The growth and challenges of cyber insurance

Andrew Granato, Andy Polacek · Chicago Fed Letter · 2019

Cyberattacks have grown in frequency and cost over the past decade, with high-profile cases, such as the 2013 Target data breach, the 2017 Equifax data breach, and the leak of Democratic National Committee emails during the 2016 election making national headlines.Ransomware attacks, intellectual property theft, and fraud cost companies billions in recovery expenses, fines, and lost revenues every year.More firms are purchasing cyber insurance as a way to cover losses and expenses resulting from cyber incidents.However, cyber insurance alone is not a panacea, and even firms that have cyber insurance may not be as protected as they think.Unlike traditional lines of business such as private auto insurance, where standardized policies provide liability or collision coverage, cyber insurance policy language is not standardized.The types of risks covered under cyber insurance vary significantly across policies and businesses, and insurers do not always agree on what loss events are covered under those policies.The features of cyber events, including a limited loss history, the unreliability of past data when predicting future events, and the possibility of a large-scale attack where losses are highly correlated across companies and/or industries, make it difficult to write comprehensive policies.In this Chicago Fed Letter, we examine the extent to which cyber insurance can help protect businesses and the wider economy from the costs of cyberattacks and how institutional factors and legal uncertainties may obstruct the development of this market.

Read the paper · More papers on PaperTik