impact
ACTIONABLE INSIGHT FOR BUSINESS LEADERS / CYBER RISK / MARCH 2016
0111 0111
1111 1111 0111 0111
0011 0111 0111 1111 1111
1 00 1111 0111 0111 0111 0111 0111 0111
0111 0011 1111 1111 1111 0111 1111 0111 1111 0111 1111
1111 1 00 0011 0011 0011 1111 0011 1111 0011 1111 0011
0011 1000 1 00 1 00 1 00 0011 1 00 0011 1 00 0011 1 00
1 00 1111 1000 1000 1000 1 00 1000 1 00 1000 1 00 1000
1000 00 1 1111 1111 1111 1000 1111 1000 1111 1000 1111
1111 1 0 00 1 00 1 00 1 1111 00 1 1111 00 1 1111 00 1
00 1 010 1 0 1 0 1 0 00 1 1 0 00 1 1 0 00 1 1 0
1 0 010 010 010 1 0 010 1 0 010 1 0 010
010 010 0111 010 0111 010 0111
1111 1111 1111
0011 0011 0111 0011
0111 1111
1111 0011
0011 1 00
1 00 1000
1000 1111
1111 00 1
00 1 1 0
1 0 010
010
CYBER RISK
REGULATION:
FIRST LINE OF DEFENCE
0111
1111 0111
0011 1111 0111
1 00
1000
0011
1 00
1111
0011
impact
02
1111 1000 1 00
ACTIONABLE INSIGHT FOR BUSINESS LEADERS / CYBER RISK / MARCH 2016
00 1 1111 1000
1 0 00 1 1111
010 1 0 00 1
010 1 0
010
Regulators and ratings agencies are beginning to take a much
closer look at cyber risk, with a particular interest in data
security and exposure management.
By Stuart Collins
C
yber risk is a hotly debated issue Milliman. Insurance supervisors and regulators will
for insurers. On the one hand have to balance their primary concerns of consumer
it offers a welcome source of protection and solvency, with societys need for cyber
new business and, as the world risk transfer products, she says.
becomes more dependent on Adam Hamm, insurance commissioner for North
technology and data, cyber risk is Dakota, and chair of the National Association of
destined to become a much bigger Insurance Commissioners (NAIC) Cyber Security Task
part of insurers business. Yet it Force, explains: Regulators do not want to stifle growth
also comes with challenges, as insurers grapple with in cyber insurance. It has an important part to play in
a lack of historical data and the threat of aggregation the USs cyber defence. We want the market to develop
and systemic risks. in the correct manner.
Against this backdrop, regulators and ratings Kathryn Morgan, director of regulatory operations,
agencies are becoming increasingly aware of the Gibraltar Financial Services Commission, agrees: Our
potential risks cyber presents to insurers balance sheets statutory objective is to protect consumers. It is not
and the industrys reputation, according to Derek the role of a regulator to predict or react in a knee-jerk
Newton, principal and consulting actuary at Milliman fashion to innovation but to keep an eye on the market
in London. and develop new rules if needed.
Cyber is a rapidly evolving area for insurers, but it On the role of the regulator in shaping the
is also an emerging challenge for regulators. We are burgeoning cyber insurance market, Hamm continues:
already seeing regulators and ratings agencies show As regulators, we would not look to micro manage
growing interest in insurers cyber security and the the way insurers develop any line of business,
exposures they are taking on their balance sheets as so we would not want to dictate how they should grow
connected technology and the Internet become more cyber insurance.
and more relevant to their business, he says.
As a result, insurers are likely to face greater
reporting of cyber security risks and exposures in the
not-too-distant future, while the way in which they use
data, as well as its security and integrity, are likely to 0111 0111
come under increasing scrutiny, he adds.
0111 1111 0111 1111
Protecting consumers, promoting growth 1111 0011 1111 0011
Regulators have a difficult task ahead, according to
Christine Fleming, claims management consultant, 0011 1 00 0011 1 00
1 00 1000 1 00 1000
1000 1111 1000 1111
1111 00 1 1111 00 1
MILLIMAN / IMPACT / MAR 2016 00 1 1 0 00 1 1 0
1 0 010 1 0 010
010 010
[Link]
0111 0111
1111 1111
0011 0111 0011
impact
03 ACTIONABLE INSIGHT FOR BUSINESS LEADERS / CYBER RISK / MARCH 2016
Targets of cyber crime
We are already seeing regulators and Regulators are concerned
ratings agencies show growing interest with both insurers own cyber
security, and the potential
in insurers cyber security and the solvency risks associated
with cyber-related exposures,
exposures they are taking on their according to Fleming. However,
balance sheets as connected technology as the cyber insurance market
is still relatively small, and
and the Internet become more and more exposures limited, the initial
emphasis seems to be on
relevant to their business. improving cyber security,
Derek Newton, principal and she says.
consulting actuary, Milliman
In the US, a number of
healthcare insurers have been
involved in massive data
However, there is concern around insurers ability breaches, including the theft of as many as 80 million
to protect consumer data. And as the market grows, policyholders at Anthem, Inc. in January 2015.
regulators will want to see that insurers understand the In the UK, Royal Sun Alliance admitted
risks they are taking on and that they are able to make in September 2015 that [some of ] its bancassurance
good on the policies they sell, he says. customers personal details were compromised after
Arguably, the NAIC has taken the lead among the a storage device was stolen from a data centre. In
worlds insurance regulators, having been particularly 2010, Zurich Insurance was fined 2.2m by the
active in addressing cyber security over the past year. Information Commissioners Office after it lost 46,000
In 2014, the organisation established a Cyber Security customer records.
Task Force, which has already made huge progress in Financial services companies, which hold large
promoting higher standards of cyber security, as well amounts of personal data on their customers, are
as moves to gather more information on insurers cyber attractive targets for cyber criminals, and this has not
insurance activities and exposures. escaped the attention of regulators.
Other regulators have been less visibly active. But According to Morgan: There is increased regulatory
that is not to say that cyber is not on their agendas. For scrutiny of IT and cyber security risks for insurers. For
example, the UKs Prudential Regulatory Authority all new licence applications in Gibraltar we review the
(PRA) does not appear to have a specific regulatory companys IT systems, including those used to price risk
policy for cyber risk, but it does have a programme and hold consumer data. We also conduct regular cyber
regarding IT resilience and risk. During the summer of security reviews based on the size of an organisation and
2015, the Bank of England and the PRA conducted a the kind of work they do.
survey of insurers IT security, which included questions According to Alan Pereira, CIO, Gibraltar Financial
on whether they offer cyber insurance. Services Commission: No company is safe from a cyber
In its 2015/16 Business Plan, the UKs Financial
Conduct Authority identified cyber crime as a risk to
insurers, as well as warning that insurers need to ensure
there is absolute clarity about what cyber insurance
policies do and do not cover. 0111
1111 0111
MILLIMAN / IMPACT / MAR 2016
0011 1111 0111
1 00 0011 1111
[Link] 1000 1 00 0011
1111 1000 1 00
00 1 1111 1000
0111 1111 0111 1111
1111 0011 1111 0011
0011 1 00 0011 1 00
1 00
1000
1000
1111
1 00
1000
1000
1111
impact
04
1111 00 1 1111 00 1 ACTIONABLE INSIGHT FOR BUSINESS LEADERS / CYBER RISK / MARCH 2016
00 1 1 0 00 1 1 0
1 0 010 1 0 010
010 0111 010 0111
1111 1111
0011 0111 0011
0111 1111
1111 0011 management and will force insurers to consider
both operational and underwriting risks in more
0011 1 00 detail, documenting the process and presenting
1 00 1000 it in a way that can be understood by regulators
and other stakeholders.
1000 1111 EIOPA says: In our view, cyber risk needs to be seen
1111 00 1 with regard to the undertakings internal measures
for protection of their data. Some relevant guidance
00 1 1 0 is mentioned in EIOPA Solvency II Guidelines on
1 0 010 System of Governance in the section risk management
of operational risks. Furthermore, the Own Risk and
010 Solvency Assessment (ORSA) under Solvency II is
the measure to assess all risks and to analyse any
impact those risks may have on the solvency needs
of the undertaking.
attack. Organisations look to mitigate cyber risk but it In practice this means that in its at-least-yearly
cant be 100% eliminated. ORSA the undertaking has to assess all types of risks it
The GFSC now looks closely at a regulated companys
reliance on IT, the precautions it takes, access to data
and business continuity planning, and whether they are
following cyber security standards.
Pereira explains: This is an issue that
the Commission is taking very seriously.
We require an annual statement of compliance
which in the future will include details of cyber
security. Well also conduct ongoing regulatory
monitoring including supervisory visits
and are in the process of adding a review
of cyber security.
Solvency II: A framework
for cyber risk
In Europe, regulators have been
occupied with Solvency II, new capital
and risk management rules which were implemented
in January 2016.
Solvency II does not specifically address cyber risk,
but it does provide a framework to capture and manage
cyber exposures and operational risks related to
cyber security.
The EU regulatory body, the European Insurance
and Occupational Pensions Authority (EIOPA), says
that Solvency II will increase the emphasis on risk
MILLIMAN / IMPACT / MAR 2016
[Link]
impact
05 ACTIONABLE INSIGHT FOR BUSINESS LEADERS / CYBER RISK / MARCH 2016
is exposed to and use scenarios and stress tests for each insurance industry, in general, and our rated entities, in
of its significant risks. According to the results of those particular, are aware and prepared to face the challenges
stressed scenarios the undertaking should define its and threats that cyber attacks and data breaches impose
capital needs and its possible management actions for upon them. We would like to see them recognising the
those significant risks. risk and have plans to confront it as part of their overall
In addition, EIOPAs Insurance & Reinsurance risk management practices and ERM framework.
Stakeholder Group has established a sub-group to For the companies issuing cyber insurance policies,
examine cyber risk and insurance. It is currently the issue becomes more critical not only since the
considering whether to formally look into the issue and exposure is higher but also because cyber security risk
how it might proceed. has interdependencies, thus measuring and managing
the aggregation of risk within cyber insurance portfolios
International guidance forthcoming becomes very critical.
Given the global nature of cyber risk, international Cyber security is now part of AM Bests annual
regulatory guidance is likely to be developed in rating review meetings. The ratings agency has also
the future. According to Morgan: The trend is in the been conducting surveys and sending out various
direction of international regulatory guidance for cyber questionnaires to create a sense of awareness within the
security. As technology creeps into more and more risks, industry that reliable data is critical.
regulators will need to keep abreast of the changing Via its annual Supplementary Ratings Questionnaire,
world and adapt. AM Best asks rated insurers for information on the
Meanwhile, the International Association of number of policies, total annual direct premiums,
Insurance Supervisors (IAIS) recently stated:
Cyber crime is becoming more frequent, more
sophisticated, and more widespread. It is therefore
important that insurance regulators and supervisors,
as well as insurers themselves, understand how
cyber crime may affect the insurance sector, and
take concrete steps to ensure development and
implementation of best practices. We are interested to ensure that the
The IAIS Financial Crime Task Force (FCTF) has
already started to draft an Issues Paper on Cyber-
insurance industry, in general,
Crime Risks to the Insurance Sector. The paper is and our rated entities, in particular,
expected to be released for public consultation in
mid-2016. are aware and prepared to face
In addition, the FCTF recently increased its
mandate to include understanding developments in
the challenges that cyber attacks
the cyber insurance market. It will produce a base- and data breaches impose upon
line memorandum as well as regular updates.
them. We would like to see them
Ratings agencies ahead of the game
Insurance ratings agencies are also starting to ask
recognising the risk and have
more questions of insurers cyber security measures plans to confront it as part of their
and their cyber insurance underwriting activities.
Fred Eslami, senior financial analyst at AM Best, overall ERM framework.
says: We are keenly interested to ensure that the Fred Eslami, senior financial analyst, AM Best
MILLIMAN / IMPACT / MAR 2016
[Link]
impact
06 ACTIONABLE INSIGHT FOR BUSINESS LEADERS / CYBER RISK / MARCH 2016
0111 0111
0111 1111 0111 1111
1111 0011 1111 0011
0011 1 00 0011 1 00
number of claims, and incurred losses and loss
adjustment expenses, as well as their top three 1 00 1000 1 00 1000
largest exposures. 1000 1111 1000 1111
Eslami adds: As we obtain more information from
our rated entities on the topic, we would be developing 1111 00 1 1111 00 1
specific criteria relevant to cyber security as we have 00 1 1 0 00 1 1 0
for natural catastrophes and terrorism. This may take
a few years; in the meantime, we continue with what I 1 0 010 1 0 010
outlined above and gather information. 010 0111 0111
At this time, when reliable consequence-oriented
data and analytics are not readily available, we do not
0111 1111 1111
consider the risk as impacting any individual insurers 1111 0011 0011
rating. But as more data and analytics become available,
0011 1 00
similar to natural catastrophes and terrorism, this risk
would become relevant to and have an impact on an 1 00 1000
insurers rating. 1000 1111
Ratings agency Fitch Ratings is also increasing its
focus on cyber exposure monitoring and the protection 1111 00 1
purchased by rated insurers. Graham Coutts, Associate 00 1 1 0
Director at the agency, says: Insurers now collect and
store more personal information about their clients than 1 0 010
ever before. This will warrant an increase in attention 010
paid to protection of data and response to breaches.
Currently cyber risk is a relatively small line of
business for most of our rated insurers. Fitch will
continue to monitor this line closely due to its relative It is clear that cyber insurance and data
infancy and rapid growth. protection are only going to grow in their relevance
for insurance. Whether its the use of big data,
Tougher laws their own cyber security or an increase
At the end of 2015, EU authorities finally reached in cyber exposures on insurers balance sheets,
agreement on EU data protection laws. The new laws, regulators are clearly taking more interest,
which are expected to be enforced in early 2018, are says Newton.
expected to significantly increase the penalties for a data
breach or mishandling of personal data by European
companies, as well as foreign companies dealing in Find out more
personal data of EU citizens. The law applies to all
sectors, including insurers. Christine Fleming
+1 781 213 6249
As a result, it is likely that Europe will follow in the [Link]@[Link]
footsteps of the US, where tougher data protection laws
Derek Newton
have helped drive demand for cyber insurance. But
+44 20 7847 1606
more stringent EU data protection laws are just part of [Link]@[Link]
the story for insurers, says Newton.
MILLIMAN / IMPACT / MAR 2016
[Link] Copyright 2016 Milliman, Inc.