Cyber Insurers on the Prospects for Attainable Coverage [Government Technology]
Jun. 16—Cyber insurance has become increasingly difficult — and pricey — for public- and private-sector organizations to obtain. Insurers have been requiring would-be customers to answer lengthy questionnaires, with no guarantee of coverage once they finish, and more expensive plans.
Insurance broker and risk manage services firm Marsh reports that the price of cyber insurance in the
But there may be ways to make coverage more attainable, and Bay and other panelists dove into the challenges and possibilities that lie ahead.
PROVING GOOD CYBER PRACTICES?
Insurance companies are confronting the fact that cyber threats evolve rapidly, and that the elements of a strong cybersecurity posture are likely to keep changing, said
"These are all things that are happening in real time as the threats change themselves, and so a risk that looks great right now may not be what looks great tomorrow," Bryant said.
"We had a few customers at a recent kickoff here that were giving us some anecdotes ... and where their original policy was five question and policy, the renewal is 300 question and maybe policy," Schneider said.
Questionnaires may not be the only way for insurance carriers to get information, however. Bryant said the cyber insurance landscape could evolve to see applicants start sharing data with insurance to demonstrate that they're keeping up with good cyber hygiene practices. He likened this to auto insurance policyholders who allow their driving to be monitored to get lower rates for safe driving practices.
"We have the ability to monitor employees to understand how fast companies patch their business, how fast they update their systems, that information is available, but at the moment it is, in essence, sitting in a lot of cybersecurity silos, a lot of MSPs [managed service providers] and a lot of other technologies," Bryant said.
Bryant and Schneider both suggested as well that insurance firms partner with cybersecurity firms that can help them better understand cyber risks.
WHAT INSURANCE FIRMS LOOK FOR
Panelists underscored that they want clients to treat cyber insurance as a backup support to turn to when recovering from cyber attacks — rather than making it their entire defense and resilience plan.
"If you have homeowners' insurance, you just don't forget about alarms," Schneider said.
Insurance companies are looking to see that would-be customers follow certain best practices that will reduce their risk exposure. Those practices may vary, but Bay said most insurers will reject clients who lack multifactor authentication or fail to patch.
Some insurance companies are discussing striking a balance and offering certain levels of cyber coverage on the condition that clients maintain good cyber hygiene practices, Bay said. Clients that fail to keep up good behaviors would see their insurance pay out less on covered claims.
"There are now new policy forums coming out that are talking about these things like, if you haven't patched within 45 days, you start having degradation of your limits," Bay said. "They're trying to put skin in the game."
IS EVERYONE INSURABLE?
Bay also said insurance firms should rethink options for how they offer cyber insurance.
"I am a big believer that we need to sort of separate traditional cyber liability to the point where it can almost become a catastrophic loss policy and then we can have lower limits, more flexible but standardized programs," Bay said.
In the homeowners' space, catastrophe insurance plans protect business and resident policyholders in case of rare-but-costly incidents typically not included in standard homeowners' insurance, per Investopedia. These might include natural disasters and terrorist attacks.
MSPs often face daunting prospects for getting covered, but insurance firms may be more willing to cover them for catastrophes only, Bay said.
"[MSPs] are almost uninsurable at this point because of supply chain risk," Bay said. "Many of these organizations are doing the right things already, but that makes them still a very high risk."
GovTech previously reported that attacks that compromise MSP's services can quickly spread through their client bases: The ransomware attack on IT software provider Kaseya affected an estimated 2,000 public- and private-sector clients worldwide, for example.
Bay suggested insurance companies might find it more palatable to treat MSPs as a high-risk group that only qualifies to receive catastrophe insurance and "not more lower-tier, less-expensive or lower-deductible insurance."
___
(c)2022 Government Technology
Visit Government Technology at www.govtech.com
Distributed by Tribune Content Agency, LLC.



Should California gun owners be forced to buy liability insurance?
Peer to Peer Insurance Market: Things to Focus on to Ensure Long-Term Success by 2022-2028 : Allied Peers, Axieme, Bandboo
Advisor News
- The modern advisor: Merging income, insurance, and investments
- Financial shocks, caregiving gaps and inflation pressures persist
- Americans unprepared for increased longevity
- More investors will seek comprehensive financial planning
- Midlife planning for women: why it matters and how advisors should adapt
More Advisor NewsAnnuity News
- LIMRA: Annuity sales notch 10th consecutive $100B+ quarter
- AIG to sell remaining shares in Corebridge Financial
- Corebridge Financial, Equitable Holdings post Q1 earnings as merger looms
- AM Best Assigns Credit Ratings to Calix Re Limited
- Transamerica introduces new RILA with optional income features
More Annuity NewsHealth/Employee Benefits News
- Tracing the decline of health care in America
- HUNTER MOVES TO ELIMINATE DISCRIMINATORY LIMITS FOR DISABILITY INSURANCE
- Hospital, clinics hurting as fewer Tri-Cities patients have health care coverage
- Reports on Insurance from State University of New York (SUNY) Albany Provide New Insights (Effects of National Insurance Reforms and State Medicaid Expansions Under the Affordable Care Act on Insurance Coverage Among American Indian and Alaska …): Insurance
- Findings from Kristi Martin et al Has Provided New Information about Managed Care and Specialty Pharmacy (Assessment of IPAY 2027 Medicare drug price negotiation maximum fair prices with prices in most-favored nation reference countries): Drugs and Therapies – Managed Care and Specialty Pharmacy
More Health/Employee Benefits NewsLife Insurance News
- AM Best Assigns Credit Ratings to Tokio Marine Newa Insurance Co., Ltd.
- Earnings roundup: Prudential works to save ‘unique’ Japanese market
- How life insurance became a living-benefits strategy
- Financial Focus : Keep your beneficiary choices up to date
- Equitable-Corebridge merger casts shadow over life insurance earnings
More Life Insurance News