Why Do Cyber Insurance Claims Get Rejected? (2024)

Date: 21 September 2023

Why Do Cyber Insurance Claims Get Rejected? (1)

Why was Merck’s battle and subsequent win against its insurer in the $1.4 billion cyber insurance battle such big news? Was it because cyber insurance claims never get rejected? Absolutely not. It made news because it’s not often that an insurance company rejects a cyber claim and the client wins a hefty payout after a long-drawn court battle.

The reality is that cyber insurance is becoming increasingly sought-after, expensive and complicated for the indemnifier and the indemnified both. It’s also not unusual for cyber insurance claims to get rejected. This is usually either on account of exclusions or poor cyber security hygiene on the part of the insured.

Let’s sample a few statistics that illustrate this point better:

  1. The cost of Cyber Insurance in the 2nd quarter of 2022 rose to 79% in the US and 68% in the UK as per this report.
  2. 81% of cyber insurance claims were caused by Ransomware Attacks in 2022-2033 as per some estimates.
  3. These estimates also suggest that around 27% of cyber insurance claims were not honoured or were partially paid due to exclusions within the cyber cover.

What the above few snippets of information illustrate is that Cyber Security Insurance is:

  1. Getting increasingly expensive because of the rise in number and cost of cyber-attacks and data breaches.
  2. Insurance companies are becoming increasingly stringent in providing cyber insurance covers and honouring claims.
  3. Indemnifying loss due to a cyber event or security breach is complicated and this landscape is going to become even more complex in the next few years.

So what can you do about it? How do you get insured at a cost that doesn’t break the bank? What fineprint should you pay attention to?

How can you try to get the best possible premiums? And is there hope that if you’re attacked your claim won’t be rejected?

Let’s answer these questions in a little more detail in the next two sections.

Why Do Cyber Insurance Claims Get Rejected? (2)

Why Your Cyber Insurance Claim Might Get Rejected?

There are plenty of reasons why your cyber insurance claim might get rejected and the most rudimentary of these is the inclusions in your policy. There could be certain clauses that the insurer doesn’t cover from the outset. Therefore, it is imperative to read and vet the policy document thoroughly with the help of cybersecurity advisors before signing on the dotted line.

In the case of the NotPetya attacks, global snack giant and owner of Oreo biscuits, Mondelez claimed $100 million from Zurich American Insurance Company and Merck claimed $1.4 billion from Ace American Insurance co. It’s important to note here that both organisations had ‘property insurance’ policies but cyber-attacks can and did cause physical damage to properties in this attack. Both companies’ claims were rejected by the insurers citing the ‘war exclusion’ clause in the policies.

Merck won the lawsuit as the New Jersey Superior court said that the damage caused by NotPetya wasn’t precisely an act of war - both countries weren’t actually at war then and no armed soldiers were involved. Mondelez, on the other hand, reached a private settlement with Zurich American Insurance.

The point here is that cyber insurance isn’t what it used to be in 2017 when NotPetya wreaked havoc across the world. It has developed rapidly and is no longer a filler in the product offerings of insurance companies.

Massive cyber disasters, expensive ransomware attacks and cases such as Merck have made underwriters become more cautious and has propelled insurers to tweak their terms and conditions in keeping with a volatile environment.

Several cyber insurers such as Lloyd’s of London have announced that their cyber insurance policies will no longer cover cyber events caused as a result of war or by nation-state actors. While this announcement is understandable from a business perspective, where does it leave an SMB who may be attacked by nation-state actors merely to steal sensitive customer data or cause disruption to business operations to make a point?

Cyber Insurers are scrutinising cybersecurity policies more strictly than ever and then there are clauses such as exclusions on attacks by nation state actors. This is why achieving cyber resilience has to become more affordable and accessible to businesses of all sizes - not just for being insured but for better overall protection. This was the primary vision behind Cyber Management Alliance's game changing Virtual Cyber Assistant service - making cyber resilience accessible to all businesses.

Why Do Cyber Insurance Claims Get Rejected? (3)

Here’s a look at some of the other reasons why your cyber claim may not be honoured:

  • Inadequate Documentation

One of the primary reasons for rejected cyber insurance claims is inadequate documentation. Insurers require detailed evidence to support your claim and this must be submitted to them within the stipulated timelines. This includes records of the cyber incident, the steps taken to mitigate damages, and any expenses incurred.

Failing to provide comprehensive documentation can lead to claim denial. Hence, it’s imperative that you have a proper cyber incident response strategy in place. This includes all the actions and documentation you need to get in order as soon as you have been attacked.

  • Poor Cyber Hygiene

If your organisation has not implemented reasonable cybersecurity measures, your claim can easily be rejected. Insurers often expect policyholders to adhere to specific security protocols and best practices. In case of an attack, if the insurer is able to attribute the compromise to your organisation’s negligence in implementing basic cybersecurity protocols and controls, you may not get paid.

  • Pre-existing Vulnerabilities

Claims may also be denied if the insurer discovers pre-existing vulnerabilities that were not disclosed during policy issuance. It is crucial to be transparent about your organisation's cybersecurity posture at the time of taking the policy to avoid rejection.

  • Policy Exclusions

Examine your policy carefully to understand the exclusions and ensure it covers the costs of your predominant threats and risks. Certain types of cyber incidents, such as those stemming from nation-state actors, as discussed above, may be excluded from coverage. Familiarise yourself with these exclusions to manage your expectations.

  • Claims Fraud

Attempting to exaggerate or falsify a cyber incident can result in not only a rejected claim but also legal consequences.

  • Navigating the Claims Process

When faced with a cyber incident, it's crucial to understand the claims process thoroughly. Engage with your insurer early, provide complete documentation, and cooperate with their investigation. A proactive approach can improve your chances of a successful claim. You may want to enlist services of a Cyber Incident Response retainer to help you manage the impact of the attack and also assist you with the claims process.

What Can You Do to Minimise the Chances of Rejected Cyber Claims?

There are a variety of steps you can take today to hopefully negotiate better cyber insurance premiums and minimise your chances of rejected cyber claims.

The foremost of these is maintaining good cybersecurity hygiene and protecting your business from reputational damage in case of an attack. Basic steps like updating and patching your systems, implementing strong security controls and having solid Incident Response Playbooks and Ransomware Response Guides are almost mandatory.

Human error is amongst the biggest causes of cyber attacks. Therefore, regular cybersecurity training and cybersecurity drills that help rehearse response to attacks is essential.

Our experts at Cyber Management Alliance have also created this comprehensive checklist of all the things you can do to negotiate a better cyber insurance premium. Embracing these steps and implementing them with agility can result in lesser chances of your claim being rejected in case of an attack.

Download this list today and make it a priority item in your business meetings. As we’ve seen through the cases discussed earlier, the omnipresence and high cost of cyber threats makes Cyber Insurance a business priority that simply cannot be ignored.

In addition, our Virtual Cyber Assistants can help you improve your cyber security posture over time at a budget and pace that suits your business. They can help you get all your cybersecurity documentation in order, implement an effective cybersecurity framework, assess your existing cyber health and assist you in achieving compliance with relevant regulatory standards and regulations.

Conclusion

Understanding why cyber insurance claims get rejected is crucial for businesses seeking financial protection in an increasingly digital world. By addressing common pitfalls, complying with security measures, and being transparent with insurers, you can enhance your chances of not only negotiating a lower cyber premium but also of having your claim honoured. Remember, cybersecurity should not be an afterthought; it should be an integral part of your business strategy and careful evaluation of your Cyber Insurance policy is a critical part of this strategy.

Why Do Cyber Insurance Claims Get Rejected? (4)

Why Do Cyber Insurance Claims Get Rejected? (2024)

FAQs

Why Do Cyber Insurance Claims Get Rejected? ›

If your organisation has not implemented reasonable cybersecurity measures, your claim can easily be rejected. Insurers often expect policyholders to adhere to specific security protocols and best practices.

Why do cyber insurance claims get rejected? ›

Failure to Document Preventative Measures

Your insurer will want to see tangible evidence, in the form of documentation, regarding the preventative measures you have under way to ward off cyberthreats. To avoid any hassles, you need to have thorough, accurate and updated documentation at all times.

Which is a common reason why insurance claims are rejected? ›

The claim has missing or incorrect information.

Whether by accident or intentionally, medical billing and coding errors are common reasons that claims are rejected or denied. Information may be incorrect, incomplete or missing. You will need to check your billing statement and EOB very carefully.

Why is it difficult to get cyber insurance? ›

Demand, losses, and premiums are all on the rise

The demand for cyber insurance coverage is skyrocketing. At the same time, insurance providers' losses are growing. High demand in combination with high payouts lead to increased premiums. Businesses report premium hikes of 50% and even 100% year over year.

What percentage of cyber insurance claims are denied? ›

4 common causes for cybersecurity claim rejections

According to the Cyber Management Alliance, it's estimated that 27% of cyber insurance claims were denied or only partially paid due to exclusions in coverage.

What does cyber insurance not cover? ›

Loss of value through intellectual property (IP) theft

Often, they won't recognize IP theft until long after an incident (for example, when a competitor takes a new product to market). Nevertheless, devaluation due to IP theft is a loss most cyber policies don't cover.

What isn t covered by cyber insurance? ›

Potential future lost profits

But they won't cover profits lost after an incident as a direct or indirect result. Devaluation of affected data, a company's diminished market share, profits lost due to reputation damage—most policies exclude such potential losses.

What are 5 reasons why a claim may be denied or rejected? ›

Six common reasons for denied claims
  • Timely filing. Each payer defines its own time frame during which a claim must be submitted to be considered for payment. ...
  • Invalid subscriber identification. ...
  • Noncovered services. ...
  • Bundled services. ...
  • Incorrect use of modifiers. ...
  • Data discrepancies.

What are the three most common mistakes on a claim that will cause denials? ›

Here, we discuss the first five most common medical coding and billing mistakes that cause claim denials so you can avoid them in your business:
  • Claim is not specific enough. ...
  • Claim is missing information. ...
  • Claim not filed on time (aka: Timely Filing)

What may lead to claim denials or improper? ›

Incorrect or Missing Patient Information

Many claim denials start at the front desk. Manual errors and patient data oversights such as missing or incorrect patient subscriber number, missing date of birth and insurance ineligibility can cause a claim to be denied.

What is the average cyber insurance limit? ›

Most small businesses purchase a cyber liability insurance policy with a $1 million per-occurrence limit, a $1 million aggregate limit, and a $1,000 deductible.

What is required to get cyber insurance? ›

Insurers may require businesses to have strong access controls. These controls mitigate the threat of cybercrimes arising from unauthorized access to sensitive data and systems. Such crimes might include phishing attacks and cyber extortion.

Does cyber insurance pay out? ›

Cyber insurance covers the liability actions that might be brought against you, arising out of a cyber event (third party loss), such as investigation and defence costs, civil damages, compensation payments to affected parties.

What is the most common cyber insurance claim? ›

As of late, the most common cyber attacks leading to insurance claims include ransomware, business email compromise, and funds transfer fraud.

How often does cyber insurance pay out? ›

However, the frequency of cyber insurance companies paying the average ransom declined over the same period. Based on a survey of IT professionals in 31 countries, cyber insurance providers made claim payouts in response to 98% of claims in 2021. This percentage is higher than the 95% payout rate two years before.

What is the most common source of insurance denials? ›

Incorrect or duplicate claims, lack of medical necessity or supporting documentation, and claims filed after the required timeframe are common reasons for denials. Experimental, investigational, or non-covered services are also likely to be denied.

Does cyber insurance make sense? ›

While cyber liability insurance can provide some financial protection in the event of a cyber attack or data breach, it is still not a complete substitute for implementing adequate cybersecurity measures.

How can I stop my insurance claim being rejected? ›

Ask to expedite the appeal if you or your doctor feels that the denial of your claim could be life-threatening. Keep copies of everything you send to the insurance company for your records. Contact your state Department of Insurance if you feel your insurer is not cooperating with the appeals process.

How effective is cyber insurance? ›

As well as directly improving security, cyber-insurance is enormously beneficial in the event of a large-scale security incident. Insurance provides a smooth funding mechanism for recovery from major losses, helping to businesses to return to normal and reducing the need for government assistance.

References

Top Articles
Latest Posts
Article information

Author: Carmelo Roob

Last Updated:

Views: 5500

Rating: 4.4 / 5 (65 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Carmelo Roob

Birthday: 1995-01-09

Address: Apt. 915 481 Sipes Cliff, New Gonzalobury, CO 80176

Phone: +6773780339780

Job: Sales Executive

Hobby: Gaming, Jogging, Rugby, Video gaming, Handball, Ice skating, Web surfing

Introduction: My name is Carmelo Roob, I am a modern, handsome, delightful, comfortable, attractive, vast, good person who loves writing and wants to share my knowledge and understanding with you.