Incorporating Cyber Insurance as part of an overall risk management strategy is evolving policy to policy. Look for guidance from Eric Wistrand, CIO at Couch Braunsdorf Insurance Group to navigate your company's policy as a cyber leader. Jack Ekelof, VP at Evolve Security will share the impact of increasing CVE's at the start of 2024.
Tune in for Discussion on Cyber Insurance Topcis:
- Analyzing your policies for correct coverages
- Aligning aspects of your operations to correct cyber insurance policies
- Determining appropriate coverage limits & deductibles in policies
- Review of a real world cyber claim
- Trade off review between premium costs vs. coverage limits vs. deductibles
- Analysis of CVE growth in 2023, and impact of cyber insurance for 2024 and beyond
Transcript
Jack Ekolof:
I'm Jack Ekolof, Vice President here at Evolve Security. I want to welcome you to "The State of the Cyber Insurance Marketplace: Your Policy and 29,000 CVEs in 2023." We're excited to have everybody join us. I want to welcome a friend to the Evolve business — Eric, why don't you introduce yourself?
Eric:
Thanks for having me, Jack. I joined in 2011, and I've been in the capacity of CIO for the last 13 years. For the past four years, I've been building out a cyber liability practice group here at the firm, as cyber liability has become an increasing area of risk and exposure for our clients. Our mission is to drive rate savings and help clients better understand their cyber liability coverage.
Jack Ekolof:
We appreciate that — it's a super relevant topic today. A little about Evolve Security: we're headquartered in Chicago, and we're an offensive cybersecurity firm doing pen testing and attack surface management. We've also got a cyber academy with a bootcamp offering for those looking to enter the cybersecurity industry and upskill to a higher-level pen tester role.
Eric:
A little about our firm: our roots date back to 1903. We're headquartered in Liberty Corner, New Jersey, and we remain a privately owned, independent insurance agency. We have carrier relationships with over 60 insurance carriers. Our goal is to handle risks on a nationwide basis while maintaining the feel of a local agency with dedicated support.
Cyber insurance is a particularly interesting coverage, because it's emerged as a need in the insurance space for highly specialized knowledge. As you know, Jack, with all the systems you interact with and the penetration tests you do on client tech stacks, everybody's technology stack is a little different — some drastically so, especially as it relates to customized software they've developed or heavily customized from the manufacturer.
Our focus on cyber insurance is really due to my background. I spent the last 15 years in IT and IT security, and prior to joining the firm, I was a consultant you'd consider a managed service provider — at a time when that acronym didn't really exist yet. So my roots are fundamentally deep in the IT space, and that's where a lot of my curiosity comes from. When I got started in the cyber insurance marketplace about five years ago, I realized that many of the cyber insurance applications coming across from our clients had been filled out by, for instance, a CFO who didn't have an in-depth understanding of the technology stack. That's not to discredit the CFO — it speaks to the fact that in many cases, agents offer cyber liability applications for customers to fill out, and they're not doing a lot of front-end underwriting to check that information.
So it's particularly important that your insurance agent has a fundamental understanding of how you do business — the nature of your business, specifically what systems are in your technology stack, and who's responsible for technology at your firm, be it your CIO, IT director, or CISO. What we've found is that, especially with insurance agents, there's typically a lot of paper-pushing in procuring cyber liability insurance: they get the application from you, send it out to a few markets, the carriers review and underwrite it and come back with proposals, and the agent forwards those on. It's particularly important that you're working with your agent to benchmark the coverages you're buying for the size of your business against what other businesses are buying, and your agent should be talking to you about the big cyber risks and claims they've seen affecting your type of business specifically.
Let me spend a minute on some simplistic graphs. On the left, you'll see a series of lines — one light blue, one dark blue — representing attacks and claims respectively. Over the last five years, there's been a rapid increase in both, which correlates well with what Jack will talk about with new CVEs. You'll see an inflection point where premiums and underwriting requirements (in red) start a meteoric rise, right around a month or two into COVID — because insurance carriers realized the attack surface changed significantly when businesses allowed staff to work remotely. Instead of relying on the physical security of offices, MFA, logical security, and endpoint protection became much more important. So carriers ran to update their filings and underwriting requirements to price more effectively for controls like MFA. In the middle of 2020, Travelers started forcing all renewals to sign off on an MFA attestation. Early on, that question basically asked, "Do you use MFA on all systems?" — and, Jack, you know as well as I do, when you ask a question that generic, answering it in the affirmative is fraught with danger. So for a lot of our clients, we worked through an analysis of their tech stack and the various technology risks to help them better codify for the underwriters what had MFA and what didn't — creating comfort on both sides: that the insured has been honest and forthright, and that the carrier fully understands the risk they're taking on.
So there was a very hard market for cyber in the 12 months after the beginning of COVID — that's the upward trajectory in the red line. In the last year or so, there's been a softening in the cyber market, but it's preparing to go up again, and we'll get into why. The graph on the right is simplistic, but it demonstrates the relationship between the premium rate per million dollars in revenue and the maturity of cybersecurity controls. Essentially, the more layers of effective cybersecurity controls you have — and roughly speaking, the more you've invested in the people, process, and technology around them — the further up the purple line you are, and the lower your premium rate per million dollars in revenue. It's simplistic, because with real numbers it's largely dependent on the type of business you operate and the number of records you have under management.
Jack Ekolof:
What are you seeing on the underwriting requirements? What kind of complexity are the carriers putting in to maximize their profit?
Eric:
Let me look at it from a high level first. Five years ago, the underwriting process was limited to maybe five to seven questions that weren't very specific and were quite simple. Now, applications can be upwards of 10 or 12 pages, asking probably 50 or 60 questions on the high end — and that's risk-size dependent. If your business is a law firm doing $10 million a year with 15 to 20 employees and 12 lawyers, your application won't be nearly as complex as a business with $1.6 billion in revenue and 1,500 employees. So the underwriting scales with the size and complexity of the risk.
Carriers are getting more specific: Do you have multifactor authentication on external access, like VPN, or on your Office 365? Do you enforce MFA on email? Do you have a process for data backup and disaster recovery that mandates at least daily backups stored onsite and offsite in some sort of air-gapped environment requiring separate authentication? They're no longer asking simply, "Do you back up your data weekly?" — they're saying, "Tell me how you do it." And they're moving toward a more active underwriting model that requires proof on an ongoing basis, including pen testing — especially if your business has custom software you've built and exposed to the outside world, or if you're dealing with a lot of open-internet transactions where customers log into your web portal, and the security elements aren't as controlled as having staff VPN in to access your private network.
Some critical questions to think about with cyber insurance — these are in the deck Jack and I will send afterward. First, how frequently do you conduct cyber risk assessments, and how do these inform your cybersecurity strategies? There's a reason to have your attorney participate in those risk assessments — to protect them under attorney-client privilege. I'll point out that neither Jack nor I are attorneys, and this is not legal advice — but part of that process is understanding your risk landscape and protecting that information in a way that lets you make better decisions and put risk-reduction measures in place. Especially with insurance, it's about understanding what you really want to protect with cyber insurance and what you don't necessarily need to purchase coverage for.
On assessing the potential financial and operational impacts of cyber incidents — the thing I want folks to think about as they leave this webinar is: what's the impact of your network being down for five business days? Could you quickly implement ways to reduce that business-interruption exposure and continue servicing your clients? Or, looked at another way, what's the value of the data you have in a ransomware event? That's not easy to calculate, but you need to work through it. Firms like Evolve, especially with their ongoing red-team-type testing, can work through those situations with your firm to help you understand your potential exposure so you can size your limits appropriately.
Here's an example. Say you're a $24 million-a-year firm, so about $2 million a month in revenue. Being out of business for a month has a potential revenue impact of $2 million, plus follow-on impact after that. You want to size your cyber liability limit to encompass that. If you were breached and down for a month with a ransomware payment, there might be $500,000 for the ransom, $250,000 for incident response and the data-breach law firm exposure, plus the business-interruption component — so you may want to size your limit at $3 million, and then look at your peer group to make sure that limit is sufficient, so that if you have a breach, you're not suffering an uninsured loss above it.
Let me quickly cover what your cyber insurance policy does. It stands in to provide financial support on a first-party and a third-party basis. On a first-party basis, it pays your expenses for incident response — the moment you call your carrier and say, "I think I have a data breach, I need help," they assign you an incident response firm to figure out how the attackers got in, secure the system, and forensically assess what happened. There's also a data breach attorney to help you report lost data to regulatory organizations. It also provides business interruption and cyber extortion coverage. The third-party side is if your cyber attack affects your customers or vendors and they sue you — it covers their financial losses and legal claims against you, so it's more of a lawsuit shield, plus reputation management if there are PR challenges around your breach, and cost of data recovery — the expenses of restoring data lost from an attack. This isn't a comprehensive list, but it's essentially what most basic cyber liability policies cover.
Now, the most exciting slide. There's a set of endorsements of particular importance depending on your type of business. On the right, you're looking at a Chubb quote. As I mentioned, there are first-party insuring agreements on top, and then third-party liability insuring agreements. In the first party, you see things like incident response, business interruption, contingent business interruption, and network extortion — ransomware payments would be paid out of that network extortion component. Below that are cyber crime and other endorsements. The ones of particular importance — and you'll notice they're not checked off on this quote — are computer fraud coverage, funds transfer coverage, social engineering fraud, and invoice manipulation. For folks in real estate holding trust money, law firms, accounting firms, and — oddly enough — insurance agencies, you'll see a need for funds transfer fraud coverage. We call this out because it's often not included automatically on basic policies and needs to be added by endorsement.
On invoice manipulation, here's a quick example. We had an event where a client's accounting person had their business email compromised. The threat actor bypassed the two-factor authentication, got into the accounts receivable person's mailbox, looked through their sent email, and found a couple of invoices sent to clients. All they did was revise the PDF of the invoice with different payment instructions pointing to a nefarious bank account, then sent that invoice to the customer. The customer dutifully paid it, thinking it was due, and it went to the wrong party. Now the insured doesn't have invoice manipulation coverage that would step in for the rerouted payment, and they're stuck asking their customer to pursue coverage under their own social engineering fraud policy — which is embarrassing and just an odd situation. So it's important to look for invoice manipulation coverage on your cyber insurance form; if it's not there, talk to your broker — it can be secured.
We've got more claims here than we have time for, but I'll talk about one. Imagine a retail business with 1,500 computers and 10 servers, coming in on a Friday at 6 a.m. to realize a lot of data is encrypted and they've fallen victim to a ransomware attack. In this case, they were quite lucky — the threat actors didn't know the size and scope of the organization, so their ransom demand was quite low, which is unique in today's threat landscape. It was a double extortion attack: they'd taken a copy of the data and threatened to release it publicly, and encrypted the data, promising decryption keys and deletion if paid. The total cost of that claim — from minute one when they call the carrier and get assigned incident response — is about $180,000 to $200,000, the law firm on retainer can add up to $200,000 quickly, and the ransom payment can be $300,000 to $500,000. If personally identifiable or non-public information is released or touched, there's a component of notification costs. In that case, the cost of the claim exceeded a million dollars. The business email compromise and invoice manipulation claim I mentioned was a total loss of $200,000 — that client didn't have the coverage and didn't elect to purchase it, but that sub-limit would have stepped in and protected them.
Jack, at this point I've talked way too much about cyber liability — we need to talk more about Evolve Security.
Jack Ekolof:
Let's go through some of the pen testing requirements in cyber policies.
Eric:
As I said, five years ago the underwriting requirements were much less stringent. Carriers are moving to active underwriting models that include external vulnerability scanning done on a regular interval — they've realized an important component of their risk modeling has to rely on external attack surface management. But they're not doing much as it relates to the inside. Many carriers are now asking about penetration testing on their application. For smaller businesses — $1 to $25 million in revenue — they're not yet requiring pen testing, but they're going to. Based on the number of records a company has under management and the complexity of their business, carriers are starting to require things like penetration testing, and moreover proof of controls on an ongoing basis, rather than simply a sign-off on the application saying "yes, we do that."
Jack Ekolof:
We're getting increasing requests for pen test reports and sanitized reports. The amount of documentation needed, both for cyber insurance and other requirements, is moving up and to the right.
Eric:
Absolutely, and it's going to continue. As we'll discuss, CVEs are increasing, and that's what's driving this. Look back at November and December — just in the microcosm of New Jersey, where I live, we had three hospital systems breached, two of them under pretty significant all-systems-down events. And in real estate, of the five major title insurance underwriters, four were breached in December. So it's increasing at almost an exponential rate — a wave of attacks against businesses that in many cases thought they were too small or not a target. I'd argue their biggest exposure now has become cyber, whereas in the past it would have been general liability, professional liability, or property.
Jack Ekolof:
How do you think active underwriting is going to change over the next five years?
Eric:
Where it needs to go is insurance carriers getting plugged into cybersecurity providers and doing a more real-time approach. One of the largest areas where cyber attacks manifest is the failure of controls — "we thought we had great controls, then didn't look at or test them for a couple of months, and something happened because we missed something." So the active approach is going to be adopted by more carriers, especially those that want to stay in the market. The carriers that don't adapt will price themselves out and no longer be relevant.
The point about maturing your cybersecurity controls is largely about how the board views security at your firm. Typically, firms look at it as a cost center and try to make it a fixed percentage of revenue, optimizing as they go. IT budgets don't necessarily get bigger, but the asks and to-dos do — and the problem is security tends to fall to the bottom of the to-do list. My urging is: don't let it get to the point of having a breach and then spending four to five times your IT budget on security tools. Integrate these things in layers over time, so the breach doesn't happen — or at least, if a breach is in process, you know about it and can jump on it quickly. Understanding your attack surface is better than having a blindfold on and saying it doesn't exist. Does that make sense, Jack?
Jack Ekolof:
Totally. Let's look back at 2023 vulnerability data — some information from NIST. There were 79 CVEs per day in 2023 input into NIST and the National Vulnerability Database, a 15% increase over 2022. So we're continuing to see a rapid rise, really since 2017 — that was probably when the explosion happened. With the increasing technology adversaries are using in the last couple of years, I think this number is only going to increase. At one point in the year, they thought they'd hit 30,000 CVEs — and that's not counting zero-days. That's known vulnerabilities.
One of the things I found most interesting here is the shifting efficiency of attackers, looking at CVSS scores. In 2023, the mean time to exploit was 44 days — but 25%, almost a quarter, were exploited on the day of publication. So the vulnerability was identified and the exploit was written and deployed that same day, for a high-risk vulnerability — above a seven. Looking at the chart, the dark oranges and reds are where the vast majority of CVEs are, and 25% of them were essentially weaponized on the day of publication. It didn't used to be that fast — the average was around 80 days in previous years for mean time to exploit — and that speed to exploit is driving that number down. I'd imagine it'll only decrease in 2024.
In some additional findings, Evolve has found that about a third of the high-risk vulnerabilities are in the network and application layers. That matches up with cyber policies, because that's where IT teams are asked to protect and have control. That's where a lot of these high-risk vulnerabilities are focused, and where teams can spend time to remediate and stop the most high-risk ones. Evolve has an approach of continuous pen testing that matches both the requirements for cyber insurance and this explosion in CVEs. We combine an attack surface management offering with a pen test, and we surge a pen tester to you when a vulnerability is identified — matching up with the exploit when attackers exploit it on day zero. We assign a pen tester to help your organization work through the issue and provide documentation that you've corrected and addressed the vulnerability. Which matches up with, I think, one of the last subjects you wanted to talk about, Eric — neglected software.
Eric:
Sure. What you're looking at is an endorsement on a Chubb cyber liability policy, referred to as the neglected software exploit endorsement. In the table at the bottom-left of the screen, it's basically saying: if a vulnerability has been listed on the CVE database operated by NIST — the data we were talking about — and a patch, fix, or mitigation technique is available to the insured but has not been applied.
Here's how it works. Say a CVE is released on January 1st, and a patch is released that same day, and you have a data breach traced back to that CVE 45 days later, on February 14th, and you haven't patched your systems. Luckily, according to this endorsement, you'll get 100% of your coverage limit — in this case $1 million — assuming you've purchased $1 million in cyber liability from Chubb with this endorsement on your policy. Now, the scary thing — and the reason patching and vulnerability scanning are so important as a belt-and-suspenders approach to your patch management — is: say you missed a critical patch released more than 365 days ago, didn't apply it, and a data breach occurred because of it. Chubb is limiting your coverage to 10% of your top-line limit — in this case, $100,000. So where you thought you had coverage, you don't, because the policy said you needed to comply with patching. This also applies to end-of-life software — keep that in mind.
Now, how does co-insurance play into this, and how do the declining limits work? Co-insurance basically forces participation from the insured in paying the loss — those of us with health insurance are familiar with it. Let me walk through a simple, typical claims scenario. You come into the office early one morning, have a bunch of encrypted files, and realize you've been breached. You call the data breach hotline and get assigned incident response — the moment you do, you're signing off on a statement of work somewhere around $180,000 for incident response. You're also engaging a law firm that will likely cost up to, or even beyond, $200,000 — in our experience, these numbers are about the median. Say there's a ransom payment involved, so the total cost of that claim would be around $780,000.
In this example, you have a $1 million limit and a $10,000 retention. If you're properly patched and everything's updated, you still have your $1 million limit, and your total out-of-pocket cost is $10,000. But in the case where you neglected to patch systems and that was the cause of the breach, your coverage limit — as I'm modeling here — has dropped to $100,000 because you hadn't patched in a year. Now you're responsible for the $10,000 retention, you have an uninsured loss of $680,000 above the $100,000 limit, and you have to pay co-insurance of $25,000 — leaving your total out-of-pocket cost at $715,000.
So two — actually three — important points before the next slide. Number one: read your policy. You may have this endorsement and not even know it, and that's a problem. Number two: patch your systems. And number three: reach out to Evolve Security to better understand your attack surface and what your vulnerabilities are.
Jack Ekolof:
One question before we move on: based on your experience, what percentage of the time are the finance team and the IT team actually talking about this policy together?
Eric:
It's a huge problem. Insurance brokers deal with the people they have relationships with internally, which is usually ownership or the CFO. The CFO wants to get that paperwork done as quickly as possible, so they send it over to the IT person — or, even worse, the outside MSP fills it out. The challenge is that not everybody is talking together; it's more of a paper-pushing scenario, and it shouldn't be. It needs to be a collaborative effort where everybody discusses the IT impacts, the financial impacts, and how it all fits together into risk management. There's too much of a disjointed approach to that process that needs to be brought together under one group effort — and that's what we try to do through the process of talking about cyber liability risks.
Jack Ekolof:
We're coming up on the end. We've got some suggestions for both cyber insurance and cybersecurity posture. Next steps: address your known exploited vulnerabilities; work with Eric and the firm to review your cyber insurance policy terms and conditions; make sure you've got a process to prove those controls on a continuous basis; build an audit trail across all cyber policies to all stakeholders; ask your insurance broker to include important endorsements; and schedule your next pen test. Those are some recommendations from Eric and me.
.webp)

%20(1).webp)

