Cyber Insurance: A Snap Poll for the Celent Executive Panel
Available Only for Members of the NA Celent Insurance Executive Panel
Abstract
Snap polls reflect questions posed by members of the Celent Executive Panel, a group of C level executives in the insurance industry. We had related questions from two insurers on cyber insurance, so combined them. The first insurer is coming up on their cyber insurance renewal and would like to get a sense of what other insurers are seeing. The other insurer has a question about how others are handling cyber insurance for their data in the cloud and controlled by the cloud provider.
This deck provides a summary of the responses to a Snap Poll conducted September 12– September 17, 2023. Questions for a snap poll come from one of the other members of the panel. The snap poll was fielded to select members of the Celent Executive Panel, a group of C level executives in the insurance industry. 13 Insurers responded to this survey over the course of 5 days
If you are an insurer and are interested in participating and receiving these snap polls, please email kcarnahan@celent.com to verify eligibility.
The question that was posed was:
Background:
This insurer is coming up on the renewal of their cyber insurance policy and would like to understand what others are seeing.
Questions:
- What coverages and limits do you include in your cyber insurance coverage?
- Have you ever exceeded your limits?
- Does your carrier provide remediation and forensics support?
- What is your deductible?
- Did you see any new restrictions?
- Did you see any notable change in pricing?
The second question is from an insurer who is trying to understand the best way to insure their data in the cloud.
Background:
This carrier has moved their core system to the cloud.Their data is in the SaaS provider’s cloud.The SaaS provider, a tier one organization, follows industry best practices; and their contracts state that because they follow these practices, that should a breach occur, they would report the issue; perform root cause analysis; assist in mitigation efforts; but would not be liable for the breach. They claim liability must be fault based, so it is incumbent on the insurer to insure against that risk.
Question
- What are you doing about liability in the event of a security breach when your data is in a SaaS providers environment and not in your own control?
- Are you insuring for this event?
- How has your cyber insurer responded to the need to insure data under someone else’s control?
- Have you seen any specific terms or conditions from your insurer around this issue?