Misconceptions about Cyber Insurance: Five Key Issues the Industry Needs to Re-examine
When Lake City, Florida, suffered a ransomware attack, it decided to pay the ransom. Behind this choice lies the increasingly complex role of cyber insurance in incident response. Through multiple cases and insights from industry experts, this article reveals common misconceptions about cyber insurance, selection strategies, and clause disputes.

When Lake City, Florida was hit with a ransomware attack, the city decided to pay the ransom. Its insurance company, Beazley, said recovery costs could reach $1 million. After weighing the math against its cyber insurance policy terms, Lake City chose to pay a $462,000 ransom. Under the policy terms, the cyber attack ultimately cost the city a $10,000 deductible and led to the resignation of its IT director.
Contrary to traditional industry practices, "paying the ransom" may be becoming the new normal. When hackers clearly understand a victim's asset situation, the math often favors paying the ransom—which is almost always cheaper than recovery costs, especially when the organization holds a cyber insurance policy.
"Insurance companies offering cyber coverage have successfully positioned themselves as a refuge of rationality and resources amid the chaos of ransomware attacks," Jerry Ray, COO of data security company SecureAge, told CIO Dive.
According to the 2019 Cyber Risk Perception Survey jointly released by Marsh and Microsoft, the proportion of organizations saying they "don't know" whether their cyber policies would meet their needs has dropped from 44% in 2017 to 31% this year. On the other hand, most organizations with cyber insurance are fairly or highly confident in their coverage.
Misconceptions abound about the role insurance plays in the aftermath of cyber incidents. There is also an assumption that insurers have inadvertently driven a 500% year-over-year increase in ransomware attacks. Matthew McCabe, senior vice president and head of the Cyber Center of Excellence at insurance brokerage Marsh, told CIO Dive that cyber insurance is "an emerging product, and we expect to receive questions about it." But "there is published misinformation about it, as well as meaningless conclusions thrown into the public debate," such as claims that insurance is encouraging more cyber attacks. "If I had one wish," McCabe said, "it would be that people had a clearer understanding of what this product does and its claims capabilities."
Cyber insurance is an investment
Cyber insurance is used to offset fines or compensation—it's straightforward. It takes over where general liability insurance leaves off, covering businesses for incident-related costs, infrastructure recovery, breach disclosure, and data restoration. "First, it's crucial to understand that cyber insurance is a hypothetical default or failure control for post-incident failures," Chris Kennedy, CISO of security company AttackIQ, told CIO Dive. "It's a way to adjust risk when you assume your security program won't work."
According to the Marsh and Microsoft survey, nearly half of organizations have adopted cyber insurance, up from 34% in 2017. Among companies with revenue over $1 billion, more than half (57%) hold policies, while among companies with revenue under $100 million, that figure is only 36%.
Privacy protection has brought cyber insurance into the mainstream. "Privacy is an invaluable component of insurance," McCabe said, especially for data aggregators. As more privacy legislation and regulation emerge, this is becoming a competitive advantage. Technology errors and omissions were once part of policies, but as technology matured and companies could offer more services to consumers, the insurance market saw growing demand for more comprehensive coverage over the past decade. "This merged with a range of other protections and evolved into what is today's cyber insurance policy," McCabe said.
According to incidents reported by Beazley's internal breach response team, nearly a quarter of ransomware incidents in the third quarter of 2019 originated from IT vendors or managed service providers. These attacks drove a 37% year-over-year increase in ransomware in the third quarter. Business interruption and data destruction are other major drivers of policy adoption. McCabe said that in 2017, NotPetya, a wiper disguised as ransomware, "proved with facts" that cyber incidents could cause catastrophic damage.
How to choose a cyber insurance policy
Cyber risks are typically outlined in SEC filings, but when considering an insurance policy, companies must assign a monetary value to them, usually derived from math based on risk assessments. Jeremy Alexander, senior risk expert at Walmart, speaking at the FAIR conference in September, said that historically, "people feared cyber incidents due to uncertainty." Insurers knew they should offer cyber coverage but were unsure how to quantify the policies. But as companies and insurers shift to quantitative methods, all parties have become more comfortable with accepting risk, Alexander said. Cyber insurance rates are improving because competition is also intensifying.
When evaluating a plan, companies must first examine the policy structure. Consider the retention: a policy provision similar to a deductible. The retention stipulates that in the event of an incident, the policyholder is responsible for up to a certain amount. Other times policies have caps, Alexander said, "beyond the deductible, you might become responsible again," referring to more severe incidents. Companies can reference multiple theoretical scenarios when assessing risk and the best policies for transferring it.
"Benign" scenarios (including cloud storage and buckets) are often mismanaged. For example, if a company exposes a bucket—which is often a default setting—but it only contains log files and no personally identifiable information, the loss would be minimal. Alexander said "doomsday" scenarios are worth considering, "excluding the absurd" or the completely unimaginable. Usually only a few scenarios fall between "benign" and "doomsday." There will always be high-priority scenarios, such as confidential data leaks. To estimate these costs, one can look at other companies' financial data. Walmart is in the same industry as Target, so the retailer can learn from a competitor's mistakes.
In 2013, Target suffered a data breach involving approximately 40 million credit cards. By 2017, Target agreed to pay nearly $19 million to 47 states in a massive settlement. Before reaching the settlement, the retailer incurred about $184 million in breach-related costs in 2014 and 2015, according to its 2016 annual report. The company said: "In 2016, data breach-related costs were negligible." By the time Target filed its annual report, it had spent $292 million on breach costs. Of that, about $90 million was "offset" by insurance recoveries. Target's net breach-related costs were approximately $200 million. With about 40 million records compromised, risk management teams like Alexander's were able to provide a data point for this specific breach: each breached record cost the retailer about $5. Using this data point, companies—or Target's competitors—can roughly predict breach costs by asking, "How many customer records do we use or own?"
This is a broad summary of assessing risk. Frequency is another component to consider, where effective communication with executives becomes especially important. "You need to be able to present uncertainty without necessarily showing the distribution," Alexander said.
Insurance gaps
Companies relying on property insurance policies for cyber-related recovery may struggle to find solace. Mondelez International, which produces Wheat Thins and Chips Ahoy! cookies, had net revenue of nearly $30 billion when it was hit by the NotPetya attack in 2017. NotPetya rendered approximately 1,700 servers and 24,000 laptops "permanently dysfunctional." The company is relying on a property policy that covers losses from electronic data, software, and physical damage caused by the "malicious introduction" of malware. The food company is suing its insurer, Zurich American Insurance, for $100 million for failing to cover losses related to NotPetya.
But Zurich has not conceded. The insurer says Mondelez's NotPetya attack was a "war-like act" during "peacetime," thus exempting Zurich from liability. "It should be noted that the litigation with Mondelez over the NotPetya claim involves Zurich's property policy, not Zurich's standalone cyber policy," Michelle Chia, head of professional liability and cyber at Zurich North America, said in an email to CIO Dive. "Standalone cyber insurance policies are better equipped to address emerging cyber risks than the cyber coverage expected in traditional policies, such as first-party property or general liability."
The litigation is ongoing, but in the months following NotPetya, the industry and the White House concluded that although it was a state-sponsored attack, most victims were collateral damage rather than primary targets, such as Mondelez and shipping giant Maersk. "I think the insurers got it very wrong," McCabe said. In reality, most NotPetya victims were not targeted as acts of war. According to Marsh research, "conflating war exclusions with non-physical cyber events (like NotPetya)" is the result of: the wiper's massive economic impact; and the U.S. and UK governments attributing the attack to Russia. According to the research, even combining these two factors is insufficient to "elevate this non-physical cyber attack to war or 'hostile war' activity." Other considerations involve descriptions of victims: Location: were they near a conflict zone, or "far from where the war occurred"? Did they have military connections?
In the NotPetya case, according to Marsh, victims were far from any war scenario. If insurers lean toward invoking war exclusions, Marsh suggests they reform them to clearly specify when the clause applies. However, given the sophistication of cyber attacks and the malicious actors behind them, this is an opportunity for businesses and insurers to strengthen cooperation. "Businesses concerned about cyber terrorism risk should consider standalone cyber insurance policies," Chia said. Zurich has specific cyber coverage and has "paid significant NotPetya-related losses" under such policies. According to Chia, "These policies contain war exclusions but include a cyber terrorism exception." Zurich's cyber policies cover cyber terrorism, including "any attack or threat by any individual, group, or government against the insured's cyber security." In other words, the "war or civil unrest exclusion" in Zurich's cyber policies does not apply to cyber terrorism. In the Mondelez case, according to information provided by Zurich, "hostile and warlike act exclusions in property policies... typically do not provide an exception for losses caused by cyber attacks that have penetrated the insured's cyber security." As of press time, Mondelez had not responded to requests for comment.
Security considerations
Unlike auto insurance (where insurers replace damaged vehicles), cyber insurance cannot cover damaged intellectual property. A former employer of Kennedy's held $116 billion in publicly available client assets. "You can't replace those," he said. The data the company possessed gave it a "beat-the-market" edge, making it an asset that cannot be fully insured. The responsibility for deciding on a plan—while influenced by risk management and other departments—typically falls on the chief security officer. Risk management will brief the security chief on the mathematical impact and consequences of incidents. According to Marsh research, the CFO, as another pillar of risk management, may raise questions similar to those of the CISO.
Security organizations must answer the following questions: What could go wrong? What protective capabilities exist? If something goes wrong, what will the security organization do? How will the security organization and the insurer collaborate in recovery? As a CISO, Kennedy said, "You need to ensure there's adequate coverage and that there are no 'traps' in the contract." Though he would prefer companies invest more in cyber security first, placing insurance "in a smaller corner of need."
The insurer's incident response role
Companies don't have to jump through hoops to obtain cyber insurance. Felicia Thorpe, assistant vice president at AHT Insurance, told CIO Dive that the bar for obtaining coverage is typically low. Most entities' quantitative risk assessments go "far beyond" what most insurers require. "Think about it: if you're the first company to enter the market and say 'we're going to require X, Y, and Z to provide coverage,' you make it harder to do business with clients," she said. Insurers are more likely to view the carrier market as a whole and collectively decide on standards. But even so, carrier influence is common, whether among other carriers or policyholders.
Ray said victims may see paying the ransom as the insurer's default choice. "The decision to pay or not becomes the insurer's option, based solely on claims of urgency or the advice of independent incident response experts brought in." Insurers are reassuring clients in various ways, such as coverage grants that extend protection to more specific areas. Thorpe said this may be due to increased demand for cyber insurance. Ultimately, insurers will tighten their standards, holding clients more responsible for their own "cyber health"—echoing Kennedy's emphasis on cyber security.
Even now, insurers are typically not the primary advisor victims seek for response recommendations after a cyber incident. Insurers that step in immediately after an incident usually provide forensic vendors to diagnose the severity of the event. "The forensic vendor works for the insured—that's where the relationship lies," McCabe said, and that vendor is likely to have experience with the malicious actors behind the incident. That experience can inform the victim whether the malicious actors keep their promises and restore functionality after a ransom is paid. The victim entity also consults legal counsel to answer key questions: What does this mean for my reputation? What mandatory requirements need to be fulfilled? Who do we need to notify? If it's a municipality, what does this mean for taxpayers? "In my experience, I've never seen a carrier in the room say you should do this," McCabe said. Ultimately, insurers, like clients, have their own business to run. A mutual understanding of how both sides operate will eliminate skepticism toward the insurance industry. Companies know cyber insurers have paid claims. "I think the product has performed as intended, and I think carriers have done a good job," McCabe said. "I just wish they got more recognition."
