PANEL DISCUSSION: Cyber Risk Insurance. 19 March 2015. (Network Security & Privacy Insurance)



Similar documents
Prudential sourcebook for Insurers (Waivers)

CYBER INSURANCE. Cyber Insurance and Gaps in Traditional Insurance. Cyber and E&O Team Willis FINEX North America

GALLAGHER CYBER LIABILITY PRACTICE. Cyber Risk Exposures and Solutions

Cyber Liability. Michael Cavanaugh, RPLU Vice President, Director of Production Apogee Insurance Group Ext. 7029

The Airport Casualty Market Overview

Capital management, capital allocation and the demand for insurance and reinsurance

The Surplus Line Association of Arizona Carrier Summary 08/01/ /01/2015

The Market for Lawyers Professional Liability Insurance for Large U.S. Firms*

Directory Of EL Insurers. List of Insurers and Old EL Accounts

Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance

Quarterly Listing of Alien Insurers October 2014

Global Insurance & Reinsurance Market Update Aon Corporation Australia Limited ABN

Quarterly Listing of Alien Insurers January 2012

CALIFORNIA DEPARTMENT OF INSURANCE

Aon & DLA Piper s 2014 Network Security & Privacy Symposium. September 2014

REINSURANCE & FRONTING MARKET UPDATE

Aon Risk Solutions Global Risk Consulting Captive & Insurance Management. Cyber risk and the captive market - a match made in the cloud?

MARKET OVERVIEW AND OUTLOOK

Managing Cyber Threats Risk Management & Insurance Solutions. Presented by: Douglas R. Jones, CPCU, ARM Senior Vice President & Principal

Mitigating and managing cyber risk: ten issues to consider

Welcome. to the Board of Marine Underwriters of San Francisco 20 th Biennial Marine Seminar. from. American Institute of Marine Underwriters (AIMU)

8 2014/2015 INSURANCE COVERAGE RENEWAL

Cyber Threats and the Insurance Response

EMERGING CYBER RISK CYBER ATTACKS AND PROPERTY DAMAGE: WILL INSURANCE RESPOND?

How To Protect Your Data From Hackers

Can space insurance offer workable solutions for outer space sustainability

CYBER & PRIVACY INSURANCE FOR FINANCIAL INSTITUTIONS

44562 Academic Medical Professionals Insurance Risk Retention Group Acceptance Indemnity Insurance Company

Cyber Risk: Global Warning? by Cinzia Altomare, Gen Re

TABLE G4 GENERAL INSURANCE: PREMIUMS OF SINGAPORE INSURANCE FUNDS FOR THE YEAR ENDED 31ST DECEMBER 2008 (PART I)

CALIFORNIA DEPARTMENT OF INSURANCE

2015 Report on Availability and Affordability of Health Care Medical Professional Liability Insurance in Maryland

Insurance Considerations Related to Data Security and Breach in Outsourcing Agreements

Are Data Breaches a Real Concern? Protecting Your Sensitive Information. Phillips Auction House NY- 03/24/2015

Acquisition of HCC. Significant international expansion by Tokio Marine. June 10, Tokio Marine Holdings, Inc. President, Tsuyoshi Nagano

Navigating Cyber Risk Exposure and Insurance. Stephen Wares EMEA Cyber Risk Practice Leader Marsh

BULLETIN B ELIGIBLE SURPLUS LINES INSURERS IN THE STATE OF ALASKA

Rogers Insurance Client Presentation

CYBER & PRIVACY LIABILITY INSURANCE GUIDE

CARRIERS WITH POWER OF ATTORNEY IN SUREPATH

SURPLUS LINES COMPANIES ELIGIBLE IN MONTANA. July 21, 2015

2.1 That the Committee notes the paper and the supplementary information on Part 2 of the agenda.

CyberSecurity for Law Firms

Cyber and Data Security. Proposal form

cyber invasions cyber risk insurance AFP Exchange

Ten Questions Your Board Should be asking about Cyber Security. Eric M. Wright, Shareholder

AT&T Global Network Client for Windows Product Support Matrix January 29, 2015

Deep Security/Intrusion Defense Firewall - IDS/IPS Coverage Statistics and Comparison

The Aon Benfield Aggregate

The Onslaught of Cyber Security Threats and What that Means to You

Achieving Cyber Resilience. By Garin Pace, Anthony Shapella and Greg Vernaci

CARRIERS WITH POWER OF ATTORNEY IN SUREPATH

A REPORT BY HARVARD BUSINESS REVIEW ANALYTIC SERVICES Meeting the Cyber Risk Challenge. Sponsored by

Hit ratios are still very low for Security & Privacy coverage: What are companies waiting for?

Advice and Reasonable Pricing Drive Customer Satisfaction with Brokers in J.D. Power 2015 Large Commercial Insurance Study

Aon Risk Solutions Aon Broking. London Market Review Property and Casualty. Risk. Reinsurance. Human Resources.

Data breach! cyber and privacy risks. Brian Wright Michael Guidry Lloyd Guidry LLC

DATA BREACH, NETWORK SECURITY, CYBER LIABILITY, PRIVACY PROTECTION: ARE YOU INSURED?

Deep Security Intrusion Detection & Prevention (IDS/IPS) Coverage Statistics and Comparison

February 2, 2015 LISTING OF APPROVED FOREIGN SURPLUS LINES INSURERS IN VIRGINIA

Cyber Risks in Italian market

CyberEdge. Desired Coverages. Application Form. Covers Required. Financial Information. Company or Trading Name: Address: Post Code: Telephone:

Privacy Liability & Data Breach Management Nikos Georgopoulos Cyber Risks Advisor cyrm October 2014

In accordance with risk management best practices, below describes the standard process for enterprise risk management (ERM), including:

Cyber and Reputational Risk Insurance. Past, Present, and Future

Cyber Liability & Data Breach Insurance Claims

Data breach, cyber and privacy risks. Brian Wright Lloyd Wright Consultants Ltd

West Virginia Offices of the Insurance Commissioner Workers' Compensation Carriers That Have Made Filings with the Rates and Forms Division

CYBER RISK SECURITY, NETWORK & PRIVACY

ISO? ISO? ISO? LTD ISO?

West Virginia Offices of the Insurance Commissioner Workers' Compensation Carriers That Have Made Filings with the Rates and Forms Division

Joe A. Ramirez Catherine Crane

COMPARISON OF FIXED & VARIABLE RATES (25 YEARS) CHARTERED BANK ADMINISTERED INTEREST RATES - PRIME BUSINESS*

COMPARISON OF FIXED & VARIABLE RATES (25 YEARS) CHARTERED BANK ADMINISTERED INTEREST RATES - PRIME BUSINESS*

THE REINSURANCE PRINCIPLES

Transcription:

PANEL DISCUSSION: Cyber Risk Insurance (Network Security & Privacy Insurance) 19 March 2015

Panelists: Cinzia Altomare, Manager Facultative, Gen Re, Italy Michael Shen, AVP, Liberty Specialty Markets, and the founding member of Cyber Risk and Insurance Forum, Great Britain Ivica Perica, Director at Business Advisory Services Department, Deloitte Adriatics, Croatia Zdenko Adelsberger, consultant for IT security and risks management, Bluefield, Croatia Moderator: Tin Lesić, Executive Director of Development, Aon, Croatia

If you can answer all of the following stop listening How did this happen? Are we sure it has stopped now? What type of information is involved? Where to find a lawyer who is knowledgeable in this area? Can the affected third parties sue and would cyber policy cover legal defense costs? Are cyber risks already covered under our existing insurance policies? Would cyber insurance policy respond if our employee steals information? Is offline data covered by cyber insurance policy as well? Do you notify the media and what are you going to say? Do you offer credit monitoring? Do you need to notify regulators, affected parties, the police, providers/suppliers? Are local or EU laws triggered and how do we comply?

Typical misconceptions about cyber risk We have a firewall, so we are protected. We have antimalware protection, so we are not at risk. We have the best IT department. Why would our organization be a target? We don t have an e-commerce website, so we are not at risk. We are compliant with PCI, ISO, etc., so we are not at risk. We outsource some of the processes / activities so the vendor will be liable for anything that goes wrong.

Typical misconceptions about cyber risk Our IT department is managing risk effectively Our existing insurance policies typically cover some cyber risk We determine coverage needs based on what our peers are doing Our data is not a high-risk target for cyber threats The cost of cyber insurance exceeds the incident cost The financial cost of an incident would not be significant Our industry is not at high risk for cyber threats We don t need it We re not subject to US style regulation I ve never had a cyber breach so I don t need this coverage We don t need it we outsource our security

Notable data breach incidents Date Breach Reported Jun 2014 Entity NYC Taxi & Limousine Commission Loss Estimate Not Known Records Impact (millions) 173M Oct 2013 Adobe Systems, Inc. Not Known 152M May 2014 ebay, Inc. Not Known 145M Jan 2009 Heartland Payments Systems $143M 130M Dec 2013 Target Brands, Inc. $200M 110M Jan 2007 TJX Companies Inc. $256M 94M Jun 2011 Sony $280M 77M Aug 2014 J.P. Morgan Not Known 76M Sep 2014 Home Depot $62M 56M Mar 2012 Global Payments $125M 7M Aon Risk Solutions

Aon Risk Solutions 7

Aon Risk Solutions

Aon Risk Solutions 9

Before you buy Risk finance is part of overall risk management program structure Quantification Transfer I. Risk & Exposure Assessment II. Scenario Quantification III. Risk Mitigation & Maturity Review IV. Insurable Risk Review Qualification Mitigation What can go wrong? What is the financial impact? How am I protected? Will my insurance respond?

What is Cyber? Where Online Offline Who Malicious Accidental Internal External What Technology Media Protected Data Financial Impact Crisis Expense Extra Expense Lost Income Defence Expense Regulatory Fine Liability

Who creates cyber risk? 8% 6% 17% 13% Internal Accidental Internal Malicious External Internal Unknown Unknown 56% Full Year 2014 Source: datalossdb.org

How could the Cyber policy respond? 5th March 2015 Breach of point-of-sale credit card systems in the US and Europe

How could the Cyber policy respond? 1st January 2015

How could the Cyber policy respond?

Insurance Coverage

Key features of cyber insurance

Use of third parties

PPM: Price per Million of Limit Comparative analysis for selected peers: Technology and Communications industry Aon Risk Solutions

Per Occurrence Deductible Comparison Comparative analysis for selected peers: Technology and Communications industry Aon Risk Solutions

A typical gap-analysis may look like this

Policy limits Comparative analysis for selected peers: Technology and Communications industry Aon Risk Solutions

European/London Cyber Insurance Markets Theoretical Capacity* in MM Any one Risk ACE Brit Aegis Catlin AGM CFC AIG Chaucer AIG Cat xs Chubb Allianz CNA Amlin Cove Underwriting ANV Endurance Arch HCC Argo HDI Gerling Ascent Hiscox Aspen Kiln AWAC Lexington Axis Liberty Barbican Markel Beazley Marketform Berkshire Hathaway Mitsui Munich Re Navigators Novae Pembroke Principia QBE Sagicor Scor Starr Swiss Re WR Berkley XL Zurich 300 250 200 150 100 50 0 *Not including new catastrophe capacity available on an excess/dic basis or from reinsurance markets

Cyber Risk Diagnostic Tool www.aoncyberdiagnostic.com

Cyber Risk Diagnostic Tool Aon Risk Solutions