Five ways to reduce your cyber insurance premiums

Issue 6 2023 Security Services & Risk Management, News & Events

With the global costs of cybercrime expected to soar to $13 trillion within the next five years, cyber insurance is booming as organisations try to mitigate the risk of financial losses. Globally, the cyber insurance market is now worth around $17 billion and is expected to grow by over 26% a year to top $84.62 billion by 2030.

“Spiking rates of cybercrime and ever higher ransom demands have increased the risks of insurers having to make massive pay-outs,” notes Tony Walt, co-founder and Director of Cyber Security Software House Port443.

“As a result, insurers have become more stringent about the minimum security related requirements, and cyber insurance premiums are increasing. In the US alone, premiums rose by over 120% between 2020 and 2022,” he says. “Rising premiums simply add to the burden of organisations already grappling with economic headwinds and increasing risk. The good news is that many insurers now offer discounts on insurance premiums to customers who take steps to reduce their cyber risk and improve their security posture.”

Walt says local insurers reduce premiums for customers adopting these cybersecurity best practices:

1. Keep security controls up to date: ‘Set-and-forget’ is not enough to stay ahead of cyber risk. Organisations should maintain visibility and control across their security environment and should use automation to ensure controls are regularly validated, patched and updated.

2. Use encryption and Wi-Fi Protected Access (WPA): Encryption and secured access reduce the risk of data exposure or loss and strengthens compliance with legislation such as PoPIA. This, in turn, reduces your risk of having to pay a ransom, incurring penalties, or being targeted in lawsuits.

3. Use multi-factor authentication: “Multi-factor authentication goes a long way in addressing the ongoing challenge of weak or vulnerable passwords and ensures that only authorised users can access your network. This greatly reduces your exposure, so insurers feel comfortable reducing your premiums,” says Walt.

4. Have secure backups: Secure, regular and trusted backups of critical data is crucial to build business resilience and support continuity. “To insurers, this means you are at a lower risk of claiming for lost production or business hours in the event of a cyberattack, given the ability to recover as a result of these backups.”

5. Have clear security policies, incident response processes and implement training and awareness programmes: Humans are the weakest link in cyber defence, with human error accounting for the bulk of cyber breaches. Clear and up-to-date cyber security policies and incident response plans must be drafted, implemented, tested and made readily available to all staff, and ongoing training and awareness programmes must be implemented. This could significantly reduce your risk profile and reduce your risk for cyber insurers.

Walt concludes, “Reducing your premiums is just one way to address the costs of cyber risk. The biggest costs associated with cybercrime are the losses suffered in ransoms, downtime, fines, legal costs and reputational damage. Applying cyber security best practices could help organisations avoid those costs altogether.”


Examples of discounts on premiums:

https://www.discovery.co.za/assets/discoverycoza/business-insurance/cyber-cover.pdf

https://www.santam.co.za/blog/business-advice/cyber-security-for-your-business/

https://satib.co.za/working-home-cyber-insurance-now-must/




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Risk management and compliance enforcement
Security Services & Risk Management
Having a risk management and compliance programme (RMCP) is not just a procedural formality; it is a legal requirement under Section 42 of the Financial Intelligence Centre Act (FICA).

Read more...
The dangers of poor-quality solar cables
Security Services & Risk Management Smart Home Automation
Reports indicate that one in six fires attended by South African firefighters is linked to substandard solar installations, often due to faulty wiring or incompatible components.

Read more...
Growing risks for employers
Security Services & Risk Management
With South Africa’s unemployment rate exceeding 32% and expected to rise beyond 33% this year, desperation is fuelling deception in the job market. Trust is no longer a given, it is a gamble.

Read more...
Chubbsafes celebrates 190 years
Gunnebo Safe Storage Africa News & Events Security Services & Risk Management
Chubbsafes marks its 190th anniversary in 2025 and as a highlight of the anniversary celebrations it is launching the Chubbsafes 1835, a limited edition 190th-anniversary collector’s safe.

Read more...
New law enforcement request portal
News & Events Security Services & Risk Management
inDrive launches law enforcement request portal in South Africa to support safety investigations. New portal allows authorised South African law enforcement officials to securely request user data related to safety incidents.

Read more...
Continuous AML risk monitoring
Access Control & Identity Management Security Services & Risk Management Financial (Industry)
AU10TIX, launched continuous risk monitoring as part of its advanced anti-money laundering (AML) solution, empowering businesses to detect behavioural anomalies and emerging threats as they arise.

Read more...
Growing risks for employers
Security Services & Risk Management
With South Africa’s unemployment rate exceeding 32% and expected to rise beyond 33% this year, desperation is fuelling deception in the job market. Trust is no longer a given, it’s a gamble.

Read more...
Managing mining physical security risks
Zulu Consulting Security Services & Risk Management Mining (Industry) Facilities & Building Management
[Sponsored] Risk-IO, a web app from Zulu Consulting, is designed to assist risk managers in automating and streamlining enterprise risk management processes, ensuring no steps are skipped and everything is securely documented.

Read more...
The rise of AI-powered cybercrime and defence
Information Security News & Events AI & Data Analytics
Check Point Software Technologies launched its inaugural AI Security Report, offering an in-depth exploration of how cybercriminals are weaponising artificial intelligence (AI), alongside strategic insights defenders need to stay ahead.

Read more...