malicious attacks can help identify all possible threat vectors, and will determine the value and scope of the assets an organization wishes to insure.

Protecting assets 

Insurers will also want organizations to convey how they are currently protecting their assets, including highlighting Identity and Access Management controls, data security, maintenance and repair strategies, and more. As credential-based cyberattacks are increasingly common, insurers are looking for strong Multi-Factor Authentication controls to be in place. These controls can help validate who is accessing systems and add an additional layer of security.

Multiple layers of malware defense are another highly requested requirement. These protect against viruses and malicious programs deployed by bad actors. This defense includes implementing and enforcing least privilege access, restricting or removing local administrative rights, and layering in threat intelligence and endpoint protection. Part of protecting assets and data is having a strong backup and recovery plan to ensure that the business is resilient to attacks such as ransomware, which can bring a business to a complete stop.

Detecting risk and breaches 

Establishing an organization’s ability to detect risks and breaches is another core component for cyber insurers. The increased reliance on remote work means that more endpoints, including laptops and cloud servers, are high-value targets for attacks. More insurers are requiring organizations to have an endpoint security tool that can seamlessly identify and respond to security events originating at endpoints.

Thus, insurers want organizations to have comprehensive monitoring, alerting and reporting capabilities for privileged behavior and possible abuse on workstations and servers. This enables information technology and security teams to quickly identify unexpected behavior and conduct an incident response and forensic analysis if a breach occurs.

Responding to cyber attacks 

Perhaps the most important part of an evaluation to an insurer is the appraisal of an organization’s incident response plan. Robust incident response game plans are non-negotiable to an insurer as they can reduce the risk of a cyber breach becoming a catastrophic event.

An incident response plan helps align IT operations, security and developers to ensure a rapid and thorough response to an attack. A robust plan includes a checklist of roles and responsibilities in the event of an attack, along with actionable steps to measure the extent of a cybersecurity incident. Conducting frequent incident simulations can help identify areas for improvement and demonstrate to insurers that readiness is more than hypothetical.

Recovery after an attack 

Finally, carriers will want to delve into an organization’s recovery plan to understand how they will navigate the aftermath of a potential breach. Organizations must effectively showcase the measures in place to return operations to normal and stem losses. While 71% of companies are confident they can quickly recover from a cyberattack, it still takes an average of 280 days to identify and contain a data breach. Organizations must demonstrate to insurers that they’re realistic, willing to learn from cyber mistakes and implement ongoing improvements.

Before applying for a cyber insurance premium and engaging with perspective carriers, it is important to evaluate your organization within these five components to better understand the risks which pertain to your organization, where gaps in security infrastructure may persist and which assets are most critical for an organization to insure.

 

Joseph Carson is chief security scientist and advisory CISO at Delinea. He may be contacted at [email protected].

 

© Entire contents copyright 2023 by InsuranceNewsNet.com Inc. All rights reserved. No part of this article may be reprinted without the expressed written consent from InsuranceNewsNet.com.

 

Joseph Carson

Older

Despite economic improvements, some fear ‘black swan’ event

Newer

Marketing tips for advisors: How to fill your calendar and sell annuities

Advisor News

  • NAIFA: Financial professionals are essential to the success of Trump Accounts
  • Changes, personalization impacting retirement plans for 2026
  • Study asks: How do different generations approach retirement?
  • LTC: A critical component of retirement planning
  • Middle-class households face worsening cost pressures
More Advisor News

Annuity News

  • Trademark Application for “INSPIRING YOUR FINANCIAL FUTURE” Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
  • Jackson Financial ramps up reinsurance strategy to grow annuity sales
  • Insurer to cut dozens of jobs after making splashy CT relocation
  • AM Best Comments on Credit Ratings of Teachers Insurance and Annuity Association of America Following Agreement to Acquire Schroders, plc.
  • Crypto meets annuities: what to know about bitcoin-linked FIAs
More Annuity News

Health/Employee Benefits News

  • Red and blue states alike want to limit AI in insurance. Trump wants to limit the states.
  • CT hospital, health insurer battle over contract, with patients caught in middle. Where it stands.
  • $2.67B settlement payout: Blue Cross Blue Shield customers to receive compensation
  • Sen. Bernie Moreno has claimed the ACA didn’t save money. But is that true?
  • State AG improves access to care for EmblemHealth members
More Health/Employee Benefits News

Life Insurance News

  • Corporate PACs vs. Silicon Valley
  • IUL tax strategy at center of new lawsuit filed in South Carolina
  • National Life Group Announces 2025-2026 LifeChanger of the Year Grand Prize Winner
  • International life insurer Talcott to lay off more than 100 in Hartford office
  • International life insurer to lay off over 100 in Hartford office
Sponsor
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Elevate Your Practice with Pacific Life
Taking your business to the next level is easier when you have experienced support.

LIMRA’s Distribution and Marketing Conference
Attend the premier event for industry sales and marketing professionals

Get up to 1,000 turning 65 leads
Access your leads, plus engagement results most agents don’t see.

What if Your FIA Cap Didn’t Reset?
CapLock™ removes annual cap resets for clearer planning and fewer surprises.

Press Releases

  • RFP #T22521
  • Hexure Launches First Fully Digital NIGO Resubmission Workflow to Accelerate Time to Issue
  • RFP #T25221
  • LIDP Named Top Digital-First Insurance Solution 2026 by Insurance CIO Outlook
  • Finseca & IAQFP Announce Unification to Strengthen Financial Planning
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet