Advice For Cyber Insurance Buyers

The cyber insurance market continues to evolve, and the number of companies buying cyber insurance continues to expand. What’s more, that expanding cyber market offers a wide variety of coverage terms at different price points.

But companies interested in securing cyber insurance should know that the underwriting process requires careful diligence on their part. CFOs and risk managers need to have a firm grasp of the processes insurers use, not only to price a policy but also to determine whether they will agree to underwrite the risk at all.

One of the first steps in the underwriting process requires the company to submit an application to the insurer. The application will seek baseline information about the company’s size, number of records maintained, type of information maintained, security policies and procedures, and disaster planning.

The company’s ability to answer those questions with complete and detailed information is critical. Comprehensive answers can help ensure that the policy will be competitively bid by a number of insurers and secure the lowest premium pricing.

Underwriters will be most interested in companies that can communicate effectively that they know where their records are maintained and how many records are at risk. They’re also more open to companies that have implemented strong security measures to protect their records and minimise the likelihood of a breach.

Further, cyber carriers will also look for representations in their application about whether the corporation, and sometimes what’s termed “any insured” (which means all employees), has knowledge of claims, facts, or circumstances that can spawn a claim.

Some companies blunder by providing a response to that question without giving enough consideration as to who within the organisation is being asked to make that representation or on whose behalf the representation will be made. The consequence of failing to understand the importance of these requested representations can be severe.

For example, let’s look at the experience of a hypothetical credit card company which has just disclosed a hacking incident that compromised many customer email accounts several years ago. In its current disclosure, the company admitted that some of its employees, including senior executives and attorneys, knew about the breach at the time of the incident.

Even though the company had applied for and bought a cyber insurance policy late last year, coverage in this fact scenario could be seriously at risk. That’s because employee previous knowledge of the facts could lead to a claim by the insurer objecting to the fact that the company hadn’t disclosed that knowledge for several years.

Further, basing their claim on these facts, some insurers may seek to rescind the entire policy, asserting that a material misrepresentation was made in the application. In other words, insurers may argue that they have no coverage obligation for the undisclosed known breach or any other claims that may arise because the policy was issued under false pretenses.

“Meet and Greet” Underwriting

Once the application has been submitted, the underwriters may want direct access to the chief information officer or others responsible for protecting company information. Companies must understand that those individuals will play a key role in whether the insurer will agree to quote and/or how much will be charged to insure the risks.

But most CIOs and other “techies” aren’t familiar with the insurance procurement process and may not understand how information should be communicated to the insurer. To avoid missteps, companies should have a detailed planning meeting with representatives of the insurer along with the insurance broker and coverage counsel before information is relayed to the underwriter.

Finally, many insurers conduct their own diligence to evaluate whether to underwrite a risk and, if so, at what premium price point. Risk managers and CFOs should be aware that insurers are using a new type of metric to assess their companies’ cyber risk exposure. It’s called a “security score”, a concept akin to a credit score.

For example, BitSight Technologies is a risk assessment vendor that analyses companies for breach risk and response preparedness and assigns a security rating. According to its website, BitSight gathers data on security breaches from sensors deployed across the globe and uses algorithms to assess a company’s records management, encryption methods, and security vulnerabilities.

The firm then assigns a security rating and provides benchmarking information to demonstrate where the company falls short on the risk assessment spectrum. Companies on the lower end of the spectrum may not receive a quote for cyber insurance, while companies on the higher end may receive such better terms as lower premium or lower retentions. Companies looking to buy cyber coverage need to know that, in an important sense, they are not alone.

CFO:

For more information and help with your organisation’s security contact: Cyber Security Intelligence

You Might Also Read:

Five Pitfalls of Cybersecurity Insurance:

Cyber Crime Drives Up The Cost Of Insurance:

Cyber Should Be Standalone Insurance:

 

« Power Companies Cyber ‘Nightmare’
AI Meets Music’s Evolution »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

CERT-IS

CERT-IS

CERT-IS is the national Computer Emergency Response Team for Iceland.

Alan Boswell Group

Alan Boswell Group

We are a Group of Companies providing specialist Insurance Broking and Risk Management advice and services including Cyber Risk cover.

Egyptian Supreme Cybersecurity Council (ESCC)

Egyptian Supreme Cybersecurity Council (ESCC)

ESCC is responsible for developing a national strategy to face and respond to the cyber threats and attacks and to oversee its implementation and update.

Very Good Security (VGS)

Very Good Security (VGS)

VGS is the modern approach to data security. Our SaaS solution gives you all the benefits of interacting with sensitive and regulated data without the liability of securing it.

Baffin Bay Networks

Baffin Bay Networks

Baffin Bay Networks operates globally distributed Threat Protection Centers™, offering DDoS protection, Web Application Protection and Threat Inspection.

Romanian Accreditation Association (RENAR)

Romanian Accreditation Association (RENAR)

RENAR is the national accreditation body for Romania. The directory of members provides details of organisations offering certification services for ISO 27001.

Incopro

Incopro

Incopro is an online IP and brand protection software provider that arms brand owners with actionable intelligence to combat online and offline intellectual property and copyright infringements.

AlJammaz Technologies

AlJammaz Technologies

AlJammaz Technologies is the leading Technology Value-Added Distributor, which distributes advanced technology products, solutions and services in area including networking and cybersecurity.

BDO Global

BDO Global

BDO is an international network of public accounting, tax and advisory firms which perform professional services under the name of BDO.

Data Protection Commission (DPC)

Data Protection Commission (DPC)

The Data Protection Commission (DPC) is the national independent authority responsible for upholding the fundamental right of individuals in the EU to have their personal data protected.

HiddenLayer

HiddenLayer

HiddenLayer is a provider of security solutions for machine learning algorithms, models and the data that power them.

Anonos

Anonos

Anonos is a global software company that provides the only technology capable of protecting data in use with 100% accuracy, even in untrusted environments.

Moonsense

Moonsense

Moonsense is on a mission to level the playing field in the fight against online fraud.

Waterleaf International

Waterleaf International

Waterleaf provide advanced network and cybersecurity solutions - informed by data sciences. Transforming Connectivity, Security and Information for Municipalities, Government & Enterprise.

AppSentinels

AppSentinels

Appsentinels are a group of security and technology experts with a mission to fix gaps in application security.

Harmonic Security

Harmonic Security

Harmonic Security helps companies to adopt Generative AI without risking the security and privacy of their data.

Quantum Bridge

Quantum Bridge

Our unbreakable key distribution technology ensures the highest level of protection for your critical infrastructure and sensitive data in an evolving digital landscape.