Cyber
Your own costs after a security incident (forensics, notification, restoration, business interruption from a network outage, extortion) and your liability to others for the data and systems you failed to protect.
On the schedule
| Also called | cyber liability, network security and privacy, data breach cover |
|---|---|
| Family | Liability |
| Responds when | A ransomware event, a data breach, a business email compromise or a system outage caused by an attacker. |
Which industries carry it
Standards this line engages
14 clausesClause text quoted from a human-verified compliance corpus under licence. Clauses marked for APRA-regulated buyers or US insurance licensees appear on a register only for those buyers.
ISO 31000 6.5.2 Selection of risk treatment optionsGuidance: choosing treatment options balances the benefits for the objectives against the cost, effort and disadvantages of implementing them. Options are not mutually exclusive and not all fit every situation; they include avoiding the risk by not starting or continuing the activity, taking or increasing the risk to pursue an opportunity, removing the risk ...
Common gap: Only mitigation considered; avoiding, taking or sharing never on the table
ISO 31000:2018 on compliance.theartofservice.com
ISO 31000 6.4.2 Risk identificationGuidance: risk identification finds, recognizes and describes the risks that might help or prevent the organization achieving its objectives, and depends on relevant, appropriate and current information. A range of techniques can be used to find the uncertainties that affect objectives, and the following factors and the relationships between them should be c...
Common gap: Only threats identified, never opportunities
ISO 31000:2018 on compliance.theartofservice.com
Lloyd's cyber Risk Selection Cyber Risk selection and the cyber hygiene baseline before bindingLloyds Cyber Insurance Requirements - Risk Selection and Cyber Hygiene Underwriting Criteria. Underwriters must conduct rigorous risk selection + due diligence assessing insured-cyber hygiene including: (a) Mandatory cyber hygiene requirements (insurance-grade baseline expectation): Multi-Factor Authentication (MFA) on all privileged accounts + all remote ac...
Common gap: No mandatory hygiene
Lloyd's cyber underwriting requirements on compliance.theartofservice.com
Lloyd's cyber Affirmative Coverage Property Affirmative cyber cover and the model clauses on property policiesLloyds of London Cyber Insurance Requirements - Affirmative Cyber Coverage Mandate. Following Lloyds Market Bulletin Y5258 (issued 16 August 2022) all Property Policies underwritten by Lloyds market participants must clearly state from 31 March 2023 onwards whether cyber-related losses are covered + excluded + with no implicit ambiguity (silent cyber elimina...
Common gap: Property policies still silent
Lloyd's cyber underwriting requirements on compliance.theartofservice.com
Lloyd's cyber Claims Handling Standards Claims handling for cyber events, sanctions and ransomware paymentsLloyds Cyber Insurance Requirements - Claims Handling Standards for Cyber Events and Sanctions/Ransomware Compliance. Claims Handling Standards for Cyber Events: (a) Specialised cyber claims handling capability + Lloyds claims handler training in cyber-specific issues + Computer Forensics + Digital Forensics and Incident Response (DFIR) integration + Coaliti...
Common gap: No specialised cyber claims
Lloyd's cyber underwriting requirements on compliance.theartofservice.com
Lloyd's cyber War Cyber Operation War and state-backed cyber operation exclusions and their carve-backsLloyds Cyber Insurance Requirements - War, Cyber Operation, and State-Backed Exclusions. Following NotPetya 2017 + WannaCry 2017 + SolarWinds 2020 + Colonial Pipeline 2021 industry-wide reassessment of war + state-backed cyber exclusion language driven by Lloyds Market Bulletin Y5258. LMA5400-LMA5403 model exclusions for war + cyber operation provide tiered ...
Common gap: No attribution mechanism
Lloyd's cyber underwriting requirements on compliance.theartofservice.com
NAIC 668 NAIC-2 Information Security Program (ISP) - Section 4 (US insurance licensees)Develop, implement, and maintain a comprehensive written Information Security Program (ISP) based on the licensees risk assessment that includes administrative, technical, and physical safeguards for protecting Nonpublic Information and the licensees information systems. Scale the ISP commensurate with size + complexity + nature + scope of activities + sensi...
Common gap: No written program
NAIC Insurance Data Security Model Law (MDL-668) on compliance.theartofservice.com
NAIC 668 NAIC-3 Risk Assessment and Risk Management - Section 4(B) and 4(C) (US insurance licensees)Conduct comprehensive risk assessments to identify reasonably foreseeable internal and external threats that could result in unauthorised access to or transmission, disclosure, misuse, alteration, or destruction of Nonpublic Information stored on the licensees information systems. Assess likelihood and potential damage. Reassess sufficiency of safeguards on ...
Common gap: No documented risk assessment
NAIC Insurance Data Security Model Law (MDL-668) on compliance.theartofservice.com
NAIC 668 NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 (US insurance licensees)Establish a written Incident Response Plan to respond to and recover from a Cybersecurity Event. Investigate Cybersecurity Events to determine scope + Nonpublic Information involved + impact of the Event + reasonable measures to restore the security of the Information Systems compromised. Notify the state insurance commissioner of the state-of-domicile withi...
Common gap: No written IRP
NAIC Insurance Data Security Model Law (MDL-668) on compliance.theartofservice.com
CPS 230 P25 Information and Technology Capability and Asset Health (APRA-regulated buyers)The entity must maintain sound information and technology capability to meet current and projected business requirements and to support critical operations and risk management, and in managing technology risk must monitor the age and health of its information assets and meet the information security requirements of CPS 234.
Common gap: Legacy asset age and health untracked
APRA CPS 230 on compliance.theartofservice.com
ISO 31000 6.4.3 Risk analysisGuidance: risk analysis builds an understanding of the nature and characteristics of a risk, including its level where appropriate, by considering in detail uncertainties, sources, consequences, likelihood, events, scenarios, controls and how effective they are; one event can have several causes and consequences and touch several objectives. Analysis can be ...
Common gap: Control effectiveness assumed rather than assessed
ISO 31000:2018 on compliance.theartofservice.com
ISO 31000 6.3.4 Defining risk criteriaGuidance: the organization should specify the amount and type of risk it may or may not take relative to its objectives, and should define criteria for judging the significance of risk and supporting decisions. Risk criteria should align with the framework and be customized to the purpose and scope of the activity; they should reflect the organization's valu...
Common gap: A five-by-five matrix with no definition of what a consequence level means
ISO 31000:2018 on compliance.theartofservice.com
COSO ERM principle 13 Implements Risk ResponsesThe organization identifies and selects risk responses.
Common gap: Response chosen without analysis
COSO ERM 2017 on compliance.theartofservice.com
COSO ERM principle 11 Assesses Severity of RiskThe organization assesses the severity of risk.
Common gap: Subjective scoring only
COSO ERM 2017 on compliance.theartofservice.com
Do this for every line on your schedule
Paste the schedule and get this classification for every line at once, with the retained and transferred figures, the rate on line, the loss ratio, the findings and the questions for the broker. Six lines free, no account.
Build my coverage registerClinical trials liability · Environmental and pollution liability