4 ms·
This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our com
by krisrm 7y ago
This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"?
On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the attack may not have been state sponsored, the insurance is certainly worthless.
- admax88q 7y ago> On one hand, how are insurers supposed to properly cost... That's more or less the core competency of insurance providers...
- krisrm 7y agoWell, no argument there, but I wrote more words in that sentence that you cut off. My point is, that a "cyber attack" is poorly constrained, compared to something like a fire or a flood... a company only has so many assets, valued at $X that are liable to be burned to the ground or ruined by a flood, and these constraints can be modeled and adjusted for. Perhaps I am mistaken, I don't see a cyberattack as being analagous to anything else in the insurance industry.
- resoluteteeth 7y agoIf it's so hard to model then why are these insurance companies offering "cyberinsurance" in the first place?
- rolph 7y agoperhaps riot or vandalism [acts of civil disobedience]
- sandworm101 7y ago>> compared to something like a fire or a flood Those are not easy things. People litigate the difference between fire and flood damage all the time. (Putting out a fire normally involves lots of water.) Sometimes flooding in building X even causes a fire in building Y. Is that covered by "fire" or "flood" insurance? The difference between various cyber attacks isn't substantively more complicated than any of the traditional insured risks. The issue is that insurers haven't invested in the experts needed to properly assess those risks. That is their problem to solve, not the customer's.
- arcticbull 7y agoAgreed with everything you said, though 'its their problem to solve' should they decide to offer cyberattack coverage and sell it, otherwise it is the customers.
- arcticbull 7y agoMaybe I'm misunderstanding but aren't a fire and a cyberattack both capped at 100% of the value of the company? If the fire takes out the whole place, or a cyberattack empties out an equivalent amount from their bank accounts, the difference feels immaterial.
- thfuran 7y agoWhat if a fire spreads to other properties not owned by the insured or destroys things on company premises but not owned by the company?
- arcticbull 7y agoFair point, I was wrong to say 100% of the property value, though I imagine the upper bound of the damage is fairly comparable in both cyber attacks and physical attacks.
- pbhjpbhj 7y agoWell a fire can do anything from cause a slight smell -- bread toaster or battery dropped in to a metal bin, maybe -- all the way to complete destruction of property and loss of lives, potentially ending the business. Seems relatively analogous in that respect to cyber attack?
- MiroF 7y ago> how are insurers supposed to properly cost and be able to provide payouts This is what insurance companies do..
- Matticus_Rex 7y agohttps://www.quora.com/What-is-the-difference-between-insurable-and-uninsurable-risk https://www.quora.com/What-is-the-difference-between-insurab...
- 0xDEFC0DE 7y agoThis hinges on the US assigning attribution, and to be fair, the US probably has a better idea than an insurance company. If the FBI publicly arrests some teenager or former employee related to a company hack, and the insurance tries to use a cyberwarfare exception, then we can go grab the pitchforks. Both sides of this are going to get tested though: does the US actually have a definition for cyberwarfare and is that the same as what's in the insurance contract? Do countries have to publicly declare cyberwar (but not necessarily regular war) on other countries for this clause to be valid? What due diligence do companies have to do to prove they weren't part of a cyberwarfare hack? This headline is misleading though. Big Companies know what's in those contracts. Maybe this is a kick in the pants for more scrutiny of those contracts to strike things like cyberwarfare.
- yub 7y agoBut the definition of "cyberwarfare" is unclear. If Russia declared war on the US, and attacked US companies, it's pretty clear this is cyberwarfare. If Anonymous DDoS's your website of some vendetta, because they declared "war" on your company, is that cyberwarfare? Does a declaration of war by a non-nation-state count as cyberwarfare? If North Korea compromised your servers to mine Bitcoin, is that cyberwarfare? Does any action by a nation-state count as cyberwarfare?
- jrochkind1 7y agoInsurers are under no obligation to offer policies which cover cyber attacks, and can even explicitly exempt them in their policies. However, in this case: > Mondelez said in a statement that while its business had recovered quickly from the attack, Zurich Insurance was responsible for honoring an insurance policy that explicitly covers cyber events.
- deleted 7y ago[deleted]
- arcticbull 7y agoIMO this feels like the whole point of insurance. You could restate this as "how are insurers supposed to cost and provide payouts for fires in the factory? It could be anything from a tiny, contained garbage can fire to the whole place going up in a blaze! [0]" Or chemicals in the case of TSMC [1]. Or blackouts at Samsung [2]. Any of this could have been industrial espionage on the same scale as a state-sponsored cyberattack. This is the domain of actuaries. Of course, they're neither required nor obligated to provide such cover. [0] https://www.extremetech.com/computing/166775-ram-pricewatch-memory-spikes-in-wake-of-hynix-fire-but-for-how-long https://www.extremetech.com/computing/166775-ram-pricewatch-... [1] https://asia.nikkei.com/Business/Companies/TSMC-takes-550m-hit-from-defective-chemical-at-chip-plant https://asia.nikkei.com/Business/Companies/TSMC-takes-550m-h... [2] https://www.anandtech.com/show/12535/power-outage-at-samsungs-fab-destroys-3-percent-of-global-nand-flash-output https://www.anandtech.com/show/12535/power-outage-at-samsung...
- ozim 7y agoWhere I live you pay premium, let's say $50 a month and then you get let's say $10000 of your damages covered. So that is what you get from insurance company $10000 and the rest is yours to pay. They just look at the probability like "hey this guy is storing fuel, fire insurance for someone who stores fuel is $100 a month and we can pay only up to $20k". So it is easy to calculate for insurance companies, they don't go over the factory inventorying what you have in factory. It is your responsibility. (they only go after to see what was damaged, because that i what they care about) Of course you can pay some insurance expert to assess your assets and tell you to buy more expensive or less expensive insurance but there are no magic super specific algorithms for "if 10 people die we pay $50k if 20 people die we pay $100k". All insurances pay up to some amount based on what is your monthly/yearly payment.
- repiret 7y agoAuto insurers have no problem covering claims ranging from a chip in a windshield to eight car pileups with multiple fatal and life-altering injuries. The range of possible losses doesn't really make it harder for insurers. The fuzzy definition of an act of cyber war is what makes it hard for policyholders though.
- jrochkind1 7y agoNah, what makes it hard for insurers isn't that we don't know what an "act of cyber war" is. That just comes up when they try to get _out_ of it, and the same thing comes up with non-cyber "acts of war" -- it might make it hard on customers who are trying to file claims, but it's not hard on the companies. But it _is_ hard on insurerers to do under-writing on cyber attacks -- UNRELATED to the "war" exemption, even non-war attacks. Because it's _new_, so they don't have all the historical data and methods for estimating risk. As others are saying, this is the business insurance companies are in, estimating statistical risk and figuring out the right premiums to charge to cover it. But the cyber stuff is new, which _does_ make it hard. As original article says: > Cyberattacks have created a unique challenge for insurers. Traditional practices, like not covering multiple buildings in the same neighborhood to avoid the risk of, say, a big fire don’t apply. Malware moves fast and unpredictably, leaving an expensive trail of collateral damage. But nobody said they had to cover cyber stuff. They can put stuff in their policies saying they don't cover it at all, if they don't know how to underwrite it. What they can't do is put stuff in their policies saying they cover it, take your premiums on that basis, but then try to weasel out of it.
- jon-wood 7y agoIt wouldn’t surprise me if at first insurers throw their own internal security teams at this. They’re used to auditing third party systems, because insurers are constantly working with externally developed software and other companies. You could go a long way just building out a team with both underwriters and security professionals to setup baseline standards and evaluate customers against those.
- imgabe 7y ago> how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? The same way they properly cost and provide payouts for, say, fire which might be anything from "one room got slightly scorched" to "the entire building burned down".