Ifrah Yousuf graphic of computer

Cyber-Insurance Rates Soaring Thanks to Rise in High-Cost Ransomware Attacks

Insurers have made “dramatic” increases in premiums for cyber-insurance and are considering lowering the ransom amounts they will pay.

Cyber-insurance rates are set to increase by as much as 25 percent thanks to insurance companies having to pay out expensive claims related to ransomware attacks, according to a Reuters report.

While ransomware attacks happened slightly less frequently in 2019 as compared to the year before, hackers are beginning to ask for higher payoffs and are doing more damage when they attack businesses or governments. Some cybersecurity experts have even gone so far as to blame insurance companies for exacerbating the problem, as many insurers would rather pay the ransom than deal with ongoing cybersecurity costs for their clients.

“The onus isn’t on the insurance company to stop the criminal, that’s not their mission,” Loretta Worters, a spokeswoman for the Insurance Information Institute, told ProPublica in August. “Their objective is to help you get back to business. But it does beg the question, when you pay out to these criminals, what happens in the future?”

Cyber-insurance premiums began to rise 5 percent to 25 percent late in 2019, Robert Parisi, the U.S. cyber product leader at Marsh & McLennan Companies, told Reuters. Policies often cover data recovery, legal liabilities and negotiators who can translate from hackers’ native languages, according to the report. Insurers have made “dramatic” increases but have not scaled back coverage, Parisi said.

Some insurers, like Sompo, are considering lowering the amounts they will pay for ransomware attacks against high-risk companies and require clients to pay 20 to 30 percent of ransomware claims, according to Reuters. Other insurance companies are thinking about making ransomware a separate product from general cyber-insurance coverage.

The high costs associated with ransomware attacks are also associated with the increasing amount of attacks on managed service providers responsible for the IT services of several companies, particularly hospitals and medical businesses. This means that one successful attack can encrypt sensitive data for dozens of facilities or companies at once, incentivizing the managed service provider to pay the ransom so that their clients can get access to crucial data as fast as possible.

In turn, malicious actors see that they can continue to raise ransoms and be rewarded by insurers and the desperate companies themselves.

While ransom payment can encourage attackers, it’s up to insurers to decide the cost-benefit analysis and make the right decision for all involved, according to Michael Lee, the city spokesman for Lake City, Florida, which was a ransomware attack victim in 2019.

“The insurer is the one who is going to get hit with most of this if it continues,” Lee told ProPublica. “It’s kind of hard to argue with them because they know the cost-benefit of [paying ransoms]. I have a hard time saying it’s the right decision, but maybe it makes sense with a certain perspective.”

Illustration courtesy of Ifrah Yousuf, via the Cybersecurity Visuals Challenge

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • It's Show Time

    I am one of those people that likes to see things get bigger and better. As advertised, ISC West is going to be bigger (more exhibitors) and better (more attendees). It’s show time in Las Vegas. Read Now

    • Industry Events
    • ISC West
  • SIA Releases New Report on Operational Security Technology

    The Security Industry Association (SIA) has released an impactful new resource – Operational Security Technology: Principles, Challenges and Achieving Mission-Critical Outcomes Leveraging OST. Read Now

  • Cyber Overconfidence Is Leaving Your Organization Vulnerable

    The increased sophistication of cyber threats pumped by the relentless use of AI and machine learning brings forth record-breaking statistics. Cyberattacks grew 44% YoY in 2024, with a weekly average of 1,673 cyberattacks per organization. While organizations up their security game to help thwart these attacks, a critical question remains: Can employees identify a threat when they come across one? A Confidence Gap survey reveals that 86% of employees feel confident in their ability to identify phishing attempts. But things are not as rosy as they appear; the more significant part of the report finds this confidence misplaced. Read Now

  • Mission 500 Debuts Refreshed Identity Ahead of Security 5K/2K at ISC West

    Mission 500, the security industry’s nonprofit charity dedicated to supporting children in need across the US, Canada, and Puerto Rico, has unveiled a refreshed brand identity ahead of ISC West. The charity’s new look includes a modernized logo with refined messaging to reinforce Mission 500’s nearly decade-long commitment to serving the needs of children and families in crisis. Read Now

    • Industry Events

New Products

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.