Cyber insurers may be getting more comfortable covering the kind of event that can trigger losses across an entire book.
Systemic cyber exposures were once risks some insurers sought to carve out through widespread-event exclusions. But the market has evolved, as insurers gain experience with events affecting many insureds simultaneously, BOXX Insurance president Neal Jardine says.
“Ten years ago, it was not a common coverage component,” Jardine said. “Nowadays, it’s something the industry can price for, something we can absorb.”
That doesn’t mean every insurer will make the same coverage decision.
“I think that some companies may choose to exclude them because of the exposure across their book and their inability to absorb that exposure or price for it or understand it,” Jardine said.
Systemic cyber risk arises when a single event can affect a large number of organizations, creating the potential for multiple claims across an insurer’s book.
“Really, at the end of the day, systemic [risk] is about one issue that can become everybody’s problem, which is unique to cyber,” Jardine said.
Erik Tifft, global head of underwriting at BOXX Insurance, described systemic exposure as “the exposure from interconnected systems that can lead to multiple claims for a given incident.”
But the biggest systemic concern may not be a particular technology at all.
“When one digital failure becomes everybody’s problem,” Jardine said when asked which scenario concerned him most.
That failure could involve software, an internet service provider, or infrastructure such as the domain name system. Software gets much of the attention because vulnerabilities are regularly identified and disclosed, Jardine said.
Tifft pointed instead to the dependency insurers haven’t identified. “I think it’s the one that we don’t know about,” he said.
The internet and systems built on top of it were developed primarily for functionality rather than from a security-first perspective, Tifft said. Computer systems now depend on other computer systems, meaning a critical point of failure can have consequences well beyond the organization where the problem originates.
That interconnectedness creates both an accumulation problem for insurers and a coverage question for brokers: What happens when the critical point of failure isn’t the insured’s own system?
A business may suffer an interruption because a cloud provider, software vendor, or other third party it relies upon has gone down. The insured doesn’t necessarily have to suffer the original cyber event to sustain a loss.
That’s where contingent business interruption coverage and the treatment of third-party dependencies become particularly important. Canadian Underwriter reported earlier this year that supply-chain and infrastructure-related cyber breaches are expected to increase as organizations shift toward cloud-based solutions and standardized software platforms.
Jardine said cyber policies exist that cover systemic events, including contingent business interruption coverage that can respond when an event affects a provider or other company on which the insured depends.
The approach effectively extends coverage beyond an event directly affecting the insured’s own systems, he said.
Recent events demonstrate how widely a technology disruption can spread. Jardine pointed to the CrowdStrike outage and Canada’s Rogers outage as examples of events whose reach may have been difficult to anticipate before they occurred.
For insurers, those events also provide information that can help them understand the exposure.
While some insurers may choose to exclude systemic risk from their policies, other cyber insurers may price for systemic risk by using data to assess the exposure, Jardine said.
Artificial intelligence adds another technology dependency, but it’s not an entirely separate category of systemic cyber exposure, Jardine says.
“AI is like any other software,” he tells CU. “If the AI miscodes or starts doing something malicious, that’s a software going rogue.”
The greater concern arises when organizations give AI significant control over their operations without appropriate governance, he adds. Companies giving AI “the keys to the car” should have a human in the loop or ring-fence what the technology is permitted to do.
Cyber policy language around AI is also developing.
Tifft said affirmative AI wording clarifies that a cyber policy covers AI-related vectors of loss. In contrast, he says, some areas of the P&C market are adding AI exclusions to their products.
But the systemic-risk issue extends beyond whether the technology involved happens to be AI.
For brokers, the issue comes back to dependency: what technology and vendors can a client rely on? and how will its cyber policy respond if one of them goes down?
A systemic event “may not be your problem initially,” Jardine said. A vendor may be affected first, with the insured suffering the consequences indirectly via halted operations or an inability to service their customers.
The insured may not be the first company hit. But it can still be the one filing the claim.
–––
Originally published on Canadian Underwriter
Get the latest updates about Cyber Insurance and Protection with our newsletter.