The rise of the cyber insurance has largely failed to promote better cybersecurity practices among the industries they cover, according to a new report released Monday from British security think tank RUSI. (Photo by Spencer Platt/Getty Images)
The security community for the last few years pointed to great potential for cyber insurance to drive progress in cyber best practices: force companies to up their game by making certain standards a requirement for coverage.
But recent research shows thats not happening.
The rise of the cyber insurance has largely failed to promote better cybersecurity practices among the industries they cover, according to a new report released Monday from the British security think tank Royal United Services Institute (RUSI). This is particularly true for the scourge of ransomware, where rising payments and business incentives to pay may pose an existential threat insurance providers in Great Britain and beyond.
Although ransomware is a societal problem, the authors note that cyber insurers are facing some heat for the role they play in financially propping up the cyber-criminal industry.
These add fuel to the fire by incentivizing cybercriminals engagement in ransomware operations and enabling existing operators to invest in and expand their capabilities, write authors Jamie MacColl, Jason R.C. Nurse and James Sullivan. Growing losses from ransomware attacks haveemphasized that the current reality is not sustainable for insurers either.
When a company is hit with ransomware, theyre often faced with three choices: pay up, lean on backups or rebuild the entire IT network. Since insurers usually opt to cover the cheapest option, paying an upfront ransom almost always ends up costing less than starting from scratch or incurring weeks of downtime while systems are restored from backups.
While this model and approach seemingly make business sense to insurers, it ends up putting an absurd amount of money into the pockets of criminal groups. These groups then have more resources to further develop their malware and infrastructure, offer better compensation to entice talented hackers to join their network and buy zero-day exploits or initial access to victim companies.
In February, a report from Chainalysis, which tracks cryptocurrency payments in law enforcement investigations, estimated that these groups took home at least $350 million in ransom payments in 2020, and experts say that many incidents are not publicly reported, because the victim has decided to quietly pay before their information is advertised online and not engage with law enforcement.
Several high-profile incidents in recent months underscored the challenges faced in this area. The U.S. government was initially unable to get information around ransom payment from executives at Colonial Pipeline, and some were outraged when CEO Joseph Blount in a media interview appeared to cast paying the $4.3 million ransom (which Blount later said the company submitted an insurance claim for) as the right thing to do and a patriotic duty to keep vital American infrastructure running. A ransomware attack on insurance giant CNA in March also resulted in a $40 million payment that is believed to be the largest ransom payment to date on record, according to Bloomberg.
The RUSI report, part of a year-long project with the University of Kent studying ways to incentivize better cybersecurity through insurance, finds little hard evidence that indicate this model is forcing companies to reevaluate their own cybersecurity practices and investments. It also warns the current model of making regular large ransom payments will not financially benefit insurers over the long term.
While some of the carriers interviewed for the report touted their pre and post-incident services like forensic analysis, incident response, legal services and public relations as valuable services that help lift a victim organization to a higher, more secure plane of cybersecurity that prevents future attacks, theres only scant, scattered evidence that this is actually happening in some places.
In fact, many companies that buy cyber insurance tend to view it as a tool for resilience against cyber attacks rather than a risk mitigation tool. Research by threat intelligence firm Cybereason in June claimed that an eye-popping 80% of companies that paid the ransom wound up getting infected by ransomware again in the following months, often by the same group.
One example of a favorable impact cited by the authors: claims by U.S. insurance provider Corvus that their scanning for ports and vulnerabilities commonly exploited by ransomware groups resulted in a 65% drop in ransomware-related claims from April to September 2020.
These insurers can do more to sharpen the kind of data they collect, push industry to adopt security standards set by government organizations like the U.S. National Institute for Standards and Technology and rate different cyber security products for their value and impact on premium costs.
There is a solid body of theoretical arguments that cyber insurance could play a meaningful role in improving cyber security among businesses, as referenced in a previous RUSI Emerging Insights paper, the report argues. However, in practice, it is still yet to be seen if cyber insurance can fulfil this promise.
While the paper is geared towards the UK insurance market, the challenges and potential solutions outlined share many parallels with that of the U.S. market, where a ransomware epidemic has forced policymakers to elevate the issue and consider a number of previously extreme solutions, like banning ransom payments, heavily regulating the cryptocurrencies used to pay and directing law enforcement and intelligence agencies to increasingly target the IT infrastructure that these groups rely on to carry out their schemes.
The findings echo similar claims made in a U.S. Government Accountability Office report on cyber insurance in May, which found that the industry on the whole lacked the kind of historical data around data breaches and their effective mitigations to properly price their coverage, though some providers of cyber insurance interviewed by SC Media disputed the conclusions at the time.
If you ever go to a restaurant and felt like having a nice lobster dinner, you probably saw the menu say market priced, because who knows how many lobsters they caught that day, or that time a month or that year? The pricing is really variable in what lobsters cost on a day-to-day basis, it can fluctuate wildly, said John Pescatore, director of emerging security trends at the SANS Institute, in May. Thats sort of what the case is [today] for cyber insurance, its essentially market price.
Read more:
Scant evidence that cyber insurance boom is leading to better security SC Magazine - SC Magazine
- Lily Allen and David Harbour Turned Their Brooklyn Home Into 'Weird' Floral WonderlandSo, What Becomes of It Amid Rumored Split? - SFGATE - February 8th, 2025 [February 8th, 2025]
- Caught on camera: Bixby woman nearly walks in on masked burglar in her home - news9.com KWTV - February 8th, 2025 [February 8th, 2025]
- Smart Lock Market to Attain Valuation of US$ 15.42 Billion by 2032 - Yahoo Finance - February 8th, 2025 [February 8th, 2025]
- Travis Kelce goes full John Wick on home security after burglary - Marca English - February 8th, 2025 [February 8th, 2025]
- Google Nest Security Camera With Floodlight Wont Stay This Cheap for Long, First Price Drop in Months - Gizmodo - February 8th, 2025 [February 8th, 2025]
- The 3 Best Smart Water-Leak Detectors of 2025 | Reviews by Wirecutter - Wirecutter, A New York Times Company - February 8th, 2025 [February 8th, 2025]
- Oil Billionaire Bill Koch Lists His Eco-Friendly 'Once in a Lifetime' Aspen Estate for $125 MillionMore Than Four Times What He Paid - SFGATE - February 8th, 2025 [February 8th, 2025]
- Home Security Systems Market is anticipated to project robust - openPR - February 8th, 2025 [February 8th, 2025]
- The best Wyze Cam alternative I've tested is only $20 with this deal - ZDNet - February 8th, 2025 [February 8th, 2025]
- Eufy SoloCam S340 review: a solar-powered and fully wireless outdoor security camera - The Independent - February 8th, 2025 [February 8th, 2025]
- Smart Lock Buying Guide: Picking Locks the Right Way - CNET - February 8th, 2025 [February 8th, 2025]
- Trump's Homeland Security pick pressed on domestic terrorism in hearing - NPR - January 21st, 2025 [January 21st, 2025]
- Man watches in horror from security camera as California wildfire engulfs his home: 'All I could do' - Fox Weather - January 21st, 2025 [January 21st, 2025]
- Unprecedented video shows falling meteorite, records sound of impact - For The Win - January 21st, 2025 [January 21st, 2025]
- HomeKit Weekly: Combat dry winter air with the SwitchBot Smart Evaporative Humidifier - 9to5Mac - January 21st, 2025 [January 21st, 2025]
- The Google Home app is getting a big update, and it's good news for your security - TechRadar - January 21st, 2025 [January 21st, 2025]
- 6 ways Reolink's CES 2025 gadgets upped the ante for every other security camera this year - Android Police - January 21st, 2025 [January 21st, 2025]
- No Monthly Fee, the Eufy Security Floodlight Cam Is Now More Affordable Than Ever - Gizmodo - January 21st, 2025 [January 21st, 2025]
- Sound of Meteorite Hitting Earth Recorded by Security Camera Moments After Couple Left Home to Walk Their Dogs - PEOPLE - January 21st, 2025 [January 21st, 2025]
- Attempted burglary in Cranford highlights importance of home security - News 12 New Jersey - January 3rd, 2025 [January 3rd, 2025]
- Matthew Stafford had police inspect his home for potential security flaws amid burglaries - Rams Wire - January 3rd, 2025 [January 3rd, 2025]
- The Ring Stick Up Cam Pro drops to its all-time low price! - Android Authority - January 3rd, 2025 [January 3rd, 2025]
- Dallas Mavericks star Luka Doncic's home targeted in string of home burglaries - CBS News - January 3rd, 2025 [January 3rd, 2025]
- How Wireless Doorbell Kits Are Changing Home Security for the Better - openPR - January 3rd, 2025 [January 3rd, 2025]
- What UHNWs can learn about home security from 10 million London mansion heist - Spear's WMS - January 3rd, 2025 [January 3rd, 2025]
- Luxury Turns to Loss: Shafira Huangs Shocking Theft - Qhubo - January 3rd, 2025 [January 3rd, 2025]
- Home Tech Companies Are Peddling 'Affectionate Intelligence.' Should We Fall for It? - CNET - January 3rd, 2025 [January 3rd, 2025]
- The Best of Smart Home in 2024: The 10 Articles You Read the Most - How-To Geek - January 3rd, 2025 [January 3rd, 2025]
- The Top Home Security Mistakes to Stop Making in 2025 - CNET - January 3rd, 2025 [January 3rd, 2025]
- MagSafe Monday: LISEN delivers the strongest MagSafe magnet Ive found for the car - 9to5Mac - January 3rd, 2025 [January 3rd, 2025]
- The best floodlight and security camera combo I've tested is $70 off - ZDNet - January 3rd, 2025 [January 3rd, 2025]
- I invested in a subscription-less video doorbell, and it's paying off for my smart home - ZDNet - January 3rd, 2025 [January 3rd, 2025]
- NBA follows NFL in warning players on burglaries - ESPN - November 29th, 2024 [November 29th, 2024]
- Find heavily discounted security cameras and video doorbells ahead of Black Friday - Mashable - November 29th, 2024 [November 29th, 2024]
- This Floodlight Camera Has My Backyard Covered, and It's Under $100 for Black Friday - Lifehacker - November 29th, 2024 [November 29th, 2024]
- Get the ultimate home security this holiday season with Wyze starting at $17 - New York Post - November 29th, 2024 [November 29th, 2024]
- This Is the Best Black Friday Deal for an All-Purpose Security Cam I've Ever Seen - CNET - November 29th, 2024 [November 29th, 2024]
- NBA memo to players urges increased vigilance regarding home security following break-ins - Ashland Daily Press - November 29th, 2024 [November 29th, 2024]
- Find discounted security cameras and video doorbells ahead of Black Friday - Mashable - November 29th, 2024 [November 29th, 2024]
- The 4 Most Common Package Scams in 2024 -- and How to Stop Them - CNET - November 29th, 2024 [November 29th, 2024]
- Keep Your Home Protected During Your Holiday Travel With Up to 60% Off Blink Outdoor 4 Cams - CNET - November 21st, 2024 [November 21st, 2024]
- Editor's Note: Whats Old is New and Innovative Again? - SecurityInfoWatch - November 21st, 2024 [November 21st, 2024]
- Beef Up Your Home Security and Get Up to 77% Off With These Arlo Black Friday Deals - CNET - November 21st, 2024 [November 21st, 2024]
- Ive ditched my Nest Cams for a Chinese smart security brand you probably havent heard of - The Ambient - November 21st, 2024 [November 21st, 2024]
- Boost Your Home's Security With the Outdoor Roku Cam, Down to $20 for Black Friday - CNET - November 21st, 2024 [November 21st, 2024]
- Home Security Experts Share Important Insights About the Travis Kelce and Patrick Mahomes Burglaries - House Beautiful - November 21st, 2024 [November 21st, 2024]
- Infinity Symbol-Shaped Circular House Hits the Market for the Unique Price of $3,399,888 - SFGATE - November 21st, 2024 [November 21st, 2024]
- The Blink Outdoor 4 Home Security Cameras Are Cheaper Than Last Year's Black Friday Prices - Gizmodo - November 21st, 2024 [November 21st, 2024]
- Blink Mini 2 review: this home security camera is good price, but unimpressive performance might make you think twice - TechRadar - November 21st, 2024 [November 21st, 2024]
- How to Scrub Your Home Address Off the Internet and Keep It Off - CNET - November 21st, 2024 [November 21st, 2024]
- Defiant Smart Home Alarm Kit review: Just the basics - TechHive - November 21st, 2024 [November 21st, 2024]
- New Report Cites Six Outdoor Home Improvements That Enhance Wellness - Forbes - November 21st, 2024 [November 21st, 2024]
- 3 New AI Smart Home Features Arrive With Gemini and Google Nest - CNET - November 21st, 2024 [November 21st, 2024]
- Announcing the 2024 Readers' Choice Product Awards! - SecurityInfoWatch - November 21st, 2024 [November 21st, 2024]
- The Arlo 2K battery-powered security camera is 60% off before Black Friday - ZDNet - November 21st, 2024 [November 21st, 2024]
- Abilene Police expert offers advice on safeguarding your home during the holiday season - KTXS - November 21st, 2024 [November 21st, 2024]
- Travis Kelce and Taylor Swift take drastic measures after home burglary: 'They have 24-hour armed security staff' - Marca.com - November 21st, 2024 [November 21st, 2024]
- Smart Home Security Market will increase to USD 10.25 Billion by 2030 - openPR - November 21st, 2024 [November 21st, 2024]
- Want better home security? Dont miss these Reolink early Black Friday deals - Digital Trends - November 21st, 2024 [November 21st, 2024]
- An Interview With the Target & Home Depot Hacker - Krebs on Security - November 21st, 2024 [November 21st, 2024]
- Protect Your Home Title & Equity from Fraud with TripleLock Monitoring, Alerts & Restoration - ABC Action News Tampa Bay - November 12th, 2024 [November 12th, 2024]
- Wireless Home Security Camera Market is growing at a CAGR of 20% in the forecast period (2024-2031) - openPR - November 12th, 2024 [November 12th, 2024]
- Yes, Smart Homes Are Vulnerable to Cybercriminals. Here's What You Need to Know. - House Beautiful - November 12th, 2024 [November 12th, 2024]
- Limited-Time Deal: Protect Your Home or Business With a Ring Indoor Camera at Almost 40% Off - CNET - November 12th, 2024 [November 12th, 2024]
- The 3 Best Indoor Security Cameras of 2024 | Reviews by Wirecutter - Wirecutter, A New York Times Company - November 12th, 2024 [November 12th, 2024]
- Get home security cameras up to 60% off and feel extra cozy this winter - Mashable - November 12th, 2024 [November 12th, 2024]
- Resideo Unveils Honeywell Home FocusPRO Thermostats - SecurityInformed - November 12th, 2024 [November 12th, 2024]
- A Smart Before-the-Holidays Decision: Arlo and Allstate are Boosting Peace of Mind with New Home Security Bundle - IoT Evolution World - November 12th, 2024 [November 12th, 2024]
- The Google Nest Cam With Floodlight Is at Its Lowest Ever Price, but Not for Long - CNET - November 12th, 2024 [November 12th, 2024]
- Man shot by security guard at Home Depot in Northeast Philly - The Philadelphia Inquirer - November 12th, 2024 [November 12th, 2024]
- Keep Eyes on Your Home at All Times With a Blink Outdoor Cam for 60% Off - CNET - November 12th, 2024 [November 12th, 2024]
- A Letter to the Nation's New Leaders: Right Now, the American Dream of Homeownership Is in Crisis - SFGATE - November 12th, 2024 [November 12th, 2024]
- Get your tickets SECURED to Z100s Jingle Ball from Slomins Home Security! - iHeart - November 12th, 2024 [November 12th, 2024]
- We test a new home security package that couldn't be simpler to install - The Scotsman - November 12th, 2024 [November 12th, 2024]
- 6 Smart Gadgets That Will Instantly Upgrade Any Home's Lighting And Security - SlashGear - November 12th, 2024 [November 12th, 2024]
- Amazon has this Blink doorbell and security camera bundle on sale for the lowest price ever and its before - NJ.com - September 29th, 2024 [September 29th, 2024]
- This Blink Video Doorbell and security camera bundle is down to $59.99 at Amazon - TechRadar - September 29th, 2024 [September 29th, 2024]
- This new Eufy home security camera uses AI to add color to its night vision - TechRadar - September 29th, 2024 [September 29th, 2024]
- Did Jennifer Lopez and Ben Affleck Just Run Into More Trouble With Sale of $68 Million Marital Mansion? - SFGATE - September 29th, 2024 [September 29th, 2024]
- Sound the alarm! This 14-piece Ring smart security system is 40% off - Android Police - September 29th, 2024 [September 29th, 2024]