Intelligent CIO LATAM Issue 11 | Page 54

FEATURE : RANSOMWARE
than anticipated to enable their rapidly growing remote workforce , dramatically increasing the vulnerability of many of them to cybercrime .
Cyber insurance bubble about to burst ?
While the need for cyber insurance has never been clearer , faced with the increased demands of ransomware victims , insurers aren ’ t as ready to provide it . Cyber insurance is a relatively new facet of the insurance industry and it seems it was only intended by insurers as being for unforeseen , unlikely and novel catastrophic events .
But as the industry ’ s loss ratio rose for the third straight year in 2020 , climbing more than 25 percentage points year over year to 72.8 %, and ransomware events jumped 93 % in the first half of
2021 , something clearly has to change . Ransomware is neither unlikely or novel any longer , but rather has become a commoditized threat .
An intensified underwriting process is making life difficult
Unsustainable loss ratios have inevitably led carriers to intensify the underwriting process for cyber insurance . On the face of it , they are increasing premiums for less coverage and higher deductibles .
Looking at the process in more detail , carriers are also becoming much more vigilant about the controls that need to be in place in order to sell cover , while brokers are also reporting that all insurance markets are asking for higher security standards . Insurers are asking more questions about organizations ’ cyber-risk posture and adding more exclusions .

ONE ESTIMATION OF ALL THE RANSOMWARE EXTORTION PAYMENTS FOR 2020 WAS TOTALLED AT US $ 350 MILLION .

While there are no signs of insured companies wanting to drop coverage , if carriers don ’ t like anything they find during the underwriting process , apart from increasing premiums or cutting limits , they are becoming increasingly likely to simply walk away .
To make things even harder for organizations seeking coverage , insurance companies have realized they also need to diversify . Companies exist in a cyber ecosystem and attacks on one company can have a huge knock-on effect .
54 INTELLIGENTCIO LATAM www . intelligentcio . com