Google Tanslate

Select Language

Sign up and be the first to know

About Hugh Terry & The Digital Insurer

Hugh Terry & The Digital Insurer Video

Contact Us

1 Scotts Road
#24-10 Shaw Centre
Singapore 228208

Write an article

Get in touch with the editor Martin Kornacki

email your ideas at [email protected]

Pre Registration Popup

itcasia2020 Registration Popup

Share Popup

Prime Member: Find out more

Access a unique programme!
  • 56 pre recorded lesson of online content from industry experts over 7 courses
  • The best in digital insurance for practitioners and by practtioners
  • Online MCQ after each lesson
  • Join the discussion forum and make new friends
  • Certificate upon completion to show your expertise and comitment
  • 3 months to complete
  • Normal price US$1,400 Your Prime member price is US$999
  • Access to future versions included in your Prime membership!
Become a member

Prime Member: Contact Us

Reach out to us. Please fill up the form below
Let us know how we can help. You can expect a response within 24 hours
Services of interest

Arthur D. Little

Arthur D. Little has been at the forefront of innovation since 1886. We are an acknowledged thought leader in linking strategy, innovation and transformation in technology-intensive and converging industries. We enable our clients to build innovation capabilities and transform their organizations. ADL is present in the most important business centers around the world. We are proud to serve most of the Fortune 1000 companies, in addition to other leading firms and public sector organizations. For further information, please visit

Library: AXA – The challenges of cyber risk insurance

Executive summary:

The digital transformation of our economies creates many opportunities but also generates ubiquitous cyber risks. Already in 2017, the OECD considered the insurance sector as a key actor to improve global cyber resilience and cyber risk management. In addition, awareness of cyber risks has greatly increased in the general population, which has witnessed a rising number of attacks during the COVID-19 crisis, including critical infrastructures, such as hospitals.

 The Digital Insurer reviews AXA XL’s Report on The challenges of cyber risk insurance

The reward of digitalisation brings risks: cyber risks

What are the challenges to cyber insurability?
Technologies that connect to the internet have not always had security as the top priority, as innovation was the first order of business. Therefore, many of the vulnerabilities introduced for companies and governments are not fully insured today. While changing, the number of governments and companies that purchase cyber insurance is still relatively low worldwide. As a result, cyber losses remain mainly uninsured today.

And indeed, there are many challenges with cyber insurability. First, the insurance sector relies on recognising patterns in data to be able to price the product. With a natural peril for example, we have historical weather data that helps us predict what happens with a hurricane or a tsunami, while in comparison, we barely have 10 to 12 years of cyber insurance data.

What makes the risk analysis even more complex is that the threat is man-made and constantly evolving. Additionally, there are many layers of connected and interconnected technologies, each with their own specificities, such as software, hardware, IoT, remote monitoring and so on.

When we look at accumulation modelling within cyber it is very immature. We have a couple of realistic disaster scenarios and models, but they are only a few years old and do not yet fully include changes in threat actor behaviour. Further, traditional risks such as fire and explosion and other types of property damage that are a result of a cyber event are not yet fully modelled in the industry. It’s very early days in the accumulation-modelling world.

Lack of data and issues with modelling generate uncertainty. This is an opportunity for the insurance sector, but you really need cyber security and insurance experts to come together to assess the issues and to analyse the cyber maturity of the company seeking the insurance coverage.

What makes the risk analysis from an insurance perspective even more complex is that the threat is constantly evolving and that there are many layers of connected and interconnected technologies, each with their own vulnerabilities and specificities, such as software, hardware, IoT, remote monitoring and so on.

What are the main trends in the development of cyber insurance?  
What is really new in 2021 is the outsized impact of ransomware cases, with severe losses this past year. It is changing the risk appetite of the insurance sector, which is in reactionary mode at this stage.

Another very important trend is the move from ‘silent’ to ‘affirmative’ policies, that is, being explicit about what is included and what is excluded from policies. The reinsurance community began exploring these questions around 2015 to 2016.

AXA XL made the move in 2019, then Lloyd’s mandated insurers be explicit in their policies and giving insurers 24 months to roll out the form changes. Some in the reinsurance community are now asking their clients whether their policies are silent or affirmative. I think that this will drive the behaviour of the insurance sector on all lines of business in the next year or two. This will not only affect the direct cyber products themselves but those products where cyber is a peril in other lines of business such as property or liability.

Finally, there is a growing global awareness of cyber risks and losses. Small businesses will start buying stand-alone policies covering cyber with higher limits, as opposed to insurance packages that include cyber.

However, the imbalance between supply and demand is impeding the development of the sector. Overall, there are not enough insurance companies or capacity for covering cyber risks yet. On the insurance company side, there is also a fear of the unknown in terms of shifting threat actor behaviour. Additionally, there’s a limitation in accessing underwriting and risk expertise in this area. There is also a lack of maturity on the topic with key stakeholders, such as agents and brokers, who are the advisors to companies. However, there is a very strong commitment by the cyber community to improve education and awareness amongst intermediaries.

What should boards of directors know about cyber risks? 
Another limitation to the development of the cyber insurance sector, is the awareness and maturity of boards of directors regarding the risk and whether they should address it through a combination of cyber security spending, self-insuring the risk or whether they want to transfer it to an insurer. Publicly traded company boards tend to have greater maturity than privately-owned ones but like much in cyber this too is relatively immature.

There are several things a publicly traded board should reasonably be required to know about cyber issues. Think of a three-legged stool: there are standards and frameworks, there is overall governance and finally there is the assessment of the financial harm of a risk un-addressed. The not-for-profit research by the Crossroads Group highlights the need to identify circumstances that contribute to the organisation’s cyber risk, first at a local scale within an organisation, and to determine the organisation’s appetite for these risks. This leads to the implementation of a cyber risk plan containing actions to be taken to manage cyber risk and of course to setting up oversight mechanisms.

This article by Libby Benet, global chief underwriting officer, financial lines, is taken from the broader AXA Research Fund report: Building Cyber Resilience: Threats, Enablers and Anticipation

See the full report for more…

Link to Full Article:: click here

Link to Source:: click here

Livefest 2019 Register Popup Event

Livefest 2019 Already Registered Popup Event

Livefest 2019 Join Live Logged-in Not Registered

Livefest 2019 Join Live Not Logged-in