Association of British Insurers

Submission to the Joint Committee on the National Security Strategy inquiry into UK National Security in a Digital World

 

Executive Summary

 

 

 

 

 

 

About the ABI

 

The ABI is the leading trade association for insurers and providers of long term savings. Our 250 members include most household names and specialist providers who contribute £12billon in taxes and manage investments of £1.6trillion.

 

The ABI works with the Government on cybersecurity through its membership of the Government’s Cyber Insurance Forum, coordinated by the Department of Culture Media and Sport. 

 

 

Government and insurers: Building cyber risk management and resilience

 

About cyber insurance

  1. Cyber insurance is one of the fastest growing lines of insurance, with insurers expecting double digit year-on-year growth.[1] While existing insurance policies such as commercial property, business interruption or professional indemnity insurance may provide some elements of cover against cyber risks, businesses are increasingly looking to specialised cyber insurance policies to supplement their existing insurance arrangements.

 

  1. Cyber insurance policies will typically cover costs associated with: cyber business interruption loss, privacy breach, cyber extortion, digital asset replacement expenses ('hacker damage'), media liability, and cyber forensic support. Policies can also provide invaluable ‘360 support’ for policy holders:

 

    1. Before: Helping a business to identify and manage cyber risk
    2. When an incident occurs: Providing near-immediate 24/7 support from cyber and crisis management specialists
    3. After: Advising on preventative measures to prevent future incidents. 

 

  1. Cyber insurance is particularly valuable for businesses which hold sensitive customer details such as names and addresses or banking information, rely heavily on IT systems and websites to conduct their business, and process payment card information as a matter of course.[2]

 

Increasing cyber awareness and understanding

 

  1. Insurance is critical to many business risk management strategies. However, this is often not the case with cyber risk and cyber insurance. Awareness and understanding of cyber risk and how insurance can help is still low. 

 

  1. For many businesses, cyber risk is still very much ‘an IT issue’. This is despite the potentially devastating cost a cyber incident can have on a business. The Government’s Cyber Governance Health Check highlighted this when it reported in 2015 that only 33 per cent of boards have clearly set and understood their appetite for cyber risk (up 18 per cent from 2014).[3]

 

  1. Take up of cyber insurance has been greatest in the United States where mandatory notification of data breaches exists in some states. In the UK, we expect interest in cyber insurance to substantially increase as the implementation of the GDPR approaches and businesses face the prospect of being fined following a data breach. 

 

  1. The ABI is already working with insurers to increase businesses’ understanding and awareness of cyber insurance. This has included releasing a guide to cyber insurance for SMEs.[4] The ABI is also communicating among members and businesses about government initiatives such as Cyber Essentials – the ABI itself became Cyber Essentials certified in 2015.

 

  1. The ABI and our members agree with the Government that Boards should be doing more to actively manage their cyber risk. Part of this message needs to be ‘talk to your insurance broker to make sure you have the right insurance cover for your cyber risks’.

 

Securing insurer access to valuable cyber breach data

 

  1. Cyber insurance policies are evolving all the time as the industry’s understanding of cyber risk grows and the threat landscape shifts.  One of the greatest challenges facing insurers underwriting these policies is the access to useful data about cyber risk. Insurers will have 350 years of fire data and 100 years of motor and aviation data, but just a few years of cyber data.

 

  1. We acknowledge that information sharing initiatives already exist for use by businesses, for example the Cybersecurity Information Sharing Partnership, which allows its members to share cyber threat and vulnerability information. These initiatives help improve situational awareness of cyber threat and help to mitigate impact.

 

  1. To more effectively underwrite, insurers need access not only to information about the threat landscape but also to information about breaches that are occurring, and the type of organisations they are affecting.

 

  1. In 2018 the UK will implement the GDPR, which will introduce a duty on all organisations to report certain types of data breach to the Information Commissioner’s Office.  As this will pick up many cyber breaches, we believe that there is an opportunity for the insurance industry to use the data collected by the Information Commissioner’s Office to build a better understanding of cyber risk and consequently to develop more specific cyber insurance products and services that respond to the different risks occurring in the economy.

 

  1. The ABI wants to work with the Information Commissioner’s Office to ensure that the information that it collects through mandatory reporting provides useful information about cyber risk and can be readily accessed by insurers. We believe that this would also be valuable for other cybersecurity stakeholders seeking to understand cyber risks.

 

Exposure of traditional lines of insurance to cyber risk

 

  1. We need to draw a distinction between “affirmative” cyber risk (insurance policies that explicitly include coverage for cyber risk) and “non-affirmative” cyber risk (insurance policies that do not explicitly include or exclude coverage for cyber risk).  A number of traditional lines of insurance (such as property, casualty, marine, aviation and transport) may nowadays have significant exposures to non-affirmative cyber risk; an example would be a fire caused in a smart home as a result of a cyber incident, which is likely to be covered by property insurance.

 

  1. The Prudential Regulation Authority (PRA) is interested in how insurers manage their exposure to non-affirmative cyber risks. The ABI works closely with the PRA and recently responded to its consultation on non-affirmative cyber risksWe recognised the need for firms to understand non-affirmative cyber risks, and to reflect these in their strategy and risk appetite statements. 

 

  1. We are committed to supporting firms in increasing their understanding of both affirmative and non-affirmative cyber risks.  However, we have cautioned the PRA against being too prescriptive, given the evolving nature of the risks and their non-uniform treatment by the marketplace.

 

Being prepared for significant events

 

  1. The systemic or connected nature of technology makes cyber risk complex and global. An attack, for instance, on a national grid or a cloud provider could have a significant impact across multiple policyholders and multiple lines of insurance, resulting in very large losses.

 

  1. In 2015, Lloyd’s and the University of Cambridge Centre for Risk Studies considered the insurance implications of a cyber-attack on the US power grid.  This was a hypothetical scenario of an improbable but technologically possible electricity blackout that affected 15 US states, leaving 93 million people without power. In this scenario, the claims paid by the insurance industry were estimated at $21.4billion, rising to $71.1billion in the most extreme scenario.[5]

 

  1. At this stage in the development of the cyber insurance market, our members do not see a need for the government to provide a ‘backstop’ for the market in readiness for a significant cyber event. However, as cyber exposure increases, it is possible that a government backstop may be needed in the future if the viability of the cyber insurance market is to be maintained, and to ensure that businesses remain fully protected.

 

  1. We imagine that such a backstop would be similar to Pool Re, a public-private reinsurance arrangement set up in 1993 for terrorism risk. This was established when reinsurers began withdrawing cover for terrorism-related damage due to the costs of the Provisional IRA’s mainland bombing campaign in the 1990s.

 

  1. Pool Re had to be established very quickly following this market failure. It would be prudent for government and the industry to work together at an early stage to do preliminary scoping of what a ‘Cyber Re’ might look like if it were needed rapidly.   

 

 

Association of British Insurers

February 2017


[1] See recent reports: Hiscox (2017) The Hiscox Cyber Readiness Report 2017, https://www.hiscox.co.uk/cyber-readiness-report/docs/cyber-readiness-report-2017.pdf and Allianz (2015) A Guide to Cyber Risk, https://www.allianzebroker.co.uk/content/allianzebroker/en_gb/application/content/documents/news-and-insight/commercial/guide-cyber-risk-agcs/_jcr_content/documentProperties/currentDocument.res/agcs-guide-cyber-risk.pdf

[2] More information about cyber insurance can be found on ABI’s website www.abi.org.uk.

[3] HM Government (2016), FTSE 350 Cyber Governance Health Check Report 2015, https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/521484/Cyber_Governance_Health_Check_report_2015.pdf

[4] ABI (2016) Making sense of cyber insurance: a guide for SMEs,  https://www.abi.org.uk/~/media/Files/Documents/Publications/Public/2016/Cyber%20Insurance/Making%20Sense%20of%20Cyber%20Insurance%20A%20Guide%20for%20SMEs.pdf

[5] Lloyd’s (2015) Business Blackout: The insurance implications of a cyber-attack on the US power grid, https://www.lloyds.com/~/media/files/news%20and%20insight/risk%20insight/2015/business%20blackout/business%20blackout20150708.pdf