1
Cyber risk and insurance
- Dr. Katsiaryna (Kate) Labunets
Safety and Security Sciences group TPM, TU Delft E: k.labunets@tudelft.nl
Cyber risk and insurance Dr. Katsiaryna (Kate) Labunets Safety and - - PowerPoint PPT Presentation
Cyber risk and insurance Dr. Katsiaryna (Kate) Labunets Safety and Security Sciences group TPM, TU Delft E: k.labunets@tudelft.nl 1 Outline Who am I? Definitions Motivation Cyber insurance market: Current practice
1
Safety and Security Sciences group TPM, TU Delft E: k.labunets@tudelft.nl
2
3
MSc in Mathematics
Belarusian State University, Minsk, Belarus 2004 - 2010
Business Systems Analyst
Outsourcing software development company in Minsk, Belarus 2008 - 2011
PhD Candidate in ICT
University of Trento, Italy Nov 2011 - April 2016
Postdoc in Empirical Security
DISI, University of Trento, Italy June 2016 - May 2017
Postdoc in Cyber Insurance
TBM, TU Delft, Netherlands June 2017 - Present
4
5
accept the risk.
6
Gartner, “Five Tips for Companies Considering Cyber Insurance,” 2015. Available: http://blogs.gartner.com/john-wheeler/five-tips-for-companies- considering-cyber- insurance/
7
WEF, "Global Risks Interconnections Map 2017", https://goo.gl/P5bkrk
8
WEF, "Global Risks Interconnections Map 2017", https://goo.gl/P5bkrk
9
WEF, "Global Risks Interconnections Map 2017", https://goo.gl/P5bkrk
10
Lloyd's, “Counting the cost: cyber exposure decoded”, 2017. https://goo.gl/fSFq9B
11
12
13
Advisen, “Information Security and Cyber Liability Risk Management”, 2015. http://bit.ly/1M9Gyp0
14
15
16
17 17
18
19
20
Insurer Agent Expert
Cover losses due to cyber risk Collect necessary data Provide results
Security provider Threat Reinsurance provider Sector regulator
S e c u r i t y s e r v i c e s f
i n s u r e r a n d i t s c l i e n t s Provide security services Compliance with regulations Pay premiums Damage or steal company's assets Cover part of insurer's clients losses Request for a specific expertise
Insurance regulator
Compliance with regulations Invest in security
Policymaker
Interests of companies Interests of insurers
Client
Provide product/service Interests of clients Policy changes
Researchers
Research results, policy recommendations Provide product/service
Vendor
21
22
23
24
25
26
IT company
Decision
27
28
MSc thesis: "The Vulnerability Ecosystem: Exploring vulnerability discovery and the resulting cyberattacks through agent-based modelling" by Y. Breukers
29
30
31
32
33
34
35
– 3rd party security and privacy claims, – network business interruption, – security failure at outsourced service provider, – electronic data incidents, – cyber extortion, – etc.
36
37
Talesh, "Data Breach, Privacy, and Cyber Insurance: How Insurance Companies Act as “Compliance Managers” for Businesses". Law & Social Inquiry, 2017
38
39
40
41
42
WP3 WP4 WP5 WP6 WP7 WP8 WP2 WP1 Ethics requirements
43
44
Category N Mean SD Cyber risk 994 40,53 443,88 Non-cyber risk 21 081 99,65 1 160,17
Losses per risk type (in million US$)
Biener et al. "Insurability of cyber risk: an empirical analysis". Geneva Papers on Risk and Insurance: Issues and Practice, 2015.
45
Bloomberg, "Cyber Crime Fears Drive Up Demand for Anti-Hacker Insurance".
https://www.bloomberg.com/news/articles/2017-05-09/cyber-crime-fears-drive-growing-demand-for-anti-hacker-insurance
46