Moral Hazards and Ethical Considerations in Cyber-Insurance
Unknown
Black Hat USA 2024 · Day 1 · Briefing
Overview
This Black Hat USA panel delves into the often-debated intersection of cybersecurity and insurance, specifically addressing the moral hazards and ethical considerations that arise within the cyber insurance landscape. The discussion brings together a diverse group of experts: a breach coach, an insurance broker specializing in cyber risk quantification, a Managing General Agent (MGA) and research VP from a cyber insurance provider, and an intermediary working with smaller insurance agents. Their collective insights aim to demystify cyber insurance, confront common misconceptions, and provide a nuanced understanding of its role in an organization's overall cybersecurity strategy.

Key moments
- 0:00 Panel introduction and topic: moral hazards in cyber insurance
- 0:30 Panelists introduce their diverse roles in the cyber insurance ecosystem
- 2:50 Addressing the core question: Do cyber insurance claims actually get paid?
- 4:00 Common reasons for cyber insurance claim denials and fraud
- 5:30 Importance of understanding cyber insurance policy terms and conditions
- 6:10 Proactive risk assessment and working effectively with your broker
- 6:50 Challenges and managing expectations for business interruption claims
Moral Hazards and Ethical Considerations in Cyber-Insurance
Speakers: Lindsay Nickel, Vice Chair, Cybersecurity and Data Privacy Team, Constangy Brooks Smith and Profit; Scott Stransky, Marsh McLennan Cyber Risk Intelligence Center; Tiago, VP of Research, Coalition; Jeffrey Smith, Intermediary
Conference: Black Hat USA
YouTube: https://www.youtube.com/watch?v=yaxXBbRYG_g
Overview
This Black Hat USA panel delves into the often-debated intersection of cybersecurity and insurance, specifically addressing the moral hazards and ethical considerations that arise within the cyber insurance landscape. The discussion brings together a diverse group of experts: a breach coach, an insurance broker specializing in cyber risk quantification, a Managing General Agent (MGA) and research VP from a cyber insurance provider, and an intermediary working with smaller insurance agents. Their collective insights aim to demystify cyber insurance, confront common misconceptions, and provide a nuanced understanding of its role in an organization's overall cybersecurity strategy.
The core of the panel's discourse revolves around two fundamental questions that frequently plague the information security community: first, whether cyber insurance policies truly pay out in the event of a breach, and second, if the existence of cyber insurance might inadvertently incentivize organizations to neglect robust security controls, thereby creating a moral hazard. The panelists offer a definitive "yes" to the former and a resounding "no" to the latter, backing their assertions with extensive industry experience and data. This talk is crucial for CISOs, security practitioners, risk managers, and business leaders seeking to understand how cyber insurance functions not merely as a financial safety net, but as an integral component of proactive risk management and security posture improvement.
The insights shared underscore that cyber insurance is not a substitute for strong security but rather a complementary layer that provides critical support, expertise, and financial protection when incidents inevitably occur. By clarifying the mechanisms of policy underwriting, claims processing, and the inherent incentives for robust security, the panel aims to equip attendees with a clearer perspective on leveraging cyber insurance effectively and ethically in today's complex threat landscape.
Background
▶ Watch: Panel introduction and topic: moral hazards in cyber insurance (0:00)
The concept of cyber insurance emerged as a direct response to the escalating financial and reputational costs associated with cyber incidents. As organizations increasingly depend on digital infrastructure, the potential for data breaches, ransomware attacks, and business interruptions has grown exponentially. Traditional insurance policies often proved inadequate for these novel, rapidly evolving risks, creating a demand for specialized coverage. However, the introduction of cyber insurance into the information security community was met with considerable skepticism and a host of fundamental questions, primarily centered around its efficacy and potential unintended consequences.
A pervasive initial concern within the Infosec community, characterized by its inherent paranoia and cynicism, was the fundamental question: "In the event of a breach, do you guys pay out?" This skepticism stemmed from a general distrust of insurance companies and a lack of transparency regarding claims processes, especially for a relatively new and complex risk like cyber. Many feared that policies would be riddled with exclusions or that carriers would find reasons to deny legitimate claims, leaving organizations vulnerable despite having paid premiums.
Beyond the payout question, a more profound ethical and strategic debate quickly arose concerning the moral hazard. In economic theory, a moral hazard occurs when one party takes on more risk because another party bears the cost of that risk. In the context of cyber insurance, the fear was that organizations, knowing they were insured, might become complacent, opting to invest less in preventative security measures. The argument posited that if an insurer would cover the costs of a breach, the insured entity might logically conclude that the financial incentive to maintain a stringent security posture was diminished, thus doing "worse for security than they otherwise would have." This concern reflected a deep-seated apprehension that insurance could undermine the very imperative for strong cybersecurity, rather than supporting it.
The panel sought to directly address these two foundational anxieties, drawing on the collective experience of its members who represent different facets of the cyber insurance ecosystem. Their aim was to provide clarity on how cyber insurance truly operates, both in terms of financial payouts and its influence on organizational security behaviors, thereby contextualizing its role within the broader cybersecurity strategy.
Key Findings
▶ Watch: Addressing the core question: Do cyber insurance claims actually get paid? (2:50)
The panel discussion yielded several critical findings that directly address the core anxieties surrounding cyber insurance, providing a clear and unified perspective from industry experts.
The first, and perhaps most reassuring, finding is that cyber insurance companies overwhelmingly pay out valid claims. Lindsay Nickel, a breach coach who has handled thousands of breaches over more than a decade, working with "dozens and dozens of different insurance companies," unequivocally states, "Yes, the insurance companies do pay for the claims." She highlights that cyber insurance is a first-party product, meaning it directly benefits the insured company by covering their own losses and expenses, rather than third-party liabilities alone. This includes not just financial reimbursement but also access to a network of specialized experts, such as legal counsel, incident response teams, and even assistance with complex tasks like acquiring cryptocurrency for ransomware payments. Scott Stransky from Marsh McLennan corroborates this, explaining that as a broker, his firm sees "thousands of claims across our clients" and uses this data for modeling and analysis, demonstrating that payouts are a fundamental part of the business model. Insurers want to pay out valid claims because it provides valuable data and reinforces the product's value to clients.
Tiago from Coalition further quantifies this, stating that in five years, his company has seen claims denied only "three times." These rare denials were attributed to specific, clear-cut scenarios:
- Claims fraud: A company attempted to sign up for insurance after being ransomed, misrepresenting their incident status during the application.
- Blatantly wrong information on purpose: Customers deliberately provided false information regarding their security controls during the application process, such as falsely claiming to have Multi-Factor Authentication (MFA) enforced on email. While minor inaccuracies might be forgiven, clear intent to deceive leads to denial.
This leads to the second major finding: cyber insurance does not create a moral hazard that discourages security investment; instead, it actively incentivizes and often mandates robust security controls. The panel firmly refutes the notion that insurance allows businesses to become complacent. Tiago emphasizes that "even applying for a policy, there's going to be minimum set of security controls you're going to need to have in place to be considered for a policy." He specifically cites the enforcement of MFA on email as a non-negotiable requirement for obtaining coverage today. Furthermore, data-driven cyber insurance providers conduct scans and assessments, making it nearly impossible to secure a policy if an organization has critical vulnerabilities like Remote Desktop Protocol (RDP) exposed to the internet or unpatched systems from vendors like SonicWall, Fortinet, or Citrix.
Jeffrey Smith highlights the importance of managing expectations regarding payouts, particularly for business interruption claims, which often have waiting periods (e.g., 8 or 12 hours) and require specific calculations of lost profits, which can differ from an insured's initial estimates. The panel also touched upon the often-overlooked reality that many small businesses, particularly those covered by package cyber insurance policies (where cyber coverage is bundled with other types of insurance), may not even realize they possess cyber insurance, thus failing to claim for covered events. This underscores the need for greater awareness and communication between insureds, brokers, and carriers.
In essence, the key findings are that cyber insurance is a functional and responsive mechanism for mitigating cyber risk, and far from fostering complacency, it acts as a powerful driver for organizations to adopt and maintain essential cybersecurity hygiene.
Technical Deep Dive
▶ Watch: Common reasons for cyber insurance claim denials and fraud (4:00)
While this panel discussion did not involve technical exploits or code demonstrations, the "technical deep dive" in this context refers to the intricate mechanics, protocols, and architectural considerations of the cyber insurance industry itself, particularly as they relate to cybersecurity controls and risk assessment. The panelists shed light on the sophisticated processes insurers employ to quantify risk, underwrite policies, and manage claims, effectively turning security posture into an insurable metric.
At the heart of modern cyber insurance is a data-driven approach to underwriting. Insurers are not simply taking an applicant's word for their security posture. As Tiago from Coalition, whose company acquired Binary Edge for large-scale data collection and internet scanning, explains, providers use external scanning and internal questionnaires to verify an organization's security hygiene. This due diligence is a critical component of risk assessment. Key security controls that are heavily scrutinized and often mandated include:
- Multi-Factor Authentication (MFA): This is consistently highlighted as a non-negotiable requirement, particularly for email access. Insurers understand that compromised credentials are a primary vector for attacks, and MFA significantly reduces this risk. If an applicant falsely claims to have MFA enforced and an incident reveals its absence, it can lead to claim denial, as seen in Coalition's experience.
- Remote Desktop Protocol (RDP) Exposure: RDP, when exposed directly to the internet without proper security controls, is a well-known entry point for ransomware and other attacks. Insurers actively scan for and flag such exposures. Organizations with RDP directly on the internet are unlikely to secure a policy from data-driven providers.
- Patch Management: The panel specifically mentions unpatched vulnerabilities in critical network devices and software from vendors like SonicWall, Fortinet, and Citrix. These are common targets for attackers due to their widespread use and the severity of exploits. Insurers expect timely patching as a fundamental security practice. The presence of known, unpatched vulnerabilities can be a significant barrier to obtaining coverage.
These security requirements are not merely suggestions; they are often warranties made during the application process. A breach of these warranties, such as misrepresenting the enforcement of MFA or the state of RDP security, can be grounds for claim denial, as described by Lindsay Nickel. This contractual obligation transforms security best practices into legally binding terms of the insurance agreement.
The claims process itself involves a sophisticated interplay of various experts. When an incident occurs, a breach coach (like Lindsay Nickel) coordinates the response, bringing in legal counsel, incident responders, forensic investigators, and even specialists for cryptocurrency payments if a ransom is involved. Brokers (like Scott Stransky) act as intermediaries, notifying carriers on behalf of their clients and assisting in the claims process. The data collected from these "thousands of claims" is then fed back into the insurers' modeling and data analysis, creating a continuous feedback loop that refines risk assessment and policy terms. This demonstrates that insurers have a vested interest in understanding the nature of breaches to improve their products and pricing.
The discussion also touched on different types of insurance products:
- First-Party Product: Cyber insurance primarily covers the direct costs incurred by the insured organization due to a cyber incident, such as forensic investigation, legal fees, notification costs, and business interruption losses.
- Parametric Policy: While not extensively detailed, Jeffrey Smith mentions parametric policies as an alternative for specific risks like cloud outages. Unlike traditional indemnity policies that pay based on actual losses, parametric policies pay out a pre-agreed amount if a specific trigger event (e.g., a cloud provider outage exceeding a certain duration) occurs, regardless of the actual financial loss. This can offer faster payouts and greater certainty.
- Package Cyber Insurance: This refers to cyber coverage bundled with other types of business insurance, often for Small and Medium-sized Enterprises (SMEs) or "mom and pop shops." While convenient, the panel notes that many insureds may not even be aware they possess this coverage, highlighting a gap in understanding and utilization.
Furthermore, the role of an intermediary or "broker's broker" (like Jeffrey Smith) in the SME space is critical. These intermediaries provide specialized cyber broking expertise to smaller insurance agents who lack in-house capabilities, ensuring that even small businesses can access appropriate coverage and guidance. Jeffrey also highlighted the development of new products, such as personal liability protection for CISOs and other security professionals, addressing concerns about individual accountability in the wake of a major security event, particularly if company insurance is exhausted.
In summary, the "technical deep dive" reveals that the cyber insurance industry is becoming increasingly sophisticated, leveraging data, external scanning, and stringent underwriting criteria to drive better security outcomes. It's a complex ecosystem where the technical details of an organization's security posture directly impact its insurability and the validity of future claims.
Demo / Proof of Concept
▶ Watch: Proactive risk assessment and working effectively with your broker (6:10)
As a panel discussion focused on the conceptual and ethical aspects of cyber insurance, this session did not include any live demonstrations or proofs of concept in the traditional sense of a technical security talk. The panelists presented their insights and findings based on their extensive professional experience and proprietary data, rather than showcasing a specific tool or exploit.
Defensive Implications
▶ Watch: Challenges and managing expectations for business interruption claims (6:50)
The insights from this panel offer several crucial defensive implications for organizations, CISOs, and security practitioners looking to navigate the complex landscape of cyber risk and insurance effectively. Far from being a passive financial product, cyber insurance emerges as an active component in shaping and reinforcing an organization's cybersecurity posture.
- Prioritize Core Security Controls: The panel unequivocally stresses the absolute necessity of foundational security measures. Multi-Factor Authentication (MFA), especially for email, is no longer optional but a mandatory prerequisite for obtaining cyber insurance. Similarly, organizations must eliminate or rigorously secure Remote Desktop Protocol (RDP) exposure to the internet and maintain diligent patch management for critical systems, particularly those from vendors like SonicWall, Fortinet, and Citrix. Defenders should view these not just as best practices but as minimum requirements for insurability and claim validity. Investing in these areas first is paramount.
- Understand Your Risk Profile Internally: Before engaging with brokers or insurers, organizations must conduct thorough internal threat modeling and risk analysis. As Tiago advises, "try to understand your risk and what you want to protect against." This internal assessment allows organizations to articulate their specific needs and vulnerabilities, leading to more tailored and effective insurance solutions, such as considering a parametric policy for cloud outages versus a standard indemnity policy.
- Be Honest and Accurate in Applications: The panel highlights that nearly all claim denials stem from misrepresentation or outright fraud during the application process. Defenders must ensure that all security controls and practices described in insurance applications are accurate and verifiable. Deliberately providing false information, such as claiming MFA enforcement when it doesn't exist, will invalidate coverage. This underscores the importance of close collaboration between security teams and those responsible for insurance procurement.
- Work Closely with a Knowledgeable Broker: A broker is an organization's "best friend" in the cyber insurance journey. They possess the expertise to understand complex policy language, negotiate terms, and guide organizations through the application and claims processes. For smaller businesses or those without in-house cyber expertise, leveraging an intermediary or "broker's broker" can bridge this knowledge gap, ensuring appropriate coverage.
- Read and Understand Policy Terms and Conditions: Expectations can lead to friction in the claims process. Defenders and business leaders must thoroughly understand their policy's terms, including deductibles, waiting periods for business interruption (e.g., 8 or 12 hours), and the specific criteria for covered events. A three-hour downtime might not trigger a payout if the waiting period is longer. This proactive understanding helps manage expectations and ensures that claims align with policy provisions.
- Leverage Insurer Expertise and Resources: Beyond financial payouts, cyber insurance provides access to a network of specialized resources, including breach coaches, legal counsel, and incident response teams. Organizations should view their insurer as a partner that can provide crucial support and expertise during an incident, helping them navigate complex legal, technical, and logistical challenges like acquiring Bitcoin for ransomware payments.
- Recognize Insurance as an Incentive for Improvement: Instead of creating a moral hazard, cyber insurance is a powerful market mechanism that drives security improvements. The stringent underwriting process effectively audits an organization's security posture, incentivizing investment in controls to secure coverage and potentially lower premiums. Defenders can use insurance requirements as leverage to advocate for increased security budgets and resources internally.
- Stay Informed about Evolving Products: The cyber insurance market is dynamic. New products, like the proposed personal liability protection for CISOs mentioned by Jeffrey Smith, are emerging to address specific concerns. Defenders should stay abreast of these developments to ensure comprehensive risk coverage for both the organization and its leadership.
In essence, the defensive implications are clear: cyber insurance is not a substitute for robust security but a sophisticated risk management tool that demands an equally sophisticated and proactive approach from organizations. By understanding its mechanics and embracing its incentives, defenders can transform cyber insurance into a strategic asset in their ongoing battle against cyber threats.
Key Takeaways
- Cyber insurance policies genuinely pay out for valid claims. The vast majority of claims are paid, with denials typically occurring only in cases of fraud or deliberate misrepresentation of security posture during the application.
- Cyber insurance actively incentivizes, rather than discourages, strong security practices. Insurers mandate minimum security controls like MFA, secure RDP, and diligent patching as prerequisites for coverage, effectively making robust security a condition of insurability.
- Understanding policy terms and conditions is crucial. Organizations must be aware of deductibles, waiting periods for business interruption (e.g., 8 or 12 hours), and specific coverage criteria to manage expectations and ensure claims are valid.
- A data-driven approach is fundamental to modern cyber insurance. Providers use extensive data, including external scanning (e.g., Coalition's use of Binary Edge) and claims data (e.g., Marsh McLennan), to assess risk, underwrite policies, and refine their offerings.
- Work with knowledgeable brokers and conduct internal risk assessments. Brokers are essential guides in navigating the complex cyber insurance landscape, and internal threat modeling helps organizations identify specific risks to ensure appropriate coverage.
- Cyber insurance provides more than just financial compensation. It offers access to a network of expert resources, including breach coaches, legal counsel, and incident response teams, which are critical during a cyber incident.
About the Speaker(s)
The panel featured a diverse group of experts representing various facets of the cyber insurance industry:
- Lindsay Nickel is the Vice Chair of the Cybersecurity and Data Privacy team at Constangy Brooks Smith and Profit. As a breach coach and specialized attorney, she assists clients with responding to cybersecurity and privacy incidents, drawing on over a decade of experience handling thousands of breaches and working with dozens of different insurance companies.
- Scott Stransky is with the Marsh McLennan Cyber Risk Intelligence Center. Marsh McLennan is a major insurance broker that helps companies acquire cyber insurance. Scott's role involves quantifying cyber risk through modeling, data, and analysis. He also contributes to understanding claims data from Marsh's thousands of clients.
- Tiago is the VP of Research at Coalition, a Managing General Agent (MGA) and cyber insurance provider. Tiago joined Coalition after they acquired his company, Binary Edge, which specializes in large-scale data collection and internet scanning, underscoring his expertise in data-driven risk assessment for cyber insurance.
- Jeffrey Smith is an intermediary, often described as a "broker's broker." He works with smaller insurance agents in the SME (Small and Medium-sized Enterprise) space, providing them with outsourced cyber broking expertise. Jeffrey is also involved in developing new insurance products, including potential personal liability protection for CISOs and other security professionals.