Annual Cyber Risk Survey finds businesses are sharpening their focus on cyber security but also reveals much room for improvement in building cyber resilience
- Sixty-five percent of respondents have invested in cyber security solutions to mitigate risk, which means that 35 percent of respondents still have not.
"At Zurich, we have been advocating for increased cyber resilience among businesses for years so seeing a continued increase in take up rate and strengthening risk mitigation efforts is very encouraging," said
The survey results reveal gaps in mitigation efforts among respondents especially related to risk monitoring, employee training and vender risk assessment efforts.
Risk monitoring: Most risk managers taking the survey are not monitoring cyber threats to their organizations frequently enough. Thirty-two percent of respondents shared that they monitored for cyber threats monthly and 28 percent just quarterly. The report states that "...in today's fast-changing environment, even monthly threat assessments will leave organizations ill-prepared for both threat actors and their cyber insurance renewals."
Vendor risk assessment: At 52 percent, barely half of the survey respondents say vendor risk assessment is a part of their risk mitigation plans. Also, respondents categorized business interruption due to technology failures or supplier cyber disruptions only as a moderate concern on the list of their business continuity concerns. With cybercriminals increasingly leveraging third-party vendors to launch attacks on a broader scale, companies should be forewarned that vendor risk is not an area to ignore.
Employee education: Human error is a major factor in successful cyber security breaches. With cyber threats evolving daily, more frequent training opportunities that keep employees in the loop on threats and help them identify and thwart efforts by bad actors will be critical in minimizing cyber events. Yet only 17 percent of respondents indicate that their companies offer cyber security training on a monthly basis. Annual training is the most common response chosen at 30 percent of survey respondents, with 25 percent conducting employee cyber education on a quarterly basis.
Ransomware:
This year is the first time the survey has featured questions on ransomware. Eighty percent of respondents say they feel very or moderately prepared to face a ransomware event. However, respondents also worry that no matter how much they prepare, it will not be enough to fully overcome a ransomware attack. A focus on business interruption persisted through the survey's ransomware section; and the "unknowns" of ransomware were apparent in the survey with one respondent adding, "While our cyber risk security efforts seem very robust, it's difficult to know what we don't know."
Other key findings of the 2021 survey include:
- The hard cyber insurance market is hitting buyers on all fronts including retention, limits, price, and coverage. Respondent comments show significant worries about a "completely dislocated" market with triple-digit rate increases, shrinking coverages, and skepticism over whether insurers adequately analyze effective loss prevention measures.
- Buyers' frustration with the cyber insurance market's policy wording varies from carrier to carrier, which makes it difficult for policy holders to compare solutions.
Considering the current state of the insurance market, risk managers will find pre-breach mitigation planning and excellent cyber security controls to be mandatory for underwriters. This year's survey highlights a few areas where risk managers may be lagging and where their insurance partners can offer education and support.
"This survey reveals that customers are concerned with the changing market and what it will mean to their renewal process," added Chia. "Risk managers are looking for coverage that protects their business at the right price and are also looking for solutions to mitigate their risk. With so many unknowns, they may find that the answers to business resilience are right in front of them in the form of risk mitigation."
For 11 consecutive years,
The results reflect the responses of nearly 400 respondents representing risk managers, insurance buyers and other risk professionals covering both large and small companies around the world. Finance, banking and insurance industries are the most highly represented. Other industries with significant representation included manufacturing, construction, professional services, educational institutions, healthcare and technology. Firms with between
Interested parties can link to the complete survey results at
https://www.advisenltd.com/zurichs-11th-annual-information-security-and-cyber-risk-management-survey.
View original content to download multimedia:https://www.prnewswire.com/news-releases/annual-cyber-risk-survey-finds-businesses-are-sharpening-their-focus-on-cyber-security-but-also-reveals-much-room-for-improvement-in-building-cyber-resilience-301409747.html
SOURCE


Swiss health insurance Sympany implements Lyfegen platform to efficiently execute complex value & data-driven agreements for high-priced medication
From Our Early Files
Advisor News
- When new investment trends emerge, Gen Z is most likely generation to be first in
- Could ‘plain English’ become an advisor’s secret weapon?
- IRI urges Senate action on 403(b) parity legislation
- Three estate planning ideas to protect your clients and their wealth
- What advisors must know about accessible client documents
More Advisor NewsAnnuity News
- NUNN INTRODUCES BILL TO CUT RED TAPE, GIVE IOWANS CLEARER INSURANCE INFORMATION
- NAIC working group pressed to accelerate annuity illustration overhaul
- State Auditor James Brown Kicks Off Life Insurance Awareness Month With Policy Locator Tool
- Wink: Annuity sales post strong Q2, led by MYGAs and structured products
- Legacy Marketing Group partners with Malibu Life USA for annuity launch
More Annuity NewsHealth/Employee Benefits News
Life Insurance News