Cyber Insurance Transferred the Risk. You Still Own the Responsibility.
Cyber Insurance Transferred the Risk. You Still Own the Responsibility.
Congratulations, you bought cyber insurance for your business. You transferred the risk. You did not transfer the responsibility.
The Real Cost Gap: What Insurance Doesn't Cover
The latest data indicates that for small and mid-sized organizations, insurance payouts cover 67% of the total cybersecurity incident cost on average. That means that even when a claim is paid, roughly a third of the cost typically lands on your organization anyway. The small and mid-sized business total incident cost averages around $566,000. That's a real number. A third of that is a real number.
- 63% of incidents exceeded the insured's policy limit.
- 58% had costs the insurer did not pay because the insured did not get approval first.
- 45% had cost categories that the policy did not cover.
(sources: NetDiligence/Sophos)
But What If the Insurance Company Decided Not to Honor Your Claim?
When CyberCloak.Tech performs risk analysis for companies, we review their insurance, especially insurance pertaining to cybersecurity and the specific risk an organization has. Having insurance that covers cyber incidents is an established part of many cyber risk mitigation strategies. However, I think a lot of companies say, "Hey I bought cyber insurance, so I'm covered if I get hit," and this perhaps gives them a sense of being covered. It is kind of the purpose of insurance, right? I've transferred my risk. I'm okay. I should be covered, which is true if you are doing your part too.
Your Responsibility as the Insured
Most insurance agreements require some skin in the game from the insured for a claim to pay. What do you need to know and be responsible for as an insured or even uninsured business?
Due Diligence: The Protocols Insurers Expect
Insurers typically require the insured to do due diligence to prevent and mitigate loss, and it includes, but is not limited to, complying with and requiring your vendors to comply with reasonable and industry-accepted protocols.
These protocols often include
- providing and maintaining appropriate physical security for your premises, computer systems, and hard copy files,
- along with appropriate computer and internet security,
- and maintaining and updating appropriate interval backups of computer data, among other things.
For some policies this set of requirements can get very specific and if not followed be a reason to deny your claim or rescind a policy.
Regulated Industries Raise the Bar
It is key to note that industry-accepted protocols become a whole different term when you're in a regulated industry such as healthcare. Do you have to apply the HIPAA Security Rule or in retail, the PCI DSS compliance set? Hint, yes.
The MFA Attestation Trap
Real trouble hits when you claim (by checking a box on your application or renewal) that you're using MFA on all systems where it is available to be used. Breach happens. Imagine if it turns out you really didn't fully have MFA rolled out and then you try to file a claim, but it is denied or worse. In the 2022 Travelers v. International Control Services case, the insurer moved to rescind the policy after it found the company attested MFA was deployed across all systems when it was only partly implemented. The court sided with the insurer.
Know Your Gaps Before Your Insurer Does
Do you know your gaps? What is and is not fully implemented and do you have the plan to fix the gaps?
While not having enough insurance or having the wrong insurance is impactful, consider if you have implemented reasonable and appropriate security controls and performed due diligence. Doing this usually prevents you from having to make a claim. But no system is totally safe.
Typically, an insurer finds your gaps after the incident. We would rather you find them now. The CyberCloak.Tech Security Pulse is 12 questions, in a 25-minute conversation, no cost, no obligation designed to identify the gaps like if MFA is up and running where you need it. Best part, You get an executive risk snapshot that shows where you stand.