News

When One Cyber Event Becomes Everybody’s Problem

  • Systemic cyber risk arises when a single event can affect a large number of organizations, creating the potential for multiple claims across an insurer’s book.

  • According to BOXX's Neal Jardine, at the end of the day, systemic risk is about one issue that can become everybody’s problem, which is unique to cyber.

  • Erik Tifft from BOXX also described systemic exposure as “the exposure from interconnected systems that can lead to multiple claims for a given incident".

One cyber event can become everybody’s problem, raising new questions about how insurers price systemic risk and how coverage responds

Cyber insurers may be getting more comfortable covering the kind of event that can trigger losses across an entire book.

Systemic cyber exposures were once risks some insurers sought to carve out through widespread-event exclusions. But the market has evolved, as insurers gain experience with events affecting many insureds simultaneously, BOXX Insurance president Neal Jardine says.

“Ten years ago, it was not a common coverage component,” Jardine said. “Nowadays, it’s something the industry can price for, something we can absorb.”

That doesn’t mean every insurer will make the same coverage decision.

“I think that some companies may choose to exclude them because of the exposure across their book and their inability to absorb that exposure or price for it or understand it,” Jardine said.

Systemic cyber risk arises when a single event can affect a large number of organizations, creating the potential for multiple claims across an insurer’s book.

“Really, at the end of the day, systemic [risk] is about one issue that can become everybody’s problem, which is unique to cyber,” Jardine said.

Erik Tifft, global head of underwriting at BOXX Insurance, described systemic exposure as “the exposure from interconnected systems that can lead to multiple claims for a given incident.”

But the biggest systemic concern may not be a particular technology at all.

“When one digital failure becomes everybody’s problem,” Jardine said when asked which scenario concerned him most.

That failure could involve software, an internet service provider, or infrastructure such as the domain name system. Software gets much of the attention because vulnerabilities are regularly identified and disclosed, Jardine said.

Tifft pointed instead to the dependency insurers haven’t identified. “I think it’s the one that we don’t know about,” he said.

The internet and systems built on top of it were developed primarily for functionality rather than from a security-first perspective, Tifft said. Computer systems now depend on other computer systems, meaning a critical point of failure can have consequences well beyond the organization where the problem originates.

That interconnectedness creates both an accumulation problem for insurers and a coverage question for brokers: What happens when the critical point of failure isn’t the insured’s own system?

A business may suffer an interruption because a cloud provider, software vendor, or other third party it relies upon has gone down. The insured doesn’t necessarily have to suffer the original cyber event to sustain a loss.

That’s where contingent business interruption coverage and the treatment of third-party dependencies become particularly important. Canadian Underwriter reported earlier this year that supply-chain and infrastructure-related cyber breaches are expected to increase as organizations shift toward cloud-based solutions and standardized software platforms.

Jardine said cyber policies exist that cover systemic events, including contingent business interruption coverage that can respond when an event affects a provider or other company on which the insured depends.

The approach effectively extends coverage beyond an event directly affecting the insured’s own systems, he said.

Recent events demonstrate how widely a technology disruption can spread. Jardine pointed to the CrowdStrike outage and Canada’s Rogers outage as examples of events whose reach may have been difficult to anticipate before they occurred.

For insurers, those events also provide information that can help them understand the exposure.

While some insurers may choose to exclude systemic risk from their policies, other cyber insurers may price for systemic risk by using data to assess the exposure, Jardine said.

What about AI?

Artificial intelligence adds another technology dependency, but it’s not an entirely separate category of systemic cyber exposure, Jardine says.

“AI is like any other software,” he tells CU. “If the AI miscodes or starts doing something malicious, that’s a software going rogue.”

The greater concern arises when organizations give AI significant control over their operations without appropriate governance, he adds. Companies giving AI “the keys to the car” should have a human in the loop or ring-fence what the technology is permitted to do.

Cyber policy language around AI is also developing.

Tifft said affirmative AI wording clarifies that a cyber policy covers AI-related vectors of loss. In contrast, he says, some areas of the P&C market are adding AI exclusions to their products.

But the systemic-risk issue extends beyond whether the technology involved happens to be AI.

For brokers, the issue comes back to dependency: what technology and vendors can a client rely on? and how will its cyber policy respond if one of them goes down?

A systemic event “may not be your problem initially,” Jardine said. A vendor may be affected first, with the insured suffering the consequences indirectly via halted operations or an inability to service their customers.

The insured may not be the first company hit. But it can still be the one filing the claim.

–––

Originally published on Canadian Underwriter

About BOXX Insurance

BOXX Insurance helps businesses, individuals and families insure and defend against cyber threats, harnessing the power of ALL IN ONE Cyber Insurance and Protection. Headquartered in Toronto, Canada, with offices worldwide, BOXX is a global, award-winning provider of cyber protection services & cyber insurance coverage.

We're not a typical insurance company. That's by design. We're obsessive about making our clients’ digital worlds safer and more livable; creating real, positive changes for our clients, partners and brokers. With comprehensive, technologically advanced products and services that have a strong emphasis on predicting, preventing and insuring against negative cyber events, BOXX is dedicated to protecting and digitally safeguarding our clients, our brokers' clients and our partners' customers, 365 days a year.

BOXX Insurance Inc. is part of Zurich Global Businesses & Operations, a global ecosystem focused on delivering meaningful value to customers and partners. By bringing together Travel, Cyber and Zurich’s global operations, including global capability centers, we operate at scale to provide customized, proactive and digital experiences that help individuals and businesses be better prepared for the future.

Related Posts

News BOXX Announces Cyberboxx® Assist – Cutting-Edge Cyber Services that Build Digital Resilience Amongst Businesses & Homes 

BOXX Announces Cyberboxx® Assist – Cutting-Edge Cyber Services that Build Digital Resilience Amongst Businesses & Homes 

BOXX Insurance announced Cyberboxx® Assist, a comprehensive suite of cyber security tools and services designed to help individuals and businesses to cyber threats through risk assessments, compliance tools and 24/7 expert support from real cyber security experts.

21/05/2025
News BOXX Insurance Ranked on Deloitte’s 2025 Technology Fast 50 and The Globe & Mail’s Top Growing Companies Lists 

BOXX Insurance Ranked on Deloitte’s 2025 Technology Fast 50 and The Globe & Mail’s Top Growing Companies Lists 

BOXX Insurance has been named to Deloitte’s 2025 Technology Fast 50™ and ranked in the top quartile of the Globe & Mail’s Top Growing Companies list.

28/10/2025

Sign up for the BOXX Insurance Newsletter

Get the latest updates about Cyber Insurance and Protection with our newsletter.