Confronting cyber risk
Cyber risk is a global phenomenon which the insurance industry has yet to get a grasp of, but the threats and attacks continue to evolve and increase in both frequency and severity. NTU Nanyang Business School Professor Shaun Wang shares his take on the current cyber risk landscape, the challenges in building cyber resilience, as well as key learnings from recent attacks such as the SingHealth data breach in Singapore.
What is your assessment of the current cyber risk landscape in Asia?
Cyber risk is a global phenomenon and Asia has had its share of cyberattacks and data breaches (eg, Bangladesh central bank heist, SingHealth data breach), which have raised public awareness of the threats of cyber risk. Organisations in Asia are generally lagging behind their US and European counterparts in ensuring that they are covered by cyber insurance. While there is a lower demand in Asia for cyber insurance cover, we noticed that the region is becoming more proactive and catching up as companies have begun showing more interest in obtaining cyber risk protection.
The threats associated with cyber risk will not be going away any time soon and will only continue to increase and potentially cause damage and disruption to the Asian economy. Asian countries must address cyber threats head-on by enhancing their cyber risk management capacity through proactive policies and enabling the business community.
While the need to tackle cyber risk is a given, what core challenges do organisations face in preparing themselves?
Large corporations (especially in the financial sector) typically have more resources and expertise to beef up their cyber security, but the same cannot be said for SMEs. Unfortunately for now, standalone cyber insurance coverage available for SMEs is relatively narrow in scope and offers limited loss protection.
The lack of education on the insurance that is available also represents a challenge for SMEs. Most SMEs would need resources to help them fully understand their risk exposures and which options are available to help them in mitigating cyber risk (including insurance cover).
Another significant hurdle is the affordability of the substantial premiums required for cyber insurance cover. This requires innovative ways of increasing scale (number of insurance policies), which will, in turn, lower the cost of marketing and servicing of cyber insurance. From an ecosystem point of view, a case can be made for governments to help SMEs to beef up their cyber security since they are typically the weakest link in the supply chain through vendor relations.
Industry bigwigs have explicitly stated that mitigating and insuring cyber risks must be a PPP effort. Do you agree? Are insurers well-equipped to model and cover cyber risks?
The insurance industry as a whole does not yet sufficiently understand the unique, complex and evolving nature of cyber risk and thus is not in a position to provide robust cyber insurance cover required by those at risk.
There is still a lot of ground to be covered. The lack of sound data; a rapidly changing cyber threat environment; non-standardised policy coverage; nascent progress of the regulatory and policy landscape; and the global nature of cyber risk, which brings with it the potential for high accumulation risk, are just some examples of the limiting factors in the development of the cyber risk insurance market.
I agree that comprehensive cyber risk covers require the involvement of both public and private stakeholders in partnership. Insurers are concerned about hidden cyber cover embedded in existing insurance policies, and the potential large risk accumulation from multiple policies. Public-private partnerships can alleviate the risk accumulation concerns, and at the same time, encourage insurers to offer more risk prevention services.
How can the insurance industry prepare itself and stay ahead in tackling cyber threats?
Education is key – organisations that are interested in purchasing insurance are looking for more help with threat intelligence (risk knowledge), cyber risk reduction, incident response and loss indemnity (cost of business disruptions and third-party liabilities).
Insurers can do more to offer streamlined services, such as deploying cyber claims adjusters and emergency response teams. Alternatively, insurers can partner with information security firms in offering such services.
As cyber attacks rise in number and severity what key conclusions can insurers draw from them?
The SingHealth data breach further highlights the importance of risk prevention measures that should be an essential part of the risk management. Hypothetically, insurers could have helped SingHealth identify its key assets that would be attractive to cyber criminals (not all individuals’ medical records have the same value to hackers), and the ring-fencing of high-value data assets with special or additional layers of protection may have helped. High-valued insurance can be placed on protecting key data assets with adequate premium.
Could you elaborate on the IRFRC cyber risk management project?
NTU-IRFRC is currently leading the cyber risk management (CyRiM) project, in collaboration with the Monetary Authority of Singapore, Cyber Security Agency of Singapore and five global insurers (Aon, Lloyds, MSIG, SCOR and TransRe), with the aim of fostering an efficient cyber insurance market In Asia. So far, the CyRiM project has collected a wealth of cyber loss data and developed quantitative models for assessing effectiveness of an organisation’s cyber security measures.
The models are built upon the NIST cybersecurity framework and top academic literature. We have also organised several roundtables between 2017-2018 with a representation of cyber security experts from government agencies, insurance, banking and information security companies and law firms. Additionally, we are partnering with the University of Cambridge to develop cyber risk aggregation scenarios.
One of the main findings that CyRiM has identified is the gap between the supply side and the demand side and we are investigating the concept of a new ‘utility-based insurance’. Conceptually, utility-based insurance would offer risk reduction-related services (by information security vendors) and insurance risk transfer (by insurers), making it more of a risk-management service than traditional insurance cover. SMEs can then subscribe to this utility-based insurance on a consortium platform.
Ideally, such new utility-based insurance products can serve as a commercial vehicle to help companies satisfy compliance requirements. To ensure such a product is feasible in the market, it still requires extensive field-testing with the buy side, the sell side and intermediaries. We look forward to working with our insurance partners and information security firms to spearhead innovation in cyber insurance through public-private partnerships.
Source: Asia Insurance Review, September 2018
![[SCTP] Advanced Professional Certificate in Sustainability Reporting and AI Analytics](https://www.ntu.edu.sg/media/images/librariesprovider84/nbs-nee/sctp--advanced-professional-certificate-in-sustainability-reporting-and-ai-analytics/sctp_720x432.tmb-listing.png?sfvrsn=b5a8b2f2_2)


