Insurance and enterprise: cyber insurance for ransomware

Author:

Baker TomORCID,Shortland Anja

Abstract

AbstractSelling insurance gives insurers an incentive to manage insured risks. The “insurance-as-governance” literature demonstrates that insurers often make insurance conditional on ex ante risk reduction or mitigation. But insurance governs in support of enterprise, not security for its own sake. Tight underwriting inhibits enterprise—not only for insured businesses but also for the business of insurance. This paper highlights ex post loss reduction as a form of insurance-based governance. Drawing on interviews with industry insiders, we explore how insurers addressed the evolving problems of moral hazard, uncertainty and correlated losses since the 1990s. We find that cyber insurance developed sophisticated remedies to contain liabilities and quickly restore affected IT systems, but largely left security decisions to the insured. This facilitated enterprise in the short run but undermined security in the longer term: funding and expediting ransom payments encourages further attacks. As businesses improved their resilience, cybercriminals adapted and ransoms escalated, calling insurability into question. Yet there remains little appetite for imposing restrictive conditionality in this highly competitive market. Instead, insurers have turned to governments to contain criminal threats and cushion catastrophic losses.

Publisher

Springer Science and Business Media LLC

Subject

Economics and Econometrics,Finance,General Business, Management and Accounting,Accounting

Reference67 articles.

1. Abraham, Kenneth S., and Daniel Schwarcz. 2021. Courting disaster: The underappreciated risk of cyber-insurance catastrophe. Connecticut Insurance Law Journal 27 (1): 51.

2. Abraham, Kenneth, and Daniel Schwarcz. 2023. The limits of regulation by insurance. Indiana Law Review 98. https://ssrn.com/abstract=4119812.

3. Arrow, Kenneth. 1963. Uncertainty and the welfare economics of medical care. American Economic Review 53: 943–971.

4. Avraham, Ronen, and Ariel Porat. 2022. The dark side of insurance. Working paper.

5. Baker, Tom. 2019. Back to the future of cyber insurance. PLUS Journal, Q3. https://scholarship.law.upenn.edu/faculty_scholarship/2184.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3