External attacks on companies result in the most expensive cybersecurity losses, but it is employee errors and technical problems that are the most common source of claims – according to the latest report "Managing the impact of growing interconnectivity - cyber trends" prepared by Allianz Global Corporate & Specialty (AGCS).
The study analysed more than 1,700 insurance claims related to cybersecurity with a total value of EUR 660 million. The data included in the study covers losses reported in 2015-2020 both to AGCS and other insurers.
- Losses caused by incidents such as distributed denial-of-service (DDoS) attacks or phishing and ransomware campaigns now account for a significant majority of the value of cyber claims. However, although cybercrime makes headlines, everyday system failures, IT failures and incidents involving human error can also cause problems for companies, even if their financial consequences are not as severe. That is why employers and employees must work together to raise awareness and increase companies' cyber resilience - says Catharina Richter, global head of the Allianz Cyber Center of Competence, AGCS.
The market in numbers
The market in numbers
The number of cybersecurity claims has been steadily growing over the past few years - from 77 in 2016, when cyber was a relatively new line of insurance, to 809 in 2019. In the first three quarters of 2020 alone, AGCS already recorded 770 such losses. This steady increase in payouts was partly driven by the growth of the global cybersecurity market, whose value is currently estimated at USD 7 billion (according to Munich Re). The report also shows that over the past five years there has been a 70% increase in the average cost (to USD 13 million) of cybercrime for organisations and a 60% increase in the average number of security breaches.
Types of incidents
Types of incidents
According to the report, the most common cause of losses by claims value were those resulting from external incidents, such as DDoS attacks or phishing and malware/ransomware campaigns (85%). The second cause indicated in the list was internal actions (9%) - which are rare but can be very costly. Analysing the cause of losses by number of claims, the largest group (54%) was those related to accidental internal incidents, including employee errors while performing everyday duties, IT failures, problems with system and software migration or data loss.
Business interruption (including mitigation costs and third-party liability) is the main cost driver causing cyber losses. It accounts for about 60% of the value of all claims included in the report. The next item on the list was costs related to data breach response.
Challenges for the future
Challenges for the future
Experts note that in the coming years the cyber threat environment will grow. Companies and insurers will face a range of challenges, including the prospect of more expensive business interruptions, the growing frequency of ransomware-related incidents, and the more costly consequences of larger data breaches involving stricter regulations and litigation.
The significant increase in remote work caused by the coronavirus pandemic is also becoming a problem. Employees located in their homes create new opportunities for cybercriminals to gain access to networks and confidential information. According to reports, the number of malware and ransomware incidents has increased by more than a third since the beginning of 2020. At the same time, coronavirus-related online fraud and pandemic phishing campaigns continue to be observed. And although exposure is growing, it cannot yet be said with full confidence that the COVID-19 pandemic is a direct cause of cyber claims.
Growth in ransomware threats
How to reduce the risk of cyber claims in a company
Internal failures as a cause of cyber claims — how to protect yourself?
Ransomware incidents, which are already common, are becoming increasingly harmful and increasingly targeted at large companies through advanced attacks. Last year, nearly half a million ransomware incidents were reported worldwide, costing organisations at least USD 6.3 billion in ransom demands. The total costs of dealing with these incidents are estimated to significantly exceed USD 100 billion.
- Advanced hacking tools are more widely available due to the growing commercialisation of cyber hacks. Increasingly, criminals sell malware to other attackers, who then attack companies demanding a "ransom" payment. However, that is only part of the picture. Business interruptions can bring the most serious losses - downtime is getting longer - while the costs of restoring systems and data can quickly rise - says Marek Stanisławski, Global Cyber Underwriting Lead, AGCS
Growing business interruptions, vulnerability for the digital supply chain and data breaches
- Whether caused by ransomware, human error or a technical fault, the loss of critical systems or data can bring an organisation to its knees in today's digital economy. Lack of access to data for an extended period can have a significant impact on revenue - for example, if a company is unable to accept orders - says Joerg Ahrens, global head of long-tail claims at AGCS.
At the same time, the costs of dealing with a large data leak are rising because IT systems and cyber events are becoming more complex. Data privacy regulations, which have recently been tightened in many countries, are also a key cost driver, as is growing third-party liability and the prospect of class actions. So-called mega data breaches (involving more than a million records) are more frequent and more expensive - they now cost an average of USD 50 million, which means a 20% increase compared with 2019.
- Entrepreneurs' awareness is growing year by year, not only in the context of much more frequent external attacks, but above all in connection with the consequences such events can have for organisations. A well-chosen cyber insurance policy is certainly one of the more important elements that can help companies deal with the possible effects of hacker attacks or employee errors – says Jacek Zębala, Product Manager, Allianz Polska
Prepare, practise and prevent
Prepare, practise and prevent
Preparing and training employees can significantly reduce the consequences of a cyber event, especially in the case of phishing and business email compromise attempts, which can often involve human error. Properly training the team can also help limit ransomware attacks, and maintaining secure backups can reduce damage. Cross-sector exchange and cooperation between businesses are also important, making it possible to counter organised cybercrime, develop common security standards and increase cyber resilience. The COVID-19 landscape brings additional, new challenges. With widespread work from home, security around access points and authentication is crucial, but organisations should also ensure sufficient network capacity, as this can have a significant impact on lost revenue in the event of a failure.
The full report is available for download: HERE.
Summary
The AGCS report shows that although external attacks generate the largest financial losses (85% of claims value), the most common cause of losses is internal incidents, such as employee errors or IT failures (54% of claims count). Business interruptions account for about 60% of the value of all claims.
Experts warn of the growing ransomware threat – nearly half a million such incidents were reported worldwide last year. Prevention is becoming key: employee training, secure backups and cross-sector cooperation, especially in the era of widespread remote work.