Reinsurance News

RIMS replies to FIO on federal cyber backstop

28th November 2022 - Author: Pete Carvill -

Share

The Risk and Insurance Management Society (RIMS) has written to the Federal Insurance Office (FIO) in response to legislative dialogue regarding a federal backstop for large-scale catastrophic cyber incidents impacting infrastructure.

cyberThe eight-page letter from RIMS says that a recent survey of its members shows that they overwhelmingly support a federal cyber insurance backstop.

RIMS wrote: “Although numerous types of cyber incidents could catastrophically impact critical infrastructure, the FIO should consider the scope of the new federal backstop: should it be limited to critical infrastructure, or should the new program be available to all organisations in light of the cascading impact of failure of critical infrastructure of the economy? We think this distinction needs to be addressed as a core question before the extent and method of coverage can be addressed.”

It added: “RIMS supports consideration of a broader federal backstop because RIMS members report that the private insurance market is not making available insurance for catastrophic cyber incidents at the desired level. Member organisations purchase significant cyber insurance limits but would purchase more limits if available for a reasonable premium. Even when available, war exclusions in cyber insurance policies could limit or eliminate coverage for catastrophic losses.”

It is for this reason, said RIMS, that a federal insurance response is warranted for catastrophic cyber incidents, whether as part of an amended Terrorism Risk Insurance Program (TRIP) or in a new independent type of insurance backstop program.

It wrote: “In whatever federal form or organisation a catastrophic cyber backstop program takes, such program should not create moral hazards by encouraging organisations to take undue risks or fail to implement cybersecurity controls because member organisations’ existing cybersecurity controls already exceed their insurance requirements. If the federal backstop does impose cybersecurity controls as a condition for federal cyber coverage, the backstop should adopt existing external standards such as by NIST or ISO (as we discuss later) rather than implement a new federal cybersecurity standard.”

According to the Federal Register notice of potential rulemaking: “Over the past several years, the Federal Insurance Office in the U.S. Department of the Treasury has continued its ongoing efforts with regard to both cyber insurance and insurer cybersecurity. Cyber insurance is a significant risk-transfer mechanism, and the insurance industry has an important role to play in strengthening cyber hygiene and building resiliency.”

RIMS said it will continue to monitor the development of a federal insurance backstop for catastrophic cyber incidents, as well as any new, evolving, and expiring legislation that impacts the global risk management community.