The rise of the cyber insurance has largely failed to promote better cybersecurity practices among the industries they cover, according to a new report released Monday from British security think tank RUSI. (Photo by Spencer Platt/Getty Images)
The security community for the last few years pointed to great potential for cyber insurance to drive progress in cyber best practices: force companies to up their game by making certain standards a requirement for coverage.
But recent research shows thats not happening.
The rise of the cyber insurance has largely failed to promote better cybersecurity practices among the industries they cover, according to a new report released Monday from the British security think tank Royal United Services Institute (RUSI). This is particularly true for the scourge of ransomware, where rising payments and business incentives to pay may pose an existential threat insurance providers in Great Britain and beyond.
Although ransomware is a societal problem, the authors note that cyber insurers are facing some heat for the role they play in financially propping up the cyber-criminal industry.
These add fuel to the fire by incentivizing cybercriminals engagement in ransomware operations and enabling existing operators to invest in and expand their capabilities, write authors Jamie MacColl, Jason R.C. Nurse and James Sullivan. Growing losses from ransomware attacks haveemphasized that the current reality is not sustainable for insurers either.
When a company is hit with ransomware, theyre often faced with three choices: pay up, lean on backups or rebuild the entire IT network. Since insurers usually opt to cover the cheapest option, paying an upfront ransom almost always ends up costing less than starting from scratch or incurring weeks of downtime while systems are restored from backups.
While this model and approach seemingly make business sense to insurers, it ends up putting an absurd amount of money into the pockets of criminal groups. These groups then have more resources to further develop their malware and infrastructure, offer better compensation to entice talented hackers to join their network and buy zero-day exploits or initial access to victim companies.
In February, a report from Chainalysis, which tracks cryptocurrency payments in law enforcement investigations, estimated that these groups took home at least $350 million in ransom payments in 2020, and experts say that many incidents are not publicly reported, because the victim has decided to quietly pay before their information is advertised online and not engage with law enforcement.
Several high-profile incidents in recent months underscored the challenges faced in this area. The U.S. government was initially unable to get information around ransom payment from executives at Colonial Pipeline, and some were outraged when CEO Joseph Blount in a media interview appeared to cast paying the $4.3 million ransom (which Blount later said the company submitted an insurance claim for) as the right thing to do and a patriotic duty to keep vital American infrastructure running. A ransomware attack on insurance giant CNA in March also resulted in a $40 million payment that is believed to be the largest ransom payment to date on record, according to Bloomberg.
The RUSI report, part of a year-long project with the University of Kent studying ways to incentivize better cybersecurity through insurance, finds little hard evidence that indicate this model is forcing companies to reevaluate their own cybersecurity practices and investments. It also warns the current model of making regular large ransom payments will not financially benefit insurers over the long term.
While some of the carriers interviewed for the report touted their pre and post-incident services like forensic analysis, incident response, legal services and public relations as valuable services that help lift a victim organization to a higher, more secure plane of cybersecurity that prevents future attacks, theres only scant, scattered evidence that this is actually happening in some places.
In fact, many companies that buy cyber insurance tend to view it as a tool for resilience against cyber attacks rather than a risk mitigation tool. Research by threat intelligence firm Cybereason in June claimed that an eye-popping 80% of companies that paid the ransom wound up getting infected by ransomware again in the following months, often by the same group.
One example of a favorable impact cited by the authors: claims by U.S. insurance provider Corvus that their scanning for ports and vulnerabilities commonly exploited by ransomware groups resulted in a 65% drop in ransomware-related claims from April to September 2020.
These insurers can do more to sharpen the kind of data they collect, push industry to adopt security standards set by government organizations like the U.S. National Institute for Standards and Technology and rate different cyber security products for their value and impact on premium costs.
There is a solid body of theoretical arguments that cyber insurance could play a meaningful role in improving cyber security among businesses, as referenced in a previous RUSI Emerging Insights paper, the report argues. However, in practice, it is still yet to be seen if cyber insurance can fulfil this promise.
While the paper is geared towards the UK insurance market, the challenges and potential solutions outlined share many parallels with that of the U.S. market, where a ransomware epidemic has forced policymakers to elevate the issue and consider a number of previously extreme solutions, like banning ransom payments, heavily regulating the cryptocurrencies used to pay and directing law enforcement and intelligence agencies to increasingly target the IT infrastructure that these groups rely on to carry out their schemes.
The findings echo similar claims made in a U.S. Government Accountability Office report on cyber insurance in May, which found that the industry on the whole lacked the kind of historical data around data breaches and their effective mitigations to properly price their coverage, though some providers of cyber insurance interviewed by SC Media disputed the conclusions at the time.
If you ever go to a restaurant and felt like having a nice lobster dinner, you probably saw the menu say market priced, because who knows how many lobsters they caught that day, or that time a month or that year? The pricing is really variable in what lobsters cost on a day-to-day basis, it can fluctuate wildly, said John Pescatore, director of emerging security trends at the SANS Institute, in May. Thats sort of what the case is [today] for cyber insurance, its essentially market price.
Read more:
Scant evidence that cyber insurance boom is leading to better security SC Magazine - SC Magazine
- Protect Your Home Title & Equity from Fraud with TripleLock Monitoring, Alerts & Restoration - ABC Action News Tampa Bay - November 12th, 2024 [November 12th, 2024]
- Wireless Home Security Camera Market is growing at a CAGR of 20% in the forecast period (2024-2031) - openPR - November 12th, 2024 [November 12th, 2024]
- Yes, Smart Homes Are Vulnerable to Cybercriminals. Here's What You Need to Know. - House Beautiful - November 12th, 2024 [November 12th, 2024]
- Limited-Time Deal: Protect Your Home or Business With a Ring Indoor Camera at Almost 40% Off - CNET - November 12th, 2024 [November 12th, 2024]
- The 3 Best Indoor Security Cameras of 2024 | Reviews by Wirecutter - Wirecutter, A New York Times Company - November 12th, 2024 [November 12th, 2024]
- Get home security cameras up to 60% off and feel extra cozy this winter - Mashable - November 12th, 2024 [November 12th, 2024]
- Resideo Unveils Honeywell Home FocusPRO Thermostats - SecurityInformed - November 12th, 2024 [November 12th, 2024]
- A Smart Before-the-Holidays Decision: Arlo and Allstate are Boosting Peace of Mind with New Home Security Bundle - IoT Evolution World - November 12th, 2024 [November 12th, 2024]
- The Google Nest Cam With Floodlight Is at Its Lowest Ever Price, but Not for Long - CNET - November 12th, 2024 [November 12th, 2024]
- Man shot by security guard at Home Depot in Northeast Philly - The Philadelphia Inquirer - November 12th, 2024 [November 12th, 2024]
- Keep Eyes on Your Home at All Times With a Blink Outdoor Cam for 60% Off - CNET - November 12th, 2024 [November 12th, 2024]
- A Letter to the Nation's New Leaders: Right Now, the American Dream of Homeownership Is in Crisis - SFGATE - November 12th, 2024 [November 12th, 2024]
- Get your tickets SECURED to Z100s Jingle Ball from Slomins Home Security! - iHeart - November 12th, 2024 [November 12th, 2024]
- We test a new home security package that couldn't be simpler to install - The Scotsman - November 12th, 2024 [November 12th, 2024]
- 6 Smart Gadgets That Will Instantly Upgrade Any Home's Lighting And Security - SlashGear - November 12th, 2024 [November 12th, 2024]
- Amazon has this Blink doorbell and security camera bundle on sale for the lowest price ever and its before - NJ.com - September 29th, 2024 [September 29th, 2024]
- This Blink Video Doorbell and security camera bundle is down to $59.99 at Amazon - TechRadar - September 29th, 2024 [September 29th, 2024]
- This new Eufy home security camera uses AI to add color to its night vision - TechRadar - September 29th, 2024 [September 29th, 2024]
- Did Jennifer Lopez and Ben Affleck Just Run Into More Trouble With Sale of $68 Million Marital Mansion? - SFGATE - September 29th, 2024 [September 29th, 2024]
- Sound the alarm! This 14-piece Ring smart security system is 40% off - Android Police - September 29th, 2024 [September 29th, 2024]
- Ring's Pan-Tilt Indoor Camera Just Crashed to a New Amazon Low Ahead of Prime Day - CNET - September 29th, 2024 [September 29th, 2024]
- The best home security cameras 2024: the smartest way to protect your home - TechRadar - September 29th, 2024 [September 29th, 2024]
- Bump Up Your Home Security With the Ultraloq Smart Lock for Only $99 - CNET - September 29th, 2024 [September 29th, 2024]
- This Early Prime Day Deal Will Score You a Blink Outdoor Camera for Over Half Off - CNET - September 29th, 2024 [September 29th, 2024]
- Supermodel Elle Macpherson Finally Sells Artsy Mansion at a Steep Discount After 2 Years on the Market - SFGATE - September 29th, 2024 [September 29th, 2024]
- Home security cameras: Learn how and where to install them for optimal protection - CNN Underscored - September 20th, 2024 [September 20th, 2024]
- Lions Dan Campbell has home address doxxed, creating series of security concerns - FOX 2 Detroit - September 20th, 2024 [September 20th, 2024]
- 2024's Best Outdoor Cameras: Vetted by Security Experts - Security.org - September 20th, 2024 [September 20th, 2024]
- Chilling home security footage shows what teen did seconds after 'fatally shooting her mother' - UNILAD - September 20th, 2024 [September 20th, 2024]
- Smart Home Security Camera Market is Expected to See a Growth of 13.2% CAGR from 2024 to 2034 | FMI - Future Market Insights - September 20th, 2024 [September 20th, 2024]
- Best Buy Deals of The Day: Save at Least $100 on Headphones, Home Security Systems, and Routers - PCMag - September 7th, 2024 [September 7th, 2024]
- How to Protect Your Outdoor Security Cameras During Stormy Weather, According to Experts - Bob Vila - September 7th, 2024 [September 7th, 2024]
- Protecting your home costs a mere $100 with this awesome Arlo setup - TechHive - September 7th, 2024 [September 7th, 2024]
- Breaking Home Security Myths: United Locksmith Keeps Houston Safe with Expert Services - openPR - September 7th, 2024 [September 7th, 2024]
- Master Locks Folding Door Security Bar Offers Cheap and Effective Home Security - Bob Vila - September 7th, 2024 [September 7th, 2024]
- Home security cameras capture father's panic after he pulls his unresponsive toddler from pool - ABC Action News Tampa Bay - September 7th, 2024 [September 7th, 2024]
- Reolink shines at IFA 2024 with major rebranding and groundbreaking new products - BGR - September 7th, 2024 [September 7th, 2024]
- Four gunshots fired in area of SW Redmond; police go door-to-door seeking witnesses, home security videos - KTVZ - September 7th, 2024 [September 7th, 2024]
- Some of Our Favorite Ring Security Cams Are Down to New Lows at Woot - CNET - September 7th, 2024 [September 7th, 2024]
- "I feel like I'm in Big Brother" the trouble with home security cameras! - Digital Camera World - September 7th, 2024 [September 7th, 2024]
- The Best Home Security Cameras and Systems for Off-the-Grid Living in 2024 - CNET - September 7th, 2024 [September 7th, 2024]
- Smith Thompson Home Security and Alarm Austin Highlights the Importance of Fire Safety Equipment in Protecting - EIN News - September 7th, 2024 [September 7th, 2024]
- Alfred DB2S: Advanced Home Security With RFID And Z-Wave - SecurityInformed - September 7th, 2024 [September 7th, 2024]
- The waterproof Blink Mini 2 security camera is the best Wyze Cam alternative available - ZDNet - September 7th, 2024 [September 7th, 2024]
- Digital Projection Unveils Radiance Home Video Wall At CEDIA Expo 2024 - SecurityInformed - September 7th, 2024 [September 7th, 2024]
- Secure your whole home with this half-off Arlo three-cam bundle - TechHive - September 7th, 2024 [September 7th, 2024]
- Best home security cameras 2024: Reviews and buying advice - TechHive - August 17th, 2024 [August 17th, 2024]
- 6 Ways to Stop Your Home Security Camera From Being Hacked - CNET - August 17th, 2024 [August 17th, 2024]
- Top Home Security Tips When You're Renting with Roommates - CNET - August 17th, 2024 [August 17th, 2024]
- Cicero Police: Looking for home security video following neighborhood thefts from cars - WSYR - August 17th, 2024 [August 17th, 2024]
- The first U.S. metro to hit $2M median home price is, of course, in the Bay Area - SFGATE - August 17th, 2024 [August 17th, 2024]
- Burglaries Spike in This California CityTips To Keep Your Home From Being the Next Target - Realtor.com News - August 17th, 2024 [August 17th, 2024]
- Smart Home Innovations 2024: Trends in AI, Security, and Sustainability - TechBullion - August 17th, 2024 [August 17th, 2024]
- Beyond the eye-popping sum, this could violate the Texas Open Meetings Act - The Dallas Express - August 17th, 2024 [August 17th, 2024]
- Zumi Introduces Advanced Gate Openers for Greater Home Security in the United States - Kirkland Lake Northern News - August 17th, 2024 [August 17th, 2024]
- Home security video in Euclid appears to show debris being thrown into Lake Erie - Cleveland 19 News - August 4th, 2024 [August 4th, 2024]
- Her Security Cameras Show Her Family Breaking Things And Hurting Her Dog, So She Ends Their Visit Early And Tells Them To Never Come Back - Twisted... - August 4th, 2024 [August 4th, 2024]
- Sarah Hyland catches live burglary of her home while out of town - The News International - August 4th, 2024 [August 4th, 2024]
- Amazon just slashed the price of our favorite budget home security camera - Tom's Guide - March 14th, 2024 [March 14th, 2024]
- Los Angeles Police Department warning home owners to hard-wire home security systems as organized theft rings ... - Notebookcheck.net - March 14th, 2024 [March 14th, 2024]
- Best Security Systems For Apartments Of 2024 Forbes Home - Forbes - March 14th, 2024 [March 14th, 2024]
- Airbnb's Unexpected Home Security Ban Sets A New Standard For Rental Property Owners - House Digest - March 14th, 2024 [March 14th, 2024]
- Best home security deal: Get the Arlo Essential Wired Video Doorbell for just $49.99 at Amazon. - Mashable - March 14th, 2024 [March 14th, 2024]
- Lithe Audio and Lilin integrate AI for home security - HiddenWires - March 14th, 2024 [March 14th, 2024]
- Why Airbnb Is Banning Cameras in Rentals - TIME - March 14th, 2024 [March 14th, 2024]
- Best Home Security Cameras of 2024 - CNET - February 16th, 2024 [February 16th, 2024]
- Blink's video doorbell just crashed to $44 and it doesn't require a subscription - Tom's Guide - February 16th, 2024 [February 16th, 2024]
- Snag Up to 43% off These Blink Security Cameras and Doorbells - CNET - February 16th, 2024 [February 16th, 2024]
- U.S. House Republicans impeach Homeland Security chief Mayorkas on second try Oregon Capital Chronicle - Oregon Capital Chronicle - February 16th, 2024 [February 16th, 2024]
- Wi-Fi jamming to knock out cameras suspected in nine Minnesota burglaries -- smart security systems vulnerable as ... - Tom's Hardware - February 16th, 2024 [February 16th, 2024]
- The 4 Best Security Cameras for Your Home of 2024 | Reviews by Wirecutter - The New York Times - February 16th, 2024 [February 16th, 2024]
- The 4 Best Smart Doorbell Cameras of 2024 | Reviews by Wirecutter - The New York Times - February 16th, 2024 [February 16th, 2024]
- Vory Threatens To 'Kill' Girlfriend In Alleged Footage Of Domestic Abuse - HipHopDX - February 16th, 2024 [February 16th, 2024]
- Best Smart Locks of 2024 - CNET - February 16th, 2024 [February 16th, 2024]
- The Ring Battery Doorbell Pro has 3D motion detection - Gadget Flow - February 16th, 2024 [February 16th, 2024]
- Ring Is Raising Rates on Some Plans by 25% in March - PCMag Middle East - February 16th, 2024 [February 16th, 2024]
- The 12 Best Home Security Cameras of 2023 - Security.org - December 11th, 2023 [December 11th, 2023]
- Traveling for the holidays? Keep an eye on your home with the Blink Mini security camera, now just $20 - Gwinnettdailypost.com - December 11th, 2023 [December 11th, 2023]
- Gangs from South America use security jammers to break in to expensive homes across country: police - WLS-TV - December 11th, 2023 [December 11th, 2023]
- Best Home Security Companies Of 2023 Forbes Home - Forbes - December 11th, 2023 [December 11th, 2023]