Given the buzz surrounding insurance in the cyber ecosystem, we have decided to dedicate an article to it. It is clear that the scope of risk is expanding, and as more companies are compelled to seek coverage, the cyber insurance market is poised for significant growth.

We will review some of these developments, characterized by shrinking risk coverage, rising premiums, and a lack of enthusiasm among policyholders. We will then address the key challenges involved.

  1. Definition and Overview
    1. Definition
    2. What does the law say?
  2. Are cyber insurance policies in crisis?
    1. Evolution of insurance policies
    2. Increase in insurance premiums
    3. Lack of enthusiasm among policyholders
  3. Why take out cyber insurance?
  4. What are the solutions?

Definition and Overview

Definition

It is always important to clarify the terminology used, so let's start by defining the term cyber insurance.

Cyber insurance is a policy specifically designed for IT risks. It covers financial losses resulting from damages caused by a cyberattack and provides legal and technical assistance.

According to the report byAnozr Way, insurers themselves are targets of cyberattackers, accounting for 20% of ransomware attacks in 2021, making it the most affected sector in France. Cybercriminals are targeting supply chain attacks, but we will explore this in more detail in a future article.

What does the law say?

Paying a ransom is not illegal in France; however, all nations agree that in the event of a ransomware attack, it is strongly advised against. Paying encourages hackers to continue their criminal activities, and furthermore, it provides no guarantee that lost data will be recovered. Conversely, companies affected by an attack have every interest in filing a complaint, as this strengthens their resilience strategy by providing telemetry, insights into the attacker's methodology, and assistance in implementing remediation measures.

The similarities between nations end there, as laws regarding cyber insurance and penalties differ by country—a point we will examine specifically in the cases of France and the United States.

In Europe

"One in six companies experienced an incident in France in 2020, and 65% paid the ransom."

Hiscox Insurance, 2020

In France, the cyber insurance market remains largely unstructured. There are no specific laws or penalties regarding the payment of ransoms. A report by the Higher Commission for Digital and Postal Services (CSNP) reveals that France remains the country that pays the most ransoms and is also the most targeted country within the European Union, accounting for 5% of global cyberattacks [1].

The parliamentary report by Valéria Faure-Muntian, presented in October 2021, recommends:

  • defining cyber risks
  • harmonizing definitions
  • implementing a law prohibiting the payment of ransoms
  • requiring insurers not to cover or indemnify ransom payments and mandating the filing of a complaint in the event of an attack.

This same report also addresses insurance coverage for administrative penalties (for example, failure to comply with personal data protection or regulatory requirements).

Only Operators of Vital Importance (OIVs) have regulatory obligations regarding detection, risk management, incident notification, and auditing. If these obligations are not met, these organizations face potential sanctions.

Finally, it is worth noting that cyber insurance is not currently mandatory.

The new European regulation adopted on data protection mandates more extensive security and total transparency, which includes individual notification to all clients whose data is contained in the affected files. This adds to an already strained budget. In addition to the GDPR, there is the NIS (Network and Information System Security) directive. It was adopted on July 6, 2016, and is applied in every European Union country. This directive establishes a common level of security for all member states. It covers security governance, the protection and defense of networks and information systems, and operational resilience.

In the United States

The cyber insurance market was born 20 years ago in the United States, whereas it is still in its infancy in France.

In the United States, the law is clear and strict: the Office of Foreign Assets Control (OFAC) [2] imposes civil penalties on any organization that assists companies in paying ransoms, including insurance companies or financial institutions.

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 requires mandatory reporting of cyber incidents within 72 hours, and within 24 hours of any ransom payment.

16 critical infrastructure sectors are affected, including assets, systems, and networks considered essential to the United States.

The project includes several provisions regarding ransomware and protection mechanisms.

Is cyber insurance in crisis?

Evolution of insurance policies

As threat actors vary their attack methods, risks continue to rise, and the attack surface expands along with them. This reality is forcing insurers to evolve their contracts. They are not hesitating to add cyber exclusions that limit their exposure to cyber risks, particularly in the case of ransomware. Indeed, some companies are beginning to withdraw from cyber coverage. This was the case for Axa France, which decided in May 2021 to stop covering ransoms paid by companies. Generali followed suit in February 2022. Others, such as Lloyd’s of London, have indicated they will no longer cover cyberattacks between nation-states.

It should be added that companies can take legal action against their insurers: this is the case for Merck & Co, which lost more than $1.4 billion following the NotPetya attack in 2017. The pharmaceutical multinational sued its insurers, who refused to cover the impacts of the attack, and won the case.

This type of event makes insurers more hesitant. The effects of this caution are undeniable and are impacting coverage terms.

The level of coverage is thus not becoming satisfactory enough in the eyes of companies. The youth of the market means there is a lack of longitudinal studies on the risk. This does not encourage cyber insurers to position themselves in this sector, and when they do, the level of requirements regarding risk protection is very high. This same level of requirement is demanded of third-party companies in order to protect the entire supply chain. Thus, equipment configuration, multi-factor authentication, backups, etc., have become mandatory.

Finally, the subscription procedure (or renewal) is becoming similarly burdensome and must therefore be anticipated well in advance, adding to an already strained budget. Recently, cyber-rating "tools" have been implemented for SMEs with less than 50 million euros in turnover. These companies will have to implement antivirus, antimalware, and firewall software, and apply a strict patching and update policy, as well as backups at least every week.

Increase in insurance premiums

Until now, companies did not know what their insurance covered until they were faced with a cyber incident. Policyholders will now be more vigilant about the content of their contracts because they feel they are paying more to ultimately get little or nothing at all. They see their premiums and deductibles increase without the assurance of being well protected. The same goes for insurers, who are struggling to make ends meet and are not making their offerings profitable. According to a survey conducted in December 2021 by Amrae[3], the claims-to-premium ratio was 167% in 2020, compared to 84% in 2019.

For example, the SolarWinds incident in 2020 cost insurance companies approximately $90 million.

This situation results in a market with little competition, which does not favor price reductions. The forecasts are not optimistic, as according to a report by Cybersecurity Ventures, ransomware will cost more than $265 billion per year by 2031.

Lack of enthusiasm among the insured

The conclusion is clear: large companies are more inclined to get insured than smaller ones. Still according to the Amrae report, 87% of large companies were covered, compared to only 8% of mid-sized companies, 0.0026% of SMEs, and 1% of municipalities with more than 5,000 inhabitants. Not all organizations can afford to be insured due to the rising costs of contracts or cyber requirement levels. Small structures that do not specialize in cybersecurity may find it difficult to prove the effectiveness of their systems. They will have to hire a subcontractor, which will generate additional costs they cannot bear. Getting insured is becoming a luxury.

Security maturity levels vary significantly from one organization to another. While cyber insurance offerings are beginning to adapt to different structures, this remains a niche area. We are once again facing a gap between limited supply and weak demand. Nevertheless, some French gems are emerging and positioning themselves in this market by offering cyber risk coverage for SMEs. This is the case for our partner Stoïk which enables a wide range of SMEs to combine their cyber insurance with the highest level of cybersecurity. Through its internal tools, Stoïk helps monitor risk exposure on an ongoing basis.

In Germany, the average total cost of cyber damages is 18,712 euros, placing the country at the top of the international ranking (compared to an average of 15,255 euros). Consequently, investments in cybersecurity continue to rise, with cyber insurance becoming a primary protection measure. As a reminder, the share of the total IT budget dedicated to cybersecurity has reached one quarter (24%).

Why take out cyber insurance?

Taking out cyber insurance requires companies to maintain a robust security policy, conduct regular audits, and have a clear, frequently updated risk map.

This vigilance helps guard against certain vulnerabilities while also providing a better understanding of the maturity level of an organization's information systems security policy (ISSP). Companies will need to implement corrective measures, formalized through procedures, and, of course, provide proof of awareness campaigns for their staff.

These insurance policies encourage the implementation of preliminary measures and certifications, such as ISO standards or SecNumCloud. Insurance companies will base their compensation on the measures taken by the policyholder; therefore, a non-certified company will have to pay a higher insurance premium.

Insurance policies can cover risks such as:

  • loss of personal data
  • protection of intellectual property
  • security incidents
  • hijacking of connected devices

But also:

  • costs for restoring destroyed data
  • costs related to expert assessment requests
  • the company's brand image
  • third-party claims

It should be noted that not all insurance policies are equal; some do not cover the risks mentioned above, which can sometimes be difficult to measure.

Finally, they do not only cover technical aspects. Beyond the protection they provide regarding guarantees in the event of GDPR violations and breaches of customer personal data, they also offer assistance and advice during a crisis.

Spain is a pioneer in this field; in fact, 83% of Spanish companies already use cyber insurance policies to help them recover from ransomware attacks.[4]

What are the solutions?

We have no doubt that cyber insurance will evolve alongside the threat landscape in the coming years.

Among the solutions that could be proposed:

  • Pooling risks within an organization by building capital to cover potential losses.
  • Supporting digitalization for small businesses.
  • Encouraging reinvestment in security.
  • Clarifying the scope of cyber coverage to make it easier to compare and purchase insurance policies. This will help restore the trust that has somewhat eroded between policyholders and insurers recently.
  • Defining European legislation for cyber insurance.
  • Offering hybrid solutions to meet market needs.
  • Implementing state support through research tax credits to encourage investment in security and prevention.
  • Promoting collaboration between the public and private sectors to pool expertise.
  • Making cyber insurance mandatory. This solution is, of course, a subject of debate.

Insurers must have a firm grasp of the scale of threats and risks. This work must be done in close cooperation with businesses.

Cyber insurance agencies require their clients to take responsibility and protect their own networks by strengthening their security with effective prevention tools. A sound cyber strategy relies on investing in protection tools. Companies should focus on using a comprehensive approach, such as TEHTRIS XDR technology, which detects threats across all systems, networks, and the cloud in a highly automated way. It blocks and neutralizes cybersecurity attacks in real time. Thanks to its various modules, automation, and knowledge base of cyber threats, it identifies suspicious behavior, malicious programs, or malicious IPs.

If you would like to explore how TEHTRIS can help protect your organization against all types of malicious actors and save you from having to file claims with your insurer, please contact us.

Contact us

BIBLIOGRAPHY

[1] Anozr Way, 2020

[2] The Office of Foreign Assets Control is a financial control agency under the U.S. Department of the Treasury. Source: Wikipedia.

[3] Association for Risk and Insurance Management. "Market Status and 2022 Outlook - Corporate Insurance."

[4] https://www.elindependiente.com/economia/2022/05/13/la-demanda-de-ciberseguros-ha-crecido-las-pymes-saben-que-un-ciberataque-es-devastador/

Continue reading
Blog
Contactez Tehtris
Nos équipes vous recontacteront au plus vite afin d'échanger sur vos challenges cyber et évaluer comment nous pouvons vous accompagner pour les adresser.
Tehtris EDR : conçu, développé et opéré en Europe
Voir nos preuves
Derniers articles
See all