Burned by the high cost of claims in recent years, cyber insurers introduce more exclusions.
Protecting yourself from cybercrime is more important than ever. Take it from the FBI, which warned last year it had tracked losses from cyber fraud at $6.9 billion in 2021, up 64% from the year prior. Following proper security hygiene is step number one, but another important aspect is cyber insurance. Unfortunately, that’s getting a little more complicated. Here’s what’s changing in the cyber insurance market, and how to maximize the potential benefits of getting a policy, in 2023.
“I THINK THE BIGGEST THING TO UNDERSTAND IS BUYING
CYBER LIABILITY ERRORS AND OMISSIONS INSURANCE
[IS] NOT LIKE BUYING AUTO INSURANCE OR WORKERS
COMP. IT’S UNREGULATED…THE DEVIL IS IN THE DETAILS.”
Read the small print
Cyber insurance (which is also called cyber risk or cyber liability insurance) can help organizations reeling from the impact of an attack, breach, or other cyber incident cover the costs of a prompt response. Some cyber insurers go one step further, helping organizations arrange an array of covered services so that responders can get rolling before costs mount.
It’s not just organizations that run their own systems and networks that need insurance—managed services providers (MSPs) and managed security services providers (MSSPs) also need their own plans for incidents involving clients. Regardless of who’s buying, cyber insurance packages vary significantly in what they cover and when, depending on the provider and the exact language of the contract. For example, MSPs/MSSPs may purchase errors and omissions coverage in addition to a standard cyber policy to limit liability if a client thinks the provider is responsible for a breach.
Cyber insurance can potentially cover everything from losses due to interruptions of business and the destruction of digital assets to recovery costs like data retrieval and theft or ransoms from various kinds of cybercrime. Justin Reinmuth, CEO and founder of Techrug, a company that specializes in policies for IT services firms, warned that buyers should look over policies carefully to determine the exact scope of coverage and be aware of exclusions.
“WE’VE SEEN EXAMPLES WHERE BREACHES HAVE TAKEN
PLACE AND THE DAMAGE GOES ON FOR 18 TO 24 OR MORE
MONTHS. THAT’S SORT OF NOT THE NORM IN INSURANCE.”
“I think the biggest thing to understand is buying cyber liability errors and omissions insurance [is] not like buying auto insurance or workers comp,” Reinmuth said. “It’s unregulated…the devil is in the details.”
Prepare for sticker shock
Premiums for cyber insurance skyrocketed last year. Professional services firm Marsh & McLennan estimated premiums were up 79% in Q2 2022 from the year prior, after more than doubling in each of the prior two quarters.
