Half Of US Firms Do Not Buy Cyber Insurance

A full 50 percent of US firms do not have cyber risk insurance and 27 percent of US executives say their firms have no plans to take out cyber insurance, even though 61 percent of them expect cyber breaches to increase in the next year.

Even among those that have insurance, only 16 percent said they have cyber-security insurance that covers all risks.

The US lags behind the UK and Canada, where about 40 percent have no cyber coverage. Mistrust about insurance pricing is one reason some firms aren’t buying.

These findings come from a survey conducted by research firm Ovum for Silicon Valley analytics firm FICO. The researchers conducted telephone interviews with 350 c-suite executives and senior security officers from financial services, telecommunications, healthcare, retail, e-commerce and media service providers. The respondents represented various size companies: 30 percent had 500 to 1,000 employees; 28 percent had 1,001 up to 4,999; 17 percent had 5,000 up to 9,999, and 25 percent had more than 10,000.

In the US, the healthcare industry is particularly behind on fully protecting itself with cyber insurance, according to the survey. None of the healthcare firms represented in the survey have insurance that covers all risk, while 74 percent have none at all.

“With so many firms concerned about a rise in the likelihood of cyber breaches in the next year, it’s troubling to see that half of them don’t have any cybersecurity insurance protection,” said Bob Shiflet, who oversees fraud and financial crime solutions at FICO.

“There are steps the insurance industry can take to make guidelines clearer and explain premium adjustments, but companies need to be willing to dedicate the resources required to protect themselves from the breaches they themselves see as likely, if not inevitable.”

The authors identify the cost and lack of clarity about insurance pricing as an obstacle to increased sales. Only 25 percent of survey respondents believe that premiums provide a genuine reflection of the risk profile of their organisation. Only 23 percent believe that the insurance industry is clear and transparent in its approaches to pricing.

US executives identified several ways the risk assessment process that insurers use could be improved. Twenty-nine percent say that insurers should provide clear guidelines about how premiums are chosen, 28 percent would like clearer communications as to why premium adjustments happen and 23 percent would like insurers to introduce an industry standard for benchmarking cyber risk.

Related Reports

Other reports have looked at why some companies are not buying cyber coverage.

A cyber readiness survey released in February by specialist insurer Hiscox suggested that momentum is building behind cyber insurance. In its survey, overall 55 percent of US firms said they had taken out cyber insurance. Hiscox analysts said its higher take-up figures may partly reflect confusion over what exactly constitutes cyber coverage with some companies believing they are protected under their existing policies.

In the Hiscox survey, among the firms that had not bought cyber cover – 26 percent of the survey sample – and do not plan to do so, two in five (41 percent) of them said “a cyber insurance policy is not relevant for me.”

More than one in six (17 percent) of those that have no plans to take out cyber insurance agreed with the statement: “Cyber insurance policies are so complicated, I don’t understand what cyber insurance would cover me for.”

A report published by Deloitte consultants suggested buyers often don’t understand cyber risks or insurance options and also cited a lack of standardization of cyber policies.

“Similar cyber insurance products offered by different providers often include alternative features, which makes it difficult for buyers to compare policies by value and price,” according to the report. Concerned about potential coverage gaps, businesses want to avoid buying coverage they don’t fully understand with language that may be subject to interpretation, the report said.

The Deloitte report recommended steps the industry could take to overcome buying obstacles including standardising policy language, developing a “risk-informed model” rather than a definitive predictive model for cyber risks, employing more targeted underwriting by industry or exposure, and offering more holistic cyber risk management programs.

Not a Big Deal

Yet another report, this one by the nonprofit RAND Corp., hints at another reason not all companies see cyber insurance or further investment in cyber-security as a good investment. The typical cost of a breach is about $200,000 and most cyber events cost companies less than 0.4 percent of their annual revenues, the study found. The $200,000 cost is roughly equivalent to a typical company’s annual information security budget.

“Relative to all the other risks companies face, the cyber risks often aren’t as big a deal as we think,” said Sasha Romanosky, author of the study and a policy researcher at RAND. “It may be bad for you if you are the victim, but it doesn’t change the behavior or strategy of a company. Like you and me, companies are self-interested and operate in ways that minimize their costs. You can’t begrudge them for working that way.”

The RAND study ‘s cost estimate is a lot less than the estimate in a May 2014 report by the Ponemon Institute at the University of Michigan. The Ponemon report put a $3.5 million price tag on an individual data breach. Ponemon surveyed 314 companies in 10 countries. The RAND study, which is published in the Journal of Cybersecurity, is based on a private dataset of 12,000 cyber incidents compiled by Advisen.

For more Information and a free Report please contact: Cyber Security Intelligence.com

Insurance Journal

You Might Also Read:

Insurance: How Cyber Risks Are Evolving:

Are Corporate Cyber Defenses Adequate?:

Advice For Cyber Insurance Buyers:

 

 

« Reinventing Cold War Spy Craft
Find Your Digital Risk »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

HackerOne

HackerOne

HackerOne was started by hackers and security leaders who are driven by a passion to make the internet safer.

Armor

Armor

Armor provide managed cloud security solutions for public, private, hybrid or on-premise cloud environments.

Datto

Datto

Datto delivers a single toolbox of easy to use products and services designed specifically for managed service providers and the businesses they serve.

AVG Technologies

AVG Technologies

AVG is focused on providing home and business computer users with the most comprehensive and proactive protection against computer security threats.

Canadian Security Intelligence Service (CSIS)

Canadian Security Intelligence Service (CSIS)

CSIS collects and analyzes threat-related information concerning the security of Canada in areas including terrorism, espionage, WMD, cybersecurity and critical infrastructure protection.

Focal Point Data Risk

Focal Point Data Risk

Focal Point is a pure-play data risk management provider capable of offering end-to-end consulting, implementation, and training services.

BankVault

BankVault

BankVault is a new type of cyber technology (called remote isolation) which sidesteps your local machine and any possible malware.

Unitrends

Unitrends

Unitrends helps IT pros do more with less by providing an all-in-one enterprise backup and continuity solution.

Halon

Halon

Halon is a flexible security and operations platform for in-transit email.

CybExer Technologies

CybExer Technologies

CybExer provide an on-premise, easily deployable solution for complex technical cyber security exercises based on experience in military grade ranges.

CyberSaint Security

CyberSaint Security

CyberSaint’s CyberStrong Platform empowers organizations to implement automated, intelligent cybersecurity compliance and risk management.

Enso Security

Enso Security

Enso is the first Application Security Posture Management (ASPM) solution, helping security teams everywhere eliminate their AppSec chaos with application discovery, classification and management.

MVP Tech

MVP Tech

MVP Tech designs and deploys next generation infrastructures where Security and Technology converge.

Char49

Char49

Char49 specialize in Penetration Testing, Red Team Assessment, Social Engineering and Security Research.

Kingston Technology

Kingston Technology

Kingston is a leading global manufacturer of memory and storage solutions including encrypted storage solutions to protect data inside and outside the firewall.

Battery Ventures

Battery Ventures

Battery partners with talented founders and teams building category-defining businesses at all stages of growth.