CSP WORKSHOP CYBER INSURANCE FROM A BROKER S PERSPECTIVE



Similar documents
MARSH REPORT October International Business Resilience Survey 2015

UK 2015 Cyber Risk Survey Report

Aon Risk Solutions Global Risk Consulting Captive & Insurance Management. Cyber risk and the captive market - a match made in the cloud?

Navigating Cyber Risk Exposure and Insurance. Stephen Wares EMEA Cyber Risk Practice Leader Marsh

SPECIALIST INSURANCE SERVICES

UNITED KINGDOM TERRORISM RISK INSURANCE PROGRAMME

CYBER LIABILITY INSURANCE MARKET TRENDS: SURVEY. October Sponsored by:

Chemicals and Life Sciences Industry Practice. Insurance and compensation in the event of injury in Phase I clinical trials in the United Kingdom

THE NEXT GENERATION OF DATA INSURANCE

The promise and pitfalls of cyber insurance January 2016

IPR Workshop Response to Follow Up Questions Property Insurance

Using Insurance Catastrophe Models to Investigate the Economics of Climate Change Impacts and Adaptation

Cyber Risk and Insurance What companies need to know

LLOYD S MINIMUM STANDARDS

What we are seeing is sustained growth and increasing interest by corporates in adopting and enhancing a captive strategy.

TESTIMONY JACQUES E. DUBOIS CHAIRMAN AND CEO, SWISS RE AMERICA HOLDING ON BEHALF OF SWISS RE BEFORE

BMUSF Marine Seminar. Project Cargo Panel. May 4, 2012 San Francisco, California

Airmic review of the supply chain insurance market Review of recent developments in the supply chain insurance market

Influence of Cyber Risk on the P&C Insurance Market

Prudential Practice Guide

Florida Hurricane Catastrophe Fund

SPECIALIST INSURANCE FOR ESTATES AND HISTORIC HOUSES. Marsh Private Clients

MAX CAPITAL GROUP LTD. Nasdaq: MXGL. Acquisition of Imagine Group (UK) Limited

How To Get A Good Deal On Insurance In Korea

Cyber Risks Management. Nikos Georgopoulos, MBA, cyrm Cyber Risks Advisor

INSURANCE AND REINSURANCE ISSUES ARISING OUT OF NATURAL CATASTROPHES

Cyber Essentials Scheme

Submission on Northern Australia Insurance Premiums Taskforce INTERIM REPORT 2015

Cyber Security Incident Response High-level Maturity Assessment Tool

Property and Liability Insurance Program

DRAFT May Objective and key requirements of this Prudential Standard

Energy Practice. Feasibility Study for a Renewable Energy Insurance Facility for the People s Republic of China

Cyber/ Network Security. FINEX Global

CYBER RISK SECURITY, NETWORK & PRIVACY

London Business Interruption Association Technology new risks and opportunities for the Insurance industry

Fleet Complete. Insight. Innovation. Intervention.

Cyber Security Evolved

MARSH AND THE DRUG DEVELOPMENT INDUSTRY

Occupational Disease Claims Practice MANAGING DISEASE LIABILITIES

Capital Requirements Directive Pillar 3 Disclosure. December 2015

HSCIC Audit of Data Sharing Activities:

Cyber Security - What Would a Breach Really Mean for your Business?

Cyber Liability Insurance Data Security, Privacy and Multimedia Protection

Captive & Insurance Management

Commercial Property Construction Property and Civil Works War, Terrorism and Political Violence

Specialist insurance and risk implications for prepaid an update. Prepaid International Forum Osborne Clarke London Thursday 9 th February 2012

MANAGED SECURITY SERVICES (MSS)

Zurich s approach to Enterprise Risk Management. John Scott Chief Risk Officer Zurich Global Corporate

Cyber Security key emerging risk Q3 2015

DATA RECOVERY SOLUTIONS EXPERT DATA RECOVERY SOLUTIONS FOR ALL DATA LOSS SCENARIOS.

CyberEdge Insurance Proposal Form

Climate Change and resilience building: a reinsurer's perspective. Southeast Florida Regional Climate Leadership Summit

Internal Audit Progress Report Performance and Overview Committee (19 th August 2015) Cheshire Fire Authority

JULY 25, Good morning, Chairwoman Kelly, Chairman Simmons and members of the

Data breach! cyber and privacy risks. Brian Wright Michael Guidry Lloyd Guidry LLC

Insurance Update. May Review. Global news. Increasing importance of Captives in non-traditional risks

Specialist Cloud Services. Acumin Cloud Security Resourcing

Some of the principles that guide the Institute s inputs into public policy are:

MANAGED SECURITY SERVICES (MSS)

BDO Consulting. Insurance Claim Services. Logo

Independent Review of Flood Insurance Analysis Professor Stephen Diacon, June 2013

WILLIS RETAIL PRACTICE ADVICE AND PROTECTION FOR THE RETAIL SECTOR

UK Healthcare Team RISK AND INSURANCE SOLUTIONS FOR THE HEALTHCARE INDUSTRY

40 Broad Street New York, NY Telephone Fax

Risk Profile, Appetite, and Tolerance: Fundamental Concepts in Risk Management and Reinsurance Effectiveness

Willis 2012 Latin American Energy Conference

ESKISP Direct security testing

OUTLOOK: PERSPECTIVES ON TOPICAL RISK AND INSURANCE ISSUES FOR UK CORPORATES

Managing Cyber Threats Risk Management & Insurance Solutions. Presented by: Douglas R. Jones, CPCU, ARM Senior Vice President & Principal

A Guide to the Cyber Essentials Scheme

Our specialist insurance services for Professionals risks

GUIDANCE NOTE FOR DEPOSIT-TAKERS. Operational Risk Management. March 2012

Table of Contents... 1

Incentives and barriers for the cyber insurance market in Europe

Insurance Regulatory Authority IRA/PG/12 GUIDELINE TO THE INSURANCE INDUSTRY ON REINSURANCE ARRANGEMENTS

Cyber Insurance: How to Investigate the Right Coverage for Your Company

Think STRENGTH. Think Chubb. Cyber Insurance. Andrew Taylor. Asia Pacific Zone Product Manager Chubb Pro PI, Media, Cyber

Michael Gaudet 2015 PHC 7/23/2015. Key Broker Challenges

Integrated Stress Testing

EMERGING CYBER RISK CYBER ATTACKS AND PROPERTY DAMAGE: WILL INSURANCE RESPOND?

Property & Casualty. Flexible insurance for retail chain stores

Impact of Global Downturn on U.S.

MEMORANDUM. Date: October 28, Federally Regulated Financial Institutions. Subject: Cyber Security Self-Assessment Guidance

Global Energy Practice CYBER GAP INSURANCE CYBER RISK: FILLING THE COVERAGE GAP

Understanding the Cyber Risk Insurance and Remediation Services Marketplace:

Insurance Guidance Note No. 14 System of Governance - Insurance Transition to Governance Requirements established under the Solvency II Directive

National Corporate Practice. Cyber risks explained what they are, what they could cost and how to protect against them

RenaissanceRe. Professional Indemnity Insurance

CYBER SECURITY AND RISK MANAGEMENT. An Executive level responsibility

Cyber Security and Data Privacy Acumin Specialist Cloud Services

- A Brokers Perspective

Cyber Defence Capability Assessment Tool (CDCAT ) Improving cyber security preparedness through risk and vulnerability analysis

Professional Indemnity Insurance for Insurance Brokers & Intermediaries Proposal Form

OECD PROJECT ON CYBER RISK INSURANCE

CLAIMS SERVICE SOLVING THE TOUGHEST PROBLEMS

Cloud Security Who do you trust?

LETTER TO BROKERS. Today we are launching Reputation Risk Solutions Limited:

BEST S SPECIAL REPORT

2013 WATER INDUSTRY INSURANCE AND RISK BENCHMARKING REPORT. Global Infrastructure Practice

Data breach, cyber and privacy risks. Brian Wright Lloyd Wright Consultants Ltd

Transcription:

CSP WORKSHOP CYBER INSURANCE FROM A BROKER S PERSPECTIVE 27 April 2015 Stephen Wares Cyber Risk Practice Leader EMEA London (Tower Place)

Corporate Risk Profile Insurer Opinion

Insurance Communication Gap Percentage of CEOs or CIOs of large organisations who believe they have insurance that would cover them in the event of a breach. Source Information Security Breaches Survey 2014, Department for Business, Innovation & Skills (BIS). Value 52% Percentage of CROs or CFOs who state that their organisation has bought cyber insurance. Percentage of firms with cyber cover, whether as standalone cover or implicit in other policies. Actual penetration of standalone cyber insurance products among UK large businesses. Marsh and Zurich cyber risk surveys. Marsh and Zurich cyber risk surveys. Estimate based on policies placed/written by insurer project participant. 15%-20% 10% 2%

Taxonomy of Cyber Risk for Corporations

Existing Solution to the Cyber Coverage Maze Brokers to provide businesses with a statement of cyber assurance, based on a review of exposure and cover versus risk appetite. The key elements of this approach are: Identification of relevant cyber perils: Based either on client scenarios generated in-house or pro-forma scenarios adapted to the client, which reflect those relevant for the firm s industry and profile. Cyber gap analysis: Determine the extent of cover provided in the event of a cyber incident, including traditional policies response to a cyber event and the response of specific cyber cover that is in place. Identification of solutions for uninsured risks: Identify and arrange the appropriate cover to address uninsured risks where an insurance solution is available. Cyber assurance: Formal report, including assurance statement that cyber cover is in place to an agreed specification for those insurable risks that have been identified, and as appropriate to the firm s risk appetite.

Pricing Maturity Source: UK Cyber Security: The Role of Insurance in Managing and Mitigating the Risk, Marsh and HM Government, March 2015.

Building an Underwriting Submission Underwriting information Network information Outsourcing and third parties Backup Physical security Policies IT security process Legal requirements PCI compliance Resilience and recovery Training and staff IT security tools Updates and patching Data security Data management Records numbers and type 7 28 April 2015 Content

Outsourced Owned What (or Who) Is Insured?

The Elephant in the Room Aggregation

Aggregation and (Re)insurance Capacity Global exposure of the insurance industry to cyber risk total value. Maximum global (re)insurance capacity any one event for natural catastrophe (Tokyo or Californian earthquakes). Maximum global insurance/reinsurance capacity for a nuclear first-party loss (more comparable to cyber). GBP100 billion. GBP65 billion. GBP3 billion. Range of possible maximum loss (PML)/total exposure ratios for property portfolios. 0.15% (for UK property) 20% (PML for hurricane for small exposed Caribbean island). PML for cyber (assume the same PML/total exposure ratio of selected property portfolios). GBP150 million GBP20 billion.

Further Reading www.uk.marsh.com https://www.gov.uk/ government/publica tions/uk-cybersecurity-the-role-ofinsurance 11

Conclusion Organisations should ensure that their cyber risk is fully investigated and understood. Insurance positions as they relate to cyber risk should be investigated and accurately communicated within the organisation. The insurance industry currently has a huge appetite for insuring cyber exposure, but market growth will create some challenges and changes. Better modelling tools are required by the insurance industry to ensure that insurers are underwriting within capacity constraints. Insuring cyber exposures is complex and fractured across many policies. Organisations need to make full use of the expertise that exists within their broker to get the right outcomes.

This PowerPoint presentation is based on sources we believe reliable and should be understood to be general risk management and insurance information only,. In the United Kingdom, Marsh Ltd is authorised and regulated by the Financial Conduct Authority. Copyright 2015 Marsh Ltd All rights reserved