State-backed cyberattacks, AI and proposal form challenges
To view full transcript, please click here

0:00

AI in itself is not a coverage trigger when it comes to cyber incidents.

0:07

Hello and welcome to Insurance Business TV for a look at the current state of the cyber insurance market. We're going to take a look at what brokers should

0:15

know about cover questions when a foreign state attacks and the latest ideas around the barriers to getting more SMEs to even sign up for cyber insurance. We've got our expert here.

0:26

Mark Luckan is National Manager, Cyber and Technology Sector, for Lockton. Hi, Mark, welcome back. Thanks, Dan. Nice to be back.

0:35

Yeah, good to have you. Um, I've been looking at some reports from the Australian Cyber Security Centre that show that foreign states are actively

0:43

targeting Aussie businesses. I think we've probably known that for quite some time. Um, but the question, I guess, for brokers like you is whether those

0:51

attacks are actually covered, um, or are they excluded because it gets quite complicated here. There's LMA 5567,

0:59

the Lloyd's cyber war exclusion. Um, and that only bites, though, if the country's essential services go down. So

1:08

I guess the question could be if a foreign government is behind the attack, does your client's policy still pay?

1:16

It's a good question and not an uncommon one. I think it's really important when we have discussions around exclusions, whether it be in

1:24

cyber or any other class of insurance, the discussions are rarely straightforward. Um, but I think it's always important to come from the

1:33

premise that the insuring clauses in a cyber policy grant cover the exclusions

1:40

are only applicable if, in instances of particular circumstances, the facts of the events are

1:48

satisfied. And I kind of open and make that initial point because discussions around cyber war exclusions, uh,

1:57

personally present a little bit of almost frustration for me because of the way that they are used by, um, alternative, uh,

2:06

or differing sectors or people, um, outside of insurance to kind of paint this kind of false, fake rhetoric around

2:14

cyber exclusions being used as an excuse to exclude cover. Turning specifically to the LMA clause that you

2:21

were speaking around, it's not as simple as if a cyber event is caused by a state-backed, um, or

2:30

alleged to be caused by a state-backed entity that they'll be excluded. First of all, you kind of face the issue

2:38

around attribution. Uh, when you look at cyber events and going through a claim, it's extremely hard and extremely

2:45

rare to truly discover uh who the party or the perpetrator is. So making that determination can be really, really difficult.

2:56

There's also then the kind of, and I spoke to it at the start, the issue around the detail of the event, what's actually happened, what's actually

3:04

occurred, and exclusions, as they largely almost always are, are very purposefully

3:12

written, and to truly trigger the LMA clause or clauses variants that that

3:18

you were talking about here, it does have to be rather—the burden of proof does sit still with the insured, like any

3:26

exclusion. Um, and it really needs to kind of trigger some key points there. So the correct starting position

3:35

in our opinion is that just having that clause doesn't translate to a state

3:41

actor being involved means no cover. It really just comes down ultimately at the end of the day to the specifics. And I

3:49

think if we have Australian organizations facing issues that are expressly clear from a state actor, to be candid,

3:57

there's probably some other bigger considerations going on then that might be more so at the front of people's mind.

4:03

Well, thank you. That was quite a curveball I threw you as the first question. This one's, I guess, arguably a bit more straightforward but psychologically complicated, perhaps.

4:12

Lately, cyber insurers and brokers have been saying the cyber insurance barrier for SMEs often isn't the price of the cyber, it's the complexity of the

4:22

proposal they get, the 10-page proposal they've got to fill in. I mean, do you agree with that? And what can fix that?

4:29

To be really honest, I think it's a it's a little bit, certainly in parts of the industry, it's a little bit of a

4:35

dated kind of position. I think it's something that's more recognizable in the larger kind of corporate space. So

4:43

when you're looking at particular examples of self-assessments that are, you know, in excess of 100 pages, I mean

4:51

that that's a barrier, um, that's always going to be a barrier for insureds or prospective insureds.

4:58

But we've kind of seen the market adapt, certainly to a point for SME risks around a shortening of the question set and

5:07

this kind of combined utilization of insured, um, external-facing scans or self

5:14

assessment tools as well. Um, I think more so the barrier around

5:21

engagement and uptake of cyber insurance is kind of three other key pillar areas, or three key pillars. Um,

5:31

the first is that broker education around cyber insurance, I think, still

5:37

lacks in particular areas. Um, don't get me wrong, the broking market has matured significantly over the last

5:44

few years and there are a number of good practitioners out there. I do still think, though, there can be cohorts

5:53

that haven't quite kind of spent the time and effort to gain the required kind of baseline understanding

6:01

here and to translate what's being put in front of them from the insurer perspective into client language to kind

6:08

of help with that conversion and, um, translate some of the language and the acronyms that are used. I kind of often joke that

6:17

cyber insurance is the worst combination of technical cyber-related discussion and insurance, which is not the two most

6:25

kind of popular dinnertime topics or points of conversation. So there really needs to be better education and translation around that. I think the

6:34

second point is also around the insurance market in terms of insurers and brokers could be doing a much, much

6:42

better job in translating the value of the questions that insurers are asking

6:51

and translating those questions into the value it provides insured or prospective insured. And what I mean by

6:58

that is collectively, the cyber insurance sector is actually one of the deepest

7:05

pools and most informative pools of data when it comes to causes of losses, uh, causes of catastrophic losses

7:14

effective mitigants, etc. And I think, um, a lot of the sector is kind of missing a trick and we're probably not quite being collegiate enough to better

7:24

communicate the value of that. I think that's a potential barrier that will help uptake. The third barrier here and

7:32

again, you know, personally I've been kind of quite vocal around this, uh, in a measured way, is that we really continue

7:40

to face a barrier or have issues, um, in getting meaningful government engagement

7:47

around the value of cyber insurance, um, cyber risk transfer. Uh, last year government called for submissions into

7:56

Horizon 2. Um, with respect to the cyber security strategy, myself and Lockton and a couple of

8:03

other industry groups, such as Atmos, incident response firm, and a couple of others put together meaningful submissions and suggested to government

8:12

that there is value in cyber insurance playing more of an active role in government strategy. And unfortunately, and we all participated

8:21

on a government round table after that and unfortunately it's just not translated through, um, to government having more engagement in that. Uh, I

8:29

think then when you look at examples like the ASD kind of retiring or updating the Essential Eight going forward

8:38

which is a baseline posture standard for Australian organizations.

8:43

They're retiring slash updating it because there was the suggestion that it's not fit for purpose in the current

8:50

threat and risk environment. Well, look at the way the insurance market has evolved and the question set that the insurance market has evolved

8:58

especially with SMEs. It's just the most perfect measure. So I think when you combine those three factors of kind of

9:05

broker education, um, not communicating the value of insurance as we best could, and a lack of government involvement.

9:14

Yeah, those are the three barriers, but in addressing those we would see a meaningful uptick and uptake in terms

9:23

of SMEs around cyber insurance. If I can ask you a follow-up on the first two pillars, you mentioned the broker

9:31

element and just translating what the insurer is offering, I suppose, into something that the client can understand. I was talking to a broker

9:39

and he was telling me that the best thing to do is to give them a very concrete claims example that's really nitty-gritty, um, that's sector-specific.

9:48

Is that a bit an important part of what you do? I mean, is the claims example an important thing here that shows them what happens, or is that not necessarily that important?

9:58

No. No, it absolutely is. It absolutely is because I think you're addressing two points there. Um, as

10:05

long as it's sector-relevant and size-relevant to the organization, um, it connects the policy with its

10:14

intent. Um, it also helps to be on the front foot and dispel the kind of misconceptions or preconceived notions

10:23

that people tend to generally have around insurance. So there's a lot of conversation, again, in particular cohorts, around insurance not paying and cyber

10:31

insurance not paying, etc. If you can provide a tangible sector- and size-specific claim example, that helps you

10:39

relate how the policy is intended to respond, the value that it adds. Um, it's that is, yeah, it's absolutely a path that

10:49

that everyone should be looking to, but a bit ironic me saying this cuz I could talk underwater about the subject and the topic, but keep it succinct as well.

10:59

people don't have, um, as much time and energy perhaps as, um, brokers that specialize in the space kind of might

11:06

want them to have around it. So keep it succinct, keep it relevant. It's hugely valuable.

11:13

Okay. Well, moving on to a survey, which is a little alarming, probably a Coveware survey of more than 400

11:20

organizations across Australia and New Zealand looking at ransoms and payment of ransoms. A third of organizations

11:27

decided to pay the ransom, but a third of those payments actually didn't go through, which, uh, throws into question the whole point. Why would you bother paying and it's not even getting getting

11:36

there? What sort of risk does that present? Um, does that—are you having conversations around that, around ransoms and whether you pay and if the payment gets through, that that sort of thing?

11:47

Yeah, absolutely. That's always been a a kind of a foundational, fundamental conversation that we have with organizations. Um, and to be frank, it's

11:56

a it's quite a common question that we get from organizations. Will the policy respond, um, to indemnify, you know, a

12:04

potential ransom payment, etc.? That—I saw that study and it, it didn't, to be honest, it didn't really fundamentally

12:11

shift the conversation that we're having, um, or have been having around ransom payments and insurance because the

12:19

conversation has always been based in: does the organization have a framework and a known practice framework, incident

12:28

response plan to respond to such an incident, and are they flexible in whether they would or wouldn't make a

12:35

ransom payment? It's great to have a position in principle, but the reality of the circumstance will always require flexibility.

12:44

The second point, I think, is that organizations always need to understand that the ransom—a ransom payment in an

12:52

extortion-type event, if it is made, is quite often, and all of the data shows this, it's never the leading or the most significant cost in a cyber claim.

13:04

Um, the leading driver of costs are always around, uh, the accompanying incident response costs. So the advice,

13:12

the technical work, the legal work, the incident response, breach coaching, etc.

13:16

So, um, I think what that study has the potential to shift or evolve the

13:22

conversation for brokers less from, um, would you ever pay a ransom but more to

13:29

what circumstances would kind of leave you with no credible alternative. And it kind of should then further encourage

13:38

brokers to take that conversation, take the learnings and apply it to how they structure the policy, how they consider

13:46

suitable retentions or deductible levels, um, business interruption retentions, you know, specific coverage

13:54

enhancements or endorsements. Uh, just to make sure it's kind of covering off that whole remit of the complexity of extortion or ransom events.

14:04

Okay, now I can't believe we've nearly finished our discussion without mentioning AI, but I'm going to mention it now. Um, when a client asks you if

14:13

their policy actually responds to an AI-enabled attack, what do you tell them? How does that conversation go?

14:20

Yeah, AI, my kind of most favorite and least favorite topic at the moment. I think everyone kind of even those deep

14:28

deep deeply involved in the space almost have a little bit of fatigue around it themselves but there's no point having

14:36

fatigue around it because it's so relevant will continue to to be so relevant. Um when it comes to the specific conversations around insurance

14:45

and policy response, I my kind of slightly flippant initial answer always um I always want it to be kind of stop

14:52

reading the AI hype and, um, you know, don't believe everything you read. But the serious answer is that AI in

15:00

itself is not a coverage trigger when it comes to cyber incidents. Um, it's my

15:08

answer, or my question I put back to clients, is tell me, you know, tell me what actually happened or tell me what you're

15:16

concerned around actually happening and then let's kind of work through the scenario from there. So cyber policies

15:24

always have since the market matured and and will continue to respond to very very broad triggers and not a particular

15:33

tool used by a threat actor or not a particular pathway in into an organization. You know you look at the

15:42

best triggers um in the leading policies it's all around things like unauthorized access. I mean what an incredibly broad

15:49

term and just because uh an AI solution or or utilization of AI or or a tool it

15:57

forms part of a process of a claim that doesn't change that kind of unauthorized access trigger by way of example. Um

16:05

where we are tending to focus instead is more around those organizations themselves that are using AI solutions

16:12

or tools as part of their advice and um services etc. But that kind of steers a little bit away from the cyber insurance conversation.

16:22

Um, despite again some of the commentary out there and some within the market but some more broadly at at this certainly

16:31

at this point in time um the market is not awash with AI exclusions or a

16:39

demand for pure standalone AI policies etc. Um, I think it's it's in a more

16:46

nuanced state at the moment where there's some evidence of some kind of affirmative endorsements coming out. Um, which which is always good,

16:54

clarification language in other policies. Um, and even some instances of some very targeted bespoke express AI

17:04

exclusions, but they're very much in their infancy and more kind of talking around particular situations for organizations.

17:12

Um, for most organizations we say a dedicated AI policy or solution is not what they should be looking for

17:20

here. It's just getting comfortable around what's actually keeping them up at night with respect to AI um and risks

17:28

and and us kind of translating that into giving them comfort around policy response of which the vast majority of the market is providing.

17:37

Mark Luckan from Lockton, thanks very much for your time. Thanks, Dan. Appreciate it.

17:42

And that wraps up our look at cyber issues. Thanks for watching Insurance Business TV. Bye for now.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB AU.