When Lake City, Florida was hit with a ransomware attack, the city decided to pay the ransom. Its insurer, Beazley, estimated recovery costs could reach $1 million. Weighing the math against its cyber insurance policy, Lake City ultimately paid a $462,000 ransom. Under the policy terms, the cyber attack ultimately cost the city a $10,000 deductible and led to the departure of its IT director.

Contrary to industry tradition, paying ransoms may be becoming the new normal. If calculated correctly—and hackers usually know the value of their victims' assets—paying the ransom is almost always cheaper than recovery costs, especially when businesses hold cyber insurance.

"Insurers offering cyber insurance have successfully positioned themselves as a haven of rationality and resources amid the chaos of ransomware attacks," Jerry Ray, COO of data security company SecureAge, told CIO Dive.

According to the 2019 Global Cyber Risk Perception Survey by Marsh and Microsoft, the percentage of businesses saying they "don't know" whether their cyber policies would meet their needs dropped from 44% in 2017 to 31% in 2019. On the other hand, most businesses with cyber insurance are fairly or highly confident in their coverage.

Source: Marsh and Microsoft 2019 Global Cyber Risk Perception Survey
Naomi Eide / CIO Dive

Misconceptions about the role of insurance in the aftermath of cyber incidents are widespread. There is also an assumption that insurers inadvertently contributed to a 500% year-over-year increase in ransomware attacks. Matthew McCabe, senior vice president at insurance broker Marsh's Center for Excellence in Cyber Risk Practices, told CIO Dive that cyber insurance is "an emerging product, so we expect to receive questions about it." But he also noted that "there is published misinformation about it, and meaningless conclusions thrown into the public debate," such as claims that insurance is encouraging more cyber attacks. "If I could have one wish, it would be that people have a clearer understanding of what this product does and what it pays for," McCabe said.

Cyber insurance is an investment

Cyber insurance is used to offset fines or compensation, plain and simple. It takes over where general liability insurance leaves off, covering costs for businesses such as incident-related expenses, infrastructure restoration, breach notification, and data recovery. "First, it's important to understand that cyber insurance is an after-the-fact control, assuming a breach or failure has already occurred. It's a way to adjust risk assuming your security program doesn't work," Chris Kennedy, CISO of security company AttackIQ, told CIO Dive.

According to the Marsh and Microsoft survey, nearly half of businesses have adopted cyber insurance, up from 34% in 2017. Among companies with revenue over $1 billion, more than half (57%) hold policies, compared to just 36% of companies with revenue under $100 million.

Source: Marsh and Microsoft 2019 Global Cyber Risk Perception Survey
Naomi Eide / CIO Dive

Privacy coverage has brought cyber insurance into the mainstream. "Privacy is an integral part of insurance," McCabe said, especially for data aggregators. As more privacy legislation and regulations emerge, privacy is becoming a competitive advantage. Technology errors and omissions were once part of policies, but as technology matured and businesses could offer more services to consumers, the demand for more comprehensive coverage grew in the insurance industry over the past decade. "This merged with a whole host of other coverages and evolved into what is today's cyber insurance policy," McCabe said.

According to incidents reported by Beazley's internal incident response team, nearly a quarter of ransomware incidents in Q3 2019 originated from IT vendors or managed service providers. These attacks contributed to a 37% year-over-year increase in ransomware in Q3. Business interruption and data destruction are other major drivers for purchasing policies. McCabe said NotPetya, a wiper disguised as ransomware in 2017, "proved with facts" that cyber incidents could lead to catastrophic losses.

How to choose a cyber insurance policy

Cyber risks are often outlined in filings submitted to the U.S. Securities and Exchange Commission, but when considering insurance policies, businesses must assign monetary values to them, values often based on the math of risk assessments. Jeremy Alexander, senior risk expert at Walmart, said at the FAIR conference in September that historically, "people were afraid of cyber incidents because of uncertainty," and as the digital economy developed, insurers knew they should offer cyber coverage but weren't sure how to quantify policies. But as businesses and insurers shift toward quantitative methods, parties are becoming more comfortable with risk, Alexander said. Cyber insurance rates are also improving because competition is equally fierce.

When evaluating plans, businesses must first examine the policy structure. Consider the retention: a clause similar to a deductible. The retention stipulates that if an incident occurs, the policyholder is responsible for losses up to a certain amount. Other times policies have limits, and "you may be on the hook for amounts above the deductible," Alexander said, referring to more severe incidents. Businesses can draw on multiple theoretical scenarios to assess risk and the best policy for transferring it.

"Benign" scenarios (including cloud storage and buckets) are often mismanaged. For example, if a company exposes a bucket—which is often the default setting—but it only contains log files and no personally identifiable information, the loss would be minimal. Alexander said "doomsday" scenarios are worth considering, "excluding the absurd" or completely unimaginable situations. Usually only a few scenarios fall between "benign" and "doomsday." There will always be high-priority scenarios, such as confidential leaks. To estimate these costs, look at other companies' financial data. Walmart is in the same retail industry as Target, so it can learn from competitors' mistakes.

In 2013, Target suffered a data breach involving approximately 40 million credit cards. By 2017, Target agreed to pay nearly $19 million in a class-action settlement to 47 states. Before the settlement, the retailer had already incurred about $184 million in breach-related expenses in 2014 and 2015, according to its 2016 annual report. The company said: "In 2016, data breach-related expenses were immaterial." By the time Target filed its annual report, its total breach costs had reached $292 million, of which about $90 million was "offset" by insurance proceeds. Target's net breach-related costs were approximately $200 million. With approximately 40 million records compromised, risk management teams (like Alexander's) were able to derive a data point: each breached record cost the retailer about $5. Using this data point, businesses—or Target's competitors—can roughly predict breach costs by asking, "How many customer records do we use or own?"

This is a rough summary of risk assessment. Frequency is another factor to consider, and this is where effective communication with senior management is crucial. "You want to be able to show uncertainty, but you don't have to show the distribution," Alexander said.

Insurance gaps

Businesses relying on property insurance policies to cover cyber-related losses may find little comfort. Mondelez International (the company behind Wheat Thins and Chips Ahoy! cookies) had net revenue of nearly $30 billion when it was hit by NotPetya in 2017. NotPetya caused approximately 1,700 servers and 24,000 laptops to be "permanently functionally destroyed." The company relied on a property policy covering electronic data, software, and physical damage caused by the "malicious introduction" of malware. The food company is suing its insurer, Zurich American Insurance, for $100 million for failing to cover losses related to NotPetya. But Zurich has not backed down. The insurer said Mondelez's NotPetya attack was a "wartime act in peacetime," thus exempting Zurich from liability.

"It should be noted that the NotPetya coverage litigation with Mondelez involves Zurich's property policy, not a standalone cyber policy. Standalone cyber insurance policies are better equipped to address emerging cyber risks than the cyber coverage expected in traditional policies, such as first-party property or general liability," Michelle Chia, head of professional liability and cyber at Zurich North America, said in an email to CIO Dive. The lawsuit is ongoing, but in the months following NotPetya, industry and the White House concluded that although it was a state-sponsored attack, most victims were collateral damage rather than primary targets, such as Mondelez and shipping giant Maersk. "I think the insurers got it wrong," McCabe said. In fact, most NotPetya victims were not targeted as acts of war.

According to Marsh's research, "conflating war exclusions with non-physical cyber events (such as NotPetya)" is the result of:

  • The wiper's massive economic impact
  • Attribution of the attack by the U.S. and U.K. governments to Russia

The research notes that even combining these two factors is insufficient to "elevate this non-physical cyber attack to an act of war or 'hostile war' activity." Other considerations involve the description of victims:

  • Location: Are they near a conflict zone, or "far from where the war is taking place"?
  • Do they have military affiliations?

Marsh believes that in the NotPetya incident, victims were far removed from any war scenario. If insurers are inclined to invoke war exclusions, Marsh recommends they reform the clause to clearly specify its applicability. However, as cyber attacks and the malicious actors behind them mature, this provides an opportunity for businesses and insurers to raise standards. "Businesses concerned about cyber terrorism risk should consider standalone cyber insurance policies," Chia said. Zurich offers cyber-specific coverage and "has paid significant NotPetya-related losses under such policies." According to Chia, "These policies contain war exclusions but include a cyber terrorism exception." Zurich's cyber policies cover cyber terrorism, including "any attack or threat against the insured's network security by any individual, group, or government." In other words, the "war or civil commotion exclusion" in Zurich's cyber policies does not apply to cyber terrorism. In the Mondelez case, "the hostile and warlike acts exclusion in the property policy... generally does not provide an exception for losses caused by cyber attacks that have penetrated the insured's network security," according to information provided by Zurich. Mondelez did not respond to a request for comment by press time.

Security considerations

Unlike auto insurance (where insurers replace damaged vehicles), cyber insurance cannot cover damaged intellectual property. Kennedy's former employer held $116 billion in public client assets. "You can't replace those," he said. The data the company possessed gave it the power to "beat the market," making it an asset that cannot be fully insured. The responsibility for deciding on plans—though influenced by risk management and other departments—often falls on the chief security officer. Risk management will brief security leaders on the mathematical impact and consequences of incidents. According to Marsh's research, chief financial officers (another pillar of risk management) may ask questions similar to those of CISOs. Security organizations must answer the following questions:

  • Where could things go wrong?
  • What protections are already in place?
  • If something goes wrong, what will the security organization do?
  • How will the security organization and insurer collaborate on recovery?

As a CISO, "you need to make sure you have adequate coverage and there are no 'traps' in the contract," Kennedy said, though he would prefer businesses invest more in cybersecurity first, relegating insurance "to a smaller corner of need."

The role of insurers in incident response

Businesses don't have to jump through hoops to obtain cyber insurance. Felicia Thorpe, assistant vice president at AHT Insurance, told CIO Dive that the bar for obtaining coverage is typically low. The quantitative risk assessments most entities conduct "far exceed" what most insurers require. "Think about it: if you're the first to enter the market saying 'we require X, Y, Z to provide coverage,' you make it harder to do business with clients," she said. Insurers are more likely to view the carrier market as a whole and set standards collectively. But even so, carrier influence is common, whether influencing other carriers or policyholders.

Ray said victims may view paying ransoms as the default option for insurers. "The decision to pay or not becomes the insurer's option, based solely on claims of urgency or the advice of independent incident response experts." Insurers are reassuring clients in multiple ways, such as coverage grants that extend coverage to more specific areas. Thorpe said this may be due to increased demand for cyber insurance. Ultimately, insurers will tighten their standards, holding clients more accountable for their own "cyber health"—echoing Kennedy's emphasis on cybersecurity.

Even now, insurers are typically not the primary advisors victims seek for response advice after a cyber incident. Insurers that step in immediately after a cyber incident typically provide forensic vendors to diagnose the severity of the incident. "The forensic vendor works for the insured, and the relationship is there," McCabe said, and that vendor likely has experience with the malicious actors behind the incident. That experience can inform victims whether malicious actors keep their promises and restore functionality after a ransom is paid. Victim entities also consult legal counsel to answer key questions:

  • What does this mean for my reputation?
  • What mandatory requirements need to be fulfilled?
  • Who do we need to notify?
  • If it's a municipality, what does this mean for taxpayers?

"I've never seen an insurer in the room saying you should do this," McCabe said. Ultimately, insurers have their own businesses to run just like clients. Mutual understanding of how both sides operate will eliminate skepticism toward the insurance industry. Businesses know cyber insurers have paid claims. "I think the product has performed as intended, and carriers have done well. I just wish they'd get more credit for it," McCabe said.