Cyber Liability Insurance: Are You Really Covered?

Ransomware attacks are fueling a surge in cyber liability insurance premiums, but having coverage doesn’t always mean you’re protected. Boards must ask: Who’s filling out your cyber insurance questionnaire? Inaccurate information can lead to denied claims when a breach occurs. Recent cases like Acer, JBS Foods, and T-Mobile reveal the growing risks. Boards must ensure cybersecurity practices align with insurance requirements to avoid costly coverage gaps.

As ransomware attacks and other cyber threats continue to evolve, the importance of cyber liability insurance for businesses has never been greater. With premiums rising due to the growing frequency of attacks, boards of directors need to be aware of both the financial implications and the potential risks associated with these policies.

Just like in the famous Progressive Insurance commercials—”Got to love bundling!”—many businesses are bundling their cyber liability coverage. But this can create complexities, especially when it comes to filling out the necessary policy forms. Let’s dive into the key points boards should consider regarding cyber liability insurance, the underwriting process, and the real-world challenges companies are facing when it comes to making claims.

The Rising Cost of Cyber Liability Insurance: A Ransomware Effect

Ransomware has had a dramatic impact on cyber insurance premiums, with attacks becoming more frequent and severe. The high-profile cases involving companies such as Acer and JBS Foods highlight the growing financial risks, leading to increased premiums for insurers.

In 2020, global computer hardware giant Acer was hit by a ransomware attack that demanded a hefty ransom. The company reportedly faced millions in losses, including ransom payments and recovery costs, prompting insurers to raise premiums for similar companies in the sector. This trend has only accelerated in the last few years, with insurers adjusting rates to compensate for the higher risk posed by cyber threats.

Similarly, JBS Foods, one of the largest meat processors in the world, experienced a major ransomware attack in 2021, forcing them to pay $11 million in ransom. This attack led to substantial disruptions in global food supply chains. As a result, companies in the food industry—and others—are facing much higher premiums for cyber liability coverage, as insurers adjust to the increased frequency and severity of such incidents.

Who’s Filling Out Your Cyber Insurance Questionnaire?

Now, here’s a critical question for your board:

Who is filling out your cyber insurance questionnaire?

Sounds simple, but this is one area where many boards make the mistake of assuming everything is covered—only to be blindsided when a breach happens. Think about it: you purchase cyber insurance to sleep easier at night, believing your company is protected. You might even feel secure with a bundled policy. But what if the information your team is submitting isn’t fully accurate?

Many companies trust their CFO or finance department to fill out these forms, but without the right cybersecurity expertise, how can they be sure that the information they’re providing is a true reflection of your company’s risk profile? If the answers to the questionnaire don’t accurately capture your company’s security posture, you could find yourself facing gaps in coverage when the worst happens.

In the case of T-Mobile, the company suffered a massive data breach in 2021, and although they had cyber liability insurance, they struggled to use it effectively. Why? Because their responses on the policy questionnaire didn’t fully reflect the cybersecurity measures in place—or more accurately, the lack of some measures. This led to delays in making a claim and an uphill battle when it came to receiving the financial protection they thought they had.

So, here’s the punchline:

Do you know if your company’s cyber insurance policy has any gaps?

Just because you have coverage doesn’t mean you have the right coverage. And that gap could be the difference between being covered and facing a financial nightmare when the inevitable breach happens.

Underwriting Practices: What’s at Stake?

Underwriting is central to determining both the premiums and coverage limits for cyber liability insurance. Insurers use the information provided in the questionnaire to assess the company’s risk profile. The more accurate the data, the better the insurer can set the appropriate premium and coverage.

However, inaccuracies in completing the questionnaire—whether intentional or accidental—can result in gaps in coverage. Ubiquiti Networks provides a notable example. In 2021, the company suffered a significant data breach, but their ability to claim under their cyber liability insurance was questioned due to inconsistencies in their reported security measures. The insurer argued that certain cyber protocols, such as multi-factor authentication, had not been implemented across all systems, even though Ubiquiti had indicated they were.

This highlights the importance for boards to ensure that cybersecurity practices are not only robust but accurately communicated during the underwriting process.

Can Companies Actually Use Their Cyber Liability Insurance After a Breach?

The real test of any insurance policy comes when it’s needed most—after a breach. But can companies actually rely on their cyber liability insurance when they suffer a breach? In some cases, the answer has been “no,” especially when companies fail to meet the conditions set by insurers.

In the case of LabCorp, a major medical testing company, it was revealed that their cyber liability insurer denied coverage after a breach in 2019. The company had failed to implement certain cybersecurity protocols, such as proper encryption of data, which ultimately led to a denial of their insurance claim. This case is a stark reminder that having insurance doesn’t automatically guarantee coverage if the company hasn’t taken the necessary steps to mitigate risk.

Boards must ensure that cybersecurity practices are robust enough to meet insurance requirements. Otherwise, they risk being left without financial protection when a breach occurs.

Transferring Risk with Cyber Liability Insurance: The Pros and Cons

Cyber liability insurance offers a way to transfer risk, but there are both advantages and disadvantages for boards to consider.

Pros:

  1. Financial Protection: Cyber liability insurance provides crucial financial protection against the high costs of a data breach, including ransom payments, legal fees, and recovery expenses.
  2. Reputation Management: Many policies include public relations coverage, helping businesses manage their reputation after an attack.
  3. Third-Party Coverage: Some policies provide third-party coverage, which is valuable if clients or partners are impacted by a breach.

Cons:

  1. Rising Premiums: As cyber threats evolve, so do the premiums. Companies that have suffered a breach may face much higher premiums, even if they’ve taken steps to mitigate future risks.
  2. Potential Gaps in Coverage: Inaccurate or incomplete answers on insurance questionnaires can leave companies exposed to certain risks, especially if the company’s cybersecurity measures do not meet the insurer’s standards.
  3. Exclusion Clauses: Many policies include exclusion clauses for certain types of breaches, leaving companies vulnerable to certain kinds of cyber incidents that are not covered.

Conclusion: What Boards Should Do Now

Cyber liability insurance is a vital tool for businesses, but it requires careful attention to detail. Boards should ensure that the company’s cybersecurity practices are aligned with the requirements outlined by insurers, and that the information submitted on policy questionnaires is accurate and comprehensive. Failure to do so could result in significant gaps in coverage, leaving the company exposed in the event of a cyberattack.

Looking at recent examples like Acer, JBS Foods, and T-Mobile, it’s clear that the risks are real—and they’re escalating. As cyber threats continue to grow in complexity and frequency, boards need to make informed decisions about how to transfer risk through insurance and ensure they have the coverage they need to protect the company.

RELATED POSTS

Discover more from Stasiak

Subscribe now to keep reading and get access to the full archive.

Continue reading

[mailpoet_form id="5"]
[mailpoet_form id="1"]