More Like This
-
Article
Mitigating Insider Threats: Managing Cyber Perils While Traveling Globally
-
Capability Overview
Cyber Resilience
One of the nuances of the cyber and errors and omissions insurance market is the lack of standardized policy forms. With the lack of a standard definition, the opportunity exists for policyholders to mold cover that is tailored to their business’s exposures. This landscape empowers risk buyers to negotiate a precise and clearly worded cyber and errors & omissions (E&O) policy. Current supply and market conditions are combining to make it an ideal time for customization in the cyber and E&O market. Here’s why:
The cyber and E&O market is favorable to buyers now but may become volatile over the next three to five years should loss frequency and severity continue to develop unfavorably in 2024. It is therefore especially important that buyers identify the right long-term insurer that understands their business risks and is willing to customize policy wording to address exposures and incident response strategies.
Article
Mitigating Insider Threats: Managing Cyber Perils While Traveling Globally
Capability Overview
Cyber Resilience
Complexity in the cyber and E&O market is only furthered by the dynamic appetites of cyber insurers and the constant evolution of technology risks. This results in regular changes to insuring agreements and exclusions. The market can often be a moving target. Yet, as daunting as it may seem, the prospects of negotiating a cyber or E&O policy that’s specifically geared to a business’s exposures are good. Buyers can enhance their chances for positive negotiations by following this advice:
Shaping cyber policy wording requires a collaborative discussion among key stakeholders as early as six months prior to renewal. This is critical because the team involved in evaluating exposures and loss scenarios will be large and varied.
The far-reaching consequences and intricacies surrounding technology risk require a team of colleagues that goes beyond risk management professionals. The team should include members of the cyber security and data privacy team, legal teams responsible for managing contracting, claims management and colleagues experienced with delivering business continuity plans.
Having the right insurance professionals to assist in crafting appropriate policy language and negotiating with the insurer is important. Outside counsel may also be brought in to focus on policy drafting and interpretation.
Policy language should be measured against the business and industry-specific exposures and loss or claim scenarios that are most concerning to the business. Identification of these scenarios, against which the policy wording will be tested, requires consideration of both frequency and severity of potential losses. This ensures that customization of the policy aligns with the organization’s risk appetite and risk management philosophy.
Similarly, policy exclusions must be critically analyzed to determine whether losses and desired covered claims could be excluded. With the breadth of coverage available under cyber and E&O policies, claims and losses are typically multifaceted with both first- and third-party components.
Other policy terms can be concerning to a business, including how business interruption losses will be calculated and presented. The base policy form often requires losses to be proven using a methodology that could be illogical or impossible for some organizations to navigate.
Decline in cyber premium rates in Q3 2023
Source: Aon data
In addition to the risk transfer value of the policy, E&O cover is often key to business facilitation for professional service companies. Customer contracts regularly are revised to include E&O insurance requirements that go beyond minimum required limits and include specific policy language requirements.
Three common examples include: an additional insured status for the customer, a waiver of the insurer’s rights of subrogation, and the service provider’s insurance being primary/non-contributory to any other insurance, including the customer’s. While E&O insurance policies can accommodate these requests, the policy language should remain aligned with the organization’s risk management philosophy and balance protecting the organization against facilitating business needs. Further:
“The base policy language in many E&O insurance policies may not strike the necessary balance and should be customized appropriately. Since this is different for every organization, it’s an area where collaboration between risk management, legal and business teams, alongside the insurance broker, is critical,” says Christopher Mee, Senior Vice President, E&O/Cyber Product Team, North America.
Cyber and E&O insurance policies provide a broad array of coverage designed to address the myriad losses associated with cyber incidents and professional service risks. These policies are not one-size-fits-all. They require a high degree of customization to ensure clarity and coverage when needed most.
Increase in ransomware attacks in Q3 2023
Source: Aon data
General Disclaimer
The information contained herein and the statements expressed are of a general nature and are not intended to address the circumstances of any particular individual or entity. Although we endeavor to provide accurate and timely information and use sources we consider reliable, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. No one should act on such information without appropriate professional advice after a thorough examination of the particular situation.
Terms of Use
The contents herein may not be reproduced, reused, reprinted or redistributed without the expressed written consent of Aon, unless otherwise authorized by Aon. To use information contained herein, please write to our team.
Our Better Being podcast series, hosted by Aon Chief Wellbeing Officer Rachel Fellowes, explores wellbeing strategies and resilience. This season we cover human sustainability, kindness in the workplace, how to measure wellbeing, managing grief and more.
Expert Views on Today's Risk Capital and Human Capital Issues
Expert Views on Today's Risk Capital and Human Capital Issues
Expert Views on Today's Risk Capital and Human Capital Issues
Better Decisions Across Interconnected Risk and People Issues.
The construction industry is under pressure from interconnected risks and notable macroeconomic developments. Learn how your organization can benefit from construction insurance and risk management.
Stay in the loop on today's most pressing cyber security matters.
Our Cyber Resilience collection gives you access to Aon’s latest insights on the evolving landscape of cyber threats and risk mitigation measures. Reach out to our experts to discuss how to make the right decisions to strengthen your organization’s cyber resilience.
Our Employee Wellbeing collection gives you access to the latest insights from Aon's human capital team. You can also reach out to the team at any time for assistance with your employee wellbeing needs.
Explore Aon's latest environmental social and governance (ESG) insights.
Our Global Insurance Market Insights highlight insurance market trends across pricing, capacity, underwriting, limits, deductibles and coverages.
Better Decisions Across Interconnected Risk and People Issues.
How do the top risks on business leaders’ minds differ by region and how can these risks be mitigated? Explore the regional results to learn more.
Trade, technology, weather and workforce stability are the central forces in today’s risk landscape.
These industry-specific articles explore the top risks, their underlying drivers and the actions leaders are taking to build resilience.
Our Human Capital Analytics collection gives you access to the latest insights from Aon's human capital team. Contact us to learn how Aon’s analytics capabilities helps organizations make better workforce decisions.
Read our collection of human capital articles that explore in depth hot topics for HR and risk professionals, including using data and analytics to measure total rewards programs, how HR and finance can better partner and the impact AI will have on the workforce.
Explore our hand-picked insights for human resources professionals.
Our Workforce Collection provides access to the latest insights from Aon’s Human Capital team on topics ranging from health and benefits, retirement and talent practices. You can reach out to our team at any time to learn how we can help address emerging workforce challenges.
Our Mergers and Acquisitions (M&A) collection gives you access to the latest insights from Aon's thought leaders to help dealmakers make better decisions. Explore our latest insights and reach out to the team at any time for assistance with transaction challenges and opportunities.
The challenges in adopting renewable energy are changing with technological advancements, increasing market competition and numerous financial support mechanisms. Learn how your organization can benefit from our renewables solutions.
How do businesses navigate their way through new forms of volatility and make decisions that protect and grow their organizations?
Our Parametric Insurance Collection provides ways your organization can benefit from this simple, straightforward and fast-paying risk transfer solution. Reach out to learn how we can help you make better decisions to manage your catastrophe exposures and near-term volatility.
Our Pay Transparency and Equity collection gives you access to the latest insights from Aon's human capital team on topics ranging from pay equity to diversity, equity and inclusion. Contact us to learn how we can help your organization address these issues.
Forecasters are predicting an extremely active 2024 Atlantic hurricane season. Take measures to build resilience to mitigate risk for hurricane-prone properties.