2222222222

Risk Focus: Cyber

Expanding Cyber BI

Cyber business interruption insurance is a thriving market, but growth carries the threat of a mega-loss. 
By: | March 5, 2018 • 7 min read

Lingering hopes that large-scale cyber attack might be a once-in-a-lifetime event were dashed last year. The four-day WannaCry ransomware strike in May across 150 countries targeted more than 300,000 computers running Microsoft Windows. A month later, NotPetya hit multinationals ranging from Danish shipping firm Maersk to pharmaceutical giant Merck.

Advertisement




Maersk’s chairman, Jim Hagemann Snabe, revealed at this year’s Davos summit that NotPetya shut down most of the group’s network. While it was replacing 45,000 PCs and 4,000 servers, freight transactions had to be completed manually. The combined cost of business interruption and rebuilding the system was up to $300 million.

Merck’s CFO Robert Davis told investors that its NotPetya bill included $135 million in lost sales plus $175 million in additional costs. Fellow victims FedEx and French construction group Saint Gobain reported similar financial hits from lost business and clean-up costs.

The fast-expanding world of cryptocurrencies is also increasingly targeted. Echoes of the 2014 hack that triggered the collapse of Bitcoin exchange Mt. Gox emerged this January when Japanese cryptocurrency exchange Coincheck pledged to repay customers $500 million stolen by hackers in a cyber heist.

The size and scope of last summer’s attacks accelerated discussions on both sides of the Atlantic, between risk managers and brokers seeking more comprehensive cyber business interruption insurance products.

It also recently persuaded Pool Re, the UK’s terrorism reinsurance pool set up 25 years ago after bomb attacks in London’s financial quarter, to announce that from April its cover will extend to include material damage and direct BI resulting from acts of terrorism using a cyber trigger.

“The threat from a cyber attack is evident, and businesses have become increasingly concerned about the extensive repercussions these types of attacks could have on them,” said Pool Re’s chief, Julian Enoizi. “This was a clear gap in our coverage which left businesses potentially exposed.”

Shifting Focus

Development of cyber BI insurance to date reveals something of a transatlantic divide, said Hans Allnutt, head of cyber and data risk at international law firm DAC Beachcroft. The first U.S. mainstream cyber insurance products were a response to California’s data security and breach notification legislation in 2003.

Jimaan Sané, technology underwriter, Beazley

Of more recent vintage, Europe’s first cyber policies’ wordings initially reflected U.S. wordings, with the focus on data breaches. “So underwriters had to innovate and push hard on other areas of cyber cover, particularly BI and cyber crimes such as ransomware demands and distributed denial of service attacks,” said Allnut.

“Europe now has regulation coming up this May in the form of the General Data Protection Regulation across the EU, so the focus has essentially come full circle.”

Cyber insurance policies also provide a degree of cover for BI resulting from one of three main triggers, said Jimaan Sané, technology underwriter for specialist insurer Beazley. “First is the malicious-type trigger, where the system goes down or an outage results directly from a hack.

“Second is any incident involving negligence — the so-called ‘fat finger’ — where human or operational error causes a loss or there has been failure to upgrade or maintain the system. Third is any broader unplanned outage that hits either the company or anyone on which it relies, such as a service provider.”

The importance of cyber BI covering negligent acts in addition to phishing and social engineering attacks was underlined by last May’s IT meltdown suffered by airline BA.

This was triggered by a technician who switched off and then reconnected the power supply to BA’s data center, physically damaging servers and distribution panels.

Compensating delayed passengers cost the company around $80 million, although the bill fell short of the $461 million operational error loss suffered by Knight Capital in 2012, which pushed it close to bankruptcy and decimated its share price.

Mistaken Assumption

Awareness of potentially huge BI losses resulting from cyber attack was heightened by well-publicized hacks suffered by retailers such as Target and Home Depot in late 2013 and 2014, said Matt Kletzli, SVP and head of management liability at Victor O. Schinnerer & Company.

Advertisement




However, the incidents didn’t initially alarm smaller, less high-profile businesses, which assumed they wouldn’t be similarly targeted.

“But perpetrators employing bots and ransomware set out to expose any firms with weaknesses in their system,” he added.

“Suddenly, smaller firms found that even when they weren’t themselves targeted, many of those around them had fallen victim to attacks. Awareness started to lift, as the focus moved from large, headline-grabbing attacks to more everyday incidents.”

Publications such as the Director’s Handbook of Cyber-Risk Oversight, issued by the National Association of Corporate Directors and the Internet Security Alliance fixed the issue firmly on boardroom agendas.

“What’s possibly of greater concern is the sheer number of different businesses that can be affected by a single cyber attack and the cost of getting them up and running again quickly.” — Jimaan Sané, technology underwriter, Beazley

Reformed ex-hackers were recruited to offer board members their insights into the most vulnerable points across the company’s systems — in much the same way as forger-turned-security-expert Frank Abagnale Jr., subject of the Spielberg biopic “Catch Me If You Can.”

There also has been an increasing focus on systemic risk related to cyber attacks. Allnutt cites “Business Blackout,” a July 2015 study by Lloyd’s of London and the Cambridge University’s Centre for Risk Studies.

This detailed analysis of what could result from a major cyber attack on America’s power grid predicted a cost to the U.S. economy of hundreds of billions and claims to the insurance industry totalling upwards of $21.4 billion.

Lloyd’s described the scenario as both “technologically possible” and “improbable.” Three years on, however, it appears less fanciful.

In January, the head of the UK’s National Cyber Security Centre, Ciaran Martin, said the UK had been fortunate in so far averting a ‘category one’ attack. A C1 would shut down the financial services sector on which the country relies heavily and other vital infrastructure. It was a case of “when, not if” such an assault would be launched, he warned.

AI: Friend or Foe?

Despite daunting potential financial losses, pioneers of cyber BI insurance such as Beazley, Zurich, AIG and Chubb now see new competitors in the market. Capacity is growing steadily, said Allnutt.

“Not only is cyber insurance a new product, it also offers a new source of premium revenue so there is considerable appetite for taking it on,” he added. “However, whilst most insurers are comfortable with the liability aspects of cyber risk; not all insurers are covering loss of income.”

Matt Kletzli, SVP and head of management liability, Victor O. Schinnerer & Company

Kletzli added that available products include several well-written, broad cyber coverages that take into account all types of potential cyber attack and don’t attempt to limit cover by applying a narrow definition of BI loss.

“It’s a rapidly-evolving coverage — and needs to be — in order to keep up with changing circumstances,” he said.

The good news, according to a Fitch report, is that the cyber loss ratio has been reduced to 45 percent as more companies buy cover and the market continues to expand, bringing down the size of the average loss.

“The bad news is that at cyber events, talk is regularly turning to ‘what will be the Hurricane Katrina-type event’ for the cyber market?” said Kletzli.

“What’s worse is that with hurricane losses, underwriters know which regions are most at risk, whereas cyber is a global risk and insurers potentially face huge aggregation.”

Advertisement




Nor is the advent of robotics and artificial intelligence (AI) necessarily cause for optimism. As Allnutt noted, while AI can potentially be used to decode malware, by the same token sophisticated criminals can employ it to develop new malware and escalate the ‘computer versus computer’ battle.

“The trend towards greater automation of business means that we can expect more incidents involving loss of income,” said Sané. “What’s possibly of greater concern is the sheer number of different businesses that can be affected by a single cyber attack and the cost of getting them up and running again quickly.

“We’re likely to see a growing number of attacks where the aim is to cause disruption, rather than demand a ransom.

“The paradox of cyber BI is that the more sophisticated your organization and the more it embraces automation, the bigger the potential impact when an outage does occur. Those old-fashioned businesses still reliant on traditional processes generally aren’t affected as much and incur smaller losses.” &

Graham Buck is a UK-based writer and has contributed to Risk & Insurance® since 1998. He can be reached at riskletters.com.

More from Risk & Insurance

More from Risk & Insurance

Insurtech

Kiss Your Annual Renewal Goodbye; On-Demand Insurance Challenges the Traditional Policy

Gig workers' unique insurance needs drive delivery of on-demand coverage.
By: | September 14, 2018 • 6 min read

The gig economy is growing. Nearly six million Americans, or 3.8 percent of the U.S. workforce, now have “contingent” work arrangements, with a further 10.6 million in categories such as independent contractors, on-call workers or temporary help agency staff and for-contract firms, often with well-known names such as Uber, Lyft and Airbnb.

Scott Walchek, founding chairman and CEO, Trōv

The number of Americans owning a drone is also increasing — one recent survey suggested as much as one in 12 of the population — sparking vigorous debate on how regulation should apply to where and when the devices operate.

Add to this other 21st century societal changes, such as consumers’ appetite for other electronic gadgets and the advent of autonomous vehicles. It’s clear that the cover offered by the annually renewable traditional insurance policy is often not fit for purpose. Helped by the sophistication of insurance technology, the response has been an expanding range of ‘on-demand’ covers.

The term ‘on-demand’ is open to various interpretations. For Scott Walchek, founding chairman and CEO of pioneering on-demand insurance platform Trōv, it’s about “giving people agency over the items they own and enabling them to turn on insurance cover whenever they want for whatever they want — often for just a single item.”

Advertisement




“On-demand represents a whole new behavior and attitude towards insurance, which for years has very much been a case of ‘get it and forget it,’ ” said Walchek.

Trōv’s mobile app enables users to insure just a single item, such as a laptop, whenever they wish and to also select the period of cover required. When ready to buy insurance, they then snap a picture of the sales receipt or product code of the item they want covered.

Welcoming Trōv: A New On-Demand Arrival

While Walchek, who set up Trōv in 2012, stressed it’s a technology company and not an insurance company, it has attracted industry giants such as AXA and Munich Re as partners. Trōv began the U.S. roll-out of its on-demand personal property products this summer by launching in Arizona, having already established itself in Australia and the United Kingdom.

“Australia and the UK were great testing grounds, thanks to their single regulatory authorities,” said Walchek. “Trōv is already approved in 45 states, and we expect to complete the process in all by November.

“On-demand products have a particular appeal to millennials who love the idea of having control via their smart devices and have embraced the concept of an unbundling of experiences: 75 percent of our users are in the 18 to 35 age group.” – Scott Walchek, founding chairman and CEO, Trōv

“On-demand products have a particular appeal to millennials who love the idea of having control via their smart devices and have embraced the concept of an unbundling of experiences: 75 percent of our users are in the 18 to 35 age group,” he added.

“But a mass of tectonic societal shifts is also impacting older generations — on-demand cover fits the new ways in which they work, particularly the ‘untethered’ who aren’t always in the same workplace or using the same device. So we see on-demand going into societal lifestyle changes.”

Wooing Baby Boomers

In addition to its backing for Trōv, across the Atlantic, AXA has partnered with Insurtech start-up By Miles, launching a pay-as-you-go car insurance policy in the UK. The product is promoted as low-cost car insurance for drivers who travel no more than 140 miles per week, or 7,000 miles annually.

“Due to the growing need for these products, companies such as Marmalade — cover for learner drivers — and Cuvva — cover for part-time drivers — have also increased in popularity, and we expect to see more enter the market in the near future,” said AXA UK’s head of telematics, Katy Simpson.

Simpson confirmed that the new products’ initial appeal is to younger motorists, who are more regular users of new technology, while older drivers are warier about sharing too much personal information. However, she expects this to change as on-demand products become more prevalent.

“Looking at mileage-based insurance, such as By Miles specifically, it’s actually older generations who are most likely to save money, as the use of their vehicles tends to decline. Our job is therefore to not only create more customer-centric products but also highlight their benefits to everyone.”

Another Insurtech ready to partner with long-established names is New York-based Slice Labs, which in the UK is working with Legal & General to enter the homeshare insurance market, recently announcing that XL Catlin will use its insurance cloud services platform to create the world’s first on-demand cyber insurance solution.

“For our cyber product, we were looking for a partner on the fintech side, which dovetailed perfectly with what Slice was trying to do,” said John Coletti, head of XL Catlin’s cyber insurance team.

“The premise of selling cyber insurance to small businesses needs a platform such as that provided by Slice — we can get to customers in a discrete, seamless manner, and the partnership offers potential to open up other products.”

Slice Labs’ CEO Tim Attia added: “You can roll up on-demand cover in many different areas, ranging from contract workers to vacation rentals.

“The next leap forward will be provided by the new economy, which will create a range of new risks for on-demand insurance to respond to. McKinsey forecasts that by 2025, ecosystems will account for 30 percent of global premium revenue.

Advertisement




“When you’re a start-up, you can innovate and question long-held assumptions, but you don’t have the scale that an insurer can provide,” said Attia. “Our platform works well in getting new products out to the market and is scalable.”

Slice Labs is now reviewing the emerging markets, which aren’t hampered by “old, outdated infrastructures,” and plans to test the water via a hackathon in southeast Asia.

Collaboration Vs Competition

Insurtech-insurer collaborations suggest that the industry noted the banking sector’s experience, which names the tech disruptors before deciding partnerships, made greater sense commercially.

“It’s an interesting correlation,” said Slice’s managing director for marketing, Emily Kosick.

“I believe the trend worth calling out is that the window for insurers to innovate is much shorter, thanks to the banking sector’s efforts to offer omni-channel banking, incorporating mobile devices and, more recently, intelligent assistants like Alexa for personal banking.

“Banks have bought into the value of these technology partnerships but had the benefit of consumer expectations changing slowly with them. This compares to insurers who are in an ever-increasing on-demand world where the risk is high for laggards to be left behind.”

As with fintechs in banking, Insurtechs initially focused on the retail segment, with 75 percent of business in personal lines and the remainder in the commercial segment.

“Banks have bought into the value of these technology partnerships but had the benefit of consumer expectations changing slowly with them. This compares to insurers who are in an ever-increasing on-demand world where the risk is high for laggards to be left behind.” — Emily Kosick, managing director, marketing, Slice

Those proportions may be set to change, with innovations such as digital commercial insurance brokerage Embroker’s recent launch of the first digital D&O liability insurance policy, designed for venture capital-backed tech start-ups and reinsured by Munich Re.

Embroker said coverage that formerly took weeks to obtain is now available instantly.

“We focus on three main issues in developing new digital business — what is the customer’s pain point, what is the expense ratio and does it lend itself to algorithmic underwriting?” said CEO Matt Miller. “Workers’ compensation is another obvious class of insurance that can benefit from this approach.”

Jason Griswold, co-founder and chief operating officer of Insurtech REIN, highlighted further opportunities: “I’d add a third category to personal and business lines and that’s business-to-business-to-consumer. It’s there we see the biggest opportunities for partnering with major ecosystems generating large numbers of insureds and also big volumes of data.”

For now, insurers are accommodating Insurtech disruption. Will that change?

Advertisement




“Insurtechs have focused on products that regulators can understand easily and for which there is clear existing legislation, with consumer protection and insurer solvency the two issues of paramount importance,” noted Shawn Hanson, litigation partner at law firm Akin Gump.

“In time, we could see the disruptors partner with reinsurers rather than primary carriers. Another possibility is the likes of Amazon, Alphabet, Facebook and Apple, with their massive balance sheets, deciding to link up with a reinsurer,” he said.

“You can imagine one of them finding a good Insurtech and buying it, much as Amazon’s purchase of Whole Foods gave it entry into the retail sector.” &

Graham Buck is a UK-based writer and has contributed to Risk & Insurance® since 1998. He can be reached at riskletters.com.