Search
Close this search box.

SolarWinds could have ‘chilling effect’ on cyber insurance

oie_oA2um37NukYk

SolarWinds could have ‘chilling effect’ on cyber insurance

Is this massive cyberattack ushering in a new era of hackers increasing their focus on supply chain vulnerabilities?

“Ultimately cyber insurance is going to demand a level of underwriting precision that is probably higher than any other form of insurance because of the nature of risk,” Seth Rachlin, of Capgemini, said. 

The overall damage dealt by the SolarWinds incident is still be determined, but the event could send shockwaves through the cyber insurance market, as it highlights the massive exposures this sector must contend with as hackers revamp their approaches.

Brian Krebs, a well-known security and cybercrimes journalist, noted the SolarWinds incident might have exposed as many as 18,000 customers after installing what they thought were routine software updates. However, hackers injected malware into the update. This gave the malicious actors, who are believed to be Russian-backed, undetected and unfettered access to high-value data.

“SolarWinds will have a chilling effect on the market,” Seth Rachlin, executive vice president and insurance lead at Capgemini, told PropertyCasualty360.com. “The most interesting aspect is that it is a supply chain attack.”

He explained typical cyberattacks in the past used methods such as phishing to gain access. These were attacks on a single organization. With a supply chain attack, the vehicle of entry is something used by many companies, such as SolarWinds’ security automation software. This results in cataclysmic events involving hundreds or, in the case of SolarWinds, thousands of companies simultaneously.

“From a market perspective, insurance companies tend to not like things like this,” Rachlin said. “This could become a sort of model event, if you will, for attackers going forward.”

While bigger payouts could be part of the reason hackers start deploying this strategy, he told PC360 it is more about other forms of malicious actions.

“Russians aren’t concerned with the payday; they want access and disruption,” Rachlin said. “As it moves to more state-based actors, some of the ransomware activity will really be a form of disruption. I’m not convinced it is so much about money as it is about power and economic influence.”

Is SolarWinds a cybercrime stalking horse?

Given the SolarWinds breach went undetected for months, there is a possibility a similarly scaled malicious endeavor is currently being run.

“There is always a chance, particularly given that a lot of the objectives of certain breach events is to steal secrets and data,” Rachlin explained. “The hackers are getting pretty crafty at doing this in an unobtrusive way. More and more, the time between the actual event and awareness of it seems to be growing.”

For some carriers, this has been a wake-up call to how pervasive cyberattacks can be.

To stay ahead of these developments, Rachlin said insurers need to consider the evolution of cyber insurance products to include more risk management and “protection type” features as opposed to strictly focusing on risk transfer.

“Ultimately, cyber insurance is going to demand a level of underwriting precision that is probably higher than any other form of insurance because of the nature of these risks,” he said.

Additionally, the industry should look at working with government agencies on something similar to the Terrorism Risk Insurance Program that would trigger protection mechanisms following catastrophic cyber losses. This, Rachlin explained, would bring stability to the market.

Leave a Reply

Your email address will not be published. Required fields are marked *

Related posts

Insurance-technology

Hard Market Needs Tech & Creativity: Navigating Challenges in the Insurance Industry

The insurance market is experiencing significant instability due to inflation, the global pandemic, evolving cybersecurity risks, and climate change. According to experts at Send’s INFUSE webinar titled Navigating the Hard Insurance Market, innovative technology and creative product design could be key in bringing stability to this challenging environment. Rising Risks and Challenges The growing frequency of weather-related disasters has especially made risk assessment difficult for insurers. Tandis Nili, managing principal of global risk management at Epic Insurance Brokers, highlighted that underwriting has struggled to keep pace. “Weather patterns are changing rapidly, and the underwriting models we’ve relied on are no longer sufficient,” Nili remarked. The traditional methods of predicting risks, based on past events, are no longer applicable as 100-year events are now happening much more frequently. Leveraging Technology for Stability Martina Conlon, executive principal at Datos Insights, emphasized the importance of utilizing automation and artificial intelligence (AI) to address this volatility. AI-driven predictive models, she explained, can assist insurers in making more accurate risk assessments, which in turn leads to better pricing and more efficient processes. “It’s all about moving beyond traditional tools like spreadsheets and policy systems,” Conlon said. By integrating more advanced technology, insurers can streamline operations and enhance accuracy in their assessments. Creative Product Innovation Another critical aspect in managing the hard market is innovative product design. Jennifer Kyung, CEO of NextGen Underwriting, discussed the opportunities for insurers to rethink product structures. This could involve adding new lines for emerging risks or restructuring existing products to share the responsibility between insurers and clients. For example, home insurance policies could evolve, particularly in regions facing heightened risks due to climate change. “This is a real opportunity for underwriters to creatively design products that better align with future risk landscapes,” Kyung added. Preparedness: A Key Lesson Lastly, the past few years have highlighted the need for insurers to be prepared for the unexpected. While it’s impossible to predict future events, the industry can ensure that it has the right tools and capabilities in place to respond swiftly and effectively when crises arise. As Kyung put it, “We may not predict what’s coming, but we can be ready for whatever it is.” Conclusion In today’s volatile market, insurers must embrace both technological advancements and creative product design to navigate the evolving risk landscape. By doing so, they can enhance stability, build consumer trust, and be prepared for future challenges.

Read More
Commercial Auto

Around the P&C Insurance Industry: November 20, 2024

Porsche Auto Insurance:Launched an unlimited insurance product for high-mileage Porsche owners driving over 10,000 miles annually. This complements their pay-per-mile policies, allowing owners to choose fixed premiums or mileage-based options. Multiple vehicles on a single policy can also have mixed coverage. Safeco Insurance:Entered a book transfer agreement with Main Street America Insurance, enhancing its personal lines presence in 22 states. Main Street America is shifting focus to commercial lines, including commercial products and bonds. Resilient Cities Network & Tokio Marine Group:Partnered to bolster urban resilience projects. The collaboration supports the Resilience Finance Taskforce, helping cities globally scale investment strategies for resilience and climate adaptation. Skyward Specialty Insurance Group:Introduced life sciences liability coverage tailored for the life sciences industry, addressing risks such as medical liability, errors and omissions, and general liability. This strategic move supports the complex insurance needs of healthcare innovators. AAIS Partner Program:Welcomed Sproutr, offering AAIS members access to tools and services that streamline operations and foster growth in insurance processes. Duck Creek Technologies:Opened its second Center of Excellence in Warsaw, Poland, enhancing global customer service capabilities, particularly in Europe, the Middle East, Africa, and the Asia-Pacific regions. Liberty Mutual & Coursera:Launched an entry-level course, Insurance Sales Agent, to train learners in risk management, sales, and ethical practices, equipping them for careers in insurance sales. World Insurance Associates:Acquired United Counties Insurance Group of Old Bridge, NJ, expanding its regional operations. Previsico:Unveiled Instacasting, a flood mitigation solution using rainfall data for real-time surface water flood predictions, enabling faster and more precise response strategies.

Read More
Try your instant quote