Sponsored Content by Nationwide

Cyber Risk Is Evolving. How Will Coverage Keep Pace?

As the cyber risk evolution continues, coverage gaps will only grow without innovative solutions.
By: | May 2, 2018 • 6 min read

Cyber risk is never the same two days in a row.

Interconnected technology, sophisticated hackers and the speed of new attacks make cyber security an ongoing and exhausting challenge. The various types of breaches — denial of service, ransomware, social engineering and outright theft of private data, among others — infiltrate systems in different ways and make it difficult for risk managers to determine whether or where they have coverage.

Traditional cyber policies primarily cover network security and privacy breaches. After a handful of high-profile security incidences, many companies have grown familiar with the consequences of such a breach, including notification, forensic investigation, credit monitoring and system security enhancement expenses.

“Cyber risk is evolving so quickly that it’s difficult to adjust and build new solutions to keep pace,” said Tim Nunziata, director and division head of Commercial E&O/Cyber, Management Liability and Specialty at Nationwide. “We are often still resolving issues from a previous attack, implementing security patches and shoring up vulnerabilities, while bad actors are already on to something new. As cyber threats take on new forms, companies may find themselves bearing related expenses not covered under any of their insurance policies.”

Addressing coverage gaps will take a concerted effort to improve network defenses, broaden cyber policies and better align them with other products.

“We are now seeing a more organized approach to cyber risk to address all potential causes of system failure,” Nunziata said.

Evolving Risks Create Coverage Gaps

Tim Nunziata, Director and Division Head of Commercial E&O/Cyber, Management Liability and Specialty

Exposures now include other forms of technology failure that could incur business interruption and property losses not typically covered by stand-alone cyber policies. Overlap with other policies or the presence of “silent” cyber coverage (non-traditional sources of cyber exposure coverage found in property and liability insurance policies by virtue of policy wording not implicitly including or excluding cyber risks) may yield some indemnification, but gaps and gray areas abound.

System failure can come in many forms and result in varied consequences depending on the type of business. Global attacks like WannaCry and NotPetya may grab headlines, but a far more common — and commonly overlooked — cyber threat is accidental system failure triggered by a negligent employee.

“I’m talking about the worker who trips over a cord in the hallway, accidentally unplugs something, or pushes the wrong button and inadvertently shuts the whole network down,” Nunziata said. “If the problem is not identified and resolved quickly, there will be a business interruption impact and it could affect the business of third parties as well.”

A typical cyber policy may respond if the incident potentially exposes confidential information, but it may not pick up extra expenses associated with business interruption. An E&O policy, however, could potentially respond if it includes coverage for employee negligence.

Similar overlaps occur between cyber and crime policies in the case of social engineering scams, which involve no network breach but amount to a theft via network channels.

“If there has been no unauthorized access to your system and an employee is tricked into willingly transferring funds, that may not be a cyber claim,” Nunziata said. “But a crime or a professional liability policy could come into play.”

Interplay between cyber and physical property exposures presents similar challenges.

“If a refrigerated truck is carrying a load of produce and someone hacks into the main system and raises the temperature in the truck by five degrees, causing everything to spoil, is that a property claim or a cyber claim?” Nunziata said. “There are many areas where overlap with other exposures creates risks that are not covered by a standard cyber policy.”

As the risk continues to evolve, coverage gaps will only grow without innovative solutions. Two coverage strategies are emerging as options to bridge those gaps.

Extending Coverage Up and Out to Fill the Gaps

Broadening language in existing cyber policies can bring business interruption and other expenses related to system failure — regardless of the cause — under the umbrella of affirmative cyber insurance. In other words, the focus is on building up the cyber vertical, rather than spreading it outward.

“Existing cyber products can be extended or amended to include those E&O exposures, broader system failure, business interruption, contingent business interruption,” Nunziata said. “These will become standard extensions on many network security and privacy policies over the next few years.”

But as cyber risk seeps into every facet of a business’s operations and overlaps with more traditional property/casualty exposures, the most robust defense may be tacking affirmative cyber coverage onto those traditional policies.

“Cyber coverage is its own vertical, but the market is starting to realize that coverage can also potentially run horizontally throughout,” Nunziata said. “In the past we were trying to find answers within the cyber policy, but I think the answer is going to be pushing cyber extensions into other property/casualty coverages. That presents the best way to underwrite specifically to the wide varying types of cyber risks, charge appropriate premium and clarify language, so there are better opportunities to seal gaps and eliminate overlaps.”

Cyber endorsements and insuring agreements could introduce affirmative cyber coverage to professional liability, property, crime and even personal lines policies. This would go a long way towards reducing the guesswork around the root cause of a system failure and how to classify the resulting losses for coverage purposes.

Those other products, however, have the benefit of multi-decade claims histories and court precedents that have helped to standardize language, or at least create precedent regarding, contract interpretation.

This is where the enforcement of new data protection and network security standards may help.

New rules, including Europe’s General Data Protection Regulation (“GDPR”) and the New York Department of Financial Services’ cybersecurity regulations, represent a first step toward a more holistic approach to combatting cyber risk, as they will aid organizations and insurers in gathering information around cyber incidents consistently and on a broader scale. They will also raise risk management standards and hold companies accountable for protecting their networks and data.

“These regulations will require clients to be prepared, and the first step of preparation is gathering information. The more information we can collect, the better products we can build,” Nunziata said.

A Long-Term Approach Built to Evolve with the Risk

No matter how ironclad a company’s network defenses may be and no matter how well-versed they are in breach response, the ever-evolving nature of the risk means a debilitating cyber incident is not a question of if, but when. Even the best risk management cannot supply clear, comprehensive coverage.

“Despite this fact, overcoming a cyber breach is possible,” said Nunziata. “There are solutions, and we work with clients to craft what they need.”

“Our cyber underwriters are partnering with other divisions within Nationwide to push affirmative coverage out to more traditional commercial policies, leveraging our multiline expertise across products. We’re looking to build out existing products through innovative structures, endorsements and new insuring agreements.”

A strategy of gradual and consistent growth within the cyber market has enabled the carrier to closely track and respond to evolving exposure thoughtfully, without rapidly raising rates or tightening terms and conditions.

“We’re going to dictate our strategy around the problem. We’ve seen markets come and go over the last five or six years, but our approach has not changed. It’s expanded and grown, but it’s been consistent,” Nunziata said.

To learn about Nationwide’s Cyber and Professional Liability services visit https://mls.nationwideexcessandsurplus.com/fs/products/cyber-and-professional-liability/ or contact Tim Nunziata, director, at 212-329-6915 or [email protected].

Speak with your agent about specific policy details and coverages. Consult your policy’s terms and conditions for specific coverage information.

 SponsoredContent

BrandStudioLogo

This article was produced by the R&I Brand Studio, a unit of the advertising department of Risk & Insurance, in collaboration with Nationwide. The editorial staff of Risk & Insurance had no role in its preparation.




Nationwide, a Fortune 100 company, is one of the largest and strongest diversified insurance and financial services organizations in the U.S. and is rated A+ by both A.M. Best and Standard & Poor’s.

The Profession

For This Pharmaceutical Risk Director, Managing Risk Means Being Part of the Mission to Save Lives

Meet Eric Dobkin, director, insurance and risk management, for Merck & Co. Inc.
By: | September 28, 2018 • 5 min read

R&I: What was your first job?
My first job out of undergrad was as an actuarial trainee at Chubb.I was a math major in school, and I think the options for a math major coming out are either a teacher or an actuary, right? Anyway, I was really happy when the opportunity at Chubb presented itself. Fantastic company. I learned a lot there.

R&I: How did you come to work in risk management?
After I went back to get my MBA, I decided I wanted to work in corporate finance. When I was interviewing, one of the opportunities was with Merck. I really liked their mission, and things worked out. Given my background, they thought a good starting job would be in Merck’s risk management group. I started there, rotated through other areas within Merck finance but ultimately came back to the Insurance & Risk Management group. I guess I’m just one of those people who enjoy this type of work.

Advertisement




R&I: What is risk management doing right?
I think the community is doing a good job of promoting education, sharing ideas and advancing knowledge. Opportunities like this help make us all better business partners. We can take these ideas and translate them into actionable solutions to help our companies.

R&I: What could the risk management community be doing a better job of?
I think we have made good advancements in articulating the value proposition of investing in risk management, but much more can be done. Sometimes there is such a focus on delivering immediate value, such as cost savings, that risk management does not get appropriate attention (until something happens). We need to develop better tools that can reinforce that risk management is value-creating and good for operational efficiency, customers and shareholders.

R&I: What’s been the biggest change in the risk management and insurance industry since you’ve been in it?
I’d actually say there hasn’t been as much change as I would have hoped. I think the industry speaks about innovation more often than it does it. To be fair, at Merck we do have key partners that are innovators, but some in the industry are less enthusiastic to consider new approaches. I think there is a real need to find new and relevant solutions for large, complex risks.

R&I: What emerging commercial risk most concerns you?
Cyber risk. While it’s not emerging anymore, it’s evolving, dynamic and deserves the attention it gets. Merck was an early adopter of risk transfer solutions for cyber risk, and we continue to see insurance as an important component of the overall cyber risk management framework. From my perspective, this risk, more than any other, demands continuous forward-thinking to ensure we evolve solutions.

R&I: What’s the biggest challenge you’ve faced in your career?
Sticking with the cyber theme, I’d say navigating through a cyber incident is right up there. In June 2017, Merck experienced a network cyber attack that led to a disruption of its worldwide operations, including manufacturing, research and sales. It was a very challenging environment. And managing the insurance claim that resulted has been extremely complex. But at the same time, I have learned a tremendous amount in terms of how to think about the risk, enterprise resiliency and how to manage through a cyber incident.

R&I: What advice might you give to students or other aspiring risk managers?
Have strong intellectual curiosity. Always be willing to listen and learn. Ask “why?” We deal with a lot of ambiguity in our business, and the more you seek to understand, the better you will be able to apply those learnings toward developing solutions that meet the evolving risk landscape and needs of the business.

Advertisement




R&I: What role does technology play in your company’s approach to risk management?
We’re continuing to look for ways to apply technology. For example, being able to extract and leverage data that resides in our systems to evaluate risk, drive efficiencies and make things like property-value reporting easier. We’re also looking to utilize data visualization tools to help gain insights into our risks.

R&I: What are your goals for the next five to 10 years of your career?
I think, at this time, I would like to continue to learn and grow in the type of work I do and broaden my scope of responsibilities. There are many opportunities to deliver value. I want to continue to focus on becoming a stronger business partner and help enable growth.

R&I: What is your favorite book or movie?
I’d say right now Star Wars is top on my list. It has been magical re-watching and re-living the series I watched as a kid through the eyes of my children.

R&I: What is the riskiest activity you ever engaged in? When I was about 15, I went to a New York Rangers versus Philadelphia Flyers game at the Philadelphia Spectrum. I wore my Rangers jersey. I would not do that again.

Eric Dobkin, director, insurance & risk management, Merck & Co. Inc

R&I: What is it about this work you find most fulfilling or rewarding?
I am passionate about Merck’s mission of saving and improving lives. “Inventing for Life” is Merck’s tagline. It’s funny, but most people don’t associate “inventing” with medicine. But Merck has been inventing medicines and vaccines for many of the world’s most challenging diseases for a long time. It’s amazing to think the products we make can help people fight terrible diseases like cancer. Whatever little bit I can do to help advance that mission is very fulfilling and rewarding.

R&I: What do your friends and family think you do?
Ha! My kids think I make medicine. I guess they think that because I work for Merck. I suppose if even in a small way I can contribute to Merck’s mission of saving and improving lives, I am good with that. &




Katie Dwyer is an associate editor at Risk & Insurance®. She can be reached at [email protected]