Aufsatz(elektronisch)4. Dezember 2022

Insurance and enterprise: cyber insurance for ransomware

In: The Geneva papers on risk and insurance - issues and practice, Band 48, Heft 2, S. 275-299

Verfügbarkeit an Ihrem Standort wird überprüft

Abstract

AbstractSelling insurance gives insurers an incentive to manage insured risks. The "insurance-as-governance" literature demonstrates that insurers often make insurance conditional on ex ante risk reduction or mitigation. But insurance governs in support of enterprise, not security for its own sake. Tight underwriting inhibits enterprise—not only for insured businesses but also for the business of insurance. This paper highlights ex post loss reduction as a form of insurance-based governance. Drawing on interviews with industry insiders, we explore how insurers addressed the evolving problems of moral hazard, uncertainty and correlated losses since the 1990s. We find that cyber insurance developed sophisticated remedies to contain liabilities and quickly restore affected IT systems, but largely left security decisions to the insured. This facilitated enterprise in the short run but undermined security in the longer term: funding and expediting ransom payments encourages further attacks. As businesses improved their resilience, cybercriminals adapted and ransoms escalated, calling insurability into question. Yet there remains little appetite for imposing restrictive conditionality in this highly competitive market. Instead, insurers have turned to governments to contain criminal threats and cushion catastrophic losses.

Sprachen

Englisch

Verlag

Springer Science and Business Media LLC

ISSN: 1468-0440

DOI

10.1057/s41288-022-00281-7

Problem melden

Wenn Sie Probleme mit dem Zugriff auf einen gefundenen Titel haben, können Sie sich über dieses Formular gern an uns wenden. Schreiben Sie uns hierüber auch gern, wenn Ihnen Fehler in der Titelanzeige aufgefallen sind.