Insurance and enterprise: cyber insurance for ransomware

被引:0
|
作者
Tom Baker
Anja Shortland
机构
[1] University of Pennsylvania Carey Law School,
[2] Kings College London,undefined
关键词
Insurance; Ransomware; Governance;
D O I
暂无
中图分类号
学科分类号
摘要
Selling insurance gives insurers an incentive to manage insured risks. The “insurance-as-governance” literature demonstrates that insurers often make insurance conditional on ex ante risk reduction or mitigation. But insurance governs in support of enterprise, not security for its own sake. Tight underwriting inhibits enterprise—not only for insured businesses but also for the business of insurance. This paper highlights ex post loss reduction as a form of insurance-based governance. Drawing on interviews with industry insiders, we explore how insurers addressed the evolving problems of moral hazard, uncertainty and correlated losses since the 1990s. We find that cyber insurance developed sophisticated remedies to contain liabilities and quickly restore affected IT systems, but largely left security decisions to the insured. This facilitated enterprise in the short run but undermined security in the longer term: funding and expediting ransom payments encourages further attacks. As businesses improved their resilience, cybercriminals adapted and ransoms escalated, calling insurability into question. Yet there remains little appetite for imposing restrictive conditionality in this highly competitive market. Instead, insurers have turned to governments to contain criminal threats and cushion catastrophic losses.
引用
收藏
页码:275 / 299
页数:24
相关论文
共 50 条
  • [1] Insurance and enterprise: cyber insurance for ransomware
    Baker, Tom
    Shortland, Anja
    GENEVA PAPERS ON RISK AND INSURANCE-ISSUES AND PRACTICE, 2023, 48 (02): : 275 - 299
  • [2] RANSOMWARE: A DARWINIAN OPPORTUNITY FOR CYBER INSURANCE
    Kenneally, Erin
    CONNECTICUT INSURANCE LAW JOURNAL, 2021, 28 (01): : 165 - 195
  • [3] How cyber insurance influences the ransomware payment decision: theory and evidence
    Cartwright, Anna
    Cartwright, Edward
    MacColl, Jamie
    Mott, Gareth
    Turner, Sarah
    Sullivan, James
    Nurse, Jason R. C.
    GENEVA PAPERS ON RISK AND INSURANCE-ISSUES AND PRACTICE, 2023, 48 (02): : 300 - 331
  • [4] How cyber insurance influences the ransomware payment decision: theory and evidence
    Anna Cartwright
    Edward Cartwright
    Jamie MacColl
    Gareth Mott
    Sarah Turner
    James Sullivan
    Jason R. C. Nurse
    The Geneva Papers on Risk and Insurance - Issues and Practice, 2023, 48 : 300 - 331
  • [5] Between a rock and a hard(ening) place: Cyber insurance in the ransomware era
    Mott, Gareth
    Turner, Sarah
    Nurse, Jason R. C.
    MacColl, Jamie
    Sullivan, James
    Cartwright, Anna
    Cartwright, Edward
    COMPUTERS & SECURITY, 2023, 128
  • [6] A framework for cyber-risk insurance against ransomware: A mixed-method approach
    Mukhopadhyay, Arunabha
    Jain, Swati
    INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2024, 74
  • [7] THE CASE FOR BANNING (AND MANDATING) RANSOMWARE INSURANCE
    Logue, Kyle D.
    Shniderman, Adam B.
    CONNECTICUT INSURANCE LAW JOURNAL, 2021, 28 (01): : 247 - 316
  • [8] Cyber insurance offering and performance: an analysis of the US cyber insurance market
    Xie, Xiaoying
    Lee, Charles
    Eling, Martin
    GENEVA PAPERS ON RISK AND INSURANCE-ISSUES AND PRACTICE, 2020, 45 (04): : 690 - 736
  • [9] NEW CYBER INSURANCE
    不详
    MATERIALS EVALUATION, 2023, 81 (01) : 16 - 16
  • [10] NEW CYBER INSURANCE
    不详
    MATERIALS EVALUATION, 2022, 80 (12) : 77 - 77