Skip to main content
Kent Academic Repository

Does Cyber Insurance promote Cyber Security Best Practice? An Analysis based on Insurance Application Forms

Adriko, Rodney, Nurse, Jason R. C. (2024) Does Cyber Insurance promote Cyber Security Best Practice? An Analysis based on Insurance Application Forms. Digital Threats: Research and Practice, . ISSN 2692-1626. (doi:10.1145/3676283) (KAR id:106506)

Abstract

The significant rise in digital threats and attacks has led to an increase in the use of cyber insurance as a risk treatment method intended to support organisations in the event of a breach. Insurance providers are set up to assume such residual risk, but they often require organisations to implement certain security controls a priori to reduce their exposure. We examine the assertion that cyber insurance promotes cyber security best practice by conducting a critical examination of cyber insurance application forms to determine how well they align with ISO 27001, the NIST Cybersecurity Framework and the UK’s Cyber Essentials security standards. We achieve this by mapping questions and requirements expressed in insurance forms to the security controls covered in each of the standards. This allows us to identify security controls and standards that are considered – and likely most valued – by insurers and those that are neglected. We find that while there is some reasonable coverage across forms, there is an underrepresentation of best practice standards and controls generally, and particularly in some control areas (e.g., procedural/governance controls, incident response and recovery).

Item Type: Article
DOI/Identification number: 10.1145/3676283
Uncontrolled keywords: Cyber insurance, cybersecurity, information security, ISO 27001, NIST Cybersecurity Framework, UK Cyber Essentials, security standards and controls, insurance proposal forms
Subjects: H Social Sciences > HF Commerce > HF5351 Business
Q Science > QA Mathematics (inc Computing science) > QA 76 Software, computer programming,
T Technology > T Technology (General)
Divisions: Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing
University-wide institutes > Institute of Cyber Security for Society
Funders: University of Kent (https://ror.org/00xkeyj56)
Depositing User: Jason Nurse
Date Deposited: 06 Jul 2024 11:08 UTC
Last Modified: 05 Nov 2024 13:12 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/106506 (The current URI for this page, for reference purposes)

University of Kent Author Information

  • Depositors only (login required):

Total unique views for this document in KAR since July 2020. For more details click on the image.