The Limits of Cyber Insurance for Enterprise IT with Arctera’s Simon Jelley
Simon Jelley, vice president and general manager for data protection at Arctera, explains what enterprise IT organizations should be wary of before opting to depend too much on cyber insurance.
Transcript
Hey guys. Thanks. The throw, we're here with Simon Jelly, who's vice president and general manager for data protection at our terror, and we're talking about cyber insurance.
Everybody's supposed to get it. I think most people have it, but I'm not sure anybody knows what it covers. Simon, how you doing?
I'm good, thanks Mike. Good to, uh, good to connect with you today. I think we've seen a lot more interest in cyber insurance.
More people are carrying it than ever, but the terms and conditions seem to have evolved and changed over the years, and I'm not sure everybody realizes what they're protected for. And just as importantly, what they may not be protected for. What's your assessment of what's going on here and what should people be looking out for?
Yeah, I, I think it's, it's, as you say, it's an evolution. You know, what we see with our customers is, you know, they've, they're struggling frankly with just a preparedness, uh, for, uh, cyber protection in terms of making sure that they really have the recovery in place and cyber insurance has come along as a new way to potentially accelerate their preparedness. But I think in a lot of ways customers see it as a shortcut to organizations see it as a shortcut to that cyber preparedness.
And that's our big concern. I think it provides that indemnity just like a, a health policy, but it potentially comes with a lot of what are the preexisting conditions that you have, just like health insurance that you need to be aware of. And I think that's the trap potentially organizations are getting into, is looking at cyber insurance as a, as a shortcut to true cyber preparedness for recovery and, and readiness as an organization to cope with the potential, uh, legal and, uh, reputational damages around, uh, cyber threats as well.
I think the insurance providers are getting a lot more aggressive, to your point, looking for issues that may have led to a compromise that would be not covered because it was your own fault for some reason or another. And this has come full circle, I think initially they started out handing out these policies pretty much like candy because they saw it as a new line of business and then they learned the hard way how much they were losing. Um, are we swinging from one extreme to the other or are we gonna find some middle ground here?
I I think we'll find some real ground. I, I definitely think it was a, maybe an uneducated or slightly unaware view of, as you say, uh, insurance providers jumping into a new op opportunity space, but then quickly realizing that maybe organizations had underlying circumstances themselves that really meant that they were truly at fault in terms of being prepared for that cyber threat and, and they couldn't indemnify 'em. Again, if you look at the average cost of a threat, it's somewhere in the region of six to $9 million.
The potential cost overall, if you look at a breach happening, uh, and policies, you know, really weren't set up in the first amount to cover that. So really I think it's trying to find that ground of where's the right level of coverage versus what truly is the potential breach cost out there. I also see the insurance carriers are a lot more proactive these days, even getting involved in the negotiations over ransomware and, uh, partnering with managed service providers to make sure people have the right level of security.
I mean, they seem to have fundamentally evolved in ways that no one might have anticipated. Yeah, I think now they're potentially becoming a great partner in terms of you, yourself as an organization understanding how prepared you truly are and have you got the right, as you mentioned, kind of security perimeter defenses in place, have you got your backup simple, uh, means of recovery in place? So those things are already in place.
Are you looking to have a team that's ready on standby to drive that communication of the impact to customers? All those things that should be, regardless of whether you have an insurance policy or not part of your recovery stance and your cyber preparedness overall. And, and now you, it's almost becoming a great assessment assessment tool for do you have those fundamentals in place?
Right. So I think, I think it's a good area to be in. And again, I, I don't wanna by any means say that cyber insurance doesn't have its place.
It absolutely does because there's a, a big potential cost of a breach and they can very much help you in covering those potential in, uh, communication costs. If it turns from a civil case into a criminal case, how do you ultimately make sure you've got the right legal costs paid for? There's very much a place for it, but I think as the cyber insurance providers have realized itself, it isn't a replacement for making sure that you've taken the fundamental steps and being prepared for a breach itself.
It also seems to me that tenor of the conversation's changing a little bit more towards cyber resilience. I mean, I think we're making some assumptions that we are gonna have a breach. It's now a question of containing it to something that's reasonable.
And the insurance companies, you know, they've been playing that game for decades. So do they have a better understanding of what it takes to, you know, triage risk? Well, a lot.
I, I think as you said, they're, they're, they're in the business of seeing this every day and I think they're building that fact base now in more cases they get on. So I think absolutely, yes, and I think in general, they're taking this, I think they have moved from the stance of perhaps not understanding when this first opportunity came up to sell insurance into this space. I don't know whether they really understood that, but, but at that particular point, it's not an, if it's a when in terms of as is a breach gonna happen to companies and taking that stance.
But I think that's very much changing now, how you see the policies that they're type are offering, the types assessment they do up front before really setting what is your, your fee for that insurance gonna be and how much they're then working proactively to do regular assessments as part of the renewals, uh, of their particular policies with organizations. I think it is very much evolving and they also see that the threat landscape is evolving, right, in terms of the types of organizations, the types of threats. And they're potentially, you know, it's a risk in terms of the indemnity they offer, but it's also potentially, if they get it right, a way to upsell their policies and look to evolve them, not just make it a, a one-time opportunity for these types of insurance organizations.
How do you think their thinking on policies will evolve in the age of ai? 'cause it's clear the bad guys are gonna be launching more attacks than ever, and they're gonna be more sophisticated. Um, so will the cybersecurity, uh, folks have to up their game when probably prompted by the insurance providers?
I, I, I'm, I, yeah, I think it's a very much an a, a continual game of cat and mouse in in the cyberspace in general. And I, as I, uh, AI has just accelerated that. I think very much so.
You know, we are seeing some evidence of the insurance brokers themselves starting to bring in assessment tools that leverage AI and looking at trying to assess and test the threat. You know, deliberately asking some organizations that have heard of running Red Hat type exercises as part of, uh, of, of actually bringing in, uh, the agreement to provide a policy to organizations is something that we've heard starting to happen rather than just you, you go online and sign a policy. Certainly that's more in the case of larger organizations where the kind of policies you're looking for are much more expensive.
So I think it is gonna be a continual evolution and certainly as part of that, in terms of accelerating that. And what's your best advice to cybersecurity teams about how to work with insurance providers? Uh, 'cause I think there's a tendency to kinda wanna get through the assessment level at, at any way possible, but maybe more transparency is required because you, you wanna make sure that if there is an issue, somebody's gonna cover you.
Yeah, I think ultimately it's, it's rather than, again, change that position where I think most organizations look at it, the shortcut to cyber, cyber preparedness is going really with, you've already done that assessment yourself and can show that you've got the, it, the organizational, the legal, the compliance policies, the communication plans. You've got that disaster recovery plan, that cyber preparedness and resiliency plan all right already to some shape so you can prove that you've got that foundation in place. 'cause that's where you're more likely to get a more favorable policy and cost from the providers themselves.
Where you start from a, you, you really seem like you're just coming into this kind of fresh, you don't have those, uh, those vehicles already in place. It's, it's very much gonna look to be a potentially no go or at least a very expensive activity in terms of the time it takes to get those policies in place. So, so again, you know, my fundamental message and our fundamental messages arc car has very much been, this doesn't shortcut the need to make sure you've got those fundamentals for cyber preparedness and recovery in place.
Um, and if you have the strong foundation, you're in a much better negotiating position in terms of the insurance providers out there as well. And that includes not just the front end for the premium, but when you do put a claim in there, there is a natural tendency for the insurance provider don't wanna reject that claim. So, um, you might have to make a stronger case later on.
Right? Absolutely. I think unfortunately, you know, thi this is like insurance that we've all dealt with on, you know, know personal levels.
I go back to the health insurance, I mean, one, they're gonna assess those preexisting conditions like they would do in any insurance policy, but as you rightly say, when it comes to the claim, uh, they're very much gonna adopt their i's and cross their T's to understand was there anything that changed in those conditions, et cetera. That could mean that indemnifies their need to pay out the policy, right? They, they absolutely are gonna assess that.
So the more that you've got that audit in place yourself, that record of what how you do recoveries, you've, you've actually done and tested those recovery procedures, it's not just a piece of paper, uh, and a paper policy, the more you can ultimately get a better position in terms of ensuring that you've got that payout there as well. It almost seems to me that one of the things that people don't really appreciate is, um, the premiums doesn't have to be a flat rate. It can be based on how resilient your organization Ernie is, just like we do with cars and people.
If, if they, if you're a safe driver or if you're in good health, you might get a lower insurance rate and the same thing should nominally apply to cybersecurity. Right? Absolutely.
And as I mentioned before, we're already seeing some evidence of that evolution. I mean, before when it first, it was literally kind of like your, you know, quote online, uh, cyber insurance was kind of the first, uh, views of what you saw of this. And at pretty low cost typically target more of them smaller and mid-market organizations that certainly have a high, uh, a high propensity potentially go out of business because of these types of threats.
But now that's trying to scale up to larger organizations, again, the premiums are, can be significantly expensive given the, and and rightly so given the potential breach cost. So you're seeing much more of an assessment based, what's your assessment based process in terms of what is the actual, uh, premium gonna be and in some cases that might actually prove, can you go through a, uh, uh, again, a, uh, a mock up, uh, threat exercise, uh, in terms of testing the organization, proving that you've got those defenses and those procedures in place as well. We've certainly seen some, uh, communication of that from our customers who are looking at premiums in the, in the higher space as well.
Do you think the bad guys are looking at who's got what level of insurance and maybe focusing their attacks and maybe even their ransomware demands based on how much they know the insurance companies who they've probably dealt with before are kinda willing to negotiate 'em? I, I think it's an interesting question. I mean, certainly it would make sense as you look at where, you know, ultimately the ransomware provides themselves are looking to get paid, right?
It's become a, whether you call it legitimate, certainly not, but it is a business that's looking to make money. Um, and I think absolutely if they know there's, there's a premium behind that customer that will ultimately accelerate or help to provide some guarantee of getting an outcome in terms of being paid, I think it's likely that does become a target for organizations and, uh, not one, you know, I can give data evidence, data backed evidence that that is actually occurring today, but I think it's certainly an interesting question in terms of how that evolves the target Space moving forwards. Alright folks, well, one way to think about it is cybersecurity is just one more risk like any other that a business needs to evaluate.
It's not all that special in that sense. The question is, is what's it gonna cost to protect ourselves? Hey Simon, thanks being on the show.
Uh, thanks Mike. All right, and back to you guys in the studio.