Cyber-Insurance Premiums Surged by Up to 30% in 2020

Cyber-Insurance Premiums Surged by Up to 30% in 2020

Take-up of cyber-insurance has almost doubled over the past four years, but premiums surged during 2020 due to more frequent attacks, according to a new congressional report.

Watchdog the Government Accountability Office (GAO) was ordered to study the industry in the National Defense Authorization Act for fiscal year 2021.

Citing data from global insurer Marsh McLennan, the GAO revealed that the percentage of clients opting to take out cyber-specific insurance policies had risen from 26% in 2016 to 47% in 2020.

However, a surge in successful cyber-attacks of late has had two negative consequences: rising premiums and reduced coverage limits for some sectors.

The GAO claimed that, according to a recent survey of insurance brokers, prices had risen 10-30% in late 2020. It also singled out healthcare and education as two sectors where insurers are now offering lower coverage limits.

Although not named in the update, ransomware is a key factor driving these trends. It was the biggest source of insurance claims in the first half of 2020, according to insurer Coalition.

Many have argued that insurers’ continued coverage perpetuates the ransomware problem as it encourages more threat actors to target organizations, knowing that the ransom will be reimbursed by providers.

Axa recently took a stand against this trend in France by resolving to stop reimbursing payments to threat actors, although it will still cover other losses incurred by attacks.

The GAO report explained that providers are also now offering more cyber-specific packages to clients. However, a lack of common terminology, such as what constitutes cyber-terrorism, can lead to inconsistencies in policies and coverage, it warned.

Confectionary giant Mondelez and global legal firm DLA Piper both sued their insurers in 2019 following major losses incurred after NotPetya. Their providers refused to pay-out due to wrangles over policy and definitions of exactly what kind of attack the global malware constituted.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

GDPR Anniversary: Security Leaders More Concerned About Litigation Than Fines

GDPR Anniversary: Security Leaders More Concerned About Litigation Than Fines

Nine in 10 (90%) security leaders are concerned about data breach litigation from class action lawsuits, according to new research by Egress.

Published on the third anniversary of the GDPR coming into force, the survey highlighted that security leaders and data protection officers (DPOs) are even more concerned about legal settlements for data subjects than they are about regulatory fines (85%) following a serious data breach.

As a result of these concerns, 91% of the 250 security leaders and DPOs in the UK polled revealed they have taken out new cyber-insurance policies or increased their cover to protect themselves from financial exposure because of GDPR.

These fears appear well founded, with high awareness among consumers of the increased rights afforded to them under GDPR also demonstrated by the study. It showed that nearly half (47%) of the 2000 UK consumers surveyed would join a class-action lawsuit against an organization that had leaked their data. Additionally, over two-thirds (67%) said they were aware they have the right to take legal action against an organization that experiences a breach that exposes their personal data.

Tony Pepper, CEO at Egress explained: “The financial cost of data breach has always driven discussion around GDPR – and initially, it was thought hefty regulatory fines would do the most damage. But the widely unforeseen consequences of class action lawsuits and independent litigation are now dominating conversation.

“Organizations can challenge the ICO’s intention to fine to reduce the price tag, and over the last year, the ICO has shown leniency towards pandemic-hit businesses, such as British Airways, letting them off with greatly reduced fines that have been seen by many as merely a slap on the wrist. With data subjects highly aware of their rights and lawsuits potentially becoming ‘opt-out’ for those affected in future, security leaders are right to be nervous about the financial impacts of litigation.”

Commenting, Lisa Forte, partner at Red Goat Cyber Security LLP, said: “The greatest financial risk post breach no longer sits with the regulatory fines that could be issued. Lawsuits are now common place and could equal the writing of a blank cheque if your data is compromised. European countries haven’t typically subscribed to a litigious way of regulating the behavior of companies. That is now changing and without explicit government intervention companies will need to accept they need deeper pockets to cover the lawsuit gold rush we are starting to see.”

“The recent Google case that currently sits with the UK Supreme Court could make group claims ‘opt out’ instead of ‘opt in'”, Lisa Forte continued. “That will inevitably mean that every single customer affected would be entered into the group action. That should be a huge worry for companies. Companies need to really prioritize preventative measures both technical and human and have a tested incident plan in place.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Only Two-Fifths of UK Firms Report Data Breaches On Time

Only Two-Fifths of UK Firms Report Data Breaches On Time

It’s three years today since the GDPR was launched across Europe but UK businesses are still failing to meet some of its most basic reporting requirements, CrowdStrike has warned.

The security vendor polled a sample of 500 UK business decision makers between April 30 and May 10 to better understand uptake of the legislation, and the Data Protection Act 2018, which applies its principles in UK law.

Unfortunately, the poll found that just 42% of UK firms that have been breached report the incident to the regulator within 72 hours, as required by law.

The study found a general lack of awareness and visibility elsewhere: 67% of respondents said they consider themselves “prepared” should they become a breach victim, but only around a third (36%) have actually readied specific protocols to deal with the fallout of such an incident.

Over a fifth (22%) claimed they either don’t know or don’t think the GDPR applies to the UK following Brexit.

What’s more, two-thirds of businesses  either don’t know (41%) or underestimated (25%) the maximum amount the Information Commissioner’s Office (ICO) can fine erring companies: 4% of global annual turnover or £17 million, whichever is higher.

Zeki Turedi, EMEA CTO at CrowdStrike, told Infosecurity that many organizations are struggling to understand what a data breach even is, and how much time they have to report it.

“For example, some companies are unaware that simply sending confidential information about an individual to an incorrect email address can trigger the need for a GDPR notification,” he argued.

“The CISO has a critical role to play here, not just in helping to protect the business in the first place, but also in ensuring the company understands its legal requirements when it comes to breaches and is in a position to meet them. The research underlines the continued need to educate organizations on the use of GDPR and how it impacts them.”

Alongside the CISO’s role here, the GDPR also mandates most large organizations appoint a Data Protection Office (DPO) to handle such issues.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk