Table of Contents
Introduction
Small businesses are prone to many kinds of risks. With the recent rise in adopting digital technologies, businesses are witnessing an increase in digital assets vital for their business continuity. Therefore, a small business must invest in cyber insurance to mitigate any risk associated with the digital assets!
As this kind of insurance is new, there are many challenges for both the insurance company and their clients. This article aims to provide a realistic picture of cyber insurance that you need to know before purchasing one for your business!
After all, the one who is informed is in the best position to make decisions.
Unclear legal framework and standards
Compared to the other risks in the market, cyber-attacks are relatively new. The damages caused by them lack a legal framework that defines the various definitions for the associated incidents and risks. Questions like who is responsible for defending against cyber attacks, the reasonable standards for IT security, and others need to be answered and documented to provide clarity for both insurers and insured!
Ambiguity in law can lead to severe consequences for businesses. For example, in 2018, Mondelez International, a food conglomerate, sued Zurich Insurance for $100 million damages incurred due to the NotPetya ransomware attack and lost! The insurance company did not provide any payout as nation-state hackers made the attack, and as such, it came under the acts-of-war exemption!
Therefore, a well-defined legal framework is needed to ensure that the insurer and the insured parties are on the same page. Small business owners must be aware of this and minimize their cyber risks!
Cyber insurance conceptual issues
As of today, there is still no proper method that measures the damages and quantifies risks. While some damages like loss of revenue due to server downtime are easy to calculate, others are much harder to determine. Many damages can be unique to the insured party or their industry.
For example, how do you determine the value of stolen data? How can a particular risk be quantified in the potential loss it will have on a client? How will each risk be categorized? Will it operate under business continuity insurance or cyber insurance policy?
Therefore, the cyber insurance company must have clear and transparent communication with the client to prevent potential misunderstandings and nasty surprises.
As a business owner, gain clarity on the following points related to your cyber insurance:
- What are the deductibles in the policy? Compare them with other policies in the market.
- Does the policy cover third-party service providers – consequently, find out if your third-party service providers have an insurance policy?
- Does the policy cover attack to which an organization falls victim or only targeted attacks against that organization in particular?
- Does the policy cover non-malicious but erroneous action by an employee?
- Does the policy cover social engineering attacks like phishing, spear phishing, and others in its coverage? Or is it only focused on network attacks?
- What is the timeframe within which the coverage is applicable? Some attacks, such as Advanced Persistent Threats, can take place over time – ranging from months to years, and it’s essential to evaluate if they will be considered in the policy.
- Scenarios in which cyber insurance will not protect you against a hack
Lack of analytical data
Since cyber insurance is a new field, there is a lack of data and standards to help insurance companies determine the premiums. For other areas, such as health and fire, companies have an extensive dataset that calculates the appropriate compensation for a client based on their characteristics and habits.
For cyber insurance, it is hard to determine the likelihood of a cyber-attack or the damages that result from it. Most of the time, companies do not discover a hack until months have passed. If the insurance company can not predict the likelihood of risk, how will they determine the premium?
Lack of visibility into a business’s cyber health
Insurers themselves are new to cybersecurity and are trying to understand this highly dynamic and technical topic. As there is a lack of awareness amongst the business owners, insurers have no visibility into a client’s cyber health. This is not present in other insurance types – for example, visibility into a person’s health is easier to determine for an appropriate insurance premium.
Businesses considering cyber insurance must conduct a cyber risk assessment, that will allow visibility of your current cyber health and security measures. As an added benefit, businesses will understand the areas they need to protect and where they are most vulnerable.
You must keep documented proof that you follow the best security practices and have an effective cybersecurity culture. Documented evidence of security defenses and controls, with regular training and penetration testing, will display that your business is serious about cybersecurity and help you get a better premium rate.
Ransomware might not be part of the coverage
Recently, the world is witnessing a stark rise in ransomware attacks, and it is the number one threat to small businesses. In the majority of the cases, the organizations had cyber insurance.
Ransomware gangs specifically target firms that purchased cyber insurance, believing that these companies are more likely to pay the ransom. Moreover, the hack usually starts with the insurer themselves, which reveals the company’s customer base.
Understandably, insurance companies are reluctant to cover ransomware damages even if you already have a policy with them, and for good measure. Paying ransom only encourages future attacks that are something the insurance company and government organizations wish to avoid. Also, paying a ransom does not guarantee that you will access the data or protect you from future attacks.
AXA insurance company has set a precedent not to award any claim for ransomware attacks in France! In response to the devastating global epidemic of ransomware. Last year, France had an estimated loss of $5.5 billion due to ransomware, and “they want the word to get out that, regarding ransomware, we don’t pay, and won’t pay!”
Conclusion
While we strongly recommend that businesses of all sizes invest in a cyber insurance policy, this article highlights their limitations. Like any other insurance cover, the buyer must be informed of the cyber insurance limitations before purchasing a policy.
Due to the above reasons, many insurance companies do not cover incidents triggered by unauthorized activity or even accidental events. Payouts for data breach might cover only legally required costs, and cover for network interruption will be limited to actual network interruption – not considering the revenue impact of disruption.
In some cases, insurance has excluded security incidents related to recently updated systems, and businesses are often limited to choose the PR, IT, or legal specialists of the insurer choice, which can cause severe headaches in the face of chaos.
Therefore, as a small business owner, you must investigate the different insurance choices available in the market and choose the best off-the-shelf and modular insurance package relevant to your business.
Lastly, while cyber insurance can be a safety net for a business that experiences cyberattacks or privacy-related loss, a business must not rely solely on the insurance when an incident occurs. At best, consider cyber insurance as a complement to sound cybersecurity policies and practices!
