TY - JOUR
T1 - On the insurability of cyber warfare
T2 - An investigation into the German cyber insurance market
AU - Cremer, Frank
AU - Sheehan, Barry
AU - Mullins, Martin
AU - Fortmann, Michael
AU - Ryan, Barry J.
AU - Materne, Stefan
N1 - Publisher Copyright:
© 2024 The Author(s)
PY - 2024/7
Y1 - 2024/7
N2 - Insurance is an important part of a constellation of institutions that assist in the provision of security, resilience and welfare. This is true across a range of threats, including those in the cyber domain. Cyber risks, particularly those associated with cyber warfare, present a considerable threat to the international economy and society owing to their inherent unpredictability and far-reaching consequences. These risks have the potential to impact security and cause significant economic losses, making them a critical concern for governments, businesses, and individuals alike. This research addresses the protection gap arising from cyber warfare exclusions in the context of cyber insurance. Furthermore, this study analyses the impact of war exclusion clauses on cyber insurance coverage during the Ukraine and Russia conflict. A mixed methods approach was employed, analyzing 44 cyber insurance policies in the German SME insurance market, and conducting interviews with 26 cyber insurance experts from various areas of the industry. It is found that insurers employ vaguely worded war exclusion clauses to restrict the scope of their policies. The study finds that such exclusionary provisions fail to account for emerging forms of warfare, including hybrid warfare and rapidly evolving cyber operations. The analysis provides practical solutions to address these challenges by highlighting the problems of the cyber war exclusion clause, demonstrating the perceptions and understanding of cyber insurers, and providing possible solutions to the insurability of cyber war risks. A well-functioning insurance market around cyber warfare would improve the resilience of nation-states in the face of such attacks. This paper provides important insights on the operation of this critical risk transfer market, based on the view of market participants.
AB - Insurance is an important part of a constellation of institutions that assist in the provision of security, resilience and welfare. This is true across a range of threats, including those in the cyber domain. Cyber risks, particularly those associated with cyber warfare, present a considerable threat to the international economy and society owing to their inherent unpredictability and far-reaching consequences. These risks have the potential to impact security and cause significant economic losses, making them a critical concern for governments, businesses, and individuals alike. This research addresses the protection gap arising from cyber warfare exclusions in the context of cyber insurance. Furthermore, this study analyses the impact of war exclusion clauses on cyber insurance coverage during the Ukraine and Russia conflict. A mixed methods approach was employed, analyzing 44 cyber insurance policies in the German SME insurance market, and conducting interviews with 26 cyber insurance experts from various areas of the industry. It is found that insurers employ vaguely worded war exclusion clauses to restrict the scope of their policies. The study finds that such exclusionary provisions fail to account for emerging forms of warfare, including hybrid warfare and rapidly evolving cyber operations. The analysis provides practical solutions to address these challenges by highlighting the problems of the cyber war exclusion clause, demonstrating the perceptions and understanding of cyber insurers, and providing possible solutions to the insurability of cyber war risks. A well-functioning insurance market around cyber warfare would improve the resilience of nation-states in the face of such attacks. This paper provides important insights on the operation of this critical risk transfer market, based on the view of market participants.
KW - Cyber insurance
KW - Cyber risk
KW - Cyber war risk
KW - Cyber warfare
KW - Cybersecurity
KW - Risk management
UR - http://www.scopus.com/inward/record.url?scp=85192306498&partnerID=8YFLogxK
U2 - 10.1016/j.cose.2024.103886
DO - 10.1016/j.cose.2024.103886
M3 - Review article
AN - SCOPUS:85192306498
SN - 0167-4048
VL - 142
JO - Computers and Security
JF - Computers and Security
M1 - 103886
ER -