Silent Cyber Demands New Approach

Insurers have been warned that their efforts to tackle the threat of silent cyber risk exposure will fail unless they create a new modelling regime.

Risk analytics firm CyberCube have issued a new study which believes that change is needed in terms of the way the industry’s cyber modelling tools are constructed..

According to the report, Accurately Assessing Silent Exposure: A Step Towards Strengthening the Cyber Market’s Development, cyber models need to expand their scope in order to cover a much broader range of insurance lines if non-affirmative cyber risks are to be identified and analysed effectively. Traditionally, cyber models have been restricted to property lines of business.

The company also warned that concern among reinsurers will compel cedants to eliminate ambiguity in primary insurance contracts. One approach by carriers relating to silent cyber is to exclude this exposure, however, insurers may not want to disrupt the coverage in place for their clients in any meaningful way.

The issue is high on the agenda of the industry. Lloyd’s syndicates have until 1 January 2020 to address silent cyber in contracts across all first-party property damage lines of business. In its Dear CEO letter in October the Prudential Regulation Authority highlighted its concerns that a number of traditional lines of business have considerable exposure to non-affirmative cyber risk.

Commenting on the report, CyberCube’s Co-founder and Head of Product & Analytics, Ashwin Kashyap, (pic) said: “Insurers are finding themselves squeezed between regulators and reinsurers who both want the issue of non-affirmative cyber risk to be tackled. The potential cost implications of failing to address it are frightening.

“At present, global standalone cyber premiums are estimated to be in the region of $5.5 billion, but the connected exposures and premiums at risk from silent cyber across all Property and Casualty lines is higher by an order of magnitude. This explains the nervousness among market regulators and reinsurers.”

The report argues that the rapid growth of cyber insurance has created challenges for claims professionals and carriers seeking to set loss reserves and forecast their capital requirements. Ashwin Kashyap, report author, added: “Insurers and reinsurers need to determine accurate cyber loss reserves, but currently it is proving very hard to allocate definitive loss reserves for the development profile of these incidents. For insurers, therefore, scenario-based modelling has got to be the route forward, but this isn’t without problems.

“The lack of high-quality, detailed exposure data for established lines of business is a brake on progress. Models need to be able to handle aggregated data and, in many cases, incomplete information is being used to provide estimates. This is clearly not helpful for the industry. Insurers will face challenges if they are held responsible for cyber-related claims as a result of ambiguous policy wordings in standard commercial products, such as business interruption covers.”