Africa's businesses are becoming increasingly digital.
Banks process enormous volumes of digital transactions. Fintech companies operate entirely through technology platforms. Manufacturers depend on connected systems and automated processes. Professional services firms store sensitive client information in cloud environments. Governments, healthcare organizations, retailers and businesses of every size increasingly depend on digital infrastructure to operate.
That digital transformation creates opportunity.
It also creates risk.
A ransomware attack can bring operations to a standstill. A compromised employee account can result in financial loss. A data breach can expose confidential customer information. Theft of intellectual property can undermine years of research and investment. A compromise of a third party can create consequences for an organization that was never directly attacked.
Cyber insurance can provide an important layer of financial protection against these risks.
But there is a question that every CISO, CIO and risk executive should ask before purchasing a policy:
Does the insurer actually understand the technology risk it is underwriting?
This is where Barbon comes in.
What is cyber insurance?
Cyber insurance is a form of insurance designed to help organizations manage financial losses associated with cyber incidents and technology related risks. Depending on the policy, coverage may include areas such as:
- Data breach response
- Cyber extortion and ransomware
- Business interruption
- Digital asset restoration
- Incident response
- Forensic investigation
- Legal expenses
- Regulatory response
- Third party liability
- Crisis management
- Certain cybercrime related losses
The exact coverage, limits, exclusions and conditions vary between policies and insurers. Organizations should evaluate the actual policy wording rather than assuming that every cyber insurance policy provides the same protection.
Why cyber insurance is different
Cyber risk behaves differently from many traditional insurance risks. A building does not suddenly change its structure because an administrator changed a configuration. A company's cyber risk can change overnight.
A new cloud application can be deployed.
A vulnerability can become publicly exploitable.
An employee account can become compromised.
A firewall rule can be changed.
A third party can suffer a breach.
A previously secure system can become exposed to the internet.
The organization's risk environment is therefore not necessarily the same six months after a policy is issued as it was on the day the application was completed.
Cyber insurance requires an understanding of technology risk
Traditional underwriting relies heavily on information supplied during the insurance application process. That information remains important. But cyber risk requires a deeper understanding of the technology environment behind the organization.
The limitations of point-in-time risk assessment
A cyber insurance application can provide an important snapshot of an organization's security posture. But a snapshot is still a snapshot.
Technology environments change.
Security controls change.
Employees change.
Applications change.
Attack techniques change.
The threat environment changes.
This is one of the reasons technology risk intelligence is becoming increasingly important to cyber insurance.
Barbon: Bringing Cybersecurity Expertise to Insurance
Barbon is a specialist technology risk intelligence company focused on the intersection of cybersecurity and insurance. Our mission is straightforward:
Bring specialist cybersecurity expertise into the insurance industry so cyber risk can be better understood, assessed and managed.
Barbon works with insurance companies and insurance partners to help bring technology risk intelligence into the cyber insurance ecosystem. The insurer remains the insurer. Barbon provides specialist expertise around the technology risk that sits behind the insurance relationship.
Insurer
Provides the insurance
Barbon
Provides specialist cyber risk intelligence
Together
A more informed approach to cyber risk
What should CISOs look for in a cyber insurance provider?
A CISO evaluating cyber insurance should consider more than the premium.
How is cyber risk assessed?
Ask how the insurer evaluates the organization's technology environment. Does the process rely entirely on a questionnaire? Are additional sources of technology risk information considered?
Does the insurer understand your technology?
The insurer should understand that your cyber risk is connected to your actual technology environment. Cloud infrastructure, identity systems, applications, endpoints, data and third parties can all affect exposure.
How does the insurer deal with changing risk?
Ask what happens when the organization's technology environment changes after the policy is issued.
What happens during an incident?
Understand the insurer's claims and incident response process before an incident occurs.
What does the policy actually cover?
Review coverage, limits, exclusions, deductibles and conditions carefully.
Cyber insurance in Africa needs better cyber intelligence
Africa's digital economy will continue to grow. So will the importance of cyber risk. The organizations that benefit most from cyber insurance will be those that understand exactly what they are trying to protect, how their technology environment creates exposure and whether their insurance provider understands that risk.
Cyber insurance needs cyber intelligence.
Don't only ask whether an insurer sells cyber insurance. Ask how they understand your technology risk.
Ask whether your insurer partners with Barbon.