The Evolving State of Cyber Insurance May Indicate More Scrutiny for IT and Security Teams

Stu Sjouwerman | Dec 15, 2021

Evolving State of Cyber InsuranceThe need to balance offering coverage for cyber incidents with maintaining a profit has cyber insurers rethinking how they will approach measuring insured risk and exposure.

In a recent SecurityWeek article on the topic, Vishaal Hariprasad, CEO at cyber insurer Resilience described how cyber insurers have changed their tactics to minimize their exposure when taking on policies: “In 2016, you could buy a million-dollar cyber insurance policy and they would ask you, do you have your IT person, and did you guys buy a firewall? They never asked is the firewall turned on, because the insurance industry didn’t care back then.”

Hariprasad went on to describe the very different and better informed position insurers take today. “Insurers need to know, is your firewall turned on? Is it consistently patched? Are you continuously bringing in the right data feeds? And are you monitoring them?” What is needed is a new cooperative relationship between the insurer and the insured.”

In essence, organizations should begin to expect a new relationship dynamic between cyberinsurer and their policyholder’s IT departments – where insurers may need to gain a detailed understanding of just how secure the organization’s environment really is before issuing a policy.

In reality, this isn’t too far off the mark for homeowner’s insurance; your home is inspected down to the number of nails in roof rafters for the insurer to understand what exactly their risk is. In cybersecurity terms, it’s reasonable to expect cyber insurers to want to look through your security stance with a fine-toothed comb looking at every possible point of exposure to better inform themselves of just how much risk you pose before issuing a policy.

In the end, it’s going to result in improved security stances, and less claims for insurers. Everybody wins. 

Topics: Cybersecurity

Access the World’s Largest Security Awareness Library

Explore over 1,000 interactive modules, videos, and games designed to sharpen user instincts and secure AI interactions. Get instant access to our Free Training Preview and find the perfect content to fortify your security culture.

Get Your Free Training Preview

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.