It seems that hardly a week goes by without some report of a cyber-attack or breach being reported in the media. These are usually only the high profile cases that we hear of too.
Businesses are facing threats such as extortion, electronic compromise or social engineering attacks to name but a few. And a huge 89% of businesses are potentially unprotected against cyber-attacks.2
Robert Morris, Account Director at Marsh Commercial, explores the history of cyber insurance. He also provides expert insight into whether your current cover may be leaving your business exposed.
When a cyber event occurs, businesses without a bespoke policy may seek to determine whether any of their traditional insurance policies offer coverage.
Many traditional insurance policies have attempted to address cyber risks, including:
Various “cyber bolt-on” covers have been added to these policies as well. This, along with the lack of any specific cyber exclusion clauses has raised false expectations that some coverage may apply.
However, often traditional policies will not specifically refer to cyber and insurers could theoretically refuse to pay claims for cyber losses in certain circumstances. If you have not already done so, 2021 should be the year that you seriously consider investing in a specialist standalone cyber insurance policy. If you’re worried about your current cyber liability insurance coverage contact your insurance broker.
Today, there are many insurance companies offering bespoke cyber insurance policies. The coverage under the policies does of course vary per provider but in general terms the policies are there to protect businesses against the:
The main 1st party cyber covers provided under a policy are:
Cyber insurance cannot and should not be seen as a replacement for a properly developed cyber security program. While a cyber liability insurance policy will serve you best in dealing with the many cyber exposures that exist today and in the future. It should complement your own cyber security efforts. Consider:
Run phishing email campaigns to help employees recognise phishing attacks.
Any remote connection to the network or business applications, require a password as well as a second factor – typically a security code. This makes it more difficult for attackers to gain unauthorised access.
Close down RDPs, or if that’s not possible, enable multi-factor authentication on the port. Change the RDP from the default port and use a strong password.
Identifying flaws before an attacker can find them is critical. Remember, if you’re unsure about the level of cyber cover in your current insurance programme, contact your insurance broker. If you wish to discuss any of the points raised in this article, be sure to contact Robert.
Sources
1. gov.uk/cyber-security-breaches-survey-2021
2. abi.org.uk/cyber-insurance-payout-rates-at-99-but-uptake-still-far-too-low