All the latest UK technology news, reviews and analysis

Hacker insurance set to rocket

by John Geralds in Silicon Valley

14 Feb 2003

Be the first to comment

  • Tweet this

Company spending on hacker insurance is set to rocket from $100m (£62m) to $2.5bn (£1.55bn) by 2005 in the US, according to industry estimates.

In January, the hacker insurance market increased as many existing commercial general liability policies expired and were replaced by policies containing explicit exclusions for hacker-related losses.

According to the Insurance Information Institute, a policy covering revenue lost due to hacking costs about $4,000 (£2,475) per year for each $1m (£620,000) in coverage.

Policies generally insure against losses caused by hackers, viruses, worms, cyber-terrorism, programming errors or intellectual property theft on the internet.

The Love Bug, Melissa, Code Red and other vulnerabilities have cost companies more than $54bn (£34bn) in down time, removal expenses and repairs, according to research organisation Computer Economics.

"Fears about how such vulnerabilities and attendant magnitudes of loss might impact on national security have reached a critical mass, particularly given the post-11 September climate," said attorney Robert Steinberg.

The Bush administration has also pushed insurers to work with businesses to set up a security baseline in the private sector.

For example, American International Group (AIG), the world's largest insurance company, said business espionage has become an increasing concern. Seventy-two per cent of US high-tech companies believe they are a target for domestic espionage, while 46 per cent cite foreign competition and 32 per cent foreign governments as potential threats.

But AIG, which writes about 70 per cent of cyber-policies in the US, has only issued 2,000 policies for far, each with a minimum price of $10,000 (£6,200).

Gartner analyst John Pescatore observed that cyber-insurance gets a temporary boost after every high-visibility attack, like Nimda or Slammer.

But he said: "Enterprise legal counsels and chief financial officers aren't yet convinced that hacker insurance will limit their liability or recover the costs of the premiums plus the deductibles."

It is not that the economic implications of attacks are not well understood but that the value of hacker insurance is unclear, he added.

No one, for example, can point to any case law or legal precedent that would indemnify a company from all liabilities that might spring from a hacker attack, he said.

"It doesn't seem particularly hard to get the insurance. Worst case, an enterprise needs to undergo a security audit, which most enterprises do regularly anyway."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

27%

1%

11%

61%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Systems Analyst/Architect

Systems Analyst/Architect £30,000 - £40,000 + excellent...

Software Developer

Software Developer Up to £27,000 + excellent...

Software Engineer/Developer (C#, C++)

Software Engineer/Developer (C++) £25,000 - £40...

Web Developer

Web Developer £25,000 - £40,000 (DOE)+ excellent...

To send to more than one email address, simply separate each address with a comma.