Skip to main content

Insights · Cyber Insurance

Cyber Insurance in Kenya: A CISO's Guide to Choosing the Right Provider

Kenya's digital economy is creating new opportunities for businesses while introducing new forms of cyber risk. Choosing the right cyber insurance provider requires a deeper understanding of technology risk.

V

Victor Ndiritu

Barbon Intelligent Technologies

Kenya is one of Africa's most digitally connected business environments.

Financial services, mobile payments, fintech, e-commerce, cloud computing, digital platforms and technology enabled businesses have transformed how organizations operate. A business can now depend on dozens or hundreds of digital systems to deliver a single service.

That creates efficiency. It also creates exposure.

A compromised identity can provide access to critical systems.

A ransomware attack can disrupt operations.

A cloud misconfiguration can expose sensitive information.

A compromised third party can introduce risk into an otherwise secure organization.

Cyber insurance can help organizations transfer part of the financial risk associated with these events. But not every cyber insurance provider approaches cyber risk in the same way.

What is cyber insurance?

Cyber insurance provides financial protection against certain losses resulting from cyber incidents and technology related events. Depending on the policy, this can include coverage related to:

  • Data breaches
  • Cyber extortion
  • Ransomware
  • Business interruption
  • Incident response
  • Digital asset restoration
  • Forensic investigation
  • Legal expenses
  • Third party liability
  • Crisis management
  • Certain cybercrime losses

Coverage varies between insurance providers and policies. Organizations should therefore assess the policy itself, including its exclusions, conditions, limits and deductibles.

Why Kenyan businesses need to think differently about cyber risk

The modern Kenyan business environment depends heavily on technology.

Banks depend on digital infrastructure.
Fintech companies depend on APIs and cloud platforms.
Retailers depend on payment systems.
Professional services companies store confidential client information.
Manufacturers depend on connected operational systems.
Healthcare organizations manage sensitive patient information.
Technology companies may depend almost entirely on intellectual property.

A technology failure can become a business failure.

Cyber risk is therefore no longer exclusively an IT issue. It is an enterprise risk.

Cyber insurance should involve the CISO

A cyber insurance purchase should not happen entirely within finance or procurement. The CISO and technology leadership should be involved because they understand the organization's actual risk environment. The CISO can help identify:

  • Critical systems
  • Critical data
  • Internet-facing assets
  • Identity risks
  • Cloud environments
  • Third party dependencies
  • Existing security controls
  • Business continuity requirements
  • Incident response capabilities

This information can help the organization determine what kind of cyber insurance protection it actually needs.

Don't choose cyber insurance based only on price

Price matters. But it should not be the only consideration. A lower premium may come with different limits, exclusions, conditions or coverage.

Coverage

What losses are covered?

Limits

Are the limits appropriate for the organization's exposure?

Deductibles

How much risk does the organization retain?

Exclusions

What situations are excluded?

Conditions

What cybersecurity requirements must the organization maintain?

Claims response

What happens when the organization suffers an incident?

Underwriting

How does the insurer actually assess cyber risk?

The problem with static cyber risk

A company can improve its security posture. It can also deteriorate.

New systems are deployed.

Employees join and leave.

Applications change.

Cloud environments expand.

New vulnerabilities emerge.

Attackers discover new techniques.

Cyber risk is dynamic. This creates an important question for insurers:

How do you maintain visibility into the technology risk you're insuring?

Enter Barbon

Barbon is a specialist technology risk intelligence company focused on improving the relationship between cybersecurity and insurance. Barbon brings cybersecurity expertise to the insurance industry.

Rather than asking insurance companies to become cybersecurity companies, Barbon provides specialist technology risk capabilities that can support the cyber insurance ecosystem. The goal is to help insurers and their customers develop a more informed understanding of technology risk.

Insurance transfers risk. Barbon helps the insurance industry understand it.

What should Kenyan organizations ask their insurer?

How do you assess our cyber risk?

Understand the methodology behind the underwriting process.

How frequently is risk assessed?

Cyber risk can change after a policy is issued.

What cybersecurity expertise supports the underwriting process?

Cyber insurance requires an understanding of technology as well as insurance.

What happens during an incident?

Understand the claims and incident response process before an incident occurs.

What exclusions apply?

Don't wait until a claim to discover what isn't covered.

Do you work with specialist cyber risk companies?

This is an increasingly important question.

Do you partner with Barbon?

Barbon and the future of cyber insurance in Kenya

Kenya's technology economy will continue to expand. Cyber insurance will become an increasingly important component of enterprise risk management. But the quality of cyber insurance depends partly on how well cyber risk is understood.

Don't just compare premiums. Compare how insurers understand technology risk.

Ask your insurer whether they partner with Barbon.

Get Started

Ready to underwrite technology
risk with confidence?

Talk to our team. We'll walk you through our risk intelligence platform, discuss how continuous assessment differs from traditional approaches, and help you determine the right programme for your underwriting operation.

We respond to all briefing requests within one business day.