Report Helps Gov Agencies Analyze ROI of Cyber Defenses/Insurance 

“Officials can look at the probabilities of attacks succeeding and probabilities that these result in different depths of financial losses. Then officials can factor in how adopting different preventive measures might draw down those costs. This lets officials estimate how much investing in a better backup system or in anti-phishing training, for example, might reduce … Read more

Feds Discourage Cyber Insurance — at Least for Ransomware (Congressional Testimony)

LIkely a confusing and counter-productive take, in our opinion. DHS is now, in effect, raising questions about whether businesses should get cyber insurance. Or is the agency implying businesses self-insure against ransomware but obtain coverage for other cyber risks? Government will not be the primary driver of improved cyber security. As with fire safety, loss … Read more

Who’s a “Radioactive” Customer for Cyber Insurers? Law Firms 

“Law firms have this treasure trove of information. Statistically, they’re about six times more likely to pay the first ransom demanded, rather than negotiate it…and I have to tell them, months in advance of their renewal, that their premium is going to shoot up. I had one law firm client whose premium went from about … Read more

Underwriting Performance for US Cyber Insurance Improved Last Year: Reinsurance News

Standalone cyber policies now the majority… “Standalone policies are more often subject to claims, given that more-sophisticated clients with more data and financial resources typically purchase these policies.  Despite the ongoing growth in cyber claims in 2021, cyber insurers’ underwriting performance still improved, as evidenced by an estimated combined ratio of 91.8 in 2021, although … Read more

GAO Prods Feds to Assess Their Potential Response to Catastrophic Cyber Attacks 

According to the report, US FIO and CISA agree with this recommendation: “The Department of the Treasury’s Federal Insurance Office (FIO) and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) both have taken steps to understand the financial implications of growing cybersecurity risks. However, they have not assessed the extent to which … Read more

×