Major Cyber Insurance Overhaul Begins Now [Government Technology] - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
April 10, 2023 Newswires
Share
Share
Tweet
Email

Major Cyber Insurance Overhaul Begins Now [Government Technology]

Government Technology

Apr. 9—One thing is clear about cyber insurance in the spring of 2023: The status quo is not sustainable.

And now, Lloyd's of London, a major player in the global insurance market, is calling for dramatic changes in the cyber insurance market. According to The Financial Times (FT), "From next month, Lloyd's will require the dozens of insurers that operate in the market to include exemptions that would prevent policies paying out if a major attack is judged to be 'state-backed.'

"Exclusions for acts of war have long been a staple of policies ranging from property to motor, shielding insurers from the potentially crippling claims that a physical conflict generates. But Lloyd's, a powerhouse in the global industry, believes war exclusions need updating for the Internet age, when cyber warfare can be government sponsored even in the absence of conventional conflict. Failure to exclude significant state-backed attacks from policies would leave insurers exposed to 'systemic risk,' Lloyd's said when it first announced the plan last summer."

The article goes on to point out that Fitch Ratings forecasts the total spend on cybersecurity policies globally could reach $22.5 billion by 2025 — up from $10 billion globally in 2022.

According to Tech Monitor, Lloyd's of London's controversial clause has caused consternation for many in the insurance industry as they rush to abide by the deadline: "The cyber war exclusion clause was announced in August of last year and recommends that standalone cybersecurity policies exclude coverage of attacks implemented by state-sponsored cyber criminals. Written by Lloyd's underwriting director Tony Chaudhry, the clause is expected to add clarity to an unclear field that can lead to billions of pounds worth of risk.

"The requirements set out here take effect from 31 March 2023 at the inception or on renewal of each policy," reads the bulletin. "There is no requirement to endorse existing, in-force policies, unless the expiry date is more than 12 months from 31 March 2023. Managing agents will nevertheless wish to start at an early stage to determine their approach to adopting appropriate exclusion clauses."

WHO TO BLAME?

There are several excellent articles on the challenges of attribution regarding cyber attacks, and these new cyber insurance clauses leave many questions unanswered that may ultimately be decided by the courts.

At the heart of this matter are questions that we have been debating for many years such as:

* How do you define "cyber war"?

* How can attribution be truly known for cyber attacks?

* Who will be the deciding organization when disagreements arise?

I like this article at Marsh.com on moving toward clarity on some of these topics. Here's an excerpt:

"In the spirit of transparency, we share here a high-level summary of themes explored through our work with Munich Re, including that:

* The endorsement should not serve as a catastrophic risk catchall.

* The endorsement should clarify the scope of coverage provided resulting from state-backed cyber attacks.

* The endorsement should bring clarity to what constitutes war, and avoid conflation with the concept of a cyber operation.

* The introduction of new concepts like 'cyber operations,' 'major detrimental impact,' 'impacted state,' and 'essential services' should be as clear and unambiguous as possible in order to avoid or minimize disputes as to the meaning of the wording.

* The inclusion of references to attribution of cyber operations should not change the legal burden of proof, nor should it alter how the policy responds. Attribution of cyber operations to a sovereign state should not automatically trigger an exclusion of coverage.

* The endorsement should clearly delineate between cyber attacks that constitute or are deployed as part of an ongoing war — and thus are beyond the scope of coverage — and cyber attacks that are not related to a war and so should not be inadvertently excluded."

I also like this cyber insurance case law history article and analysis at Law.com, and highlight the last two paragraphs here: "The summary review of recent case law discussed here, and comparison to earlier law makes it clear that the basic rubrics of contract law continue to guide the courts in their interpretation of cybersecurity insurance. Although it is well established that the new digital world has ushered in the burgeoning growth of cyber crime, and it is well advised to obtain coverage for anticipated cybersecurity events, the insured must be on alert as insurance policies will be contoured by insurers to limit their exposure.

"The relevant provisions of the policy must be scrutinized by the insured so as to assure that the policy will provide the broadest protection against a fraudster's creative and ingenious schemes that may befuddle the staff of the insured and may lead to significant fraudulent transfers and losses."

NEW U.S. NATIONAL STRATEGY AND CYBER INSURANCE

And if you think this topic can get no more complex, think again. As I identified in a recent blog on the new National Cybersecurity Strategy, cyber insurance is a major topic of discussion in the U.S. federal government.

This Forbes article (contributed by Forrester) does a nice job of summarizing the many strategic objectives in the strategy at a high level and is worth reading. Here is what they say about objective 3.6 under cyber insurance:

"Cyber insurance is one component of a multilayered cybersecurity and risk management strategy. Today's environment of systemic risks stemming from global events, geopolitical threats and third-party risk events has a cascading impact on and across organizations — and the cyber insurance market. The call for a federal response to support the existing cyber insurance market is welcomed. This kind of subsidization, however, could be costly to the government, much like individual flood insurance. If exploration moves to enactment, reforms will likely be needed in the future. Meanwhile, organizations must address the current reality of cyber insurance market dynamics and increasingly stringent requirements for obtaining cyber insurance policies."

Many are calling for the federal government to become the insurer of last resort for cyber insurance; however, that would require an act of Congress and seems unlikely in the short term.

WHAT CAN ORGANIZATIONS DO NOW?

In an Eversheds-Sutherland Legal Alert, the following advice was given to cybersecurity policyholders in the current environment:

"It remains to be seen the extent to which Lloyd's decision to exclude state-backed cyber attacks from standard cyber insurance policies will be mimicked by other insurance providers. However, Marsh Insurance initially published a critique of the exclusion requirement shortly after it was published, then softened its stance and suggested its own exclusion language some weeks later, perhaps indicating the direction of travel. From the insurance industry's perspective, it is possible that some of the risk of state-backed attacks are shared with the public sector, as happens with other risks such as terrorism and the pandemic, and this is something which has already been called for by certain insurers.

"But, in this new environment, organizations may want to:

1. Pay particular attention to how terms like 'cyber operation' are defined, and how attribution will be determined in cases of suspected state-backed cyber attacks;

2. Scour definitions integral to policy coverage, such 'software systems,' 'networks' and 'equipment,' to ensure appropriate coverage, including when attacks impact third-party applications, vendors, virtual networks and cloud services;

3. Verify the extent to which insurance company pre-approval is required, including in the heat of a crippling attack; and

4. Confirm they have robust and tested breach response plans in place, aligned with insurers, and that insurers have pre-approved the companies' preferred outside counsel (not just panel counsel), forensic providers and crisis communicators."

Davis Hake is the co-founder and vice president of communications and policy at Resilience Insurance. He offered this advice in his LinkedIn blog called Resilience:

"In advance of this discussion, however, there is more the insurance industry can do today to reduce the impact of these types of risks on clients and capacity providers.

1. First, regularly scan and warn all clients about critical vulnerabilities being exploited and have actionable mitigations. When Log4Shell was discovered, the Resilience Security team immediately checked all its clients and followed up directly with remediation actions. If there is a highly "contagious" vulnerability, we will ensure we are a part of the immune system response.

2. Second, leverage data-driven frameworks like the NIST Cybersecurity Framework and CIS Critical Controls as a part of underwriting and guidance to clients. Resilience leverages these tools in our modeling to ensure that our clients and capital placement follow the most up-to-date guidance on cyber hygiene.

3. Finally, use data tools to understand and model your portfolio risk. This has been a long-term goal for Resilience to help provide visibility to capital providers on sources of systemic risk. This drives proactive mitigations into our client base through guidance and policy language when we see trends that could lead to massive systemic-level losses."

FINAL THOUGHTS

When I posted the FT.com article that I began this blog with on my LinkedIn page on Saturday, April 1, the responses came flooding in from all over the world.

If your read those comments and feedback on cyber insurance, you will see that perspectives are all over the map. But to sum up a widely held view, look at this comment from Niko Marjomaa, who works in Cybersecurity in Transaction Strategy and Execution at EY-Parthenon:

"Expected. There are so many companies already insured that should have never gotten one because of lacking investments and emphasis on cybersecurity. Also, recent court case decisions on liability have not been favorable to insurers. It was a matter of time, but the key question is: Where will they draw the line between state-sponsored and non-state sponsored because in case of China and Russia the line is very thin."

___

(c)2023 Government Technology

Visit Government Technology at www.govtech.com

Distributed by Tribune Content Agency, LLC.

Older

Pocket Insurance on Bajaj Markets: Beat the Summer Heat with Home Inverter Insurance [Business Wire India]

Newer

Charlie Javice Charged with Defrauding JPMorgan Chase of Millions

Advisor News

  • Study finds more households move investable assets across firms
  • Could workplace benefits help solve America’s long-term care gap?
  • The best way to use a tax refund? Create a holistic plan
  • CFP Board appoints K. Dane Snowden as CEO
  • TIAA unveils ‘policy roadmap’ to boost retirement readiness
More Advisor News

Annuity News

  • $80k surrender charge at stake as Navy vet, Ameritas do battle in court
  • Sammons Institutional Group® Launches Summit LadderedSM
  • Protective Expands Life & Annuity Distribution with Alfa Insurance
  • Annuities: A key tool in battling inflation
  • Pinnacle Financial Services Launches New Agent Website, Elevating the Digital Experience for Independent Agents Nationwide
More Annuity News

Health/Employee Benefits News

  • National Health Insurance Service Ilsan Hospital Describes Findings in Gastric Cancer (Incidence and risk factors for symptomatic gallstone disease after gastrectomy for gastric cancer: a nationwide population-based study): Oncology – Gastric Cancer
  • Reports from Stanford University School of Medicine Highlight Recent Findings in Mental Health Diseases and Conditions (PERSPECTIVE: Self-Funded Group Health Plans: A Public Mental Health Threat to Employees?): Mental Health Diseases and Conditions
  • Health insurance cost increases predicted to cut millions from needed protection
  • Department of Labor proposes pharmacy benefit manager fee disclosure rule
  • WALKINSHAW, DUCKWORTH IMPLORE TRUMP ADMINISTRATION TO EXPAND IVF COVERAGE FOR THE MILLIONS OF HARDWORKING AMERICANS ENROLLED IN FEHB PLANS
More Health/Employee Benefits News

Life Insurance News

  • AM Best Affirms Credit Ratings of Etiqa General Insurance Berhad
  • Life insurance application activity hits record growth in 2025, MIB reports
  • AM Best Revises Outlooks to Positive for Well Link Life Insurance Company Limited
  • Investors holding $130M in PHL benefits slam liquidation, seek to intervene
  • Elevance making difficult decisions amid healthcare minefield
Sponsor
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Elevate Your Practice with Pacific Life
Taking your business to the next level is easier when you have experienced support.

ICMG 2026: 3 Days to Transform Your Business
Speed Networking, deal-making, and insights that spark real growth — all in Miami.

Your trusted annuity partner.
Knighthead Life provides dependable annuities that help your clients retire with confidence.

8.25% Cap Guaranteed for the Full Term
Guaranteed cap rate for 5 & 7 years—no annual resets. Explore Oceanview CapLock FIA.

Press Releases

  • Financial Independence Group Marks 50 Years of Growth, Innovation, and Advisor Support
  • Buckner Insurance Names Greg Taylor President of Idaho
  • ePIC Services Company and WebPrez Announce Exclusive Strategic Relationship; Carter Wilcoxson Appointed President of WebPrez
  • Agent Review Announces Major AI & AIO Platform Enhancements for Consumer Trust and Agent Discovery
  • Prosperity Life Group® Names Industry Veteran Mark Williams VP, National Accounts
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet