# How security ratings can contribute to delivering a suitable cyber liability policy
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2019-02-05
Category: INSURANCE
Category URL: https://financedigest.com/category/insurance
Meta Title: Cyber Insurance Importance and Challenges
Meta Description: Learn about the importance of cyber insurance, common cyber insurance breaches, cyber risk assessment, and how security ratings can help insurance providers
URL: https://financedigest.com/security-ratings-can-contribute-delivering-suitable-cyber-liability-policyhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd260418-10-1736839173423-compressed.jpg)

**Matthew Mckenna** Vice President EMEA at SecurityScorecard

Cyber insurance is growing in popularity because of the increasing number of data breaches reported over the last few years.Some common examples of cyber insurance breaches are data theft, spyware virus, dumpster diving etc.To prepare for unforeseeable attacks, [insurance companies write focused cyber liability](https://www.financedigest.com/are-you-getting-what-you-are-paying-for-when-it-comes-to-cyber-liability-insurance.html "ARE YOU GETTING WHAT YOU ARE PAYING FOR WHEN IT COMES TO CYBER LIABILITY INSURANCE?") policies.These policies may carve out specific protections for [companies and their executives from potentially devasting costs](https://www.financedigest.com/companies-cost-inflation-is-slowing-but-shoppers-may-wait-for-lower-prices.html "Companies’ cost inflation is slowing but shoppers may wait for lower prices") required to recover from a major cyber incident.  An important data point for consideration during the underwriting process is the [cyber risk](https://www.financedigest.com/selfie-awareness-the-cyber-risk-going-undetected-in-banks.html "Selfie-awareness: the cyber risk going undetected in banks") that a company might pose as a result of their cybersecurity posture. Something like security ratings can help here as they [provide an up-to-date reflection of a potential](https://www.financedigest.com/french-cloud-provider-ovh-lines-up-diesel-generators-to-offset-potential-power-cuts.html "French cloud provider OVH lines up diesel generators to offset potential power cuts") insured’s security weaknesses, ensuring the correct policy is written.

**Cyber Insurance and Compliance**

![Matthew Mckenna](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/matthew-450x450-1736839173386-compressed.jpg)

Matthew Mckenna

While cyber [liability policies do not discount a company’s obligation to meet their specific regulatory mandates, existing and emerging liability insurance products](https://www.financedigest.com/bionics-guide-to-product-liability-insurance.html "Bionic’s Guide to Product Liability Insurance") may provide a safety net for certain classes of companies that have a specific regulatory burden. Depending on the size of a company or the scope of the business, cyber [insurance policies](https://www.financedigest.com/what-type-of-life-insurance-policy-is-right-for-me.html "What Type of Life Insurance Policy Is Right For Me?") may change or may not even be available. For example, restricting a policy to have [limits on personal records or bank](https://www.financedigest.com/irish-central-bank-eases-strict-mortgage-lending-limits.html "Irish central bank eases strict mortgage-lending limits") information. Sectors such as healthcare, retail, food and beverage, education and financial will buy these cyber insurance policies as it may help cover expenses and attempt to prevent cyber breaches that have, for example PCI-DSS implications.

**Challenges**

Firstly, one challenge is how to effectively assess the cyber-risk a company might pose. Insurance [policies](https://www.financedigest.com/insurance-types-of-coverage-and-how-to-choose-the-right-policy.html "Insurance: Types of Coverage and How to Choose the Right Policy") are price based on calculated risk by the issuing insurance company. It’s pretty simple if you look at it in terms of auto insurance, it’s typically determined on a driving record. The more auto accidents or moving violations a driver has – the more expensive an insurance policy will be. Cyber liability is very similar in that the more cyber incidents or poor cyber health [track record](https://www.financedigest.com/britain-on-track-for-record-black-friday-sales.html "Britain on track for record Black Friday sales") a company has – the more expensive the insurance policy will be.

A secondary challenge is how to have a common [cyber risk taxonomy that is easily understood by insurance](https://www.financedigest.com/using-threat-intelligence-to-minimise-cyber-insurance-risks.html "Using Threat Intelligence to Minimise Cyber Insurance Risks") staff, agents and brokers, that in many cases are not knowledgeable about cyber risk. Lastly, a third challenge is how to effectively inform customers on their [company’s cyber](https://www.financedigest.com/7-cyber-threats-fintech-companies-should-watch-out-for.html "7 Cyber Threats FinTech Companies Should Watch Out For") risk as it relates to the premium price of a policy.

**Example of how security ratings fits in**

Insurance providers can integrate [security ratings into their cyber](https://www.financedigest.com/how-to-handle-cyber-security-during-mergers-and-acquisitions.html "How to Handle Cyber Security during Mergers and Acquisitions") insurance underwriting process in multiple ways, including:

**Cyber Risk Assessment:**

[Security ratings provide an automated assessment of cyber](https://www.financedigest.com/the-future-of-cyber-security.html "THE FUTURE OF CYBER SECURITY") risk for any company looking to purchase a cyber liability policy. In the case of a company not qualifying for a policy, security [ratings will then report](https://www.financedigest.com/yen-stems-losses-after-report-of-boj-rate-check-hints-on-intervention.html "Yen stems losses after report of BOJ rate check, hints on intervention") a simple school-based letter grade (e.g. A-F) that assesses how [well a company](https://www.financedigest.com/computerized-physician-order-entry-cpoe-systems-market-to-generate-profitable-avenues-for-existing-companies-as-well-as-new-players.html "Computerized Physician Order Entry (CPOE) Systems Market to Generate Profitable Avenues for Existing Companies as Well as New Players") has broadly addressed their cyber health. The solution gives a [detailed insight](https://www.financedigest.com/acth-deficiency-treatment-market-in-depth-insights-revenue-details-regional-analysis-by-2026.html "ACTH Deficiency Treatment Market In-depth Insights, Revenue Details, Regional Analysis by 2026") into a company’s cyber health via fine grain scores for each of ten important cybersecurity factor areas. Using a cybersecurity rating solution, [insurance providers can align potential risk](https://www.financedigest.com/emerging-risks-is-our-insurance-system-able-to-cope.html "Emerging risks: is our Insurance system able to cope?") across the entire underwriting process.

**Cyber Posture Transparency:**

Most individuals who are responsible for selling, quoting, issuing, or buying a cyber liability policy do not have expertise in cybersecurity. Security ratings can provide a solution for insurance companies that introduces a common cybersecurity language. On the other hand, security [ratings also provide a sufficient level](https://www.financedigest.com/ecbs-lagarde-raises-prospect-of-rate-hikes-beyond-neutral-level.html "ECB’s Lagarde raises prospect of rate hikes beyond neutral level") of detail for more cyber-aware individuals when required. The [security ratings solution provides a strong](https://www.financedigest.com/industrial-cyber-security-solutions-and-services-strong-increase-in-user-base-pans-out-for-north-america-to-lead-market.html "Industrial Cyber Security Solutions and Services – Strong Increase in User Base Pans Out for North America to Lead Market") basis for insurance agents and brokers to quote cyber liability insurance policies using a consistent representation of a company’s potential cyber risk. Similarly, the ability for an insurance buyer to see his company’s [security ratings introduces unique transparency during the process of buying or renewing a cyber](https://www.financedigest.com/cyber-security-data-re-assurance.html "Cyber Security: Data ‘Re’-Assurance") liability policy.

**Cyber Gap Assessment:**

[Insurance providers that do not use an automated](https://www.financedigest.com/automated-cyber-risk-quantification-saving-the-insurance-industry.html "Automated Cyber Risk Quantification: Saving the Insurance Industry") security rating solution often find themselves cobbling together a company’s cyber risk using various manual assessment methods which takes up much more time and makes it a lengthier process than it needs to be using methods such as cyber risk questionnaires. [Security ratings provide the ability to quickly assess gaps in a company’s cybersecurity efforts which is important when preparing a cyber](https://www.financedigest.com/transport-operator-go-ahead-flags-cyber-security-breach.html "Transport operator Go-Ahead flags cyber security breach") liability policy. Gap [assessment provided by a cyber rating](https://www.financedigest.com/dollar-tentative-as-investors-assess-rate-hike-path.html "Dollar tentative as investors assess rate-hike path") solution can be invaluable for both novice and advanced cybersecurity professionals. For example, the breadth provided by security ratings can assist a cybersecurity novice document in broad security gaps (e.g., historical breach frequency, use of secure websites etc.)

**Integrated Workflows:**

Unlike more manual assessment methods, workflow integration greatly improves the efficiency and accuracy of quoting, selling, and renewing cyber liability insurance policies. Security ratings provide APIs and custom integrations that enable connecting cybersecurity ratings into an insurance providers [business process](https://www.financedigest.com/automating-business-processes-is-essential-to-digital-transformation.html "Automating business processes is essential to digital transformation").

**Results and Benefits**

One significant benefit of using security ratings is that downstream constituents (e.g., agents, brokers, customers, etc.) perceive the insurance provider being a trusted advisor concerning cybersecurity. A secondary benefit is that the [ratings provide an accurate and transparent test against company’s cyber risk](https://www.financedigest.com/boe-flags-risk-of-recession-and-10-inflation-as-it-raises-rates-again.html "BoE flags risk of recession and 10% inflation as it raises rates again"). Independent [research has shown that a company with a rating of less than ‘D’ is five times](https://www.financedigest.com/automotive-timing-chain-and-belt-market-to-be-valued-at-us-10-20-bn-by-2027-comprehensive-research-report-by-fmi.html "Automotive Timing Chain and Belt Market to be valued at US$ 10.20 Bn by 2027 – Comprehensive Research Report by FMI") more likely to be breached as opposed to a company with a better score. Insurance providers are likely to decide that companies with a grade of “D”, “E” or “F” are too high [risk to issue a cyber liability policy](https://www.financedigest.com/asian-economic-powers-warn-of-risks-from-war-monetary-policy-normalisation.html "Asian economic powers warn of risks from war, monetary policy normalisation"). However, the transparency of security ratings [enables](https://www.financedigest.com/game-company-roblox-enabled-girls-sexual-exploitation-lawsuit-claims.html "Game company Roblox enabled girl’s sexual exploitation, lawsuit claims") companies to understand and address their company’s cyber concerns and go on to fix them.

**Conclusion**

Insurance companies can gain numerous benefits using a [security rating solution as a part of their cyber](https://www.financedigest.com/a-culture-of-cyber-security-throughout-financial-services-organisations.html "A Culture of Cyber Security Throughout Financial Services Organisations") liability insurance programs. Security ratings are used by insurance companies to help across multiple phases of defining and issuing cyber liability policies including underwriting, quoting, and renewals. The result is the ability to [offer the best cyber liability policies while maintain trusted advisor status across all relevant constituents including insurance](https://www.financedigest.com/why-insurers-have-started-listening-to-what-sonic-branding-has-to-offer.html "Why insurers have started listening to what sonic branding has to offer") agents, brokers, and customers.

**Matthew Mckenna** has extensive experience in the technology and [security industry](https://www.financedigest.com/embedded-security-for-internet-of-things-market-2021-by-global-key-players-types-applications-countries-industry-size-and-forecast-to-2027.html "Embedded Security For Internet Of Things Market 2021 by Global Key Players, Types, Applications, Countries, Industry Size and Forecast to 2027"). Matthew is a high-energy strategy and operations executive with a [track record of commercialising emerging technologies across sectors in global markets](https://www.financedigest.com/subsea-navigation-and-tracking-market-one-the-most-booming-industry-in-upcoming-years-due-to-global-demand-in-industry-by-2027.html "Subsea Navigation And Tracking Market| One the Most Booming Industry in Upcoming Years Due to Global Demand in Industry by 2027").


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

