With the European Union’s General Data Protection Regulation (GDPR) due to take effect in May 2018, cyber risk has been pushed to the top of the corporate risk agenda for businesses throughout Europe, according to a survey of over 1,300 senior executives by Marsh.
The GDPR is a new legal framework with the aim to give control back to citizens over their personal data as well as simplify the regulatory environment for international businesses by unifying EU regulation.
The regulation places firms under a legal obligation to notify the Supervisory Authority within 72 hours of having become aware of the data breach and inform individuals if they’re adversely impacted.
In cases of non-compliance firms could be hit with a maximum fine of up to 4% of the annual worldwide turnover of the preceding financial year.
“The imminent implementation of the GDPR is spurring firms to take a fresh look at their cyber risk, not just their privacy protocols,” said John Drzik, President of Global Risk & Digital at Marsh.
65% of respondents operating in the EU said that they now consider cyber as a top risk – showing that concerns over cyber risk have doubled since last year when in a similar Marsh survey just 32% of participants cited cyber as a top five risk.
“This survey indicates that the most prepared firms are using GDPR as a catalyst to enhance their cyber risk management, including a more economic evaluation of their risks and an increased focus on building resilience in the face of an inevitable cyber incident,” Drzik added.
Respondents whose organisations have plans for GDPR implementation, 78% said they would increase spending on addressing cyber risk over the next 12 months, including spending on cyber insurance.
52% of those without a plan for GDPR indicated their investment in cyber risk management would increase.
Nearly one quarter of executives surveyed revealed their European organisations were subject to a successful cyber-attack in the past year – but only 8% of respondents surveyed said their firms were fully compliant with the GDPR requirements.
Over half of respondents said they were still in the process of developing compliance plans, with smaller organisations in particular with less than $50 million annual revenue falling behind on GDPR preparation compared to their larger counterparts.
“In our experience, smaller UK companies have typically viewed the GDPR as a compliance-driven, tick-box exercise,” said Siobhan O’Brien, Managing Director at Marsh UK; “however – for these organisations in particular – it presents an opportunity for them to better understand their cyber risks and their data capabilities in such a way that enables them to grow their business.”
The Marsh survey demonstrates the impact on prioritising cyber risk the GDPR has had on businesses operating in the EU, with twice as many executives now recognising cyber as a top risk, compared with last year.
However, it also shows a clear overall lack of preparedness on the part of enterprises, particularly in smaller firms, and unless these firms vamp up their efforts for cyber risk protection, a lack of proactivity in managing cyber risk could have serious consequences and see some tagged with heavy fines.
Rating agency A.M. Best anticipates an upcoming boom in cyber insurance revenues, as firms are more likely to opt for securing themselves with cyber cover, opening up new demand in the European re/insurance cyber market, which is still nascent compared with the growth occurring in the U.S.
“The GDPR further intends to increase the effectiveness of the right to data protection, and whilst this is expected to provide regulatory challenges for (re)insurers, the requirement for mandatory notification of serious data breaches is also likely to fuel supply of and demand for cyber insurance in Europe,” noted A.M. Best.
In the short-term, re/insurers stand to benefit from higher demand for cyber products as tougher data-breach reporting rules lead to many more reported breaches and greater awareness of cyber risk.




