Cyber claims: crisis & claims managment
April 2019
Jean Bayon de la Tour
Cyber Development Leader
FINPRO | Continental Europe
MARSH
Agenda
1
Section 1 What is cyber insurance ?
Section 2 Overview of claims handled by Marsh
Section 3 Key learnings
Section 4 How/when to use cyber insurance ?
Section 5 Business cases
Conclusion
MARSH 2 23 April 2019
Section 1
What is cyber insurance ?
MARSH
Operational impact
3
What is Cyber Risk?
Reminder
YOUR IT SYSTEM / DATA
(insourced or outsourced)
Accidental Event Malicious Attacks
t
Confidentiality
(including Privacy)
Integrity Availability and/or and/or
3
rd
Party Liability Loss of Turnover Additional Costs
Financial Impact
MARSH 4
What Can be Covered Through Cyber Insurance?
24/7/365 hotline
IT experts
Legal experts
Communication crisis
Cyberextortion experts
Loss of Turnover
Costs & Expenses
Third Party Claims
Training /
sensibilization
Identify your
vulnerabilities
Crisis management
exercise
Prevention
Assistance
Malicious acts
on the IT system
Breach of
personal data
Accidental event
on the IT system
Indemnification
5 23 April 2019
Section 2
Overview of claims handled by Marsh
MARSH
Feedback
Quick overview
6
Typology
of claims
DDOS/Ransomware
Ransomware
Targeted internal attacks
Data loss
Main coverages
triggered
60% Assistance
100% First party
25% Civil liability
State of play
in 2018
60 + losses handled by
Marsh Europe
Number of losses
increasing faster than
the Cyber book
> 75% of cyber claims
are malicious attacks
MARSH
Focus Marsh France: 47 cyber claims since 2016
7
2016 2017 2018 2019
Year of
declaration
2 5 25 15
Paid Closed without
payment
Ongoing
Status 8 9 30
Accidental Malicious
Type 9 38
MAJ 10 Avril 2019
MARSH 8 23 April 2019
Section 3
Key learnings
MARSH
Feedback
Marsh key learnings
9 23 April 2019
Claims management
(after the cyber crisis)
Crisis
management
Marsh cyber
Claims team
Tested
broker
wording
Loss assessor
FAS
Assistance
(during cyber crisis)
Prevention
(before the event)
For Marsh
Training
your
employees
about
phishing
&
password
Performing
crisis
management
exercises
on a
regular
basis
Be prepared to work in
project mode with
many stakeholders
For Clients
Qualitative
assessment
of insurers
Qualitative
assessment
of the assistance
Claims feedback /
recommendation
from the broker
Assistance from
broker to write your
cyber claims process
MARSH 10 23 April 2019
Who in the crisis management team ?
Client
-CISO
-RM/insurance
-General counsel
-CFO
Consultants
-IT/Forensics
-Legal
-PR/Communication
-…
Broker
Insurer
Loss adjuster
Loss assessor
Other expert (IT ?)
(rebuilding phase)
Who is the boss ?
MARSH 11 23 April 2019
Section 4
How/when to use cyber insurance
MARSH 12 23 April 2019
How can my cyber policy help ?
Expiry
date
Discovery of a IT event (actual or alleged)
OR
Claim first made
Insurance
cover
Inception
date
Insurance
cover
Crisis
AND/ OR
Claims managment
Assistance
cover
LOCAL
EXPERTS
THROUGH
CALL CENTER
OR
NO PRIOR WRITTEN CONSENT
FORMAL CLAIMS NOTIFICATION
MARSH 13 23 April 2019
When should I trigger the assistance ?
You need more
advice ?
You need more
ressource ?
MARSH
Cyber claim management process
Scenario 1: IT System unavailable or disrupted
Crisis management - Support & Emergency measures
–Internal or external Cyber Security and/or IT specialists to: analyse the attack, its origins and
consequences. Limit or contain its impact.
–Crisis management or communication consultants
14 23 April 2019
Claim declaration and appointment of loss adjuster by the insurer / loss assessor by the client
System recovery and data recovery
Consolidating fees and losses, preparing the valuation of the claim
Can take several weeks depending on the extent of the attack
Assessment of the claim, reviewing the coverage
Can take several weeks depending on the number of supporting evidence to be provided
Advance payment if necessary
Definitive costing and indemnity proposal
Settlement/ Payment of the claim
MARSH
Cyber claim management process
Scenario 2: Privacy breach
Crisis management - Support & Emergency measures
–Cyber Security Consultants to: analyse the attack, its origins and consequences, assessment of the
extent of data disclosure
–Crisis management and/or communication consultants
–Lawyers: legal assistance in relation to legal obligations and steps to be taken
15 23 April 2019
Claim declaration and appointment of loss adjuster by the insurer
Precise identification of diverted personal data. Exhaustive list of persons and their nationality.
Additional declaration to the CNIL.
Preliminary declaration to the CNIL (In France)
Individual notifications depending on the nature of the personal data and nationality
Consolidating fees and losses, waiting for third party claims, preparing the valuation of the
claim
Assessment of the claim – reviewing the coverage
Advance payment if necessary
Definitive costing and indemnity proposal
Settlement/ Payment of the claim
16 23 April 2019
Section 5
Business cases
MARSH 17
Focus on Mondelez & DLA Piper cases
1
st
party 3
rd
party
Tangible
PD/BI
Cyber
CGL
Pure financial
loss
Tangible
Crime
Cyber
peril
•Property vs cyber standalone
•US law vs French law
•Marsh position paper: https://www.marsh.com/us/insights/research/notpetya-was-not-
cyber-war.html
MARSH
Business cases
Maersk (container ship operator) – Denmark – Ransomware (NotPetya)
18 23 April 2019
Consequences
Causes
“We only had
a 20% drop in volume,
so we managed 80%
of that volume manually”
“The damages caused by
NotPetya estimated between $250
and $300 million” *
“We had to reinstall
an entire infrastructure”
“It took ten days”
“We had to install
4,000 new servers, 45,000 new
PCs, 2,500 applications” *
Diagram Comments
* Source: Maersk Chairman, Jim Hagemann Snabe @ Davos Forum (link)
Accidental Event Malicious Attacks
Financial Impact
IT system & data
(insourced or outsourced)
Integrity Availability
Confidentiality
(incl. privacy)
and/or and/or
Loss of turnover
Increased cost of working
Additional costs
Costs to help & evaluation
Third party claims
Insurance & Assistance
External
expert
costs
and/or
MARSH
Business cases
British Airways (airline) – United Kingdom – Data breach
19 23 April 2019
Consequences
Causes
Violations may lead to fines* of as
much as 4% of a company’s
annual sales, which could reach
about £489 million (US$633
million) based on 2017 figures
“Very sophisticated, malicious
criminal attack”
Alex Cruz, British Airways Chief
Executive
Regulatory & communication
impact
~ 380,000 payment cards
information exposed
Diagram Comments
Source: British Airways (link) & Insurance Business Mag (link) * Insurability of GDPR fines is subject to national regulations.
Accidental Event Malicious Attacks
Financial Impact
IT system & data
(insourced or outsourced)
Integrity Availability
Confidentiality
(incl. privacy)
and/or and/or
Loss of turnover
Increased cost of working
Additional costs
Costs to help & evaluation
Third party claims
Insurance & Assistance
External
expert
costs
and/or
MARSH
Business cases
Marriott (hospitality) – United States – Data breach
20 23 April 2019
Consequences
Causes
Marriott’s share price fell around
5% the day after the attack
The insurable loss could rise to as
much as $600 million
Marriott could potentially spend
about $1 per customer notifying
victims and providing free data
monitoring services
The attack began 4 years back and
left the personal data of 500
million guests exposed
Hackers accessed payment card
numbers, passport numbers,
emails & mailing addresses
Diagram Comments
Accidental Event Malicious Attacks
Financial Impact
IT system & data
(insourced or outsourced)
Integrity Availability
Confidentiality
(incl. privacy)
and/or and/or
Loss of turnover
Increased cost of working
Additional costs
Costs to help & evaluation
Third party claims
Insurance & Assistance
External
expert
costs
and/or
Source: AIR Worldwide (link), GDPR report (link) & Bloomberg (link)
MARSH
Business cases
O2 (telecommunication) – United Kingdom – Business interruption
21 23 April 2019
Consequences
Causes
O2 (30m customers) is seeking up
to £100m compensation from
Ericsson for business interruption
and supply chain failure caused by
its software
O2 customers will get a 10%
discount
O2 sued its technology supplier
Ericsson after a disastrous
software failure that cut
customers off from the internet
between December 6 - 7
Diagram Comments
Accidental Event Malicious Attacks
Financial Impact
IT system & data
(insourced or outsourced)
Integrity Availability
Confidentiality
(incl. privacy)
and/or and/or
Loss of turnover
Increased cost of working
Additional costs
Costs to help & evaluation
Third party claims
Insurance & Assistance
External
expert
costs
and/or
Source: The Telegraph (link)
MARSH
Business cases
Norsk Hydro (aluminum producers) – Norway – Business interruption
22 23 April 2019
Consequences
Causes
Hydro has allocated all available
internal and external resources to
make further progress in securing
safe and stable operations across
the company.
31-36M€ total costs for the first
week
“The malicious virus attack caused
many of Hydro’s IT-systems to be
shut down, not because they were
infected but to contain the virus and
prevent it from spreading further.”
Diagram Comments
Accidental Event Malicious Attacks
Financial Impact
IT system & data
(insourced or outsourced)
Integrity Availability
Confidentiality
(incl. privacy)
and/or and/or
Loss of turnover
Increased cost of working
Additional costs
Costs to help & evaluation
Third party claims
Insurance & Assistance
External
expert
costs
and/or
Source: Press – Norsk Hydro (link)
23 23 April 2019
CONCLUSION
MARSH 24 23 April 2019
CYBER CLAIMS TEAM FAS : LOSS ASSESSORS
A specialized and
internal team
composed of financial
experts
In Marsh France: 4 advocates
(Liability, PDBI & Financial Lines
background)
Close
collaboratio
n between
teams
Conclusion
After crisis, it is time for claims management
Expiry
date
Discovery of a IT event (actual or alleged)
OR
Claim first made
Inception
date
Crisis Claims managment
Claims managment
This document and any recommendations, analysis, or advice provided by Marsh (collectively, the “Marsh Analysis”) are intended solely for the entity identified as the
recipient herein (“you”). This document contains proprietary, confidential information of Marsh and may not be shared with any third party, including other insurance
producers, without Marsh’s prior written consent. Any statements concerning actuarial, tax, accounting, or legal matters are based solely on our experience as insurance
brokers and risk consultants and are not to be relied upon as actuarial, accounting, tax, or legal advice, for which you should consult your own professional advisors.
Any modeling, analytics, or projections are subject to inherent uncertainty, and the Marsh Analysis could be materially affected if any underlying assumptions,
conditions, information, or factors are inaccurate or incomplete or should change. The information contained herein is based on sources we believe reliable, but we
make no representation or warranty as to its accuracy. Except as may be set forth in an agreement between you and Marsh, Marsh shall have no obligation to update
the Marsh Analysis and shall have no liability to you or any other party with regard to the Marsh Analysis or to any services provided by a third party to you or Marsh.
Marsh makes no representation or warranty concerning the application of policy wordings or the financial condition or solvency of insurers or reinsurers. Marsh makes
no assurances regarding the availability, cost, or terms of insurance coverage.
Cyber claims : crisis & claims management - Marsh - Avril 2019
Cyber claims : crisis & claims management - Marsh - Avril 2019