Cyber risk never sleeps - neither should cyber protection
BOXX leaders reveal the biggest cyber insurance red flags - and why rapid response matters
Cyber risk never sleeps - neither should cyber protection
INSURANCE NEWS
By Emily Douglas
05 Oct 2006

Cybercrime is a constant and unyielding threat for businesses, with the average cost of a data breach in the US now sitting at a record $10.22 million - the highest globally.

For smaller businesses, the risk is even greater. Despite the fact that media headlines tend to focus on large-scale cyber breaches across global conglomerates, it’s those local small to medium enterprises (SMEs) that really feel the pinch when an attack occurs. The sheer scale and speed of these cyberattacks mean having the best, most responsive cyber insurance partner is even more important.

But for many customers, gaps and red flags are beginning to emerge in the way their claims are handled, leading to anxieties, friction points and losses.

“The biggest friction point for customers is just the fear of reaching out and actually starting a claim,” explained Neal Jardine, Chief Operating Officer at BOXX Insurance. “Customers are always worried about making a claim under their insurance policy and what that means to them. It’s so important to have a waiver of retention or the ability for customers to ask questions during this process - which is exactly what BOXX’s Hackbusters® Team is there for.”

‘Clients should phone us whenever they have a blip on their radar’

Hackbusters® is the in-house breach response and cybersecurity team at BOXX Insurance, operating an immediate 24/7 response line for all policyholders. And, most importantly, it means that customers can reach out and get advice without needing to file an insurance claim - something that’s rather unique in the cyber insurance world.

“Clients are reluctant to engage with their insurance until they know for certain it's a claim and there's potentially money to be paid out,” added Jardine. “Whereas at BOXX, we’ve taken the approach that clients should phone us whenever they have a blip on their radar - and we're not going to penalize them. In fact, we're going to waive their deductible, we’re going to engage with them and provide them with the best services and technologies to help identify whether it actually is a claim or whether we can mitigate it.”

And it goes beyond that initial anxiety around reaching out. For many customers, issues around data exfiltration and the public fallout or release of information when a ransomware attack happens may push them to act impulsively rather than touching base with their insurer.

“When the worst happens, customers will naturally be worried about their data,” added Elizabeth Kim, President of BOXX USA. “What do they do? Do they pay the ransom right away? Do they notify us? Sometimes the biggest issue is that they need to slow down and figure out what actually happened, what their legal and other obligations are, and what exactly they’re being exposed to.”

At BOXX, they offer a retention waiver. That means early reporting of a cyber incident within the first 24 hours automatically triggers a waiver for most retentions in the policy (except for those retentions applicable to Financial Crime & Fraud Coverages).

“It’s an incentive to ensure early reporting,” added Erik Tifft, Global Head of Underwriting at BOXX Insurance. “We incentivize our clients to break those friction points. It’s so important to have an expert cyber insurer behind you because you’ll have support like the Hackbusters® Team, and experts who can respond to claims right away. Insurers that lack cyber expertise might take a while to respond, resulting in furthering damages and losses.”

It’s this human-led approach that can make all the difference when the worst happens. For a customer in the midst of a cyberattack, being able to reach out and speak to an actual professional in this field is a lifeline.

“Complete cyber protection means having someone there to hold your hand and walk you through what’s actually going on,” added Tifft. “Most SMEs don't have a full in-house cybersecurity team. At BOXX, we offer a vCISO and cyber services to reduce digital risks among our insureds.”

And there’s no hidden costs here. While a lot of cyber insurers charge for those ‘pre-breach’ services, at BOXX it’s all part and parcel of the plan.

‘Having clear policy language that addresses today's threat environment is critical’

“We want to be a proactive partner in protection,” added Kim. “We're not going to penalize brokers and clients for reaching out - we incentivize them by working alongside them to isolate the issue and reduce its impact without the need to notify a claim under the policy.”

For brokers, it can be a minefield out there when it comes to assessing all the different cyber policies on the market. Riddled with overcomplicated or jazzed-up jargon, policies sometimes don’t mean what they say or say what they mean, and it inevitably leads to confusion on the client’s end.

“Having clear policy language that addresses today's threat environment is critical,” added Tifft. “Threats evolve; the nature of how these attacks occur changes. Having clear policy language gives insureds confidence that they have coverage for today’s digital threats is important, that's why they ultimately buy insurance.”

The nature of that overly flowery language in policies means it’s difficult to understand what’s covered and where the gaps are - which, in cyber, is very dangerous. Jardine told IB that a huge red flag brokers should be watching out for here is having too much affirmative coverage.

“Overdefining what’s in a policy can actually limit coverage, for example. Although it may look like the policy covers more, it doesn’t shape up that way.”

‘If you have another discrete cyber event, there will be coverage’

And Tifft agrees, adding that it’s important to have a balance between broad language and clear language.

“A lot of insurers, if they’re not careful, may use that clarity to restrict or reduce coverage in some way. This is why reputation matters so much. Are they experts? Are they conducting themselves as cyber professionals? Do they have claims handling that backs up their underwriting? It's about having services that support the insured instead of just trying to sell them something extra. That whole totality matters and that's what we strive to do at BOXX.”

Part of BOXX’s all-in-one cyber approach includes First Party Each and Every Loss coverage - meaning that when clients have a first-party cyber incident on its form, BOXX will reinstate the aggregate limits each time they have a loss.

“If you have another discrete cyber event, there will be coverage,” added Tifft. “The limit will reset, and you'll have coverage for that separate cyber incident. The benefit of this coverage is that insureds are buying coverage because we’re protecting them from catastrophic loss. And so, having the ability to have two catastrophic losses on this line of coverage within one policy period provides additional financial security to the insured.”

For BOXX, this level of care in its coverage was built intentionally to bridge the gaps and solve the challenges within the cyber market right now. Looking back at how far cyber insurance has come since its development in the late 1990s, it has evolved naturally in response to different statutes and claims. And, thinking of the future ahead, the development of cyber coverage will inevitably follow that same organic growth pattern.

BOXX doesn’t just insure businesses and individuals against cyber liability; their team offers complete protection against cyber risk. Find out how BOXX can help your clients here.

 

This article was created in partnership with BOXX Insurance

Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB CA.