When a company is shut down by ransomware, cyber criminals often demand a ransom payment before releasing the hijacked data -- something many companies choose to pay so they can resume their business operations. Most cyber insurers reimburse the ransom paid by their clients. According to critics, however, this only leads to an uptick in this type of cybercrime. Partly for this reason, the Ministry of Justice and Security is considering banning ransom payments by cyber insurers.
“That’s little more than a drop in the ocean. In my research I found no clear links between insurance coverage for ransom payments and the company’s decision to pay. Insured or not, companies pay because they have no other choice.” Brouwer doesn’t see a general ban on ransom payments as a good solution. “A ban only makes the payment itself illegal. Companies will just find another way to pay the ransom. An insurance policy is a legal agreement subject to freedom of contract. Banning insurance coverage for this will have far-reaching consequences.”
Incident response services
The number of cyber insurers has been on the rise in recent years. They offer extensive coverage in the event of a cybercrime, including recovery costs following a cyberattack, fines, and liability coverage for privacy breaches and network incidents, damages caused by an interruption of business operations, and legal representation costs. “So-called incident response services are relatively unique for insurers. For example, if a company is hit by a ransomware attack, the insurer can dispatch a team of IT, legal and communication experts to minimise the impact of the attack. This range of services offers companies a degree of certainty, especially when it comes to continuing their business operations.”
“It’s worth noting that almost all insurers define the key terms of their policy conditions, such as the term ‘cyberincident’. This can make it hard for companies to determine what is and isn’t covered. But it’s also understandable: with other types of insurance, hundreds of years of claims history were used to define these terms. We all know what a fire is and only marginal differences exist in what is and isn’t covered by insurance companies. We don’t have the same history when it comes to cyberincidents, which is problematic.”
Better security
That said, Brouwers believes the government shouldn’t view cyber insurers as a nuisance, but as a tool to help strengthen cyber security. In practice, these insurance companies can help ramp up a company’s security. ”A company has to meet certain requirements before it can take out cyber insurance. While more consensus should certainly be reached about what these requirements are, market developments are already underway. Many incidents can be prevented by considering the risks of cyber incidents, by implementing measures to combat them and by evaluating and improving these measures regularly.
Photo: Clint Patterson via Unsplash