Similarities between property and cyber markets present an opportunity

At first glance, the property and cyber markets don’t have much in common, with the property’s scale of losses in the last year of $123 billion, far exceeding those of cyber. But there are some parallels that can help risk officers present a cohesive risk management strategy to the C-suite and board across both risks with the common objectives of more efficient risk financing and avoiding losses.

 

The widening protection gap – property

 

Both markets are seeing a growing protection gap. While not news to any risk manager, recent statistics from Gallagher provide an instructive scene-setter. The global commercial property sector has seen an increase in companies with inadequate cover at a time when property replacement costs have increased 45% per year between 2020-23.

 

Buyers in the property sector haven’t been able to secure adequate limits to protect themselves against these rising costs – often due to an inability to determine adequate limits at commercially viable prices.

 

According to the Gallagher white paper, the urgency of the problem is only growing as the frequency of large loss events has accelerated: between 1980-2022, the sector globally saw on average eight billion-dollar claims events per year. Between 2018-2022, that number grew to eighteen billion-dollar claims events on average per year.

 

As a result, the market is looking at alternative approaches that include more robust risk management approaches by insureds, increased risk retentions,
and alternative risk transfer solutions.

 

The widening protection gap—cyber

 

As we talked about recently, the protection gap in cyber is also growing—put at $900 billion last year by the Global Federation of Insurance Associations.

Unlike property though, cyber has been in a soft market over the past couple of years. Even with rates stabilizing and loss ratios improving for insurers, the right amount of cover has been elusive, especially for large organizations. Similar to property, the frequency and scale of cyber losses grew to record levels in 2023. Also similar to property, risk officers are increasingly looking at alternative approaches to both risk management and risk financing, including increased risk retentions and alternative transfer solutions. On the latter, organizations are looking to captive structures, as we talked about a few months ago.

 

Captives as a solution

 

Faced with the same challenge as property of being unable to secure adequate limits at commercially viable prices, cyber moved towards captives for reasons outlined by a FTSE100 risk officer: 

 

“We lost confidence in the value of the product the market was offering. We were being put in the wrong risk bucket by the market. Our best solution was running cyber through the captive.”

 

For this approach to work and to transition from being ‘insurance buyers’ to ‘sellers of risk’, risk officers need a validated answer to the question: ‘how much risk should we retain?’ That’s why this question is at the core of what Intangic does. 

 

Highly protected risk status

 

Similar to property, the other part of the equation is the drive for risk teams to have the organization be defined as a ‘highly protected risk’ (HPR) for cyber.

 

There’s no doubt that robust controls play an important role in preventing breaches, just as fire protection systems, surveillance cameras, and access controls do in property. But as we highlighted last week, it’s not enough.

 

Apart from cyber being a more dynamic business risk, a key difference between cyber and property is the strong working relationship required between the risk officer and Chief Information Security Officer (CISO) or Head of Security to first transparently validate the risk, then manage it.

 

This includes the risk officer providing up-to-date information (and resources as justified) to the security team such as whether the company is being more targeted by attackers than peers.

 

This is information that will help prevent a loss, improve that first layer of protection and help companies achieve and maintain highly protected risk status.

 

Navigating the headwinds 

 

Risk officers, whether focusing on cyber or property, know they can’t change the macro forces that shape the markets in which they work. However, early adopters of new approaches to risk financing that emphasize prevention and loss avoidance will better navigate headwinds such as inflation, rising building costs, increased prices, shrinking capacity, or a constantly changing cyber threat environment.