Report

Cyber insurance and the cyber security challenge

Think tank: RUSI

Author(s): Jamie MacColl; Dr Jason R. C. Nurse; James Sullivan

June 28, 2021

This report from UK think tank RUSI looks at whether cyber insurance can incentivise better cyber security practices among policyholders.

This paper explores whether cyber insurance can incentivise better cyber security practices among policyholders. It finds that the shortcomings of cyber insurance mean that its contribution to improving cyber security practices is more limited than policymakers and businesses might hope. Although several means by which cyber insurance can incentivise better cyber security practices are identified, they have significant limitations. Interviewees from across government, industry and business consistently stated that the positive effects of cyber insurance on cyber security have yet to fully materialise. While some mature insurers are moving in the right direction, cyber insurance as a whole is still struggling to move from theory into practice when it comes to incentivising cyber security.