Welcome to Cybersecurity Insights, the podcast with the CyberEd.io Learning Community. Our goal is to bring Cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern Cybersecurity world. Good day, everyone. This is Steve King.
I'm the Managing Director at CyberEd.io and in our podcast session today, I have the pleasure of Libby Bennett's Company. She's the Global Chief Underwriting Officer at AXXL, at Division of AXA, the largest insurer in the world. She's a licensed attorney and an insurance industry expert who specializes in emerging issues like cyber security, with over 25 years in the cyber insurance space. No one is probably better qualified than Libby to lend a hand in understanding the present and future of insurance issues in the cyber security space.
And I believe that we're going to get more and more as time goes on here. Libby earned her undergrad in political science from Towson University and her JD from the University of Baltimore School of Law. So welcome, Libby. It's great to have you with us.
Thank you, Steve. I'm delighted to be here with you and your audience today. Yeah, terrific. Let's dive in here.
Tell us what has changed in the world of cyber security insurance in the last 12 months and how should the insured look at it from a risk transfer point of view and insurers from a risk, a shared risk point of view? Yeah. I'll tell you sort of the landscape over the last three years, if I might, to help express what's happened in the last 12. So in 2019, 2020, 2021, the insurance industry, as well as businesses and governments out there, saw quite a substantial uptick in ransom activity and the value of the demands for ransom.
We saw different types of ransom attacks that were going on and we really went from a period of time where ransom demands were like $500 or $1,000 to sometimes $15 million, $20 million, $40 million. So a real change in the threat actor behavior and the frequency with which this was happening. And then we saw, I would say, I guess it was in May of 2022, we saw the Biden administration kind of come off the porch after colonial pipeline was hit and you saw very public activity from the governments to try and reduce the attacks that were going on worldwide. And the governments collectively got together in the fall, there was a conference, and they worked actively law enforcement and others to try and tamp down these gangs.
And we did see an impact on the claim activity during this period of time. And then as we got into February of 2022, we saw, of course, Ukrainian war kick off and there was definitely a collapse of the ransom activity for about 60 days, 75 days. So we'd gone from this period where it was pretty benign, $500, you know, ransom charges all the way. Then we saw this huge surge of both frequency and we call severity, so how big the losses are.
And then we saw this trajectory that came down again because law enforcement is doing its thing and the Ukrainian war kicked off. And now we're seeing it returned back into somewhere between the 2019 levels of frequency. And so what that means for buyers of insurance is you're going to see price volatility because insurance is a product where we do not know what our costs of goods sold are. When we sit down, we're not like manufacturers where I can add up all my supplies and my labor, and I know what my unit cost is.
In insurance, we forecast what we think the losses are going to be. Then we add the margin, and we add our expenses, and that's what the price is when it goes out the door. Well, if you miss estimate your losses, you're going to have to raise your prices or you're going to have to restrict your coverage. You have to do something to get the portfolio back in balance.
So what we saw in the marketplace was really a very what we call a hardening market. People were not able to get the capacity, and what I mean by capacity is the stretch of limit they want to buy. Let's say you want to buy a $5 million policy, but no one will sell it to you, the only sell you a million. Well, for large corporations, they want to buy $500 million towers, and there were not enough players in the market to fill out that tower because we all that brought our limits down so we could reduce our loss exposure.
So that's a long way to tell you that there's a lot of market volatility in the last four or five years, and part of that has to do with how many players are in the marketplace from the insurance side, what the threat actors are doing, and how they're changing both the frequency and the severity of the losses that hit the industry, and all of those things impact the product that gets sold in the marketplace, and what can be bought by potential insurance out there in the market? That's a bit too unpack here, but are the insurance companies making any money in this business, say, in the last look at it over the last 12 to 18 months? I would say today, in the last 12 to 18 months, the answer is yes, but it's because the rates had to go up so substantially to cover the forecast of what the losses are going to look like. So I'll make a simple example.
If you think you're going to have a million dollars of losses, and so you price your product for a million dollar loss of expectation, and then you have five million dollars of losses come in. Then when you go to look for the next year, what you think your estimate's going to be, do you pick the million dollar estimate or do you pick the five million dollar estimate? So you're going to pick the five million dollar estimate because you don't know what caused it, caused it to come off the rails in the first place, and so then you're going to raise your rates so that you recoup that to be able to pay losses. So what happened is because the government started working on tamping down the criminal activity, and the Ukrainian war, our expectations of losses came down, but we were charging what we thought it was going to be had the activity not changed.
Does that make sense? Yeah, but the activity hasn't actually, if it's changed, it's increased, does it not? It increased this year in 23, but it had not in 22. It was down in 22.
Down in terms of numbers of breaches or in terms of total value of those breaches? Both. Yeah. And you attribute that to the Ukrainian conflict?
I attribute it to really to a number of different forces. So I think it's government activity to try and track down these groups. I think it's the Ukrainian war disrupted the threat actors themselves for a period of time. And I also think the industry tightened its security controls.
And we raised what's called, we reduced our limits. So if you used to sell 10 million of limit, now you're only going to sell five. And if you had a deductible on your program or a self-insured retention, we raised those. So you as a buyer would have more of your own capital at risk than the insurer, you know, as much as the insurer would have or depending on how big you are.
So think about it. Think about a $10 billion revenue company instead of having a $100,000 deductible. They now had a million dollars deductible. That's what I'm talking about.
If you're small business, it's quite different. So each of these markets, whether you're in a small market, a medium market or a large corporate market, will have different features to them. I'm just having to be talking about sort of a mid-market, large corporate kind of customer enterprise type customer. But the third thing that happened was the thinking of the security controls.
So all carriers that were losing lots of money in 1920 and 21 went through their claims activity determined if there was any themes about how we could be. What were the conditions that caused the losses or things that were not in place that made the insured ultimately sustain and breach? And things like multi-factor authentication and especially during COVID, ensuring that, you know, your port, your RDP and your VPNs are secure, those types of things became very important. And we could see people working losses because they had an open RDP port.
We use a number of tools to evaluate the insured security. One of them is outside in scans. They don't tell you everything, but they can tell you some basic hygiene about what's happening for that insured. And it can tell you pretty easily when they have some vulnerabilities that can be easily fixed.
So we look at those types of things. We look at the user access protocols that the companies are following and a number of other techniques and tools that we use to evaluate the risk. Yeah. I'm sure you do that.
And I want to come back to that because I have a question about that in specifically in a bit. You cover, I assume, both IT and OT security. If an OT environment gets attacked and there's a ransomware payment, does the policy differ comparing the two different environments? Yeah.
So the great question, because the original design of these insurance policies was really around privacy. So when they started in the late 2000s, they were really covering violation of privacy. And so think of all of our personally identifiable information. Then they expanded to cover sensitive corporate information.
So in that respect, they're really designed for the IT end of the spectrum because these policies do not cover property damage or bodily injury. So in the typical cyber policy, you'll have an exclusion for property damage and bodily injury. That's because those types of exposures are covered someplace else in the whole suite of insurance products. So we don't cover them in what we call the direct cyber insurance policies.
So if you were to have an event that caused a business interruption to the, because the operational technology got stole, you would have cover for that. But you would not have coverage for the equipment melting down because they'd hacked into the OT equipment and mess with the thermostat or something like that. So that kind of equipment breakdown exposure would not be covered under a cyber policy unless somehow you crafted and were able to get the carrier to sell you some specific cover for that exposure. Okay.
That would be covered elsewhere and other business insurance, right? They could be covered under an equipment breakdown policy. It could be covered under a property policy. So the particulars of these different types of risks actually have to be analyzed against the different insurance that a company buys.
Yeah. When we talk about the target case as a case example where, you know, I think everybody understands that their HVAC contractor had access to their core systems and that there was, let's call it weak security around the contractor's access. And that was kind of the source of the breach. We would typically would you expect that that that cyber insurance policy would cover third party attacks and would it also then include the contractor itself or, or just the origin of the attack.
So these direct cyber policies cover what we call first party or the insured personal losses, business losses, and they cover network security liability. So in the target case, if that HVAC contractor had purchased a direct cyber policy, the attack for the HVAC contractor that hit target target could put a claim against the HVAC contractor's liability network liability cover and would likely be covered because of the facts of this particular case. Now, an HVAC contractor is tiny. So maybe they have a million dollar limit, whereas target being the size company it is, you know, that's not going to be adequate to cover targets losses.
So while there could be insurance or there, there also could be a mismatch between the amount of damage the third party has and what the limit of liability is available to pay the loss. So in that case, I don't think the HVAC contractor purchased cyber insurance. So I think they only had a premises liability so slip and fall type of liability cover. So I'm not sure that it would have been covered under their regular business insurance.
They would have to buy a direct cyber policy. Now, if the HVAC contractor in this example, because of the attack that was because of the attackers went through their system and into the target system. If that HVAC contractor had sustained some business interruption or data damage or what have you, the first party side of that direct cyber policy would give compensation to the insured HVAC contractor in our example. Likewise, if target had purchased direct cyber policy, let's say they bought, you know, a $200 million dollar tower above first party and third party, they would have had cover first party cover for the losses they sustained.
So it just depends on when the partners get together, who has the insurance, how much insurance do they have, and whether or not it's adequate to cover, you know, one of the entities exposures. Yeah, but in this case, the HVAC contractor was clearly negligent and wouldn't the insurance companies claim that negligence in an attempt to avoid any kind of a payout to that we covered their, their exposure. And we say that they're, you know, were they clearly negligent? Yeah, I guess they were in a sense, but target gave them wide user access.
What does an HVAC contractor need access to a point of sale system for? Well, well, target also easily be argued. The target was also had the same liability. Right.
So what was the, so then you get into the proximate cause of the loss. What was the proximate cause of the loss targets, wide user access. Wappiness was the cause of the loss and kind of right. I mean, then we see that today every day, every time I turn around, more slides.
Yeah, it is. It makes sorting out who's responsible for what in these cases really tricky. In the case of target, neither one of them bought cyber insurance. The target loss was like 2014 or something.
And about six or seven years later, they tried to file a claim under their liability policy and ultimately the claim was denied, but it was, but because they didn't have the right insurance. They didn't buy the right insurance at the time. They tried to recover years later under their traditional business insurance, but they were not successful. Okay.
How often do these cases end up in court? Not that frequently. Right. Yeah.
I mean, the job of an insurance company is actually to pay losses. I know, I know people, you know, love to talk about the frustrations I might have with an insurer, but we're not in business. If we don't pay losses, that's our, that's our, you know, that is what our business is. When somebody gets a claim denied, it's because the adjuster who's looking at this doesn't believe the loss fits under the terms of the policy.
But I would say, I mean, I don't have exact statistics, but I would suggest that it's somewhere around 1%. I mean, it's a small number. And especially in the United States, the denial, depending on who your customer is, if it's a small business owner, you know, you can get regulators involved. If it's a large corporate, they can sue you, you know, you have to do a commercial analysis of whether it's worth it.
And so industry typically only fights claims when they feel like they have a solid legal footing or denying a claim and then willing to litigate it, but it's a small, very, very small minority of situations. Unless you're a Marisk. Well, Marisk's problem was they didn't buy a cyber policy. They brought a property policy and the property policies are never written to cover cyber.
Now the court disagreed with that interpretation. I don't fault the analysis of the court, but at the time these property policies, the language from these property policies are probably 25, 30 years old. Yeah. Okay.
So, I mean, the penalty goes to the carrier, right? Because the carrier could have changed the language and did not. Today, that would not happen. So many, like companies like mine, after not Pecha, we didn't wait for the murder case, but after not Pecha seeing what happened, the industry tightened the or clarified coverage under all of the non cyber policy.
So today, if you were to pick up a property policy, you would see a full cyber exclusion with a right back for fire or explosion. Yeah. Because trying to be as clear as possible to their insured is a cyber event covered only if it's concurrently causing a fire or an explosion is a cover. And you can buy back.
Again, everything's negotiable and everything has a price. So you can buy things back that you want to have covered under property policy, but today you would not see a Marisk case come up the way it did. Yeah. And so the people that are in the business of enterprise risk management, you know, let's call the board members and officers who make these risk decisions every day.
Always, you know, look to risk transfer as an alternate path to solve a risk challenge of one sort or another, right? I mean, some, you know, what's the probable cause? What's the probable probability of an event actually happening that would cause us that kind of a loss and how big could that loss possibly be? And that number is $5 million.
And the question is, you know, I'm an $8 billion company. What, you know, $5 million is like copy money, right? So I want to either accept that risk or transfer to insurance policy. It sounds to me like you're sounding to me like that avenue is going to be continued to be available to folks that are looking for ways to protect themselves from substantial loss in this business.
I guess the question is, do you see that will the whole industry be commercially viable as we head into the future? And if not, what kind of changes have to happen on, on behalf of the insured? So the way I would think about it is look at it. If I looked at it from the company or the insureds position, director of the board, president, the risk manager, whatever, you have a slew of risks.
Some of them, you can lay off to a third party like an insurer. Some of them you cannot. Insurance doesn't cover everything. It covers a subset of things.
So it's a tool, just like you're buying endpoint protection or you're doing employee training. Insurance is one of the tools in the toolbox. And when you buy an insurance policy, particularly in the cyber area, what are you buying? You are buying a network of professional crisis managers who have done this day in and day out.
When you've never had an event before, and you don't know what to do, you've paid for this entire bench strength of people who know exactly what to do, what to do in every state, what to do in other countries. That's what we provide is that whole network of support, and we get you back up and running as soon as possible, and we give you cash, offset the losses, for example, from a business interruption. So it is, if you've ever sustained a breach or ever worked with anybody that's out of breach, you'll know it's a catastrophic event. It can be existential for some companies.
What happens when they get around some? What are they going to do? How's it going to show up in the press? I mean, these are really traumatic events for the people who have to deal with them.
And so what you've got is this professional team of people who can help. I think as long as we're able to adapt our pricing based on what the threat actor behavior is, we will continue to be a viable market, but it will constrain how many new players come in. So if you want 4,000 insurance companies to participate, we need to have a much more stable way of dealing with cyber risk across insurance and carriers and how we look at the risk. Sure.
That makes perfect sense. You know, at one point, I think it was Martian and Microsoft had formed some sort of coalition and they were going to, and I think this goes back in five years, six years, something like that. They were going to offer a service to companies and they would come in and basically do essentially an audit and then they would publish their results and the basis of those results would be, you know, you'd get more expensive insurance coverage. You'd have different, you know, lost caps or what have you.
And then that sort of disappeared. To me and to others who are, you know, on our side of the fence, if you will in the business, you know, if you looked at sports warehouse, for example, they just figured out that they were breached over the last couple of years, and were buying some slap on the risk level fine for doing this. But you could, based on their, the way that they were set up from the technology in a process. And a hygiene point of view, you know, I could line up 20 people that could walk through that place and have told a given insurance assessment that would have said, you know, don't even go near this place in terms of writing a policy.
It seems to many folks in my business that that's true of a lot of companies. Why don't we have a process like that with Microsoft's probably not the right guys, but I mean, you know, a mandate or somebody that that offers that as, you know, some kind of a service that you could, you could purchase to help you make evaluation. Yeah, it's not, it's not on our side. We would do it.
It's on the insured side. So it's, you know, it's the security personnel that don't want their, don't want the information about their crown jewels and hands of third parties. So it's complicated. And what we know, wait, wait, when you said the inch, you mean the capital one, for example.
So the CISO's of insurance, right, wants to necessarily protect the information about the security of their firm. They want to protect it from outside eyes. And so the idea of having a third party, either an auditor, it's not required. So if it was a regulation, right, then we would have it, but we don't require it.
And generally speaking. And so what's the incentive for the CISO to participate and is really saving 50,000, 100,000, whatever on your insurance enough to bring them to the table. It's the right question you're asking Steve. And I think what we have to do as an industry is we need to raise the education level of the CISO's about what is insurance and what is it doing and how does it fit and why should you talk to us.
And right now we have intermediaries that stand between the insurance company and the insured and those intermediaries, agents and brokers, you know, they have a different job to do. So it's a complex, you know, situation, but on its face, it makes total sense to want to be able to have somebody translate the security of the internal security of a firm to the insurer so we can make better pricing and coverage decisions. That's to me, the no brainer, but it's not worked. And it's, you know, we keep trying, but.
So it's going to take the or FTC or somebody like that to lay down the law, essentially, it says you must, you must produce an audit, you know, an auditable result here. It's going to take government to require it because they won't do it voluntarily. The incentives aren't there. It's not where the incentives are not strong enough to make that.
To ensure that the insurers stop covering policy, you know, separating policies that that's a pretty good incentive right by itself. It is, except we have adapted our methods to try and detect the information we know that caused losses. So we evolve, we have client presentations, you know, we do, we do do a lot of investigation while we're working on whether we're going to ensure somebody or not. That's perfect as having an audit or somebody who's really can go in there and kick the tires.
Yeah, do you think that you guys do you think that the industry is a whole lot smarter today than it was, say, three years ago about what it's, you know, about the conditions that are that it's covering with these policies? Yes, I think it's a lot smarter. And I think we continue to search for the conversation with the security community to continue to educate and inform and to also provide insights on what the security community thinks ought to be done. I mean, we know in the standards, we know ISO 27,000, I mean, we know we know we know all that right, but there's stuff down the paper and then there's the real way you can have loss.
And so we've focused on the ways we know we've had losses. I mentioned those RDP and MFA, those types of things, we focused on that. And if you don't meet our security criteria, we will not write you. So we are we have taken a strong position there, but we've also seen that ensures it really stepped up their game.
So both are happening at the same time, and those that are not carrying insurance, many of them have decided they're not paying a ransom. So that's also having an impact on the threat actor behavior. So it remains a very vivid, full blown sport out there between threat actors and the good guys to try and secure our businesses and our homes and our governments. Yeah, I have a kind of a little bit off the wall question for you, your personal opinion about if the FBI, for example, has an adamant position, which they seem to have about not paying ransoms.
Isn't there a collateral duty on their part or at least one that's implied that suggests that if you're not going to pay the ransom, the government, however you think of the government has a has a collateral duty to support your future in light of whatever's about to happen to you because you refuse to pay the ransom. I think the current sanctions regime is trying to pick on the wrong party. So in answer to your question, I wouldn't put it as I have a duty, but I think they're missing an opportunity. The government understands very well because it's protecting government and the military, et cetera.
They have a very, they have a much stronger picture of what's really happening out there. And I as a commercial entity, you know, I've got a view, but I got to buy it from private sector people who are sending in threat of intelligence information or whatever. And what would be really useful is to be able to have a window at the government where you could say I'm a victim of a cyber attack. What do you got that can help me?
And they don't do it that way. Right. If you were mugged on the street and you went into the police station and you said you were mugged, they would try and help you. They get you to the hospital.
They would, right? They would help you. And you wouldn't be victimized again because you did something with a gun in your head. So it's, I think, I think this tactic is the wrong, personally, there's not an on speak for my company.
But personally, I think it's the wrong tactic because what you want to do is you want people to report and you want people to come to you and help. But by having a strict liability regime hanging over their head, they're making a very, you know, you're making a really risky decision when you make that payment. Absolutely. Absolutely.
It's not helping. It's not helping. We have an opportunity with the government to improve, I think, the support of people who have embraced. And it's in the government's interest to try and come up with that because most of our critical infrastructure is in private sector hands.
So even if we don't care about the dry cleaner around the street, we do get around the corner. We do care very much about, you know, very large enterprises and our critical infrastructure and what have you and we should be trying to see if we can collectively find some support for our communities. Amen. It's been a delightful 35 minutes or so, and I appreciate you taking the time out of your schedule to meet with us and answer some questions and discuss some of these issues that I think, you know, a lot of people I don't understand and, you know, cyber security insurance is a fairly arcane topic.
I think and there's lots of opportunity here for improvement both on, well, certainly on behalf of the insurance conditions and and I hope that as we go forward, you know, to your point about getting a lot smarter in the last three years and we have been prior to that, that we also on the insurance side can learn from that and aren't so broke, you'll, I guess, about about not being willing to have other folks come in and render their opinion about our insurability, if you will, against these things. So thank you. I hope we can get back together again in a few months and talk some more through this and see what's changed in that period of time. Well, I'd like to thank you to Steve.
It's been a real honor to be able to come and do this podcast with you. It would be delighted to come and speak again and I'm also quite interested in any feedback on what we can be doing from an industry standpoint, to be more understandable. How can we're not doing a very good job getting our message out, I think sometimes and would welcome the opportunity to do a dialogue on how we could be better at that. So look forward to speaking with you again.
Terrific. Thank you to our audience for hanging with us here through another session. I hope you found equally engaging and until next time, this is your host, Steve King, signing up. Thank you for joining us for another episode of Cyber Security Insights.
You can connect with us on LinkedIn or Facebook or send us an email at social at cybered.io. For more information about the podcast, visit cybered.io or a podcast. Until next week, stay safe and secure, and we'll see you on the next episode of Cyber Security Insights.