{"id":24763,"date":"2024-06-26T05:20:54","date_gmt":"2024-06-26T13:20:54","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/06\/26\/news-18493\/"},"modified":"2024-06-26T05:20:54","modified_gmt":"2024-06-26T13:20:54","slug":"news-18493","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/06\/26\/news-18493\/","title":{"rendered":"Cyber Insurance and Cyber Defenses 2024: Lessons from IT and Cybersecurity Leaders"},"content":{"rendered":"<p><strong>Credit to Author: Sally Adam| Date: Wed, 26 Jun 2024 12:30:46 +0000<\/strong><\/p>\n<div class=\"entry-content lg:prose-lg mx-auto prose max-w-4xl\">\n<figure id=\"attachment_955926\" aria-describedby=\"caption-attachment-955926\" style=\"width: 300px\" class=\"wp-caption alignright\"><a href=\"https:\/\/www.sophos.com\/en-us\/whitepaper\/cyber-insurance-and-defenses\"><img loading=\"lazy\" decoding=\"async\" class=\"border wp-image-955926 size-medium\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Untitled.png?w=300\" alt=\"Download whitepaper : Cyber Insurance and Cyber Defenses 2024\" width=\"300\" height=\"275\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Untitled.png 819w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Untitled.png?resize=300,275 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Untitled.png?resize=768,703 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><figcaption id=\"caption-attachment-955926\" class=\"wp-caption-text\">Click above to read this as a PDF instead<\/figcaption><\/figure>\n<p>Cyber risk is inevitable. In today\u2019s business environment, the goal should not be to eradicate risk, but rather to manage it as efficiently as possible. Two primary\u00a0approaches are <em>treatment<\/em> by deploying cyber controls and changing user behaviors, and <em>transfer<\/em> through cyber insurance. These approaches are interconnected: strong controls lower risk which facilitates access to coverage, while weak controls increase risk, making affordable policies harder to obtain.<\/p>\n<p>Today we have published <a href=\"https:\/\/www.sophos.com\/en-us\/whitepaper\/cyber-insurance-and-defenses\">a new report<\/a> that explores this relationship in depth. Based on an independent survey of 5,000 IT leaders it looks at cyber insurance adoption among mid-market organizations, highlighting purchase drivers, the impact of defense investments on insurability, and reasons why cyber incidents costs are not always covered in full.<\/p>\n<h3>Executive summary<\/h3>\n<p>In the face of inevitable cyberattacks, adopting a holistic approach to cyber risk management that takes advantage of the interplay between cyber defenses and cyber insurance will enable organizations to lower their overall total cost of ownership (TCO) of cyber risk management while reducing their likelihood of experiencing a major incident.<\/p>\n<p>The research also reveals that investing in cyber defenses not only makes getting insurance easier and cheaper but also improves protection and reduces IT workload. This finding further emphasizes the importance of considering cyber risk investments holistically, rather than as individual components.<\/p>\n<p>One area of concern highlighted by the survey is the potential for policy purchases to be misaligned to business needs. Cyber insurance is an investment, so policies must cover the right risks. All stakeholders, especially IT and cybersecurity teams, should be involved in choosing policies to ensure they meet the organization&#8217;s needs.<\/p>\n<h3>Adoption of cyber insurance is widespread<\/h3>\n<p>The survey confirms that adoption of cyber insurance is widespread among organizations with 100-5,000 employees, with 90% of organizations having some form of cyber coverage. 50% have a standalone policy while 40% have cyber as part of a wider business insurance policy, such as a general liability policy. Adoption levels are high across all 14 countries surveyed, with Singapore reporting the highest propensity to have coverage.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-955909 aligncenter\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images.png?w=300\" alt=\"chart showing cyber insurance adoption rates in 14 different countries\" width=\"1053\" height=\"448\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images.png 1760w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images.png?resize=300,128 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images.png?resize=768,327 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images.png?resize=1024,436 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images.png?resize=1536,655 1536w\" sizes=\"auto, (max-width: 1053px) 100vw, 1053px\" \/><\/a><\/p>\n<h3>General awareness of the business impact of cyberattacks is the most common reason behind insurance adoption<\/h3>\n<p>Organizations adopt cyber insurance for multiple and various reasons, with nearly half (48%) citing <em>awareness of the business impact of cyberattacks<\/em> as the primary motivator. 45% reported it was <em>part of their cyber risk mitigation strategy<\/em> and 42% said that they <em>need cyber insurance to work with clients or partners who require it<\/em>.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-955913 aligncenter\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-1.png?w=232\" alt=\"chart showing the factors driving cyber insurance purchases\" width=\"459\" height=\"594\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-1.png 758w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-1.png?resize=232,300 232w\" sizes=\"auto, (max-width: 459px) 100vw, 459px\" \/><\/a><\/p>\n<h3>Investing in cyber defenses to optimize insurance position is common practice &#8211; and its working<\/h3>\n<p>97% of organizations that purchased cyber insurance last year improved their defenses to optimize their insurance position. Nearly two-thirds (63%) made major investments, while 34% made minor ones.<\/p>\n<p>These security investments are paying off, as the survey found that nearly every company that invested in improving their cyber defenses said it had a positive impact on their cyber insurance position (99.6%, 4,351 of 4,370 respondents).<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-955911 aligncenter\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-4.png?w=300\" alt=\"graphic that shows the impact of cyber defense investments on cyber insurance position\" width=\"564\" height=\"385\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-4.png 1390w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-4.png?resize=300,205 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-4.png?resize=768,524 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-4.png?resize=1024,699 1024w\" sizes=\"auto, (max-width: 564px) 100vw, 564px\" \/><\/a><\/p>\n<p>Cyber insurance requirements are driving organizations to elevate their defenses (the \u201cstick\u201d), with 76% of respondents saying their investments secured coverage they couldn&#8217;t otherwise obtain. The \u201ccarrot\u201d is that two-thirds (67%) were able to get better-priced coverage, and 30% received improved terms thanks to their improved protection (e.g., higher coverage limits).<\/p>\n<p>Furthermore, organizations investing in security enjoyed benefits beyond just insurance. 99% reported wider benefits such as improved protection, fewer alerts and reduced IT workload.<\/p>\n<h3>Insurers almost always pay out in some capacity on a claim<\/h3>\n<p>Organizations that have invested in a cyber policy will be encouraged to learn that insurers almost always pay out in some capacity on a claim, with only one respondent saying their claim was fully rejected.<\/p>\n<p>At the same time, in 99% of claims insurers did not cover the full incident cost. Overall, insurers typically paid 63% of the total incident cost, with the modal payout rate coming in at 71-80%.<\/p>\n<h3>Reasons for costs not being fully covered<\/h3>\n<p>The survey also revealed that recovery costs from cyberattacks are outpacing insurance coverage. The most common reason (63%) for the recovery bill not being paid in full was <em>total costs exceeded policy limits<\/em>. According to Sophos\u2019 <a href=\"https:\/\/assets.sophos.com\/X24WTUEQ\/at\/9brgj5n44hqvgsp5f5bqcps\/sophos-state-of-ransomware-2024-wp.pdf\">The State of Ransomware 2024 survey,<\/a> recovery costs following a ransomware incident increased by 50% over the last year, likely resulting in misalignment between policies and expenses.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-955912 aligncenter\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-5.png?w=300\" alt=\"chart showing why cyber insurers do not cover full incident costs\" width=\"554\" height=\"473\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-5.png 1153w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-5.png?resize=300,256 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-5.png?resize=768,655 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-5.png?resize=1024,874 1024w\" sizes=\"auto, (max-width: 554px) 100vw, 554px\" \/><\/a><\/p>\n<h2>There is widespread uncertainly around what policies cover in the event of a cyber incident<\/h2>\n<p>Many cybersecurity\/IT leaders are unsure about what their policy covers in the event of an incident. Among those with a policy, 40% <em>think<\/em> it covers ransom payments, and 41% <em>think<\/em> it covers income loss, but are not certain. These findings are cause for concern on several fronts:<\/p>\n<ol>\n<li>Organizations risk not getting the coverage they need \u2013 illustrated by 45% of those whose incident costs were not covered in full saying that some costs\/losses were not covered by their insurance policy<\/li>\n<li>Organizations risk not getting the support they anticipate in the event of a claim<\/li>\n<\/ol>\n<p>The lack of visibility into policy coverage likely results, at least in part, from a disconnect between those purchasing the policy and those on the frontline should a major incident occur.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-955910 aligncenter\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-2.png?w=300\" alt=\"table that looks at perceived cyber policy coverage\" width=\"966\" height=\"237\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-2.png 1702w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-2.png?resize=300,74 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-2.png?resize=768,188 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-2.png?resize=1024,251 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/Cyber-Insurance-WP-Article-Images-2.png?resize=1536,376 1536w\" sizes=\"auto, (max-width: 966px) 100vw, 966px\" \/><\/a><\/p>\n<h3>Read the full report<\/h3>\n<p>For more detailed insights including a look at the impact of cyber insurance coverage on ransomware outcomes, and many other areas,\u00a0<a href=\"https:\/\/www.sophos.com\/en-us\/whitepaper\/cyber-insurance-and-defenses\">download the full report<\/a>.<\/p>\n<h3>About the survey<\/h3>\n<p>The report is based on the findings of an independent, vendor-agnostic survey commissioned by Sophos of 5,000 IT\/cybersecurity leaders across 14 countries in the Americas, EMEA, and Asia Pacific. All respondents represent organizations with between 100 and 5,000 employees. The survey was conducted by research specialist Vanson Bourne between January and February 2024, and participants were asked to respond based on their experiences over the previous year.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2024\/06\/26\/cyber-insurance-and-cyber-defenses-2024-lessons-from-it-and-cybersecurity-leaders\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/06\/SOR24.png\"\/><\/p>\n<p><strong>Credit to Author: Sally Adam| Date: Wed, 26 Jun 2024 12:30:46 +0000<\/strong><\/p>\n<p>Investing in cyber defenses to optimize your insurance position is a win-win: organizations report easier, cheaper access to cyber coverage as well as improved protection and a reduction in IT workload.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[22869,129,24562,3765,27443],"class_list":["post-24763","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-cyber-insurance","tag-featured","tag-products-services","tag-ransomware","tag-risk"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24763","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24763"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24763\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24763"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24763"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}