IRDAI circular · 08 Sept 2021
Guidance Document On Product Structure for Cyber Insurance Table of Contents Personal Cyber Insurance Para Subject Page No. 1 Introduction 1 2 Emergence of Cyber risk for Individuals 2 3 Cyber Insurance Policy -Coverage 3 4 Need for Personal Cyber Insurance 4 5 Personal Cyber Insurance Cover – Salient features 7 6 Gaps…
Guidance Document On Product Structure for Cyber Insurance Table of Contents Personal Cyber Insurance Para Subject Page No. 1 Introduction 1 2 Emergence of Cyber risk for Individuals 2 3 Cyber Insurance Policy -Coverage 3 4 Need for Personal Cyber Insurance 4 5 Personal Cyber Insurance Cover – Salient features 7 6 Gaps in the current covers and recommendations for improvements 8 7 Standardisation of Cyber Insurance Policies – Challenges and Difficulties 10 8 Suggestions to popularise Personal Cyber Insurance 11 9 Suggested Dos and Don’ts for Personal Cyber Insurance policy buyers 12 Annexure Model Policy Wordings 15 Cyber Insurance Common Reference Framework Para Subject Page No. 1 Introduction 31 2 Various statutory provisions on Information and Cyber Security 33 3 Critical issues involving legal aspects of transactions in cyber space 47 4 Various types of incidents involving cyber security in the recent past and possible insurance coverage strategies for those 52 5 Cyber liability insurance covers available in Indian market and in other developed jurisdictions 60 6 Recommendation of the scope of the cyber liability insurance covers for the present context and for the medium term 72 7 Challenges in developing standard coverages, exclusions, and optional extensions for various categories 79 8 Other Matters of Relevance 91 1 Product Structure for Cyber Insurance 1. INTRODUCTION 1.1. We live in an ever-connected world today and every technology, every interface, every click we do on our devices (in some cases you don’t even do anything e.g., connected homes) produces various forms of data. This is why many call it the information age quickly evolving into an age of artificial intelligence. Technology as we know is changing faster than ever and data is being generated at exponential rates. IBM estimates that about 90% of the data in the world today has been created in the last two years. 1.2. While the ability to capture data and putting it to right use benefits governments, corporations, institutions, science, social welfare and many others; more data also means vulnerability to data related risks & crimes. Every technology misuse, wrongful access or resulting losses are directly or indirectly about generation, storage, access and use of data. Digital data and technology related crimes are referred to as “Cyber Crimes”. 1.3. India has been at the forefront of digital adoption driven by government impetus, infrastructural investments in communication, our need for remote connectivity and a vibrant technology driven industry. Our digital scale, spread, penetration and demographics are unique in many ways and aids our development. For example, India’s smartphone base is estimated to reach 820 million in the next two years, which can unlock 80% improvement in efficiency and 8 times reduction in processing time for e-governance services. Initiatives like Digital India, the India stack, UID, RBI regulated UPI, etc have helped permeate digitisation in several aspects of our life, businesses, finances and work. Along with industry driven platforms for e-commerce, travel, health, banking, education, social media, etc; these digital solutions have become inseparable to our day to day life. 1.4. Every aspect of us from who we are (identity), what we do (work, travel, entertainment, etc), what & how we earn and transact (finances, payments, etc), what we communicate & consume as content (social media, internet, OTT platforms, etc), etc. is now interconnected. We are sharing, generating and consuming a lot of data and utilising data driven services in the process. 1.5. Looking at where we stand, it is hard to imagine that we are still in early stages of digital evolution and the immense potential a country like ours has to turn around its socioeconomic fortune & global status by leveraging digital data. 2 Product Structure for Cyber Insurance 2. EMERGENCE OF CYBER RISK FOR INDIVIDUALS 2.1 There is always an element of risk involved in all online activities. But the way individuals use online services, such as storing credit card details on a retailer’s website or sharing sensitive personal data via an unprotected wireless network, or use of non-encrypted websites, they expose themselves to risks. 2.2 When an individual’s bank details are compromised or stolen it can be the start of a series of losses such as unlawful withdrawal of funds, identity theft, and such other losses. 2.3 Fraudsters may use personal information to open bank accounts or take out loans in victim’s name. This will involve payment default notices and a damaged credit record all of which may only come to light several months after the fraud was perpetrated. 2.4 In case of identity theft, there might be emotional and psychological setbacks due to Cyberbullying and stalking. This is how our digital lives can start to impact on our overall wellbeing. 2.5 Impact of Covid–19 2.5.1 While everyone is focused on health and economic threats of the COVID 19 virus, cyber criminals around the world are taking it as an opportunity and capitalising on this crisis. 2.5.2 Cyber risks have accelerated by as much as 500% since the first lockdown was imposed in India in March 2020. There is an increase in coronavirus-themed spam, likely resulting in more infected personal computers and phones. 2.5.3 As per the national cyber security agency The Computer Emergency Response Team of India (CERT-In), there has been an increase in the number of cyber- attacks on personal computer networks and routers since professionals were asked to work from home in the wake of the COVID-19 outbreak in the country. Cybercriminals are releasing new computing viruses and mobile applications relating to COVID-19 updates and other information. They are also designing phishing websites, emails and phishing UPI accounts in name of COVID-19, which are leading to Cyber frauds. They are using the heightened digital footprint and traffic to find vulnerabilities, or to siphon off money. 3 Product Structure for Cyber Insurance They are launching Covid-19-themed attacks in the form of phishing emails with malicious attachments that drop malware to disrupt systems or steal data and credentials. They are creating temporary websites or taking over vulnerable ones to host malicious code. They lure people to these sites and then drop malicious code on their digital devices. Fake websites have also been soliciting donations for daily wage earners through email links. Some Covid-19 patient count-status apps and links are laden with viruses and identity theft malware. The bait websites pretending to be official government webpages have also resulted in major cyber frauds and have affected individuals severely. 2.5.4 The surge in communications and the wholesale shift to digitisation and to operate online have increased the risk of cyber-attacks by an order of magnitude. 2.5.5 The tendency towards adhoc decision making during crisis only accelerates the opportunity to infiltrate data. The awareness around the different forms of cybercrimes is in nascent stage in India and therefore, it is of prime importance to look at different scenarios that could be unfavourable and the methods of addressing various risks. 2.5.6 In the context of above, one of the risk transfer instruments available to individuals is Cyber Insurance. 3. CYBER INSURANCE POLICY - COVERAGE Losses normally covered under a cyber-insurance policy can be split into 4 categories: a) First Party Losses: Direct Financial Loss, Data recovery, Business Interruption Cover and Mitigation Costs Cover, b) Regulatory Actions: Costs of Regulatory actions and investigations, Civil fines and penalties and Defence Costs.