skip to main content

10 tips to ensure there are no gaps in your cyber insurance coverage

Wave
March 21, 2024

You may be aware that the costs of everything, including your insurance, are increasing. We are currently in a ‘hard market’ insurance cycle, simply meaning that premiums have been on the rise and insurers are adopting a more cautious approach to risk than they have in the past.

PwC’s 2024 Digital Trust Insights survey found nearly 7 out of 10 Irish respondents reported they would increase their cyber budget in the year ahead. However, companies still lag behind their global peers¹. There are proactive measures you can implement in your business to ensure that you cover all bases when reviewing your cyber insurance needs. Following these tips will provide insurers with your action plan for mitigating cyber risks in your business, increasing the likelihood of securing competitive insurance terms and demonstrating that you’re prepared for any eventuality.

1. Conduct a cyber risk assessment

One of the major mistakes businesses can make is not preparing in case of a cyber incident. While 69% of SMEs in Ireland have cyber insurance, the average cyber-specific spend only forms 23% of an average overall IT budget². Investing more by conducting a risk assessment will help you identify any vulnerabilities in your information systems, networks, and processes. This includes weaknesses in hardware, software, and human factors that could easily be exploited by cyber threats.

Cybersecurity insurance providers often require businesses to conduct regular risk assessments as part of their coverage. Demonstrating a proactive approach to managing cyber risks can positively impact insurance premiums and coverage terms.

2. Be transparent about your cyber vulnerabilities

Acknowledging any weak points in your online operations can help your insurance provider have a better overall view of your requirements and can help quantify the potential impact and likelihood of various cyber threats. This involves openly communicating any identified vulnerabilities or weaknesses in their systems and networks, as well as providing details about past incidents and the measures implemented to address similar risks moving forward.

This enables organisations to prioritise and allocate resources effectively based on the level of risk associated with different assets and processes and works in their favour to enhance their risk profile, contributing to a more favourable perception by insurers.

3. Follow best practices

Enforcing strategies within your workplace to take all necessary steps to prevent cyber attacks will help you maintain a clear claims history, which could help to reduce your insurance premiums. This includes training your people in good cyber hygiene in order to avoid phishing scams, data loss, malware and ransomware attacks, and more.

4. Obtain a cyber accreditation

While not compulsory, a cyber security business accreditation can provide compelling proof that your business is following effective procedures to guard against cyber attacks, such as Cyber Essentials or the ISO 27001 certification.

In terms of insurance, it’s worth looking into recognised certifications such as these to show insurers you are investing considerable resources into this area, as you will also be audited on an annual basis to maintain them. However, the benefits of an accreditation extend far beyond insurance: you will be reassuring customers of your cyber commitment, and it may even help to encourage new business.

5. Keep software updated

Outdated software lacks the necessary targeted updates from operating system providers that patch out vulnerabilities and exploits that are known to cyber criminals. In 2022, NHS England was hit by yet another ransomware attack due to the abundance of outdated software used within the health service, even after the WannaCry ransomware attack in May 2017. Ensure to roll out updates to your devices company-wide within 14 days of the update being released, and that your settings are configured so that they can’t be cancelled by the user.

6. Prove you have an incident response plan

While the majority of organisations say they will take action following a cyber incident, only a minority have processes already in place to support this, with just 28% of Irish businesses implementing a formal incident response plan.

Whether your organisation has 10 people or 10,000, putting guidance in place on how to handle incidents will help you make good decisions under the pressure of a real incident, and will minimise the impact of a potential loss. IT Governance EU advises how to create a cyber incident response plan here.

7. Create an incident response team

In the event of a cyber incident, ensure that your operations team knows who will do what if the worst were to happen. Who will communicate to staff and clients, and how? Who will organise secondary devices if needed? Who will obtain backups from a secure location? Depending on your circumstances, you will need to consider these questions and plan who will be responsible and review your plan on a yearly basis.

8. Hire a cybersecurity professional

For larger enterprises or those regularly dealing with sensitive customer data, having in-house personnel responsible for your core digital assets might be the best option for detecting potential threats and bolstering your defences, leading to a more secure and resilient system.

Benefits range from safeguarding sensitive data and mitigating risks to ensuring compliance with ever-evolving industry standards; cybersecurity specialists offer unique services to enhance your organisation’s security posture.

9. Know your policy coverage

Organisations should be aware of the responsibilities they must uphold for their cyber insurance policy to pay out in the worst-case scenario. Any failure to meet insurance terms may lead to the insurer not paying out.

For example, your broker will advise you that for most minimum cover insurance, you must have firewall protection, antivirus software and backup procedures in place. Depending on your chosen policy, the requirements may be different.

10. Work with an experienced broker

NFP’s cyber security professionals stay ahead of the latest trends and threats, and our network of diverse risk professionals ensures that we provide holistic, forward-thinking solutions. The result is a tailored cyber insurance solution that is best suited to your business needs and goals.


Author

Michelle Ruddy CIP, Financial Lines Executive and cyber insurance champion

Our team of cyber insurance specialists are here to manage your risks and claims proactively and use their vast experience to find the best cyber insurance solutions for your business. To find out more, visit our cyber insurance section.

https://www.nfpireland.ie/media/insights/10-tips-to-ensure-there-are-no-gaps-in-your-cyber-insurance-coverage/
2024 Copyright | All Right Reserved