TY - JOUR
T1 - Bridging the cyber protection gap
T2 - An investigation into the efficacy of the German cyber insurance market
AU - Cremer, Frank
AU - Sheehan, Barry
AU - Fortmann, Michael
AU - Mullins, Martin
AU - Murphy, Finbarr
AU - Materne, Stefan
N1 - Publisher Copyright:
© 2024 The Authors. Risk Management and Insurance Review published by Wiley Periodicals LLC on behalf of American Risk and Insurance Association.
PY - 2024/4/1
Y1 - 2024/4/1
N2 - Cybersecurity requires an effective risk transfer regime and a well-functioning insurance market to improve stakeholder resilience. However, rapid cyber threat adaptation, limited data availability, and inadequate risk understanding pose significant challenges for the insurance industry and its customers. This research uses a mixed methods approach to analyze the inclusions, exclusions, and suitability of current cyber policies in the German cyber insurance market. The study analyzes 41 cyber insurance policies, representing about 80% of the German cyber insurance market. This examination is supported by semistructured interviews with 23 cyber insurance experts. The authors find that there are no standardized cyber policy wordings, and insurers use different terms and definitions in their insurance policies. Specifically, the results show a significant lack of clarity around coverages and exclusions. This research contributes to the cybersecurity risk management community and will enable businesses, insurance companies, and policymakers to better understand, measure, and manage cyber risk.
AB - Cybersecurity requires an effective risk transfer regime and a well-functioning insurance market to improve stakeholder resilience. However, rapid cyber threat adaptation, limited data availability, and inadequate risk understanding pose significant challenges for the insurance industry and its customers. This research uses a mixed methods approach to analyze the inclusions, exclusions, and suitability of current cyber policies in the German cyber insurance market. The study analyzes 41 cyber insurance policies, representing about 80% of the German cyber insurance market. This examination is supported by semistructured interviews with 23 cyber insurance experts. The authors find that there are no standardized cyber policy wordings, and insurers use different terms and definitions in their insurance policies. Specifically, the results show a significant lack of clarity around coverages and exclusions. This research contributes to the cybersecurity risk management community and will enable businesses, insurance companies, and policymakers to better understand, measure, and manage cyber risk.
UR - http://www.scopus.com/inward/record.url?scp=85187182441&partnerID=8YFLogxK
U2 - 10.1111/rmir.12261
DO - 10.1111/rmir.12261
M3 - Article
AN - SCOPUS:85187182441
SN - 1098-1616
VL - 27
SP - 57
EP - 87
JO - Risk Management and Insurance Review
JF - Risk Management and Insurance Review
IS - 1
ER -