UK insurers need to up their game on cyber gaps, says PRA

Gaps and limitations in how insurers respond to cyber risk need to be addressed, according to the Bank of England regulator, the Prudential Regulation Authority

Alex Scroxton

By

Published: 24 Jan 2023 16:30

The Bank of England regulator, the Prudential Regulation Authority (PRA), has highlighted a number of concerning gaps and limitations in how major insurers model and respond to cyber risk, after conducting a stress test of the sector.

The stress test exercise saw 17 general insurers and 21 Lloyd’s of London syndicates assess their solvency position against losses arising from cyber incidents. Participants provided an assessment of their ability to prevent, react and respond to cyber attacks.

“We note that cyber is an evolving peril, and consequently cyber coverage will continue to develop,” wrote Charlotte Garden, executive director of insurance supervision at the PRA. “This exercise has provided us with a wide range of current practices across the market, which will inform future supervision.”

It found that insurers struggled to ascertain the likelihood of cyber incidents – defined for the purposes of the test as ransomware attacks, data leaks and cloud computing outages – and tended to word their cyber policies too ambiguously.

It warned that current practices could lead to a “misestimation of scenario impacts for individual insurers”.

Among other things, the exercise found evidence of substantial variance in how insurers assessed risk, which is not necessarily out of the ordinary in a relatively youthful market, but needs to be addressed moving forward.

It also highlighted disparities in the ability of individual insurers and syndicates to identify the implications of contract uncertainty, with a number of parties unable to properly assess the potential impact should key exclusions – such as for nation state attacks – not hold. It warned of untested policy language and contractual uncertainty, and said boards needed to be made better aware of this problem.

The PRA further noted that the percentage of potential claims identified as arising from non-affirmative or silent cover – where policies are triggered following an incident but where cyber risks have not been explicitly included in them, or exclusionary language is ambiguous on the point – was reducing, which is in line with the guidance it previously issued.

Finally, it also noted that in general, insurance companies are still materially dependent on reinsurance to mitigate the impact of cyber incidents on their books.

Garden said that moving forward, the PRA would be on-hand to help insurance firms enhance their practices to manage and mitigate the potential damage arising from cyber incidents.

Achi Lewis, area vice-president for EMEA for Absolute Software, said: “Especially during periods of economic uncertainty, it is vital that organisations are aware of their cyber resilience, the likelihood of threats, and how to both prevent and respond to attacks.

“The PRA’s caution is important to prepare firms in the event of a worst-case outcome, with major cyber attacks the cause of significant downtime, data breaches and financial cost.

“Remediation from major attacks can prove costly, often resulting in weeks, months, or even years for a full investigation, restoration and legal procedures to take place, beyond the initial damage of the attack itself,” he said. “It is therefore essential that all organisations have cyber security as a top priority.”

Read more on IT risk management

Read More
Elroy Wrona

Latest

Want Your Music Featured on Netflix? Having a Major Label Helps

Music More Netflix blow-ups, please (Photo Credit: Yousafbhutta)Music Bagging...

Dhurandhar franchise re-writes film template as makers revise, review upcoming and existing films

Music SynopsisThe Dhurandhar franchise has redefined Hindi cinema. Its...

Mario Wonder’s ‘Meetup In Bellabel Park’ Soundtrack Has Been Added To Nintendo Music

MusicWonderful! by Liam Doolan Thu 26th Mar 2026Earlier...

Newsletter

Don't miss

Want Your Music Featured on Netflix? Having a Major Label Helps

Music More Netflix blow-ups, please (Photo Credit: Yousafbhutta)Music Bagging...

Dhurandhar franchise re-writes film template as makers revise, review upcoming and existing films

Music SynopsisThe Dhurandhar franchise has redefined Hindi cinema. Its...

Mario Wonder’s ‘Meetup In Bellabel Park’ Soundtrack Has Been Added To Nintendo Music

MusicWonderful! by Liam Doolan Thu 26th Mar 2026Earlier...

Kunlun Tech’s Mureka V8 Tops Global AI Music Model Rankings

Music Kunlun Tech’s Mureka V8 Tops Global AI Music...

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day

The Big Business of Carolyn Bessette-Kennedy

Can a nine-episode limited series really impact an entire season of shopping trends? Today brands are experiencing—and chasing—the “Carolyn Bessette-Kennedy effect” as a result of Ryan Murphy’s Love Story. And in many cases, it’s more pervasive than they could have prepared for. The FX series, based on the relationship between John F. Kennedy Jr. and

‘Mind Your Own Business’: Kamal Haasan Rebukes Trump Over ‘Permission’ To Buy Russian Oil

Updated 8 March 2026 at 18:20 IST Actor and Rajya Sabha MP Kamal Haasan has hit out at US President Donald Trump after America announced that it has given India temporary "permission" to buy Russian oil amid global supply disruptions caused by the Middle East conflict. 'Mind Your Own Business': Kamal Haasan Rebukes Trump Over