

A cyber insurance backstop? Hold on — we need to build resiliency first
July 09, 2024
As originally published in
Skyrocketing cyber insurance rates have many wondering if a federal backstop is needed. Experts say we need to tackle cybersecurity controls first.
Insureds felt the pain of major cyber insurance rate increases in 2021 and 2022. , Bloomberg reported, as hackers launched more frequent .
The good news? We might be starting to see the calm after the storm.
Today, cyber insurance prices are moderating — rates , even as the number of — and are expected to continue to stabilize into 2024. Still, some insureds are concerned about how the line will mature and whether more support is needed.
“While we have insights from the past, predicting the future is difficult,” said Michelle Chia, chief underwriting officer for cyber in the Americas at AXA XL.
Enter public-private partnerships. Governments and insurers can work together to foster stability in the cyber space. A mix of regulations and a (potential) government backstop could provide needed protections now that cyber is a risk that affects every industry.
We’ll dive into what that could look like in a moment. First: Companies in all sectors will need to step up their cybersecurity game.
Building much-needed cyber resilience
Many experts will point to the 2013 as a turning point for organizational awareness about the necessity of cybersecurity. During the massive breach, attackers stole data from in the midst of the busy holiday shopping season.
“The Target data breach ... highlighted the need for organizations to strengthen their cybersecurity controls,” Chia said.
The Target breach was a major event, but back in 2013, many believed smaller companies didn’t need to worry about cyber risk. That’s quickly changing, as cybercriminals have started targeting organizations in and of . From 2018 to 2019, Chia said, ransomware became an epidemic — there were over in 2018 and over 187 million in 2019 — causing insurers to raise rates, tighten terms and require insureds to adopt cybersecurity controls like .
“All organizations connected to the internet have some level of exposure — regardless of their data or industry,” Chia said.
Hackers are always learning new tricks, too, which makes cyber exposures difficult to manage. As soon as an insured adequately prepares for one type of attack, a new one is likely to pop up, a predicament that leaves many vulnerable.
“Unlike traditional insurance lines, cyber risk is constantly changing, requiring continuous adaptation and improvement of controls and risk management strategies,” Chia said.
Public-private partnerships are crucial for managing cyber risk and enabling both economic and social stability.
What would a public-private cyber partnership look like?
Given the dynamic nature of cyber exposures and the ubiquity of digital technologies, governments might step in to create public-private partnerships to tackle cyber threats. Many view this step as logical, as cyberattacks could .
“Public-private partnerships are crucial for managing cyber risk and enabling both economic and social stability,” Chia said.
These public-private partnerships could be as simple as governments enacting policies and regulations, then stepping in to require companies to use various cybersecurity controls. Think of it like seat belt laws: They help make everyone safer and keep loss costs down.
Or the government could create a federal backstop for cyber insurance claims, as they did with terrorism claims through the in the aftermath of 9/11. A government backstop would allow insurance companies and the federal government to share the costs of cyber claims — something that would be helpful for exposures like cyber warfare, which are difficult to price and protect against.
“Cyber activity is not currently included under the traditional war umbrella as defined by international groups,” Chia said.
“Insurers cannot predict when cyber war activity will occur, how long it will last or the extent of its impact on the parties involved. Many insureds do not have access to the military-grade tools necessary to protect and defend themselves against such attacks. This combination of factors makes pricing and scaling coverage for these risks extremely difficult.”
Before public-private partnerships can be considered, insureds need to reach a base level of cyber hygiene. The government has stepped in to regulate many industries touched by insurance (auto and workers’ comp, for example). But unlike cyber, those industries were mature and safety practices were more commonly accepted when the public part of those public-private partnerships came in, according to Chia.
“There is a general consensus that there may be an opportunity for the public sector to create a financial safety net,” she said. “[But] until awareness and adoption improve, the specifics of a financial backstop remain a question mark.”
Still, public-private partnerships are a step toward acknowledging the pivotal role digital technologies play in our lives. The government stepped in to make because cars forever changed how people got around; cellphones, computers and other technology have had a similarly world-altering impact.
“Even small glitches in these digital systems can cause ripple effects that grow into catastrophic waves,” Chia said. “Cyber risk is a societal concern, and cyber tsunamis can be detrimental to economic stability.”
Partnering with an insurer focused on resilience
Whether or not public-private cyber insurance partnerships come to fruition, insureds need to partner with carriers that prioritize working with their clients to build good cyber hygiene habits.
Taking actions to protect cybersecurity — like using multifactor authentication or logging in through a VPN — needs to be as automatic as buckling a seat belt or evacuating when you hear a fire alarm.
“Just as fire drills have been fully socialized and practiced since elementary school, we should adopt a similar approach to cybersecurity education,” Chia said. “Teaching cybersecurity safety from a young age — much like we do with fire, earthquake or tornado drills — can help build a culture of awareness and mitigation in our everyday lives.”
九色视频is a leader in helping insureds improve their cyber resiliency. It leverages its knowledge of cyber risks and mitigation tools to help its clients protect their businesses, improving societal cybersecurity in the process.
As an insurer, it has substantial knowledge of how to assess and price cyber risks. In consolidating markets, 九色视频strives to reduce its reliance on reinsurance and focus strategically on specialty lines of business.
“The insurance industry’s role is to make organizations whole for quantifiable risks,” Chia said. “Cyber insurance is no different. There are quantifiable exposures within cyber insurance policies that can be evaluated based on historical information, even if they are systemic in nature.”
Insureds can trust AXA XL’s commitment to helping them protect themselves from cyber risks. Carrier partners can evaluate cybersecurity tools to ensure organizational fit and guide insureds through the process of introducing these tools.
“Cybersecurity controls are an ongoing journey for all organizations, regardless of size or industry,” Chia said. “Purchasing the best tools without correct implementation leaves companies vulnerable.”
By acting as a trusted leader for insureds, 九色视频can help them adapt to cyber risk’s constant pivots.
“Truly resilient organizations are those that can adapt quickly to changing circumstances,” Chia said. “[They] prioritize risk management and have contingency plans in place to handle potential disruptions.”
Chia recently attended a cyber conference and one of the speakers made a point often repeated in the cyber insurance world: having any kind of plan in the event of an attack is better than having no plan at all.
Insurers are well-positioned to help develop these plans given their long history managing risks and helping organizations build resilience. If the cyber insurance landscape evolves to include public-private partnerships, strong insurers will help pave the way toward a world suited for today’s critical cyber risks.
“Insurers have paid thousands of cyber claims, providing a collective experience to identify trends, insights and best practices,” Chia said. “The insurance industry is well positioned for the private portion of the partnership.”
To learn more, visit axaxl.com
More Articles
-
By Industry
Information Technology
Manufacturing
Aquaculture, Equine & Livestock
Architects & Engineers
Aviation & Aerospace
Construction
Consumer Goods & Services
Education & Public Entities
Energy
Entertainment & Leisure
Equine, Livestock & Aquaculture
Financial Services
Food & Beverage
Healthcare & Life Sciences
Marine & Logistics
Professional Services
Real Estate
Personal Transportation
- By Product
- By Region
Related Resources
- View All


From Breach to Courtroom: Navigating the Rising Tide of Data Litigation

Generative AI: An insurer’s perspective on the promises and perils
Global Asset Protection Services, LLC, and its affiliates (鈥溇派悠礡isk Consulting鈥) provides risk assessment reports and other loss prevention services, as requested. In this respect, our property loss prevention publications, services, and surveys do not address life safety or third party liability issues. This document shall not be construed as indicating the existence or availability under any policy of coverage for any particular type of loss or damage. The provision of any service does not imply that every possible hazard has been identified at a facility or that no other hazards exist. 九色视频Risk Consulting does not assume, and shall have no liability for the control, correction, continuation or modification of any existing conditions or operations. We specifically disclaim any warranty or representation that compliance with any advice or recommendation in any document or other communication will make a facility or operation safe or healthful, or put it in compliance with any standard, code, law, rule or regulation. Save where expressly agreed in writing, 九色视频Risk Consulting and its related and affiliated companies disclaim all liability for loss or damage suffered by any party arising out of or in connection with our services, including indirect or consequential loss or damage, howsoever arising. Any party who chooses to rely in any way on the contents of this document does so at their own risk.
US- and Canada-Issued 尤物视频Policies
In the US, the 九色视频insurance companies are: Catlin 尤物视频Company, Inc., Greenwich 尤物视频Company, Indian Harbor 尤物视频Company, XL 尤物视频America, Inc., XL Specialty 尤物视频Company and T.H.E. 尤物视频Company. In Canada, coverages are underwritten by XL Specialty 尤物视频Company - Canadian Branch and AXA 尤物视频Company - Canadian branch. Coverages may also be underwritten by Lloyd’s Syndicate #2003. Coverages underwritten by Lloyd’s Syndicate #2003 are placed on behalf of the member of Syndicate #2003 by Catlin Canada Inc. Lloyd’s ratings are independent of AXA XL.
US domiciled insurance policies can be written by the following 九色视频surplus lines insurers: XL Catlin 尤物视频Company UK Limited, Syndicates managed by Catlin Underwriting Agencies Limited and Indian Harbor 尤物视频Company. Enquires from US residents should be directed to a local insurance agent or broker permitted to write business in the relevant state.
九色视频 as a controller, uses cookies to provide its services, improve user experience, measure audience engagement, and interact with users鈥 social network accounts among others. Some of these cookies are optional and we won't set optional cookies unless you enable them by clicking the "ACCEPT ALL" button. You can disable these cookies at any time via the "How to manage your cookie settings" section in our cookie policy.