A lot of companies have cyber insurance. The problem is that many of them may not actually know whether the coverage they bought has much relationship to the loss they could experience.
New research commissioned by Cohesity looked at 100 CEOs of large UK businesses and found that only 22% believe their cyber insurance would cover both the additional costs and lost revenue associated with a cyberattack. The CEOs surveyed estimated that a significant cyber event could reduce revenue by an average of 15.17%. What caught my attention, though, was another number in the research. Twenty-one percent said their organization has never conducted business-impact modelling to understand what a cyberattack could actually cost.
I think that exposes a much bigger problem than an insurance coverage gap. If a company hasn't worked out what happens to the business during a serious technology disruption, it becomes very difficult to determine whether the insurance it purchased is adequate in the first place. You can negotiate limits, deductibles and coverage terms, but those numbers only become meaningful when they're compared with what could actually happen to the business.
Most companies have some understanding of their technology environment. They know which applications are important and probably have recovery plans for at least some of them. What isn't always understood is how those systems connect to the ability of the company to operate. A system can be classified as critical from an IT perspective without anyone having really examined what happens to revenue when it becomes unavailable for three days instead of three hours.
That distinction becomes important when you start thinking about cyber insurance. Insurance is designed to transfer some of the financial consequences of an event. To make an informed decision about how much risk should be transferred, the business first has to understand the consequences it is trying to transfer.
That sounds obvious, but the Cohesity research suggests it isn't happening consistently.
A business can spend a considerable amount of time working with its broker to evaluate cyber coverage while still having a fairly limited understanding of what a major cyber event would do operationally. The policy gets evaluated against expected cyber losses, but the business itself may never have been examined closely enough to understand where those losses actually come from. This is where I think the conversation needs to move beyond traditional cyber risk.
A ransomware event isn't expensive simply because ransomware occurred. It becomes expensive because something the business depends on is no longer available. Orders may stop moving. Employees may lose access to systems they need to work. Production can slow down or stop completely. Customers can start experiencing problems while the company is still trying to determine what happened. Eventually those operational problems begin showing up financially.
That is also why business-impact modeling matters so much. The objective isn't to predict exactly how much the next cyberattack will cost. Nobody can do that with any real precision. The value comes from understanding where the company becomes vulnerable as disruption continues and identifying which parts of the business have to be restored before the consequences become difficult to absorb.
The Cohesity research points in that direction. It recommends identifying the minimum applications, data and services necessary to maintain essential operations and then regularly proving that those systems can actually be recovered into a trusted state. I think that's an important distinction because having a recovery capability documented somewhere is very different from knowing that it will work quickly enough when the business actually needs it.
This is where cyber insurance and business survivability start to separate.
Cyber insurance can be extremely valuable after a significant incident. Depending on the policy and circumstances, it can help absorb costs that would otherwise land directly on the company. But insurance doesn't remove the operational consequences of the event. A covered loss can still be enormously disruptive, and the company still has to operate while systems are being restored and the claim is being worked through.
That's why I think buying cyber insurance before understanding the business impact is somewhat backwards. The insurance decision should come from a broader understanding of how the company would experience the event. Once leadership understands which operations are most vulnerable and how quickly disruption begins affecting the business, the insurance conversation becomes much more useful.
It also changes the questions executives should be asking. Instead of beginning with how much cyber insurance the company should buy, leadership can start by understanding what the business cannot afford to lose for any meaningful period of time. From there, it becomes possible to make better decisions about where resilience needs to be improved and where transferring financial risk through insurance makes sense.
There will always be uncertainty in that process. No business-impact model will perfectly predict the next incident, and no insurance policy can eliminate every financial consequence. The objective isn't certainty. It's making decisions with a much clearer understanding of what the company is actually exposed to.
That is why the 21% number bothers me more than the 22% who believe their insurance would cover the financial impact. A company can discover that it needs more insurance and fix that problem. It is much harder to make a good insurance decision when the organization hasn't determined what a serious disruption could actually do to the business.
Cyber insurance should be part of the survivability strategy, but it can't be the strategy itself. The policy helps determine how much of the financial damage someone else is willing to absorb. The company still has to understand how much damage it can absorb itself and how long it can continue operating while recovery is underway.
That is ultimately the question behind all of this. Having cyber insurance tells you something important about how you've chosen to finance risk. It doesn't tell you whether the business can survive the event you bought the policy for.
