Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor with KuppingerCole Analysts. My guest today is John Tolbert. He's the Director of Cybersecurity Research at KuppingerCole and I'm glad to have him here.
Hi, John. Matthias, glad to be here. Great to have you and it's a bit of a change for today.
Usually, we are talking about on the one hand either three or four letter acronyms with the newest technology in cybersecurity or we are just talking about concepts and the newest technologies in cybersecurity but this time it's a bit different. We want to talk about a topic that sounds a bit boring but it isn't. We want to talk about cybersecurity insurance. Why are we doing this?
You know, it's not boring and we can make an acronym out of it if you want. We can just call it CI.
You know, it's actually pretty fascinating as a subject because it really does incorporate a lot of cybersecurity topics and as we'll dig in, we'll learn a little bit more about that. This is actually a preview of a paper that I'm hoping to get published next week on cybersecurity insurance.
You know, and in that, I want to cover what are the prerequisites for getting it, what are the reasons why people look for cybersecurity insurance and then what are some of the risks that are covered and finally our recommendations. So, yeah, I think it's an important topic and really for many organizations it's a part of their overall enterprise risk management strategy.
Right, and I think that that's the important part. So, where it's not only technology, it's only also processes and it's in the end also insurance to cover parts thereof of what is the threat landscape. Neither me nor you, we are no lawyers but we talk about that as practitioners or as analysts to really find a better, bigger picture of all of this. Maybe we can start with that. Can you give me an overview of what cybersecurity actually is and which role it actually takes? I just made a hint at it, but what is it really? Cybersecurity insurance, you mean?
If you think about other forms of insurance, this has evolved over the last 25 or 30 years. It's actually been around longer than you might think, but it's still relatively young compared to other types of insurance. If you think of business liability insurance or property casualty insurance, it's sort of a way of paying up in advance, saving money to help you in situations where you're faced with a really, really big expenditure. And of course, most insurance companies though do turn a profit, so there's a profit motive for them too.
But cybersecurity insurance is really designed to help you, maybe as a small or mid-sized business or even enterprise, deal with situations where you have a catastrophic cybersecurity incident. And that can be, well, the first thing everybody thinks about is ransomware. And even though cybersecurity insurance has been around for going on 30 years, it really got the spotlight when ransomware sort of exploded on the scene, roughly eight to 10 years ago. And since then, many organizations have sought out cybersecurity insurance policies to help them get through major events like that.
Because the cost of a ransomware attack, I mean, you'd see various statistics all over the place. And I think maybe those statistics provide you the averages, 4 million for this or 2 million for that, but you really don't know what the cost is going to be to your own organization until it happens. Because it depends on how prepared you are, whether or not you can have backups you can restore from, what your overall cybersecurity posture is, were you able to limit or contain the damage? And that's just the breach response stuff.
I mean, yeah, Matthias, you're right, we're not lawyers and we don't play them on podcasts either, but you have to engage legal professionals to help you get through this too. And those are costs that a cybersecurity insurance policy could help you with as well. Right. And you said you made some research around that, so an advisory notes or a rather in-depth document. And if the audience listens to that right now, I think it will already be published once they are listening to that.
But when we look at the overall landscape of how to protect cybersecurity threats really striking you, what are the key technical requirements that organizations must meet to get such a cybersecurity insurance? Because I think they cannot just lay back and say, okay, I'm covered. I don't have to create this fancy cybersecurity infrastructure because if something happens, they will pay. So what is the part that the actual organization needs to do?
Well, that in itself is what I think makes this a really interesting question because you're right. An insurance company isn't going to insure you if you don't have some things in place to start with. And what I've discovered is that there are many different insurance providers. Many of your old standard insurance providers now offer cybersecurity cybersecurity liability insurance, more formally called. And then there are also some newer companies that just specialize in cybersecurity liability insurance.
And at the very top of the list on every one list of prerequisites you have to have is multi-factor authentication. So that is pretty much across the board. Multi-factor authentication, of course, is having something in your possession, something you are or something you know to really provide a much higher level of authentication assurance. And that is necessary to be able to get access to very sensitive resources. So insurance policies will require multi-factor authentication in place to protect those sensitive resources and more generally for all users.
And it's just a good cybersecurity practice. Then we also see, you know, lots of other things.
And again, this can vary depending on the insurer you may be working with or the broker that you may be going through. But they also tend to like to see things like zero trust network access, a full identity and access management deployment, not just MFA, not just zero trust, but this would also include things like identity governance and good authorization systems. I've seen called out the need for attack surface management. This is looking at what assets your organization has, both internally and externally, and then being able to do vulnerability assessments and risk prioritization.
Endpoint security, EPDR, endpoint protection detection and response. Every endpoint needs some sort of security mechanism to defend it against ransomware and then also or other forms of malware and then be able to respond to that. We see managed detection and response sometimes called up. So having a third-party firm help you with managing your EPDR and network security and other things. And a really interesting development here is some of those newer cybersecurity insurance providers are actually MDR service providers.
And in order to get coverage, you need to be able to sign on with them to essentially help you with your security. That makes a lot of sense from their perspective because they can more directly control their risks and they're also controlling your security.
Other things on the list, you know, network security solutions, firewalls, network detection and response, network segmentation, email and web security gateways, because so much malware, especially ransomware, comes in through email, cloud security tools, privileged access management, monitoring, having a security information and event management system, vulnerability and patch management, and then process things like employee security training, having an incident response plan, having reliable data backups, using data encryption, and lastly, I see this more and more too, having a vendor risk management program to know which vendors you're using and what risks you may be accepting by using their software, for example.
So other than I said before, you need to be really good at cybersecurity. You need to have a full range of cybersecurity technology and processes in place to be even in the position to get such a cybersecurity liability insurance, as you said. So it will be really the cherry on the icing of the cake. So you need to do everything yourself. And then if still there is a residual risk that can kick in, then maybe the insurance would take over the liability.
And maybe there's also some kind of misconceptions around even when you are at that point, there will be even again, threats and risks that are still not covered. And that is often a misconception that people don't understand what is covered, what is not, even if you're doing cybersecurity really well. What would be something like that, that is not covered well?
Well, even looking at the list of requirements like vulnerability and patch management. So they will expect you to keep your infrastructure up to date.
So if you, let's say, have a bunch of desktops or laptops that are not up to date with patches, then if they're compromised, then that might constitute a breach of the policy conditions too, and may make it so that they may not pay a claim. So that is definitely something to think about. Other things that are typically not covered would be, okay, let's say you have a breach or you have a compromise and you realize that there are a lot of things that you do need to upgrade. In many cases, they will not cover post-attack upgrades.
There are some cases where if you get the right policy, they may cover some of the enhancements afterward. They call that betterment if they do, but this is not usually part of the base policy. It's something you may have to ask about if you can add that kind of coverage. Pre-existing incidents, let's say you get hit and, you know, it may take months to recover from it. You really can't go out during that recovery process and try to engage an insurer because you're in the middle of an incident.
The vulnerabilities too, if you, if during the process of discovery they find that you have vulnerabilities that aren't patched, they'll make you patch those before you could get insurance. Many times there are insider threats, anything that might be considered negligence. That's another reason why employee security training is really important, but also just if it is determined that an insider deliberately did something to sabotage or steal data, many times that won't be covered. War and terrorism, there's a lot of chatter about that these days.
Can you add a war and terrorism rider to a policy? In general, base policies do not cover things related to war and terrorism, and since there's plenty of that going on in the world today, you can understand why organizations are asking about that. Fines and penalties, so there are some cases where certain kinds of fines and penalties might be something that can be reimbursed, but certainly not all. And GDPR is a leading candidate for not being covered in most countries within the EU. Lost revenue beyond the policy limits. When you get an insurance policy, it's going to have a cap on it.
You know, this is the maximum amount they'll pay, and if you happen to overrun that, you're not going to be reimbursed beyond whatever the policy limit says. Damage to property, bodily injury, now you think maybe how can a cyber attack do that? But we've seen, unfortunately, quite a few instances where hospitals have been hit with ransomware, and the, you know, doctors and clinicians are not able to deliver medicine on time or do surgery. Those can generate, you know, sizable claims, but those are not covered by cybersecurity insurance.
You have to have a, of course, a separate property and casualty insurance policy for things like that. Yeah, there's a long list of them. I'll just highlight one more. Wrongful collection. I think this one is really interesting, because think of how many consumer-facing organizations collect PII or even personal health information about clients, and if you're collecting too much, and too much would be defined by, you know, whatever you set out in your privacy policy, and then you've had people consent to that.
If you're collecting and storing more information than you should, and that gets breached, then that in itself can be a reason why an insurer wouldn't pay a claim, because they consider it wrongful collection of a PII. Data minimization, only collect what you need and get rid of it when you don't need it anymore should be a real motivator there too.
Right, and that would be best practice, and exactly that is what the perspective that I wanted to take for a second. So, if we look at this cyber and the liability insurance from those who want to protect themselves, their organization from cyber security threats, the cyber incident costs are rising, the investment into cyber security technology are rising, and now we add the aspect of having a cyber security liability insurance.
This is a strategic decision, or at least an operational decision to say, okay, shall I invest into a new technology to protect me from things happening at all, or should I invest into the cyber security liability insurance? These are strategic decisions, so how can, or how should organizations weigh the costs of those to each other and make the right decisions? Is this an analyst job, and is this a CISO job? Who does that, and what are the mechanisms that should be in place?
You know, that is an excellent point. In doing this research, I've talked to several CISOs, and the approach to whether or not you want to engage a cyber security insurance provider may depend on your own maturity and strengths and posture of your cyber security infrastructure.
So, as we all know, there have been more and more ransomware attacks and other kinds of security concerns, fraud, things like that, such that people are out there wondering, is cyber security insurance something that we should do? But premiums, of course, the amount you have to pay to get a policy and maintain it have also gone up a bit, especially in the last couple years. It looks like the premiums have kind of leveled off for some customers, at least, but premiums are pretty expensive.
And then, you know, you have the cap on the coverage that you can get. So, I've talked to some organizations that have decided it's too much to pay the premium. We would be better off investing that money that we would pay for premium in upgrading our infrastructure or maintaining it or hiring additional staff.
So, that is a very valid thing to do if you feel like, and you have had analysis to say that your infrastructure is good enough. You've got the backups, you have an incident response plan, you practice it on a regular basis so that you know you can recover from a serious incident.
But then, on the other hand, you have maybe small mid-sized businesses that may not have a fully staffed SOC, Security Operations Center, may not have all the pieces there in terms of process. Because like we said, you know, you're going to have to be able to demonstrate in one way or another that you have the infrastructure that can withstand an attack. But maybe you don't have enough people. In this case, a cybersecurity insurance policy could be very advantageous. And a lot of it, too, depends on your cash flow.
If you have a big reserve and you can take a $3 million expense in a given quarter and it not affect the rest of your business operations, maybe you don't need that. But many companies, many organizations don't have that big reserve.
And again, paying the premium is just kind of like paying it ahead so that when something happens, you've got that money on hand to be able to sustain your operations and make payroll and meet your other obligations. So, it really is a organization by organization decision that needs to happen. We can't really make a blanket recommendation that, yes, everybody should go and look at cybersecurity insurance. There is a chance you don't need it. But if you see that maybe you have a gap in your overall enterprise management strategy, cybersecurity insurance could be an important part of that.
So, definitely something to think about. Interesting.
Really, really interesting. So, it's really a decision for the individual organizations that also might require some assistance from outside, from peers, to support you in your decision making. If we now switch the perspective over to the insurer.
So, they need to understand the cybersecurity threat landscape at any time. So, they need to adopt to what is happening out there.
So, how are these cybersecurity insurers adapting to what's happening right now? If we think of AI-driven attacks, deep fakes, whatever, it's just happening. Ransomware as a service.
So, there are things happening at a high pace and a large volume. How can they adopt to what's happening? Is this something that you looked into as well? Yes. I think that's why we see a few cybersecurity insurers offering managed detection and response services directly. And there are other cases where these insurers are partnering with MDRs or MSSPs so that they can have a recommendation for their clients and their client prospects for having a service provider who can help fill in some of those gaps.
We also see that in many locations, insurance, cybersecurity insurance are sold through brokers. So, a broker might represent multiple cybersecurity insurance companies. The brokers then take on the role of doing some of that initial assessment to see whether or not a given client prospect would meet some of the initial policy terms and conditions.
So, brokers may either hire their own cybersecurity experts who can do these assessments or we also see in many cases brokers partnering with cybersecurity consulting and analyst firms to understand what a given client prospect has, what they might need. That way they can decide, A, whether or not they want to underwrite it, and B, what the cost premiums might be, what the cap for the policy might be, and then actually make technical recommendations to their clients and client prospects.
So, yeah, we do see this industry maturing. We see more specialization, and yeah, that is likely driven by the frequency and the changing nature of the attacks. Maybe a final topic to look at that, and this is really an interesting topic, and I excuse for saying boring. It is not.
So, the legal and compliance considerations, many organizations, those in critical sectors and finance, they need to make sure that they fulfill their NIS2, DORA, GDPR, HIPAA, whatever, and how important and what kind of role do cybersecurity liability insurances play in that context? Can they help? Can they support in demonstrating compliance with these regulations?
Yeah, you know, the first thing that comes to mind is many times if you have a cybersecurity insurance policy, they, in addition to having MDR or MSSP services or companies they can recommend, they can also put you in contact with legal teams that specialize in this. So, you'll want to talk to a legal team for a lot of different reasons.
I mean, you may have your own inside counsel that you can work with, but they might also want to talk to people, external counsel, that can help with specific questions around this. They can help you look over the policy terms and conditions and see if they are favorable for your organization. They can help you prepare to have an incident. It's always good to have, you know, a legal team that you have sort of retained already so that when something happens you can just call them and get working on it immediately.
They can help you with, you know, preparing communications for when an event happens. And then, yeah, the regulatory piece. They can help you understand what are your reporting requirements. Things like GDPR and NIST have reporting requirements and you as a CISO or a member of the security staff need to understand when an event happens, how long do you have to get all that preliminary information together before you have to report it to the authorities and then the public.
I think definitely you'll want to have good legal advice from the beginning of the time when you're trying to get a policy all the way until the point where you, you know, unfortunately have an incident. So there's lots of reasons why having a good legal team in place or on call can help you. Same thing with knowing who the proper law enforcement organizations or governmental authorities that you need to report to or to be able to get assistance from.
That also, this process of trying to get a cybersecurity insurance policy could help you make all that more clear. Thank you. Really interesting. Thank you very much, John, for explaining all of this. I can only recommend to the audience to read the document. It should be out when you listen to that. I'm looking forward to reading it as well. If you have any specific questions to John or about this topic in general, please leave a message below that video on YouTube or drop us a mail. We are easy to find at copyandgold.com. We really are looking forward to having or to continue this discussion.
And there's so much more questions that I could ask, but the time is over for this episode. So please reach out to us, reach out to John, let us know what you are interested in. This is a new topic for many. It's already a topic that's been out there for a while. So maybe we can share also best practices and experiences and more input from your research, John. Thanks again for being my guest today, John. Thank you. Looking forward to having you soon. Bye-bye.