# The New Normal: Cyber Security Insurance
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2017-08-21
Category: INSURANCE
Category URL: https://financedigest.com/category/insurance
Meta Title: Cyber Security Insurance: The Growing Market Explained
Meta Description: Learn about the rise of cyber security insurance as a vital protection against data breaches, and the challenges faced by insurance companies in assessing IT
Tags: featured
Tag URLs: featured (https://financedigest.com/tag/featured)
URL: https://financedigest.com/the-new-normal-cyber-security-insurancehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd21aug172-1736843592419-compressed.jpg)

_By **Kevin Cunningham**, president and founder at SailPoint_

You may not have realised it, but in 2014 the IT security industry hit a tipping point. That’s when many of the world’s largest corporations realised that cyber security was no longer just a technical problem for the IT department or an audit issue for the Chief Compliance Officer. Instead, it was a potentially [catastrophic risk](https://www.financedigest.com/putin-sanctions-risk-causing-energy-price-catastrophe-for-west.html "Putin: sanctions risk causing energy price catastrophe for West") that executives and corporate boards had to address.

In the wake of dozens of high-profile security breaches, costing corporations tens of [millions of pounds](https://www.financedigest.com/uks-nationwide-to-pay-340-million-pounds-to-customers-after-profit-leap.html "UK’s Nationwide to pay 340 million pounds to customers after profit leap"), c-level executives heard the wake-up call. There was no denying that [cyber security risk was one of the biggest threats](https://www.financedigest.com/using-threat-intelligence-to-minimise-cyber-insurance-risks.html "Using Threat Intelligence to Minimise Cyber Insurance Risks") facing today’s organisations.

That’s when the market for [cyber security insurance](http://www.cio.com/article/2376802/security0/5-things-you-need-to-know-about-cybersecurity-insurance.html) began to take off.

According to a recent study by PwC, the current cyber security insurance market is around £1.95 billion ($2.5bn) and is expected to triple to £5.8 billion ($7.5bn) by 2020, as more companies recognise the need for [coverage and more insurers](https://www.financedigest.com/5-tips-for-selecting-the-best-car-insurance-coverage.html "5 Tips for Selecting the Best Car Insurance Coverage") enter the market. [Insurers say every new data](https://www.financedigest.com/how-data-is-revolutionising-car-insurance.html "How data is revolutionising car insurance") breach that hits the headlines drives new demand for coverage. And there is speculation that [cyber security insurance](https://www.financedigest.com/are-you-getting-what-you-are-paying-for-when-it-comes-to-cyber-liability-insurance.html "ARE YOU GETTING WHAT YOU ARE PAYING FOR WHEN IT COMES TO CYBER LIABILITY INSURANCE?") will become a regulatory requirement for some industries, like financial services, or that business partners may require it as part of contractual agreements.

So what protection does [cyber security](https://www.financedigest.com/how-to-handle-cyber-security-during-mergers-and-acquisitions.html "How to Handle Cyber Security during Mergers and Acquisitions") insurance offer? Typically, coverage provides protection from the financial consequences of [data breaches](https://www.financedigest.com/amazons-twitch-blames-configuration-error-for-data-breach.html "Amazon’s Twitch blames configuration error for data breach"), including things like security audits, customer credit monitoring services, and legal expenses. That means it usually does _not_ cover longer term damages such as loss of customers, lawsuits, and reputational damage. In the [Target](https://www.sailpoint.com/blog/2016/01/third-party-contractors-the-target-breachs-bulls-eye/) and [Home Depot](http://krebsonsecurity.com/tag/home-depot-breach/) cases, less than half the total cost of the breaches was covered by insurance.

Interestingly, [cyber security](https://www.financedigest.com/the-future-of-cyber-security.html "THE FUTURE OF CYBER SECURITY") insurance has proved to be a huge challenge for insurance companies and their actuaries. It [turns out that applying](https://www.financedigest.com/techie-turn-offs-top-7-things-that-put-talent-off-applying-for-tech-roles.html "Techie turn-offs: Top 7 things that put talent off applying for tech roles") mathematical and statistical methods to assess IT security risk is not easy. The wide variety of risks posed by [cyber attacks](https://www.financedigest.com/lloyds-of-london-investigates-possible-cyber-attack.html "Lloyd’s of London investigates possible cyber attack"), lack of knowledge to assess an organisation’s security effectiveness, and the lack of historical data on breaches has made it difficult to estimate probabilities of loss and loss values. To cope with this uncertainty, many [insurers](https://www.financedigest.com/different-countries-different-insurance-cultures-how-insurers-can-adapt-their-products.html "insurers") have increased premiums, raised deductibles, and established ceilings on potential losses through restrictive limits, exclusions and conditions. Nonetheless, an estimated one third of large.companies have some form of cyber security insurance.

What do you think? On the surface, [increased awareness](https://www.sailpoint.com/blog/2015/10/the-data-breach-question/) and [focus on risk management](https://www.sailpoint.com/blog/2016/01/new-year-new-hackers-how-to-prepare-for-insider-threats/) would seem like a good thing. But at the same time, cyber security insurance could result in increased complacency once the risk is transferred.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

