Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance



Similar documents
Aon Risk Solutions Global Risk Consulting Captive & Insurance Management. Cyber risk and the captive market - a match made in the cloud?

Cyber Insurance Presentation

Cyber Risks Management. Nikos Georgopoulos, MBA, cyrm Cyber Risks Advisor

Joe A. Ramirez Catherine Crane

Cyber Risks in Italian market

GALLAGHER CYBER LIABILITY PRACTICE. Tailored Solutions for Cyber Liability and Professional Liability

Cyber Risk: Global Warning? by Cinzia Altomare, Gen Re

Data Breach and Senior Living Communities May 29, 2015

Willis Healthcare Practice 11 th Annual Forum July 10,2007. Managing and Insuring Risks in Network Privacy/Cyber Risk

Insurance Considerations Related to Data Security and Breach in Outsourcing Agreements

Data Breach and Cybersecurity: What Happens If You or Your Vendor Is Hacked

Managing Cyber Threats Risk Management & Insurance Solutions. Presented by: Douglas R. Jones, CPCU, ARM Senior Vice President & Principal

Cyber Liability & Data Breach Insurance Claims

Implementing Electronic Medical Records (EMR): Mitigate Security Risks and Create Peace of Mind

Managing Cyber & Privacy Risks

DATA BREACH: hy you should care!

Ten Questions Your Board Should be asking about Cyber Security. Eric M. Wright, Shareholder

Privacy Liability & Data Breach Management Nikos Georgopoulos Cyber Risks Advisor cyrm October 2014

Understanding the Business Risk

Cyber Liability Insurance

Cyber Risk State of the Art

Cyber Insurance as one element of the Cyber risk management strategy

THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS

Policy Considerations for Covering Special Exposures. Claire Lee Reiss Program Director National League of Cities Risk Information Sharing Consortium

Senate Committee on Commerce, Science, and Transportation March 19, 2015, Hearing Examining the Evolving Cyber Insurance Marketplace

RISKY BUSINESS SEMINAR CYBER LIABILITY DISCUSSION

Cyber Risk, Legal And Regulatory Issues, And Insurance Mitigation ISACA Pittsburgh Information Security Awareness Day

Embracing Cyber Risk: Insurance Solutions

CYBER INSURANCE. Cyber Insurance and Gaps in Traditional Insurance. Cyber and E&O Team Willis FINEX North America

Preparing for the Inevitable Data Breach: What to Do Before Sensitive Customer and Employee Data is Breached, Stolen or Compromised

Cyber Liability & Data Breach Insurance Claims

Distributor Liability Contract Risk Management THOMAS DOUGLASS APRIL 15, 2015

Mitigating and managing cyber risk: ten issues to consider

Insurance for Data Breaches in the Hospitality Industry

4/30/2015 CYBER LIABILITY AND AVIATION AGENDA LEARNING OBJECTIVES. Presented by Hal Hunt May 3, 2015

cyber invasions cyber risk insurance AFP Exchange

Can Cyber Insurance Be Linked to Assurance?

CYBER RISK MANAGEMENT IN THE BOATING INDUSTRY

Rogers Insurance Client Presentation

Beazley presentation master

Glossary of Insurance Terms: (obtained from website:

Cyber/Information Security Insurance. Pros / Cons and Facts to Consider

Cyber Liability. Michael Cavanaugh, RPLU Vice President, Director of Production Apogee Insurance Group Ext. 7029

Best practices and insight to protect your firm today against tomorrow s cybersecurity breach

Cyber Liability Insurance: It May Surprise You

How To Buy Cyber Insurance

Cyber Liability. AlaHA Annual Meeting 2013

Cyber-insurance: Understanding Your Risks

Data Security Breaches: Learn more about two new regulations and how to help reduce your risks

How to Respond When Sensitive Customer and Employee Data is Breached, Stolen or Compromised

9/13/2011. Miscellaneous Current Topics in Healthcare Professional Liability. Antitrust Notice. Table of Contents. Cyber Liability.

Reducing Risk. Raising Expectations. CyberRisk and Professional Liability

CYBER & PRIVACY INSURANCE FOR FINANCIAL INSTITUTIONS

Privacy / Network Security Liability Insurance Discussion. January 30, Kevin Violette RT ProExec

Delaware Cyber Security Workshop September 29, William R. Denny, Esquire Potter Anderson & Corroon LLP

Don t Wait Until It s Too Late: Top 10 Recommendations for Negotiating Your Cyber Insurance Policy

CYBER & PRIVACY LIABILITY INSURANCE GUIDE

Insurance & Risk Management Update: November 2011

Protecting Your Assets: How To Safeguard Your Fund Against Cyber Security Attacks

ISO? ISO? ISO? LTD ISO?

How To Protect Your Data From Hackers

Cyber Insurance: How to Investigate the Right Coverage for Your Company

Specialty Risk Protector

2015 PIAA Corporate Counsel Workshop October 22 23, 2015 Considerations in Cyber Liability Coverage

Cyber Risk in Healthcare AOHC, 3 June 2015

Cyber Risks Connect With Directors and Officers

Cyber and Privacy Risk What Are the Trends? Is Insurance the Answer?

Cyberinsurance: Insuring for Data Breach Risk

OECD PROJECT ON CYBER RISK INSURANCE

Is Cyber Insurance the Next Big Think? 2nd Digital Payments Summit - May Nikos Georgopoulos, MBA, cyrm Cyber Risks Advisor

CYBER SECURITY SPECIALREPORT

Cybersecurity. Shamoil T. Shipchandler Partner, Bracewell & Giuliani LLP

Tools Conference Toronto November 26, 2014 Insurance for NFP s. Presented by Paul Spark HUB International HKMB Limited

Anatomy of a Privacy and Data Breach

Privacy Liability & Data Breach Management Nikos Georgopoulos 1 st Athens Privacy & Data Breach Management Conference

SINGAPORE HEALTHCARE ENTERPRISE RISK MANAGEMENT CONGRESS Data Breach : The Emerging Threat to Healthcare Industry

MANAGING Cybersecurity Risk AND DISCLOSURE OBLIGATIONS

Fiduciary Insurance and the Board of Retirement in New York State

Data security: A growing liability threat

Network Security & Privacy Landscape

GALLAGHER CYBER LIABILITY PRACTICE. Cyber Risk Exposures and Solutions

Protecting Your Credit Union

Hit ratios are still very low for Security & Privacy coverage: What are companies waiting for?

T H E R E A L C O S T O F A D ATA B R E A C H

Cyber-Insurance Metrics and Impact on Cyber-Security

Practical Cyber Law: Why the Standard of Care Requires Lawyers to Have a Basic Understanding of Cyber Insurance

THE DIGITAL AGE THE DEFINITIVE CYBERSECURITY GUIDE FOR DIRECTORS AND OFFICERS

Cyber Exposure for Credit Unions

Insulate Your Company from a Cyber Breach: Proactive Steps to Minimize Breach Risks & Impact. February 10, 2015

The Current State of Side A Insurance Coverage. American Conference Institute s 17 th Forum on D&O Liability October 21-22, 2013

CAGNY Spring 2015 Meeting Fundamentals of Cyber Risk. Brad Gow June 9th, 2015 Endurance

Second Annual Conference September 16, 2015 to September 18, 2015 Chicago, IL

Protecting Your Credit Union

Cyber/ Network Security. FINEX Global

Incentives and barriers for the cyber insurance market in Europe

Managing Your Cyber & Data Risk 2010 NTA Convention Montreal, Quebec

Managing Cyber Risk through Insurance

Cyber Insurance in an Evolving Liability Landscape: Informed, Strategic Expectations Monday, February 29, :00pm 3:00pm

Zurich Public Sector Solution

Don t Be a Victim to Data Breach Risks Protecting Your Organization From Data Breach and Privacy Risks

Transcription:

Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance

Today s agenda Introductions Cyber exposure overview Cyber insurance market and coverages Captive cyber insurance pros, cons and strategies Page 2

Panelists Jim Bulkowski New York Jim.Bulkowski@ey.com 1 212 773 3567 Mark Millard New York Mark.Millard@ey.com 1 212 773 4704 Page 3

Cyber exposure overview Page 4

Cyber exposure and mitigation key topics Modeling of cyber exposure Mega claims (Sony, Target, US OPM, Anthem, etc.) S&P Ratings National Data Breach Law Cyber Risk Ability to pursue recoveries from thirdparties Potential personal liability for Directors & Officers Bodily injury and property damage exposure Current program vs. ideal coverage tailored to risk profile Page 5

Number and types of incidents Page 6

Risk ID What generates your risk exposure Industry type Services you provide Third party service providers Type of information you have Healthcare Business to Business Data Hosting PII Retail Consumer Data Processing PHI Financial Institutions Data Storage SCI Technology Services FI Page 7

Risk ID Where does your exposure come from Employees Government Vendors Cyber Exposure Clients Criminal elements Short of using the postal service as your sole method of communication, no level of security protection is guaranteed to completely mitigate exposure to cyber damage and liability Page 8

Cyber liability market and coverages Page 9

Growth of cyber insurance market Market place has doubled from 2013 2014 with $2B in gross written premium Market is expected to grow to $5B - $6B in the coming years Approximately 50 markets are writing cyber coverage with more entering the market every month Only about 1% of captive owners write cyber liability in their captive! Page 10

Risk quantification Global risk quantification IBM / Ponemon Study Average record cost $217 Average breach cost $6.53 million $143 indirect $74 direct 62 companies participated Breached records 5.6K 96.5K (capped at 100K) Netdiligence Insurance Claim Study Average record cost $956 Median record cost $19.84 Average claim payout $733K 111 claims evaluated Average records exposed 2.4M (no cap) Page 11

Cyber liability insurance coverage Information Security and Privacy Liability Loss, theft, or authorized disclosure Damage to data stored on systems Violation of breach notification law Privacy Notification and Crisis Management Expenses Computer security expert after breach Call center for information on breach Credit monitoring (typically 1 year) Pay losses of theft from identity Regulatory Defense and Penalties Coverage for defense costs, fines and penalties Website Media Content Liability Personal injury Commercial violation Time Element Coverage Business Interruption and Extra Expense Data Assets Extortion Computer fraud Funds transfer Theft of Assets Insurance marketplace Available capacity - $500M Less than $100M for certain industries Typical deductible ranges - $5K - $1M Page 12

Captive cyber liability insurance strategies Page 13

Captive market Cyber 1% of captive owners Cyber liability may not be perceived material enough to justify inclusion within the captive Not fully understood Coverages and forms varied US based captives Majority are from the healthcare industry and financial institutions Other industries are professional services groups and retailers EU based captives Proposed EU legislation will empower national data commissioners to fine companies that violate EU data protection rules - penalties of up to 100 million Risk-based capital model of the Solvency II - promotes the diversification benefits of writing new and additional insurance covers Page 14

Captive insurance Traditional advantages also apply to cyber risk Page 15

Captive cyber insurance advantages TOPIC PRO D&O Protection May protect the D&O s against shareholder lawsuits for not managing risk Reinsurance Market Surplus Build Policy Terms Market Volatility Structured Programs Deductible Buy Down Cyber Liability Occurrence Coverage Gaps Claim Payments Tax Efficiencies Transferred to reinsurance - currently offering higher capacity than primary insurance Companies can retain the premium dollars for this new coverage area in a captive rather than pay a commercial insurer Ability to receive better policy terms through their captive Ability to avoid the volatility of commercial insurance pricing and policy term restrictions Ability to structure your insurance program more easily given that the captive can fill any gaps in coverage that could materialize over time The ability to buy down one s deductible or serve as a cyber risk reinsurer write cyber risk insurance using a manuscript policy occurrence form. Build up solid surplus in their captive to use for their cyber risk losses down the road. The ability to structure your insurance program more easily given that the captive can fill any gaps in coverage that could materialize over time Captive typically settled quickly Potential state, federal, international tax benefits Page 16

Cyber captive insurance Bespoke concepts Policy limits: $50k to $50m per occurrence - reflect the relatively unknown quantity of cyber insurance limits Coverage Mirror: Most captive cyber limits are based on what the market insurers are offering tailored coverage Exposure Assessment: Organizations often struggle with understanding their individual exposure to a level that would allow a scientific approach to calculating the organization's cyber exposure. Page 17

Cyber captive insurance Bespoke concepts Litigation Coverage: Cyber claims defense costs Special cyber risk coverage: Future lost revenue Dependent system failure business interruption Physical damage or bodily injury resulting from cyber peril (excess/dic above other applicable insurance) First-party loss of inventory due to technology failure Loss of value of intangible assets Insure first party loss, third party liability and crisis expenses cover may be available in the reinsurance market Combine Risks: Encompass highly correlated risks, for example cyber and reputation, which may not be packaged in the commercial market. Page 18

Captive cyber insurance challenges Cyber risk is a high-severity, low frequency risk that does not easily lend itself to a captive solution. Captives do better with more predictable high-frequency, low-severity risk resulting in a large probable number of claims Capital requirements? Regulators do not understand it You may have a loss! Page 19

What to do? next steps Analyze your companies exposure to cyber risk probably already done through IT department Explore traditional insurance risk transfer products/ pricing and coverage Identify captive solutions in concert with self insurance/risk transfer Obtain executive concurrence on next steps Page 20

Questions? Page 21