Google AI
The Times Australia
The Times World News

.

Just 25% of business are insured against cyber attacks. Here's why

  • Written by: Jongkil Jay Jeong, CyberCRC Senior Research Fellow, Centre for Cyber Security Research and Innovation (CSRI), Deakin University
Just 25% of business are insured against cyber attacks. Here's why

In the past financial year, the Australian Cyber Security Centre received 76,000 cyber-crime reports[1] – on average, one every seven minutes. The year before, it was a report every eight minutes. The year before that, every ten minutes.

The growth of cyber crime means it is now arguably the top risk facing any business[2] with an online presence. One successful cyber attack is all it takes to ruin an organisation’s reputation and bottom line. The estimated cost to the Australian economy in 2021 was $42 billion[3].

Read more: Why are there so many data breaches? A growing industry of criminals is brokering in stolen data[4]

To protect itself (and its customers), a business has three main options. It can limit the amount of sensitive data it stores. It can take greater care to protect the data it does store. And it can insure itself against the consequences of a cyber attack.

Cyber-insurance is a broad term for insurance policies that address losses as a result of a computer-based attack or malfunction of a firm’s information technology systems. This can include costs associated with business interruptions, responding to the incident and paying relevant fines and penalties.

The global cyber-insurance market is now worth an estimated US$9 billion (A$13.9 billion). It is tipped to grow to US$22 billion by 2025[5].

But a big part of this growth reflects escalating premium costs – in Australia they increased more than 80% in 2021[6] – rather than more business taking up insurance.

So coverage rates are growing slowly, with about 75% of all businesses in Australia having no cyber-insurance, according to 2021 figures from the Insurance Council of Australia[7].

Challenges in pricing cyber-insurance

With cyber-insurance still in its infancy, insurers face significant complexities in quantifying cyber risk pricing premiums accordingly – high enough for the insurers not to lose money, but as competitive as possible to encourage greater uptake.

A 2018 assessment of the cyber-insurance market by the US Cybersecurity and Infrastructure Security Agency[8] identified three major challenges: lack of data, methodological limitations, and lack of information sharing.

Read more: How cybercriminals turn paper checks stolen from mailboxes into bitcoin[9]

Lack of historical loss data means insurers are hampered in accurately predicting risks and costs.

Because of the relative newness of cyber crime, many insurers use risk-assessment methodologies derived from more established insurance markets such as for car, house and contents[10]. These markets, however, are not analogous to cyber crime.

Companies may be hesitant to disclose information about cyber incidents, unless required to do so. Insurance carriers are reluctant to share data pertaining to damage and claims.

This makes it hard to create effective risk models that can calculate and predict the likelihood and cost of future incidents.

So what needs to be done?

Deakin University’s Centre for Cyber Security Research and Innovation[11] has been working with insurance companies to understand what must be done to improve premium and risks models pertaining to cyber insurance.

Here is what we have found so far.

First, greater transparency is needed around cyber-related incidents and insurance to help remedy the lack of data and information sharing.

The federal government has taken two steps in the right direction on this.

One is the Consumer Data Right[12], which provides guidelines on how service providers must share data about customers. This came into effect in mid-2021.

The other is the government’s proposal to amend privacy legislation[13] to increase penalties for breaches and give the Privacy Commissioner new powers.

Read more: After the Optus data breach, Australia needs mandatory disclosure laws[14]

Second, insurers must find better ways to measure the financial value and worth of the data that organisations hold.

The primary asset covered by cyber insurance is the data itself. But there is no concrete measure of how that data is worth.

The recent Optus and Medibank Private data breaches provide clear examples. The Optus event affected millions more people than the Medibank Private hack, but the Medibank Private data includes sensitive medical data[15] that, in principle, is worth far more than data regarding just your personal identity.

Without an accurate way to measure the financial value of data, it is difficult to determine the appropriate premium costs and coverage.

Cyber insurance is a new, specialised market with significant uncertainty. Given the ever-increasing risks to individuals, organisations and society, it is imperative that insurers develop robust and reliable risk-based models as soon as possible.

This will require a consolidated effort between cyber-security experts, accountants and actuaries, insurance professionals and policymakers.

References

  1. ^ 76,000 cyber-crime reports (www.cyber.gov.au)
  2. ^ top risk facing any business (www.aon.com)
  3. ^ 2021 was $42 billion (www.unsw.adfa.edu.au)
  4. ^ Why are there so many data breaches? A growing industry of criminals is brokering in stolen data (theconversation.com)
  5. ^ US$22 billion by 2025 (www.munichre.com)
  6. ^ than 80% in 2021 (www.insurancebusinessmag.com)
  7. ^ Insurance Council of Australia (insurancecouncil.com.au)
  8. ^ US Cybersecurity and Infrastructure Security Agency (www.cisa.gov)
  9. ^ How cybercriminals turn paper checks stolen from mailboxes into bitcoin (theconversation.com)
  10. ^ such as for car, house and contents (www.rand.org)
  11. ^ Centre for Cyber Security Research and Innovation (cybercentre.org.au)
  12. ^ Consumer Data Right (www.accc.gov.au)
  13. ^ privacy legislation (www.aph.gov.au)
  14. ^ After the Optus data breach, Australia needs mandatory disclosure laws (theconversation.com)
  15. ^ sensitive medical data (www.afr.com)

Read more https://theconversation.com/just-25-of-business-are-insured-against-cyber-attacks-heres-why-193533

Times Magazine

Why Is Professional Porsche Servicing Important for Performance and Longevity?

Owning a Porsche is a symbol of precision engineering, luxury, and high performance. To maintain t...

6 ways your smartwatch is lying to you, according to science

You check your smartwatch after a run. Your fitness score has dropped. You’ve burnt hardly any...

Has the adoption of electric vehicles led to new forms of electricity theft

Why the concern exists Electric vehicles (EVs) like the Tesla Model 3 or Nissan Leaf shift “fue...

Adobe Ushers in a New Era of Creativity with New Creative Agent and Generative AI Innovations in Adobe Firefly

Adobe (Nasdaq: ADBE) — the global technology leader that unleashes creativity, productivity and ...

CRO Tech Stack: A Technical Guide to Conversion Rate Optimization Tools

The fascinating thing is that the value of this website lies in the fact that creating a high-cali...

How Decentralised Applications Are Reshaping Enterprise Software in Australia

Australian businesses are experiencing a quiet revolution in how they manage data, execute agreeme...

The Times Features

Cost of living increases worry Farrer residents

COST OF LIVING ‘CRUNCH’ HITS FARRER HARD, THE NATIONALS HEAR During a visit to Albury this week...

What's On: Two Psychics and a Medium – Australian …

HIT LIVE SHOW TWO PSYCHICS AND A MEDIUM EMBARK ON  AUSTRALIAN TOUR — AND NO TWO NIGHTS WILL BE T...

Before vaccines, diphtheria used to kill hundreds each …

The Northern Territory[1] and Western Australia[2] are experiencing outbreaks of an almost-era...

realestate.com.au attracts the buyer for 9 in 10 listed…

New PropTrack data reveals the impact realestate.com.au has on property sales, with the  platfor...

The Hidden Threat Inside Data Centers: Why Fuel Degrada…

Data centers are designed with one overriding objective: uninterrupted operation. To achieve this...

Holidays: How to Book a Flight — and Protect Your Money…

For decades, booking an overseas holiday was a straightforward transaction: choose your destinat...

Olivia Colman, Kate Box to join an exclusive Live Q…

Fresh out of cinemas, JIMPA - the new film by acclaimed director Sophie Hyde (Good Luck to you, ...

Homemade Food: Cheaper Than Takeaway, Healthier Than Yo…

As the cost of living continues to bite across Australia, households are taking a harder look at...

The Coalition wants NDIS reform to focus on 3 things. H…

The government is expected to announce further changes to the National Disability Insurance Sche...