Transcript
I hope you have been enjoying the conference so far. You got a chance to reconnect with some old friends and make some new connections. Today we have three experts here joining me on stage. We have an important topic to discuss. It's all about cyber insurance and how identity security is really impacting that landscape. So let's do a quick round of introduction. Thanks Wendy for inviting and everyone for joining. Soumya Banerjee, associate partner at McKinsey, part of the cyber risk practice. Hi, I'm Jay Bhakti. I'm a senior managing director at Aon Cyber Solutions. Hi I'm Gautam Sehgal. I'm a partner at PwC, cyber risk and regulatory practice. So before we get started, we actually have a question for all of you guys. How many of you have some form of cyber insurance in your current organization? Raise your hand if you do. I see quite a few hands up. Now keep that hand up if that insurance is dedicated to manage your cyber risks but not part of a general insurance policy. Still quite a few hands. Yeah, thank you. So that is not surprising to us. We have data from McKinsey that actually showed 90% of the companies in North America have some form of cyber insurance. They purchased that and that coverage rate is very high. As we heard this morning from our keynote speakers, cyber attacks are becoming more complex and it's becoming more frequent. These global disruptions are really pushing the organizations to reassess their cyber insurance coverage to make sure they're properly covered. While at the same time, cyber insurance companies and brokers, they're also tightening up their policies and they're putting in place much more strict requirements. So that's what we're going to discuss today here. Let's get started. So all three of you represent the top expertise in our industry, whether it's strategy consulting or insurance broker or a technology consultant. Tell us how you see cyber threat landscape evolving and how cyber insurance is evolving in response to the threats and challenges we're seeing today. Sure. Happy to, Wendy. In order to understand where we're at today from a cyber threat landscape, I want to take you back memory lane a few years ago. I realize it's probably a memory we don't want to have, but it's important to understand what got us to this point that we're in today and where we'll likely precipitate here in the upcoming months. Back in 2019, I think everyone remembers in quarter three, quarter four, COVID-19 and the pandemic changed our lives professionally and personally. And what we saw in the corporate landscape is that organizations were lifting and shifting their entire workforces or making significant changes in their environments to accommodate the new way of working. We saw organizations, and I suspect that some of you went through this, where you were having to scale and embrace new technologies that you did not feel comfortable embracing at first but had to because of the urgency to get things up and running. Well, again, if I have you go back memory lane, technology functionality was at the forefront of that and security was not always contemplated in those decisions. And what we saw was in 2020, in 2021, in 2022, the amount of cyber incident activity was off the chain. Ransomware attacks were up. The adversaries found a wonderful opportunity to be able to capitalize on all these environments that were ridden with problems and vulnerabilities, take advantage of that and cause the damage that they did. Well, the insurance markets were not, you know, their premium costing to their clients or what have you was not commensurate with the losses that they were sustaining as a result of the incident response activity. And so what do they do? They said, hold up, wait a minute, this is not okay. We are not going to continue to sustain these losses and not have organizations have a fair shake and a fair investment into their information security posture. And so as a result, they came up with 12 control families that they were really, really laser focused on after talking to the top tier incident response firms and what have you to understand what would have the best impact in mitigating the risk of something bad happening. They, you know, they came up with 12 controls. And so where they're at right now is really focusing on those control families to ensure that organizations are doing what they can to mitigate risk. And then to add on to that, where we're at today, you know, the adversaries, you know, because they're always evolving their TTPs and things of that nature, they have found ways to circumvent the very controls that we have spent the last few years investing in. And so as a result, what we see today is very sophisticated TTPs, very sophisticated ways of attacking. And for those organizations that don't have awareness of what's going on, they're going to be in a world of trouble. Yeah. Maybe, Jay, to add to that, I think we see the cyber insurance as almost an inflection point in the market right now to, you know, to augment your point around insurance carriers getting smarter. Some of the third party like research data around this we saw was they were able to reduce the loss ratio by 46% when it came to cyber insurance. What that means is carriers are getting much more smarter in the way they're assessing the risk and associating the cyber premium to that. And that could be, you know, not paying ransomware the way they were able to cover it in the past, or not covering the operational loss in the way they used to do in the past. Or premium-wise, they are assessing the risk in a much more better way to hike up the premium that they're charging. The other side of it, and especially, you know, some of the global outages recently have created a lot of conversations that we see top-down from the board and the CEO level asking, you know, what is the resilient strategy and how can I transfer risk in that resilient strategy to insurance, particularly when it comes to cyber insurance? So, there's a momentum growing, you know, not just, you know, the general insurance that covers cyber, but in particular, how do I cover my cyber and operational disruption risk associated with that? Both of that combined is creating this whole question around, you know, where does cyber insurance go from there, and what role do these capabilities need to play? So, I think accordingly, the regulatory landscape is also catching up, and we are seeing that across the spectrum of different regulators across industry, they are making recommendations of having cyber insurance as part of your broader cybersecurity strategy and as part of the portfolio, specifically thinking of financial services, there's NYDFS 500 that has inclusion of it, SEC, FFIEC has guidance on healthcare side, HIPAA has guidances around, we're seeing Federal Trade Commission calling out FTC guidance state and local regulations also calling for the need for having cyber insurance as part of your enterprise security portfolio. Yeah, so clearly, the threats are now slowing down, there are more policy requirements coming, and it's just clear that cyber insurance is becoming a much bigger part in how we manage the overall risks. So, let's take a moment to focus on the role that identity security plays in managing all of this. So, all of us in the room here are identity security leaders. What is the vital role that identity security plays in terms of how we help shape the insurance coverage and its effectiveness? Yeah, and one way to look at it, so this year with our Identity Horizon study, when we asked this particular question around, let's list up all the major cybersecurity controls, from identity network, endpoint, et cetera, and ask what are the top three ones that would impact your cyber insurance premium, which by the way, one of the other questions was, is it increasing or not? And it has been significantly increasing in the last three, four years, right? And 73% of the respondents talked about that identity security was one of the top three areas that impacted their cyber insurance premium, which is interesting, it was a little bit of a counterintuitive, I wasn't expecting it when we wrote that answer, it will be important, but we didn't expect it to be ranked as the highest. And we dug deeper into it a little bit, and it came down to a couple of things. It came down to, identity security is one which is easier to test and gives a very clear signal of your overall cyber maturity. It's hard for an insurance firm to go and look at your network firewall configuration rules, but it's easier to assess like, hey, are you onboarding, offboarding your employees, your machine identities, et cetera, in a robust way. And then second is, it's actually able to also overall increase the way that you're able to respond to an issue, respond to an attack, and overall contain the damage out of it. So it was interesting to see the high, where it ranked, 73%, as a top three, and I don't know what you all are seeing there. I think Soumya, you brought a great point there. I think just to summarize a few domains, just from an identity access management standpoint, what the cyber insurance carriers who are issuing the policies are looking for, first and foremost, they are looking at how effective governance and strategy from an IAM standpoint do you have in place. Secondary, they are looking for your broader IAM program as a whole from access certification standpoint, access provisioning standpoint, and then also from a standpoint of secure credential management, which involves a lot of third party and a lot of integration type, non-human type IDs. Finally, last not the least, access reviews and reporting is something that they also look from a program's maturity standpoint. These data points or domains in IAM helps them understand what is the overall risk that they are signing up for. It also helps them to come up with the coverage and the pricing accordingly. Yeah, absolutely. So this morning we heard from Matt that enterprise securities next act, it's really around identity security, which is now at a center of how we protect our entire enterprise security. So when a cyber insurance company go assess a company's readiness and preparedness, what factors are they taking into consideration? And in particular, how do they assess the identity security part of their practice? Again, if you look at the past few years, the markets were really focused on, do you have multi-factor authentication? Do you have endpoint detection or response? Are you segmenting your network? Do you have incident response readiness? Do you have a business continuity program? They were very focused on the blocking and tackling controls. But where we're at in 2024 and where we're going to likely continue in 2025 is, now that we have the core blocking and tackling controls, how effective, what's the efficacy of the controls, right? So the markets now, as stated earlier by our respective subject matter experts here, it's about making sure the controls are effective and we're leveraging them in their best capability. So for example, if you can go to an insurance carrier or to a market and say, we have this particular control in place and we've ensured that it's effective by doing this, or we've been thinking a lot about identity, right? Because we want to make sure that if there's an incident, we can identify it, we can detect it as quickly as possible and know what the actor did in our environment. That is a much better story than saying, we have this solution in place, right? So a lot of it is just optics. It's getting the markets to feel assured that the good things that you have done perspectively within the information security program to mitigate risk is actually functional and it's working. And furthermore, another thing that we have found is that a lot of those organizations that are getting the best results from an insurance perspective can really demonstrate their understanding of what attackers typically do when they attack and then aligning that to the very controls that they had in their environment and demonstrate competency across the board. Yeah, it's really knowing what you have and then when things happen, what do you do to mitigate that risk? So Soumya, in the Horizon Studies, you looked at a lot of data. Can you tell us what's the correlation between the maturity of a business identity practice and the cyber insurance premium they have to pay? Yeah, one of the things we were looking at was how much of your identity security investment is impacting your business value. One of the factors was cyber insurance and we saw a clear linkage of investing in identity security was having an outsized impact also in your cyber insurance premium. And it came down to a few things here, right? It came down to three things when it comes to the risk pusher as carriers were looking at the insurance premium. Look, with the advent of AI and where generative AI is going and everything else, cloud has been a story. It's hard to create a circle of security with some of the parameters and it's one area's identity security that will apply to it, that actually can protect who has access to what. In three components, right? Number one, increases the visibility, increases the visibility across in terms of what type of identity is accessing what data. Number two, it enables you for better protection. And number three, which I think is the most important when it comes to a premium was faster response. We know that when it comes to a security incident, it's about how quickly I can contain the damage. And when it comes to that, it's the blast radius, the way to ability to determine that is you look into your identities that got impacted. So do you have the right governance across those identities to contain the blast radius in a quick fashion, which actually directly impacts how much the cyber insurance carriers is going to pay in terms of whether it's a ransomware or whether it's an operational issue or whatnot. Thanks, Swami. I agree. I think a couple of other things, just from an identity standpoint, what we are seeing is identities now treated no different than how assets, software assets, hardware assets have been treated in organizations. So what we are seeing constantly, again, from a regulatory standpoint, having a good source of your identity in one place and having a visibility across the ecosystem from that lens is important. Having the right KPIs, which is the three performance indicators, three risk indicators defined and managing your risk based on that is another second indicator that is very important. And third, last not the least, like I said previously as well, having an effective governance around your identity program definitely helps. A few other things I think that the panel also mentioned here, it's not just about getting the right premiums. It's not just about making the regulators happy. Having the right program in place reduces the enterprise risk as well. There's a lot of cost efficiencies as well that comes with it. So yeah. You know, that's a great point. I talked about earlier the efficacy and the effectiveness of the controls and if that could be demonstrated, that really gains the trust of the markets, which obviously translates into better results, right? But it's also really understanding, if you look at every single cyber attack that has occurred, whether it's a ransomware attack, whether it's a business email compromise, whether it's a bad lever situation where that bad lever took intellectual property or something of value to the organization or a good arriver situation where somebody came with a bunch of goods stolen from another company, a previous employer, and started to use that for, you know, advancing at their new employer. It all revolves around identity. The attackers are after the identity of a privileged user or a super user or an admin because of the power that's bestowed upon that identity. You know, I always say the most powerful hacking tool in the world is the employee badge and the access that's bestowed upon that badge logically, right? And so, you know, what we're recommending every day to our clients is it's great that you have a robust identity solution, but it's about making sure that that identity solution matches all of the different use cases from a prevention perspective, detection perspective, and then also litigation and all of the other needs that could occur. A general counsel may have very particular needs that they have, who are they going to go to? The IT team. They're going to launch an investigation, probably through outside counsel, and they're going to say, help us. If there's a breach or an incident, the insurance carriers are going to want to know more. Identity is going to be a core topic. HR, there could be, again, an employee-related situation. Somebody breaching their fiduciary duty. The list goes on and on. Identity is going to be core to that, right? And what they did. So, it's about making sure that there's alignment to the very controls that we've deployed to the use cases in the business to make sure that we can support the business effectively. Yeah, well said. We have data that shows 90% of the breaches all come down to identity. So, it truly is the core of how we look at the entire security posture for our business. So, I know we can keep talking here all the time, but the clock is ticking. Before we wrap up, I would love each one of you to give a piece of advice for everyone here. So, how should we really prioritize investment in identity security so that we can keep our business safe, right, while keeping the cyber insurance in mind? Thanks, Wendy. So, I think, first and foremost, adopt a framework, whether, for example, there are a lot of good frameworks out there. There's a NIST cybersecurity framework, Adopter Controls Framework. This helps to standardize the effectiveness of your program. This helps to standardize and demonstrate how you're orchestrating and running different controls that we talked about. Secondly, have a good strategy in place. Review your strategy periodically. It evolves as the business is evolving, so having that is very critical. Last not the least, the technology investments you have made in your identity platform, leverage those investments as much as possible, and also promote a lot of automation through those investments. The more automated controls you have, the less of the risk is, the easier it is to operationally manage and report on the program itself. Yeah. I mean, maybe one takeaway I would have, look, when we came to identity security conference, I'm assuming everyone is like, we don't have to convince that identity security is important if we're all in the identity space or investing it, right? Unless you're a big Star Wars or Mickey Mouse fan, you came to Orlando for identity security, so you believe identity security is important. I think one of my big asks here will be, go back to your organization and talk to your leaders who are determining this insurance and cyber insurance here, whether it's the general counsel, whether it's the CFO, or as identity leaders, we are very focused in determining how many connectors and how many applications and whatnot. Let's go and talk and see, how is our company determining the cyber insurance? And then there are two things we can do there, right? So one, if we have, and we believe in our organization, we have a good, robust identity security, can you use that data to share and optimize your cyber insurance premiums, especially in the light of premiums being increasing, and you can actually show a correlation here. And number two is, if you are one of those leaders who are asking for more investments in identity security, bake in insurance as one of the factors that is determining the business value you are getting out of this investment and the ROI out of it. I think that's it, unless Star Wars and Mickey Mouse. I think my recommendations would be actually quite simple. You know, we've had some really wonderful dialogue about insurance, but if we really sort of look at things at face value, insurance is the last resort. It's a risk transfer strategy, right? We use insurance to ultimately protect our balance sheet from the exposure that a cyber incident would cause, right? So, you know, the whole goal is really to prevent something bad from happening. So, you know, please reach out to your insurance broker, and if you work with a risk manager or you work with whoever's in charge of the insurance program within your respective organization, please ask them as a security leader, a technology leader, understand what it is that the markets are really focused on. So, the good work that we're doing and the road mapping that we're doing around identity and other projects, respectively, are going to position the organization admirably to get the best insurance results. Second recommendation would be, please leverage your incident response providers, those that you would rely on in a 911 situation and say, what are you guys seeing on the street? We don't want to secure in a vacuum. We want to understand the latest adversarial TTPs, techniques, tactics, and procedures that the adversaries are starting to leverage or leverage or how they're evolving to break into our environments. That is incredible insight that you can get. So, once you get that information, you can look at the controls that you have and, again, go back to that effectiveness and efficacy to ensure the controls are going to withstand the attacks of today, at least detect that something bad is happening in your environment, respectively. Yeah. Thank you all. Such good advice for all of us. I think my key takeaway is, as Che pointed out, at the end of the day, cyber insurance is just a risk transfer, right? It does not take the place of a robust security program that's centered around identity security. So, I hope each one of you will walk away with some good insights, good learning all around how important identity security is to keeping your business safe. It helps reduce your cyber risks while keeping the insurance premium in check. It also protects your operation and maximize the business value that you're getting out of investment. So, thank you, everyone. Appreciate it. Thank you.