While 2016 may have been one of the worst years in history for network security, there is at least one silver lining for enterprise IT departments: insurance companies are becoming increasingly skilled at underwriting cybersecurity risks.
According to the Insurance Information Institute, more than 60 different insurance companies are now offering standalone cyber insurance policies, with an estimated U.S. market of more than $3.25 billion in gross written premiums this year.
That figure is the direct result of two related trends. First, data breaches are becoming more expensive for enterprises, with the average breach in 2016 costing $7 million and representing the third-costliest business risk this year. That increase has given rise to the second trend, which is that businesses are becoming much more concerned about protecting themselves against potential financial losses as the result of hacks that are becoming almost inevitable.
A New Challenge
Historically, the insurance industry has successfully managed to adapt to the risks posed by new technologies, including automotive and air travel tech. Nonetheless, insuring against data breaches and other attacks presents its own set of challenges and complications.
In particular, the constantly changing range of perpetrators, targets and exposure values, a lack of historical actuarial data and the interconnected nature of cyberspace, combine to make it difficult for insurers to assess the likely severity of future cyberattacks.
While most traditional commercial general liability policies do not cover cyber risks, standalone cyber insurance policies typically address a number of risks associated with data breaches or attacks.
About Time
Chief among these is liability insurance to help companies cover costs, such as legal fees and court judgments, that may be incurred following the theft of enterprises data and the unintentional transmission of a computer virus that causes financial harm to a third party.
Crisis management is another aspect of standalone…