Time For Insurers to Reassess ‘Grim’ Cyber Insurance Market: AM Best
It comes as no secret that there has been an increase in both cyber events as well as the average cost per event. This escalation seems to be fueled by the ever-increasing volume of ransomware attacks. A few fun facts from the below article from our friends at Carrier Management, citing AM Best as a source.
- Year over year loss ratio went up 551% from 44.8% to 67.8%. 15 of the top 20 cyber insurers saw deteriorating results (9 of top 10)
- Industry stalwarts CNA, AIG, XL and Travelers got hit especially hard on this line
- Defense and cost containment costs (the cost to contain claims like attorneys and forensic experts) are going to be substantial due to nature and sophistication of claims; prediction of costs uncertain based on lack of historical data to support it
- Cyber claims number of claims is up 18%, strictly due the surge in first party ransomware. Ransomware was up 35% and now accounts for 75% of all cyber claims
Needless to say, pay attention to the market if you already buy this coverage as it is quickly shifting. Critical focus should be given on ransomware limits, deductibles and responsiveness due to significant amount of overall exposure this type of attack can bring.
With the cyber risk hazard environment—ransomware, business interruption and aggregation—worsening significantly, “prospects for the U.S. cyber insurance market are grim,” according to a report from AM Best.
According to the global rating agency’s analysts, insurers “urgently need to reassess all aspects of their cyber risk, including their appetite, risk controls, modeling, stress testing and pricing, to remain a viable long-term partner dealing with cyber risk.”
The reassessment is needed because cyber insurance, which began as a diversifying, secondary line and another endorsement on policies, is now a “primary component of a corporation’s risk management and insurance purchasing decisions,” notes Best’s in its report, “Ransomware and Aggregation Issues Call for New Approaches to Cyber Risk.”
The loss ratio for cyber insurance rose dramatically in 2020, to 67.8 percent from 44.8 percent in 2019. However, the increase was not limited to just a few insurers—the loss ratio rose for 15 of the 20 largest cyber insurers, AM Best reports.
“The rate increases for cyber insurance outpaced that of the broader property/casualty industry, but the increase in cyber losses outstripped the rate hikes, which suggests more trouble for 2021 as ransom demands continue to grow,” said Sridhar Manyem, director, industry research and analytics.
Of special note, defense and cost containment (DCC) expenses are rising and “could become a significant issue because of potentially significant costs to defend claims as a result of either ambiguous coverage language or regulatory investigations that may involve defense costs,” the report adds.
According to the report, the challenges the cyber insurance market are facing include:
- Rapid growth in exposure without adequate underwriting controls;
- The growing sophistication of cyber criminals that have exploited malware and cyber vulnerabilities faster than companies that may have been late in protecting themselves; and
- The far-reaching implications of the cascading effects of cyber risks and the lack of geographic or commercial boundaries.
See related article, “Federal Lawmakers Probe CNA, Cyber Insurance Payouts,” for a loss ratio ranking of the top 10 U.S. cyber insurers.
Direct written premiums for cyber insurance grew 22 percent in 2020, to $2.7 billion, which AM Best attributes to increases in both rates and demand for cyber insurance in the wake of well-known firms such as SolarWinds, Facebook and Capital One becoming victims. The average annual growth rate in premium has been 20 percent the past four years , while the average growth in claims has been 39.2 percent.
“Rapid growth is viewed with a healthy skepticism, as it comes with underwriting and reserving risks,” the authors comment.
Standalone cyber insurance policies, up 28 percent in 2020, have seen a higher rate of growth compared with packaged policies, which the report indicates signal organizations’ escalating concerns about cyber risk. Frequency on standalone policies also has increased faster than for packaged policies the last three years.
Hackers are becoming more sophisticated in their attacks and moving toward larger targets. The report also notes that hackers’ motives also appear to be changing as well, from stealing identities (third-party claims) to shutting down systems for ransom (first-party claims).
Total claims rose 18 percent in 2020 owing strictly to first-party ransomware claims, which were up 35 percent in 2020 and now account for 75 percent of cyber claims.
“The recent Colonial Pipeline hack—for a multi-million dollar ransom—is an example of first-party claims that have become so prevalent,” said Christopher Graham, senior industry analyst, AM Best.
Although AM Best said it views the industry as being well-capitalized, it also warns that individual insurers that venture into cyber risk without a thorough understanding of the market can find themselves in a vulnerable situation.
Noting that the industry has not yet faced a systemic event that challenges traditional underwriting categories of region, industry, size, the authors urge insurers to hire experts to help with mitigation and to take steps to improve their abilities to quantify their exposure and define their risk appetites.
“An insurer whose risk management approach is deficient can find itself subject to accumulation risk beyond its tolerance and could face ratings pressure,” said Fred Eslami, associate director, AM Best.
Source: Ransomware and Aggregation Issues Call for New Approaches to Cyber Risk – AM Best
Join the Conversation on Linkedin | About PEO Compass
Contact Professional Employer Organization (PEO) Expert, Paul Hughes
Paul Hughes has been working with the Professional Employer Organization (“PEO”) industry since 1995 and data management since 2005. He is responsible for the day to day operations of both Libertate Insurance Services, LLC and RiskMD, which reports into the overall Ballator Insurance Group family of companies. Learn more about Paul.
Specializing in PEO Services: Workers Compensation, Mergers & Acquisitions, Data Management, Insurance Focus on: Employment Practices Liability (EPLI), Cyber Liability, Health Insurance, Occupational Accident, Business Insurance, Client Company, Casualty, and Disability Insurance.