# Driving out Silent Cyber Losses and Risks for Insurers and the Insured
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2019-03-27
Category: INSURANCE
Category URL: https://financedigest.com/category/insurance
Meta Title: Uncovering the Hidden Risks of Silent Cyber in Insurance
Meta Description: Discover how cyberattacks can disrupt physical operations and services, and the potential risks of insurance policies being silent on cyber coverage.
Tags: featured
Tag URLs: featured (https://financedigest.com/tag/featured)
URL: https://financedigest.com/driving-out-silent-cyber-losses-and-risks-for-insurers-and-the-insuredhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/keith-stonell-1736839092473-compressed.jpg)

Cyberattacks still make headlines even as they become more regular. One reason is that the damage from an attack extends beyond inflicting serious reputational and financial damage. A new generation of ransomware like WannaCry and Not Petya, growing evidence of nation-state cyberattacks, and the targeting of connected devices that are automating critical systems, have shown how cyberattacks can disrupt physical operations and services.

![Keith Stonell, managing director EMEA, Guidewire Software](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/keith-stonell-1736839092473-compressed.jpg)

Keith Stonell, managing director EMEA, Guidewire Software

The effect of attacks on a specific organisation’s infrastructure overall cannot be minimised. They can range from the [disruption of ATM systems](https://www.financedigest.com/trapping-and-mating-disruption-systems-market-is-witnessing-high-sales-growth-over-2028-fact-mr-report.html "Trapping And Mating Disruption Systems Market Is Witnessing High Sales Growth Over 2028, Fact.MR Report"), pumping systems for water and gas, power supplies, to access to essential digital services that support everything from shopping to surgery.

Remediating these kinds of disruptions has exposed the issue of silent cyber in the [insurance policies](https://www.financedigest.com/what-type-of-life-insurance-policy-is-right-for-me.html "What Type of Life Insurance Policy Is Right For Me?") used by enterprises and other organisations. When an organisation has claimed for physical damage caused by a cyberattack that has incapacitated or destroyed essential systems, they have found these losses are not covered because cyber is not written into their main [property policies](https://www.financedigest.com/frances-axa-q1-sales-rise-2-as-property-policy-demand-grows.html "France’s AXA Q1 sales rise 2% as property policy demand grows").

[Insurance policies can be silent on many things](https://www.financedigest.com/ten-things-youre-doing-that-are-invalidating-your-car-insurance.html "TEN THINGS YOU’RE DOING THAT ARE INVALIDATING YOUR CAR INSURANCE"). For example, insurance contracts are neither affirmative or negative on whether an organisation is covered for a Martian invasion, or whether a sperm whale will smash down on top of your building’s roof.

Joking about fantastical threats aside, silence in insurance contracts can be bad for both the [insured and the insurer because risks](https://www.financedigest.com/improving-risk-management-in-the-insurance-industry.html "Improving risk management in the insurance industry") that have not been articulated are likely to be either unpriced and/or unprotected.

If the contract is silent about the physical effects of a cyberattack, then the insured organisation could be rolling the dice on whether their claim is accepted or not. They may believe that because cyber is not explicitly excluded, they can claim on their main [business](https://www.financedigest.com/business-insurance-what-does-it-cover.html "Business Insurance: What does it cover?") insurance policy only to get push back from their insurer.

For the insurer, silence on [cyber risks](https://www.financedigest.com/minimising-supply-chain-cyber-risks-by-asking-the-right-questions.html "MINIMISING SUPPLY CHAIN CYBER RISKS BY ASKING THE RIGHT QUESTIONS") means they cannot be certain about what their ultimate exposures might be for a policy that includes a property within which there are connected computer systems running essential services that could be destroyed or severely disrupted by an attack. The risk for the insurer is that the [coverage from property insurance](https://www.financedigest.com/5-tips-for-selecting-the-best-car-insurance-coverage.html "5 Tips for Selecting the Best Car Insurance Coverage") policies is many times greater than those on cyber insurance policies.

Last year, we conducted an analysis of silent cyber risks with Aon, a [leading global professional services](https://www.financedigest.com/sterilization-services-market-global-leading-companies-analysis-revenue-trends-and-forecasts-2027.html "Sterilization Services Market Global Leading Companies Analysis, Revenue, Trends and Forecasts 2027") firm that provides a broad range of risk, retirement, and health solutions.

Our [study considered the scenario](https://www.financedigest.com/area-rug-market-study-current-scenario-and-forecast-to-2027.html "Area Rug Market Study – Current Scenario and Forecast to 2027") of a hypothetical attack by hackers on a U.S. hydroelectric dam, which could [impact businesses](https://www.financedigest.com/how-technology-consultants-impact-business-growth.html "How Technology Consultants Impact Business Growth") and homeowners. The attack imagined how hackers opened the flood gates at a hydroelectric dam. If such a scenario were to occur it would be likely to cause significant downstream flood damages, resulting in silent cyber losses for [insurers](https://www.financedigest.com/different-countries-different-insurance-cultures-how-insurers-can-adapt-their-products.html "insurers"). Using computer models, the total insured losses of one dam being physically breached by a [cyber attack](https://www.financedigest.com/lloyds-of-london-investigates-possible-cyber-attack.html "Lloyd’s of London investigates possible cyber attack") were estimated at $10 billion. This is equivalent to the damage from the wind and sea surge associated with a hurricane.

Silent cyber is not a deliberate avoiding tactic by insurers, but its persistence does undermine the value proposition of [insurers in helping customers have greater certainty about risks; and there could be repercussions from insurers selling products that are not relevant to customer needs](https://www.financedigest.com/breaking-down-the-types-of-insurance-you-need.html "Breaking Down the Types of Insurance You Need").

The starting point for remedying silent cyber is to define cyber as a peril that like a severe storm or overflowing rivers can cause [huge insured losses in the real world](https://www.financedigest.com/fund-nature-protection-now-or-face-huge-losses-says-world-bank.html "Fund nature protection now or face huge losses, says World Bank").  [Policy contracts need to be rewritten to be either affirmative or negative on coverage](https://www.financedigest.com/insurance-types-of-coverage-and-how-to-choose-the-right-policy.html "Insurance: Types of Coverage and How to Choose the Right Policy") for cyber-related damage. This is not an easy task given how the contract wordings can vary greatly, but this is an essential step and one that many insurers are now undertaking.

Ending silent cyber is not a trivial matter. Rewriting policies needs to be accompanied by the development and availability of cyber insurance [products](https://www.financedigest.com/insurance-products-growing-in-importance-in-2021-and-beyond.html "Insurance products growing in importance in 2021 and beyond") that take account of physical insured losses. These might be part of re-imagined [property insurance](https://www.financedigest.com/simplifying-home-insurance-through-property-characteristics-data.html "Simplifying home insurance through property characteristics data") policies or as standalone cyber policies.

[Insurers also need new tools to identify and understand risks](https://www.financedigest.com/emerging-risks-is-our-insurance-system-able-to-cope.html "Emerging risks: is our Insurance system able to cope?") that are more difficult to predict than established perils from weather, flood or fire risks. [Stress testing](https://www.financedigest.com/stress-test-backs-extending-lifespan-of-two-german-nuclear-plants-sources.html "Stress test backs extending lifespan of two German nuclear plants: sources") their property insurance portfolios against new cyber-driven scenarios that damage critical physical infrastructure needs to be done more regularly. In addition, understanding the potential physical impact of [cyber risks enables an insurer](https://www.financedigest.com/using-threat-intelligence-to-minimise-cyber-insurance-risks.html "Using Threat Intelligence to Minimise Cyber Insurance Risks") to work with customers to mitigate these risks through encouraging greater business resiliency or involving reinsurance partners.

Ultimately the goal of insurers must be to build up a much broader [market](https://www.financedigest.com/insurance-marketing-is-more-targeted-with-the-single-customer-view.html "Insurance marketing is more targeted with the single customer view") for insuring against cyber losses. Insurers do not just want the high-risk cyberattack targets to buy cyber [insurance but for all types](https://www.financedigest.com/types-of-insurance-for-yourself-and-your-family.html "Types Of Insurance For Yourself And Your Family") of businesses and individuals to be protected. In this way, the [industry can create a market](https://www.financedigest.com/water-soluble-vitamins-market-industry-research-segmentation-key-players-analysis-and-forecast-to-2029.html "Water Soluble Vitamins Market Industry Research, Segmentation, Key Players Analysis and Forecast to 2029") that is large enough to absorb the risks even from a serious, critical national infrastructure attack.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

