Beinsure Media ⭐ Insurance & InsurTech Insights

6 Steps to Customize Cyber and E&O Insurance Contracts

6 Steps How to Customize Cyber and E&O Insurance Contracts

The non-standardized nature of cyber insurance and E&O insurance policy wording creates the opportunity to mold an individually tailored and responsive risk transfer tool.

One of the nuances of the cyber and errors and omissions insurance market is the lack of standardized policy forms. With the lack of a standard definition, the opportunity exists for policyholders to mold cover that is tailored to their business’s exposures, according to Aon’s report “Why Now is the Right Time to Customize Cyber and E&O Contracts”.

This landscape empowers risk buyers to negotiate a precise and clearly worded cyber and errors & omissions (E&O) policy.

Current supply and market conditions are combining to make it an ideal time for customization in the cyber and E&O market.

According to Aon’s Global Risk Management Survey, cyber attacks and data breaches continue to be the number one risk facing organizations globally. Even further, they are predicted to stay on top for the next three years, as costs of single data breaches reach all-time highs and ransomware attacks return with a vengeance.

Ransomware attacks rose 203% and cyber premium rates declined by 17 percent in Q3 2023, extending trends in each for a third consecutive quarter.

Overall buyer-friendly cyber market conditions have continued through Q3 2023, with greater competition and more capacity available (see Cybersecurity Spending Trends).

The Aon report emphasizes the current market opportunity for policyholders to tailor their cyber and Errors & Omissions (E&O) coverages to better fit their specific risk needs.

The key takeaways from the report:

  1. Non-Standardized Policy Wording: Unlike other policies with standardized wording, cyber and E&O forms present a unique opportunity for variance in policy wording, allowing for more tailored risk transfer tools.
  2. Favorable Market Conditions: Current market conditions are more favorable compared to recent years, making it an ideal time for organizations, with the help of their counsel, to customize their cyber and E&O policies.
  3. Early Start and Right Team: The report advises starting the policy negotiation process early, at least six months prior to renewal, and forming a comprehensive team that includes not just risk management professionals but also cybersecurity, data privacy teams, and legal experts.
  4. Cyber Risk Landscape: The report notes that cyber attacks and data breaches remain the top risk globally, with ransomware attacks and cyber premium rates showing significant trends in recent years.
  5. Customization Approach: Businesses are encouraged to analyze their specific industry and business risks to tailor policy language effectively. This includes a close examination of policy exclusions and managing terms like business interruption.
  6. E&O Coverage Points: For professional service companies, E&O cover is critical for business facilitation. The report suggests ensuring E&O policies address both risk transfer and business goals, including specific policy language requirements often demanded in customer contracts.
  7. Long-Term Partnerships with Insurers: Identifying insurers that understand an organization’s business risks and are willing to customize policy wording is crucial, especially considering the potential volatility in the market in the coming years.
  8. Rising Privacy Concerns: There is an increasing underwriting scrutiny around privacy exposures and data collection, including new regulations, which businesses need to consider in their policy customizations.

The report Challenges for Cyber Insurance Market’s Growth Potential concludes that given the dynamic nature of cyber risks and the evolving technology landscape, a high degree of customization in cyber and E&O policies is essential to ensure clarity and adequate coverage when it is most needed.

Randomsware frequency & cyber premium rates

Source: Aon

The cyber and E&O market is favorable to buyers now but may become volatile over the next three to five years should loss frequency and severity continue to develop unfavorably in 2024.

It is therefore especially important that buyers identify the right long-term insurer that understands their business risks and is willing to customize policy wording to address exposures and incident response strategies.

Systemic risk remains a top concern for insurers. Carriers continue to evaluate, scrutinize and, in some instances, restrict coverage offered for critical infrastructure, systemic or correlated events, supply chain and other critical third-party dependencies, and war.

Privacy-related losses are mounting and becoming more severe as well. Underwriting scrutiny related to privacy exposures and data collection, including biometric information, pixel tracking, and new privacy and consumer protection regulations is increasing (see how Cyber Insurance Market Dynamics Changed Significantly).

Steps Toward Creating a Customized Cyber and E&O Policy

Complexity in the cyber and E&O market is only furthered by the dynamic appetites of cyber insurers and the constant evolution of technology risks. This results in regular changes to insuring agreements and exclusions.

The market can often be a moving target. Yet, as daunting as it may seem, the prospects of negotiating a cyber or E&O policy that’s specifically geared to a business’s exposures are good.

Buyers can enhance their chances for positive negotiations by following this advice:

Consider These E&O Insurance Coverage Points

In addition to the risk transfer value of the policy, E&O cover is often key to business facilitation for professional service companies. Customer contracts regularly are revised to include E&O insurance requirements that go beyond minimum required limits and include specific policy language requirements.

Three common examples include: an additional insured status for the customer, a waiver of the insurer’s rights of subrogation, and the service provider’s insurance being primary/non-contributory to any other insurance, including the customer’s.

While E&O insurance policies can accommodate these requests, the policy language should remain aligned with the organization’s risk management philosophy and balance protecting the organization against facilitating business needs.

Further:

The base policy language in many E&O insurance policies may not strike the necessary balance and should be customized appropriately. Since this is different for every organization, it’s an area where collaboration between risk management, legal and business teams, alongside the insurance broker, is critical

Christopher Mee, Senior Vice President, E&O/Cyber Product Team, North America

Cyber and E&O insurance policies provide a broad array of coverage designed to address the myriad losses associated with cyber incidents and professional service risks. These policies are not one-size-fits-all.

They require a high degree of customization to ensure clarity and coverage when needed most.

……………………

AUTHORS: Darin McMullen – E&O/Cyber Product Leader, Cyber Solutions, North America, Christopher Mee – Senior Vice President, E&O/Cyber Product Team, Cyber Solutions, North America, Pablo Constenla – Head of Cyber Coverage & Claims, Cyber Solutions, EMEA, Helen Chapman – Head of Coverage and Insurable Risk – Specialty Products, Global Broking Center and UK Commercial Risk, Dan Screene – Head of Cyber Coverage, Global Broking Center and UK Commercial Risk

Exit mobile version