Sep 4, 2018

The rise of cybersecurity insurance

Illustration: Sarah Grillo/Axios

All companies are potential victims of cyber attacks, and buying insurance is one way many are trying to manage that risk.

Why it matters: Companies hit by attacks are exposed to incredible costs — Equifax lost $4 billion in stock market value in just a week — so companies are increasingly looking beyond traditional safety nets to avoid financial ruin.

How it works: Firms interested in obtaining cybersecurity insurance can go through an intermediary firm that helps them assess their cyber risk with a score, similar to a credit score. Some firms work on behalf of insurers to assess risk in potential client companies.

  • Some of these firms simultaneously offer services to help mitigate companies’ risk or respond to cyber incidents.
  • The market is already seeing some coordination, like the jointly offered Allianz-Aon-Apple-Cisco cybersecurity insurance package that simultaneously assesses risk and offers insurance and incident response.
  • CyberCube CEO Pascal Millaire tells Axios his company thinks about pricing by multiplying frequency by severity. In other words, how often attacks can be expected in that industry, how often they are successful, and what the operational and financial impacts could be.

Where things get murky: The cybersecurity insurance marketplace is young and fragmented. Not all formulas for premiums are equal, and there’s no consensus in the market about how to price them.

  • The result: 26% of U.S. companies reported this year they don’t believe their cyber insurer priced their premium based on an accurate analysis of their risk, per a survey run by Ovum and commissioned by FICO.
  • That’s in part because actuarial data isn’t available yet, which results in a patchwork of assessments.
  • Pricing cyber insurance premiums can be even more challenging than underwriting other premiums because cyberattacks can happen at any time, regardless of geography or seasonality. And other disasters warranting insurance, like floods and fires, exhibit more predictable behavior than hackers.

There’s a reason traditional insurance is successful, Srinivas Mukkamala, CEO and Co-Founder of RiskSense, tells Axios: “They can put a model and put a number behind it.” For now, most pricing in cyber insurance inevitably lags behind cyberthreats.

The big picture: “The key is this isn’t just an IT thing, it’s not just a tech company thing. It’s everyone,” says Jason Hogg, Aon’s CEO of Cyber Solutions. As more internet-of-things devices come online, the attack surface will continue to grow, so the need for cybersecurity insurance will likely grow, too.

  • That goes for individuals as well. “If you look out 5, 10, 15 years, it’s hard to imagine any line of insurance not being impacted in some way, shape or form…by internet-connected risk,” Millaire said.
  • High net-worth individuals are already buying cybersecurity insurance from Aon, Hogg tells Axios.

What to watch: Some insurance providers, like cybersecurity insurance startup At-Bay, require companies to meet a baseline of security before even allowing them to purchase insurance. That could encourage better security practices to begin with.

  • Yes, but: Once companies reveal the security thresholds for companies, threat actors have a head start on exploiting them.

Go deeper

America's rundown roads add to farmers' struggles

Illustration: Sarah Grillo/Axios

American farmers are struggling to safely use the roads that cut through their fields; decades of neglect and lack of funding have made the routes dangerous.

The big picture: President Trump has long promised to invest billions in rural infrastructure, and his latest proposal would allocate $1 trillion for such projects. Rural America, where many of Trump's supporters live, would see a large chunk of that money.

South Korea and Italy see spikes in coronavirus cases

Data: The Center for Systems Science and Engineering at Johns Hopkins, the CDC, and China's Health Ministry. Note: China numbers are for the mainland only and U.S. numbers include repatriated citizens.

The novel coronavirus continues to spread to more nations, and the U.S. reports a doubling of its confirmed cases to 34 — while noting those are mostly due to repatriated citizens, emphasizing there's no "community spread" yet in the U.S. South Korea's confirmed cases jumped from 204 on Friday to 433 on Saturday, while Italy's case count rose from 3 to 62 as of Saturday.

The big picture: COVID-19 has now killed at least 2,362 people and infected more than 77,000 others, mostly in mainland China. New countries to announce infections recently include Israel, Lebanon and Iran.

Go deeperArrowUpdated 4 hours ago - Health

Centrist Democrats beseech 2020 candidates: "Stand up to Bernie" or Trump wins

Bernie Sanders rallies in Las Vegas, Nevada on Feb. 21. Photo: Mario Tama/Getty Images

Center-left think tank Third Way urgently called on the Democratic front-runners of the 2020 presidential election to challenge Sen. Bernie Sanders on the South Carolina debate stage on Feb. 25, in a memo provided to Axios' Mike Allen on Saturday.

What they're saying: "At the Las Vegas debate ... you declined to really challenge Senator Sanders. If you repeat this strategy at the South Carolina debate this week, you could hand the nomination to Sanders, likely dooming the Democratic Party — and the nation — to Trump and sweeping down-ballot Republican victories in November."