UK insurers need to up their game on cyber gaps, says PRA

Gaps and limitations in how insurers respond to cyber risk need to be addressed, according to the Bank of England regulator, the Prudential Regulation Authority

Alex Scroxton

By

Published: 24 Jan 2023 16:30

The Bank of England regulator, the Prudential Regulation Authority (PRA), has highlighted a number of concerning gaps and limitations in how major insurers model and respond to cyber risk, after conducting a stress test of the sector.

The stress test exercise saw 17 general insurers and 21 Lloyd’s of London syndicates assess their solvency position against losses arising from cyber incidents. Participants provided an assessment of their ability to prevent, react and respond to cyber attacks.

“We note that cyber is an evolving peril, and consequently cyber coverage will continue to develop,” wrote Charlotte Garden, executive director of insurance supervision at the PRA. “This exercise has provided us with a wide range of current practices across the market, which will inform future supervision.”

It found that insurers struggled to ascertain the likelihood of cyber incidents – defined for the purposes of the test as ransomware attacks, data leaks and cloud computing outages – and tended to word their cyber policies too ambiguously.

It warned that current practices could lead to a “misestimation of scenario impacts for individual insurers”.

Among other things, the exercise found evidence of substantial variance in how insurers assessed risk, which is not necessarily out of the ordinary in a relatively youthful market, but needs to be addressed moving forward.

It also highlighted disparities in the ability of individual insurers and syndicates to identify the implications of contract uncertainty, with a number of parties unable to properly assess the potential impact should key exclusions – such as for nation state attacks – not hold. It warned of untested policy language and contractual uncertainty, and said boards needed to be made better aware of this problem.

The PRA further noted that the percentage of potential claims identified as arising from non-affirmative or silent cover – where policies are triggered following an incident but where cyber risks have not been explicitly included in them, or exclusionary language is ambiguous on the point – was reducing, which is in line with the guidance it previously issued.

Finally, it also noted that in general, insurance companies are still materially dependent on reinsurance to mitigate the impact of cyber incidents on their books.

Garden said that moving forward, the PRA would be on-hand to help insurance firms enhance their practices to manage and mitigate the potential damage arising from cyber incidents.

Achi Lewis, area vice-president for EMEA for Absolute Software, said: “Especially during periods of economic uncertainty, it is vital that organisations are aware of their cyber resilience, the likelihood of threats, and how to both prevent and respond to attacks.

“The PRA’s caution is important to prepare firms in the event of a worst-case outcome, with major cyber attacks the cause of significant downtime, data breaches and financial cost.

“Remediation from major attacks can prove costly, often resulting in weeks, months, or even years for a full investigation, restoration and legal procedures to take place, beyond the initial damage of the attack itself,” he said. “It is therefore essential that all organisations have cyber security as a top priority.”

Read more on IT risk management

Read More
Elroy Wrona

Latest

FCS Draft Surge: The Rise of Small-School Prospects in Modern NFL Conversations

FCS Draft Surge: The Rise of Small-School Prospects in Modern NFL Conversations Every spring, draft chatter once focused almost entirely on blue-blood programs such as Alabama or Ohio State. Today that narrative feels outdated. Championship rosters increasingly feature players who sharpened skills on modest Football Championship Subdivision (FCS) fields, developing technique rather than basking in

Two Trap Games that Georgia Tech Football Cannot Overlook This Season

While Georgia Tech Football did not face its usual gauntlet of a schedule last season, the Yellow Jackets are no strangers to playing tough schedules, usually among the toughest in the country. Georgia Tech is going to be playing 11 power conference opponents this season, with eight ACC opponents and a non-conference schedule that includes

“I cannot divorce the two”: How Star Wars is blending technology, creativity, and products into the experience itself

(Image credit: Disney) “It’s like a community, right? And it’s a global community that people really love and identify with.” That’s how Bobby Kim, Global Creative Director at Disney Consumer Products, describes Star Wars fandom. And it’s a framing that feels especially fitting as another May the 4th is behind us and we’re weeks out

Trump administration defends right to ban content moderation experts from US

The Trump administration is fighting for the right to keep some social media moderation advocates out of the US. On Wednesday, US District Court Judge James Boasberg heard arguments in a lawsuit between the nonprofit Coalition for Independent Technology Research (CITR) and Secretary of State Marco Rubio and other Trump administration officials. The suit concerns

Newsletter

Don't miss

FCS Draft Surge: The Rise of Small-School Prospects in Modern NFL Conversations

FCS Draft Surge: The Rise of Small-School Prospects in Modern NFL Conversations Every spring, draft chatter once focused almost entirely on blue-blood programs such as Alabama or Ohio State. Today that narrative feels outdated. Championship rosters increasingly feature players who sharpened skills on modest Football Championship Subdivision (FCS) fields, developing technique rather than basking in

Two Trap Games that Georgia Tech Football Cannot Overlook This Season

While Georgia Tech Football did not face its usual gauntlet of a schedule last season, the Yellow Jackets are no strangers to playing tough schedules, usually among the toughest in the country. Georgia Tech is going to be playing 11 power conference opponents this season, with eight ACC opponents and a non-conference schedule that includes

“I cannot divorce the two”: How Star Wars is blending technology, creativity, and products into the experience itself

(Image credit: Disney) “It’s like a community, right? And it’s a global community that people really love and identify with.” That’s how Bobby Kim, Global Creative Director at Disney Consumer Products, describes Star Wars fandom. And it’s a framing that feels especially fitting as another May the 4th is behind us and we’re weeks out

Trump administration defends right to ban content moderation experts from US

The Trump administration is fighting for the right to keep some social media moderation advocates out of the US. On Wednesday, US District Court Judge James Boasberg heard arguments in a lawsuit between the nonprofit Coalition for Independent Technology Research (CITR) and Secretary of State Marco Rubio and other Trump administration officials. The suit concerns

Apple’s 2028 iPhone display sounds impossible, but Samsung and LG are scrambling to build it

Android phones have had curved displays for years and accepted the distortion as the price of aesthetics. Apple is spending two years and billions of supplier dollars to not accept it. Apple's all-screen iPhone 20 mockup Ice Universe / X Apple doesn’t ask its suppliers to build things. It tells them to, hands them a

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand

Getting a business loan now comes with a frequent flyer upside

Australian fintech Prospa has partnered with Qantas Business Rewards, letting eligible SMEs earn up to 500,000 points per loan. What’s happening: Australian fintech lender Prospa has partnered with Qantas Business Rewards to allow eligible small and medium business owners to earn up to 500,000 Qantas Points per loan when taking out a Prospa Small Business