Insurance and enterprise: cyber insurance for ransomware

Страхование и предпринимательство: киберстрахование от атак с использованием программ-вымогателей
Tom Baker, Anja Shortland
2022-12-04

correlated lossescyber insuranceinsurance-as-governancemoral hazardransomware
Abstract Selling insurance gives insurers an incentive to manage insured risks. The “insurance-as-governance” literature demonstrates that insurers often make insurance conditional on ex ante risk reduction or mitigation. But insurance governs in support of enterprise, not security for its own sake. Tight underwriting inhibits enterprise—not only for insured businesses but also for the business of insurance. This paper highlights ex post loss reduction as a form of insurance-based governance. Drawing on interviews with industry insiders, we explore how insurers addressed the evolving problems of moral hazard, uncertainty and correlated losses since the 1990s. We find that cyber insurance developed sophisticated remedies to contain liabilities and quickly restore affected IT systems, but largely left security decisions to the insured. This facilitated enterprise in the short run but undermined security in the longer term: funding and expediting ransom payments encourages further attacks. As businesses improved their resilience, cybercriminals adapted and ransoms escalated, calling insurability into question. Yet there remains little appetite for imposing restrictive conditionality in this highly competitive market. Instead, insurers have turned to governments to contain criminal threats and cushion catastrophic losses.
1
As businesses improved resilience, cybercriminals adapted and ransom demands escalated, increasingly challenging the insurability of ransomware risks.
2
Cyber insurers developed mechanisms to contain liabilities and rapidly restore affected IT systems while largely leaving security decisions to insured firms.
3
Despite these challenges, competitive pressures limit restrictive underwriting; insurers instead seek government help against criminal threats and catastrophic losses.
4
Facilitating ransom payments supported enterprise continuity in the short term but weakened long-term security by encouraging further ransomware attacks.
5
The paper identifies ex post loss reduction, rather than strict ex ante conditionality, as a major form of insurance-based cyber governance.

cyber insurance for ransomware affecting insured businesses and their IT systems

insurance-based governance of ransomware risk, including ex post loss reduction, liability containment, IT-system recovery, and the effects of ransom-payment incentives on security and insurability

Publication Details
Publication Date
2022-12-04
Journal
Publisher
ISSN
Cited by
42
Access Type
Author Information
Authors
Tom Baker
Anja Shortland
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%