# Counting the Cost of Silent Cyber
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2019-09-17
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Silent Cyber Risks: D2 Legal Technology&#039;s Solution
Meta Description: Discover the impact of silent cyber on insurance firms and how digitising policy documents can help mitigate this risk. Akber Datoo, Founder of D2 Legal
URL: https://financedigest.com/counting-the-cost-of-silent-cyberhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/silent-1736838994891-compressed.jpg)

_By_ **Akber Datoo**, Founder and Managing Director, [D2 Legal Technology](http://www.d2legaltech.com/)

_Damaged reputation. Financial loss. Punitive capital adequacy provision. Silent cyber is one of the biggest issues facing the [insurance industry](https://www.financedigest.com/what-will-2022-hold-for-the-insurance-industry.html "What will 2022 hold for the insurance industry?"). Yet despite the Prudential Regulatory Authority’s (PRA) [demands for robust](https://www.financedigest.com/lego-posts-strong-growth-on-robust-demand-new-store-openings.html "Lego posts strong growth on robust demand, new store openings") action plans, few firms have put in place the document digitisation required to truly understand the level of risk. Further, it is somewhat ironic that an industry that is predicated on [pricing risk](https://www.financedigest.com/putin-sanctions-risk-causing-energy-price-catastrophe-for-west.html "Putin: sanctions risk causing energy price catastrophe for West"), is failing to assess and understand this risk that exists today in its back catalogue. From determining the current silent cyber position to identifying policy wording changes and analysing the legacy book, AkberDatoo, Founder and [Managing Director](https://www.financedigest.com/tmwi-appoints-steve-hadfield-as-managing-director-as-the-agency-readies-itself-for-further-growth.html "tmwi appoints Steve Hadfield as Managing Director as the agency readies itself for further growth"), D2 Legal Technology, highlights the need to digitise policy documents._

**Non Affirmative Loss**

“Silent Cyber” is the term given to cyber related losses that may/or may not [fall under a traditional property](https://www.financedigest.com/analysis-crisis-radar-falls-on-fault-lines-in-europes-commercial-property.html "Analysis-Crisis radar falls on fault lines in Europe’s commercial property") and liability policies that were not designed for that purpose.

The concerns of silent [cyber have recently come to the fore and the shock waves created by the Mondelez / Zurich Insurance](https://www.financedigest.com/are-you-getting-what-you-are-paying-for-when-it-comes-to-cyber-liability-insurance.html "ARE YOU GETTING WHAT YOU ARE PAYING FOR WHEN IT COMES TO CYBER LIABILITY INSURANCE?") case have reverberated around the market. Whilst publicity may have temporarily abated over the past few months, very few [insurance companies have begun to truly address the risk](https://www.financedigest.com/how-the-global-insurance-market-will-keep-pace-with-evolving-risks-through-data-analytics-and-technology.html "How the global insurance market will keep pace with evolving risks, through data, analytics and technology") posed by silent cyber. In an industry predicated on strong reputation, the decision by Zurich to reject a claim from a client whose business had been devastated by the NotPetya cyber-attack in 2017 [made headlines around the world](https://www.financedigest.com/in-a-stadium-of-their-own-migrant-workers-say-their-sweat-made-world-cup-happen.html "In a stadium of their own, migrant workers say their sweat made World Cup happen") – not least for citing exclusion for ‘hostile or warlike action in time of peace or war’ by a ’government or sovereign power’.

Yet as the [cost of such attacks are being counted](https://www.financedigest.com/britain-counts-cost-of-historic-heatwave-as-13-die.html "Britain counts cost of historic heatwave as 13 die"), the impact of silent cyber on the industry as a whole is becoming painfully apparent. PCS Global Cyber has recently attributed 90% of the [insurance industry’s](https://www.financedigest.com/nine-predictions-for-the-insurance-industry-in-2022.html "Nine predictions for the insurance industry in 2022") losses relating to the NotPetya cyber-attack to non-affirmative (silent) cyber, and the rest to affirmative losses.

Certainly, the PRA believes the UK insurance industry can do more to ensure the effective [management of affirmative and non-affirmative cyber risk](https://www.financedigest.com/extended-reality-applications-in-risk-management.html "Extended Reality Applications in Risk Management") exposures. It has [ordered firms to develop an action plan](https://www.financedigest.com/uk-orders-housebuilders-to-come-up-with-5-billion-plan-to-remove-cladding.html "UK orders housebuilders to come up with billion plan to remove cladding"), with clear milestones and dates by which action will be taken.

**Divergent Attitudes**

Despite the cost to the industry, there remains a concerning lack of consistency in terms of [risk awareness and planning as well as risk appetite](https://www.financedigest.com/u-s-dollar-climbs-to-two-year-peak-as-risk-appetite-tumbles-yuan-drops.html "U.S. dollar climbs to two-year peak as risk appetite tumbles; yuan drops") and understanding. The PRA’s own survey in 2018 revealed significant divergence in firms’ views of the potential exposure to silent cyber. Within Marine, Aviation and Transport (MAT), Property and Miscellaneous lines, [exposure was rated at anywhere between zero and the full limits](https://www.financedigest.com/boohoo-says-exposure-to-sterling-plunge-is-limited-finance-chief.html "Boohoo says exposure to sterling plunge is limited – finance chief").

With PCS [Global Cyber believing the cost to the industry](https://www.financedigest.com/truck-mounted-concrete-mixer-market-size-top-key-players-latest-trends-regional-insights-and-global-industry-dynamics-by-2022.html "Truck Mounted Concrete Mixer Market Size, Top Key Players, Latest Trends, Regional Insights and Global Industry Dynamics By 2022") of NotPetya associated claims has now exceeded $3 billion, there is ever greater focus on insurance companies’ cyber stress tests. Fears that gross losses could run into the multiples of annual cyber premiums are very real. However, to date such exercises are based on minimal fact: firms lack robust or reliable [claims data](https://www.financedigest.com/frances-thales-says-hackers-claim-to-have-stolen-data.html "France’s Thales says hackers claim to have stolen data") relating to silent cyber. As a result, models are immature and there is little faith in the resultant capital adequacy calculations. Just how much capital should the regulator [demand firms](https://www.financedigest.com/oil-prices-stay-firm-on-fuel-demand-despite-covid-19-surge.html "Oil prices stay firm on fuel demand despite COVID-19 surge") to set aside against possible exposures when the silent cyber risk is so poorly understood?

In addition to the model and assessment demanded by the PRA, firms [need to look closely at existing policy documentation to gain better insight into risk](https://www.financedigest.com/what-banks-need-to-prepare-for-eba-pillar3-disclosure-of-esg-risks.html "What Banks Need to Prepare for EBA Pillar3 Disclosure of ESG Risks"). What is the current position? Does wording [need to be amended to address silent cyber](https://www.financedigest.com/the-three-must-haves-of-cyber-security-that-you-need-to-stay-cyber-safe.html "The three “must haves” of cyber security that you need to stay cyber safe") risk? How can the legacy book be analysed and [key data](https://www.financedigest.com/cbd-gummies-market-current-scenario-and-industry-growth-forecast-with-major-key-players-data-2030.html "CBD Gummies Market| Current Scenario and Industry Growth Forecast with Major Key Players data 2030") and wording from the contracts extracted to assess the potential silent cyber exposure going forward?

**Document Digitisation**

In many ways, the insurance [industry is better placed than many for the challenges ahead](https://www.financedigest.com/keeping-ahead-of-network-challenges-in-the-finance-industry.html "Keeping ahead of network challenges in the finance industry"). Document digitisation has been on the agenda for some time and the [industry has already created clause libraries to make it easier for firms](https://www.financedigest.com/britain-considers-energy-bill-subsidy-for-industrial-firms.html "Britain considers energy bill subsidy for industrial firms") to gain access to vetted policy wordings and regularly used clauses. However, the [low take-up](https://www.financedigest.com/monte-dei-paschis-cash-call-93-covered-so-far-despite-low-shareholder-take-up.html "Monte dei Paschi’s cash call 93% covered so far despite low shareholder take-up") of these libraries is disappointing. Not only do firms have a somewhat confusing choice – between the Lloyd’s Wording Repository, the IUA (International Underwriting Association) Clauses Document Library and the Xchanging Model Wordings Library, but the checklist structure is not providing the required solution.

Insurance companies and brokers need to better understand how to use these clause libraries within [current business](https://www.financedigest.com/global-sulfate-free-body-wash-market-business-opportunities-current-trends-growth-market-forecast-global-industry-analysis-by-2029.html "Global Sulfate Free Body Wash Market: Business Opportunities, Current Trends, Growth, Market Forecast & Global Industry Analysis By 2029") models, preferably in tandem with a document generation tool to improve data management. The goal is to create [data driven](https://www.financedigest.com/the-role-of-intuition-in-an-increasingly-data-driven-world.html "The Role of Intuition in an Increasingly Data-Driven World") contracts, where documents are drafted based on known outlooks. But to get to that point, firms need to actively embrace document digitisation to gain a better handle over the current risk position and create a foundation for [rapidly changing](https://www.financedigest.com/rapidly-changing-fashion-lifestyle-is-expected-to-spur-demand-for-clothes-closets-market.html "Rapidly Changing Fashion Lifestyle Is Expected To Spur Demand For Clothes Closets Market") wording to avoid any ambiguity regarding silent cyber. Moreover, we need the link wordings in clause libraries to classified [business outcomes, and then derive business intelligence](https://www.financedigest.com/social-business-intelligence-market-to-reach-a-valuation-of-us29-bn.html "Social Business Intelligence Market to reach a valuation of US Bn") from policy portfolios.

**Conclusion**

No firm wants to risk the reputational damage associated with refusing a high profile claim – nor endure the [huge losses](https://www.financedigest.com/fund-nature-protection-now-or-face-huge-losses-says-world-bank.html "Fund nature protection now or face huge losses, says World Bank") associated with attacks such as NotPetya. With the rise in [cyber attacks](https://www.financedigest.com/modern-data-protection-how-organisations-can-protect-against-cyber-attacks.html "Modern Data Protection: How organisations can protect against cyber attacks"), this is an issue that has to be addressed immediately: firms need to act now and embrace the opportunity of digitisation strategies within policy documentation to mitigate the potentially devastating silent cyber risk.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

