Ifrah Yousuf graphic of computer

Cyber-Insurance Rates Soaring Thanks to Rise in High-Cost Ransomware Attacks

Insurers have made “dramatic” increases in premiums for cyber-insurance and are considering lowering the ransom amounts they will pay.

Cyber-insurance rates are set to increase by as much as 25 percent thanks to insurance companies having to pay out expensive claims related to ransomware attacks, according to a Reuters report.

While ransomware attacks happened slightly less frequently in 2019 as compared to the year before, hackers are beginning to ask for higher payoffs and are doing more damage when they attack businesses or governments. Some cybersecurity experts have even gone so far as to blame insurance companies for exacerbating the problem, as many insurers would rather pay the ransom than deal with ongoing cybersecurity costs for their clients.

“The onus isn’t on the insurance company to stop the criminal, that’s not their mission,” Loretta Worters, a spokeswoman for the Insurance Information Institute, told ProPublica in August. “Their objective is to help you get back to business. But it does beg the question, when you pay out to these criminals, what happens in the future?”

Cyber-insurance premiums began to rise 5 percent to 25 percent late in 2019, Robert Parisi, the U.S. cyber product leader at Marsh & McLennan Companies, told Reuters. Policies often cover data recovery, legal liabilities and negotiators who can translate from hackers’ native languages, according to the report. Insurers have made “dramatic” increases but have not scaled back coverage, Parisi said.

Some insurers, like Sompo, are considering lowering the amounts they will pay for ransomware attacks against high-risk companies and require clients to pay 20 to 30 percent of ransomware claims, according to Reuters. Other insurance companies are thinking about making ransomware a separate product from general cyber-insurance coverage.

The high costs associated with ransomware attacks are also associated with the increasing amount of attacks on managed service providers responsible for the IT services of several companies, particularly hospitals and medical businesses. This means that one successful attack can encrypt sensitive data for dozens of facilities or companies at once, incentivizing the managed service provider to pay the ransom so that their clients can get access to crucial data as fast as possible.

In turn, malicious actors see that they can continue to raise ransoms and be rewarded by insurers and the desperate companies themselves.

While ransom payment can encourage attackers, it’s up to insurers to decide the cost-benefit analysis and make the right decision for all involved, according to Michael Lee, the city spokesman for Lake City, Florida, which was a ransomware attack victim in 2019.

“The insurer is the one who is going to get hit with most of this if it continues,” Lee told ProPublica. “It’s kind of hard to argue with them because they know the cost-benefit of [paying ransoms]. I have a hard time saying it’s the right decision, but maybe it makes sense with a certain perspective.”

Illustration courtesy of Ifrah Yousuf, via the Cybersecurity Visuals Challenge

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • Surveillance Cameras Provide Peace of Mind for New Florida Homeowners

    Managing a large estate is never easy. Tack on 2 acres of property and keeping track of the comings and goings of family and visitors becomes nearly impossible. Needless to say, the new owner of a $10 million spec home in Florida was eager for a simple way to monitor and manage his 15,000-square-foot residence, 2,800-square-foot clubhouse and expansive outdoor areas. Read Now

  • Survey: 72% of CISOs Are Concerned Generative AI Solutions Could Result In Security Breach

    Metomic recently released its “2024 CISO Survey: Insights from the Security Leaders Keeping Critical Business Data Safe.” Metomic surveyed more than 400 Chief Information Security Officers (CISOs) from the U.S. and UK to gain deeper insights on the state of data security. The report includes survey findings on various cybersecurity issues, including security leaders’ top priorities and challenges, SaaS app usage across their organization, and biggest concerns with implementing generative AI solutions. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

Featured Cybersecurity

Webinars

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3