Guidance Document On Product Structure for Cyber Insurance Table of Contents Personal Cyber Insurance Para Subject Page No. 1 Introduction 1 2 Emergence of Cyber risk for Individuals 2 3 Cyber Insurance Policy -Coverage 3 4 Need for Personal Cyber Insurance 4 5 Personal Cyber Insurance Cover – Salient features 7 6 Gaps…
Guidance Document On Product Structure for Cyber Insurance Table of Contents Personal Cyber Insurance Para Subject Page No. 1 Introduction 1 2 Emergence of Cyber risk for Individuals 2 3 Cyber Insurance Policy -Coverage 3 4 Need for Personal Cyber Insurance 4 5 Personal Cyber Insurance Cover – Salient features 7 6 Gaps in the current covers and recommendations for improvements 8 7 Standardisation of Cyber Insurance Policies – Challenges and Difficulties 10 8 Suggestions to popularise Personal Cyber Insurance 11 9 Suggested Dos and Don’ts for Personal Cyber Insurance policy buyers 12 Annexure Model Policy Wordings 15 Cyber Insurance Common Reference Framework Para Subject Page No. 1 Introduction 31 2 Various statutory provisions on Information and Cyber Security 33 3 Critical issues involving legal aspects of transactions in cyber space 47 4 Various types of incidents involving cyber security in the recent past and possible insurance coverage strategies for those 52 5 Cyber liability insurance covers available in Indian market and in other developed jurisdictions 60 6 Recommendation of the scope of the cyber liability insurance covers for the present context and for the medium term 72 7 Challenges in developing standard coverages, exclusions, and optional extensions for various categories 79 8 Other Matters of Relevance 91 1 Product Structure for Cyber Insurance 1. INTRODUCTION 1.1. We live in an ever-connected world today and every technology, every interface, every click we do on our devices (in some cases you don’t even do anything e.g., connected homes) produces various forms of data. This is why many call it the information age quickly evolving into an age of artificial intelligence. Technology as we know is changing faster than ever and data is being generated at exponential rates. IBM estimates that about 90% of the data in the world today has been created in the last two years. 1.2. While the ability to capture data and putting it to right use benefits governments, corporations, institutions, science, social welfare and many others; more data also means vulnerability to data related risks & crimes. Every technology misuse, wrongful access or resulting losses are directly or indirectly about generation, storage, access and use of data. Digital data and technology related crimes are referred to as “Cyber Crimes”. 1.3. India has been at the forefront of digital adoption driven by government impetus, infrastructural investments in communication, our need for remote connectivity and a vibrant technology driven industry. Our digital scale, spread, penetration and demographics are unique in many ways and aids our development. For example, India’s smartphone base is estimated to reach 820 million in the next two years, which can unlock 80% improvement in efficiency and 8 times reduction in processing time for e-governance services. Initiatives like Digital India, the India stack, UID, RBI regulated UPI, etc have helped permeate digitisation in several aspects of our life, businesses, finances and work. Along with industry driven platforms for e-commerce, travel, health, banking, education, social media, etc; these digital solutions have become inseparable to our day to day life. 1.4. Every aspect of us from who we are (identity), what we do (work, travel, entertainment, etc), what & how we earn and transact (finances, payments, etc), what we communicate & consume as content (social media, internet, OTT platforms, etc), etc. is now interconnected. We are sharing, generating and consuming a lot of data and utilising data driven services in the process. 1.5. Looking at where we stand, it is hard to imagine that we are still in early stages of digital evolution and the immense potential a country like ours has to turn around its socioeconomic fortune & global status by leveraging digital data. 2 Product Structure for Cyber Insurance 2. EMERGENCE OF CYBER RISK FOR INDIVIDUALS 2.1 There is always an element of risk involved in all online activities. But the way individuals use online services, such as storing credit card details on a retailer’s website or sharing sensitive personal data via an unprotected wireless network, or use of non-encrypted websites, they expose themselves to risks. 2.2 When an individual’s bank details are compromised or stolen it can be the start of a series of losses such as unlawful withdrawal of funds, identity theft, and such other losses. 2.3 Fraudsters may use personal information to open bank accounts or take out loans in victim’s name. This will involve payment default notices and a damaged credit record all of which may only come to light several months after the fraud was perpetrated. 2.4 In case of identity theft, there might be emotional and psychological setbacks due to Cyberbullying and stalking. This is how our digital lives can start to impact on our overall wellbeing. 2.5 Impact of Covid–19 2.5.1 While everyone is focused on health and economic threats of the COVID 19 virus, cyber criminals around the world are taking it as an opportunity and capitalising on this crisis. 2.5.2 Cyber risks have accelerated by as much as 500% since the first lockdown was imposed in India in March 2020. There is an increase in coronavirus-themed spam, likely resulting in more infected personal computers and phones. 2.5.3 As per the national cyber security agency The Computer Emergency Response Team of India (CERT-In), there has been an increase in the number of cyber- attacks on personal computer networks and routers since professionals were asked to work from home in the wake of the COVID-19 outbreak in the country. Cybercriminals are releasing new computing viruses and mobile applications relating to COVID-19 updates and other information. They are also designing phishing websites, emails and phishing UPI accounts in name of COVID-19, which are leading to Cyber frauds. They are using the heightened digital footprint and traffic to find vulnerabilities, or to siphon off money. 3 Product Structure for Cyber Insurance They are launching Covid-19-themed attacks in the form of phishing emails with malicious attachments that drop malware to disrupt systems or steal data and credentials. They are creating temporary websites or taking over vulnerable ones to host malicious code. They lure people to these sites and then drop malicious code on their digital devices. Fake websites have also been soliciting donations for daily wage earners through email links. Some Covid-19 patient count-status apps and links are laden with viruses and identity theft malware. The bait websites pretending to be official government webpages have also resulted in major cyber frauds and have affected individuals severely. 2.5.4 The surge in communications and the wholesale shift to digitisation and to operate online have increased the risk of cyber-attacks by an order of magnitude. 2.5.5 The tendency towards adhoc decision making during crisis only accelerates the opportunity to infiltrate data. The awareness around the different forms of cybercrimes is in nascent stage in India and therefore, it is of prime importance to look at different scenarios that could be unfavourable and the methods of addressing various risks. 2.5.6 In the context of above, one of the risk transfer instruments available to individuals is Cyber Insurance. 3. CYBER INSURANCE POLICY - COVERAGE Losses normally covered under a cyber-insurance policy can be split into 4 categories: a) First Party Losses: Direct Financial Loss, Data recovery, Business Interruption Cover and Mitigation Costs Cover, b) Regulatory Actions: Costs of Regulatory actions and investigations, Civil fines and penalties and Defence Costs. c) Crisis Management Costs: Forensic Expert Cover including security consultation, Reputation Damage Cover, Legal Costs Cover for matters including notification, coordination with service providers, strategy etc., Credit and Identity Theft Monitoring Cover, Cyber extortion/ Ransomware Cover, 4 Product Structure for Cyber Insurance Operation of a 24x7 Hotline, Cyber Stalking, Counselling, Information removal and pursuing action. d) Liability Claims: Legal liability/damages directly arising from privacy or data/ security breach, Defamation, Intellectual Property Right (IPR) infringement and Defence Costs. 4. NEED FOR INDIVIDUAL CYBER INSURANCE 4.1 What is Cyber Insurance? 4.1.1 Cyber insurance is an insurance policy designed to protect the policy holders from cybercrimes. Data Security Council of India (DSCI) describes cyber insurance as under. 4.1.2 “Cyber Insurance is designed to guard businesses from the potential effects of cyber-attacks. It helps an organisation mitigate risk exposure by offsetting costs, after a cyber-attack/breach has happened. To simplify, cyber Insurance is designed to cover the fees, expenses and legal costs associated with cyber breaches that occur after an organisation has been hacked or from theft or loss of client/employee information. 4.1.3 Cyber Insurance is a risk management and mitigation strategy having a corollary benefit of improving the adoption of preventive measures (products, services, and best practices), thus, helping improve the cyber security posture of organisations, and thereby the country as well”. 4.1.4 Individual cyber insurance policy is the one which is designed to meet the requirements of an individual as against an organisation. What are the big cyber worries for an individual? 4.1.5 As per Swiss Re’s global survey, the top four cyber risk scenarios that people worry about most are: a) illicit access of financial credentials (a hacker gets access to your online banking details and might therefore be able to steal money) b) identity theft (an attacker steals your digital identity to purchase goods or services online in your name) c) data loss due to a technical issue (your personal data gets deleted by a virus or software glitch) 5 Product Structure for Cyber Insurance d) illicit publication of personal data (somebody else publishes your private pictures online) These are the four main areas where customers are receptive to the idea of a cyber-insurance policy that will cover them against some of the consequences of these fears coming true. 4.1.6 In the Indian context, the following information about increased digitisation of transactions and internet usage would help understand the vulnerabilities and the resultant need for individual cyber insurance to mitigate the impact of adverse consequences. Government have taken many initiatives in order to spread the awareness of about digitisation of transactions, have encouraged individuals to avail digital facilities such as online portal to store personally identifiable information including health record and use payment system such as Rupay etc. It is possible that those portals may get breached and information obtained misused. As a result, individuals may face losses. The number of internet users in India is currently estimated at 700 million. India is ranked as the second largest online market worldwide in 2019, coming second only to China. The number of internet users is estimated to increase in both urban as well as rural regions. This number is increasing rapidly so also is the number of users of online banking. The number of online banking users is expected to reach 150 million by 2020 from 45 million in 2017. The Ecommerce industry is expected to reach $99 billion in size while the online retail penetration is expected to more than double to around 11% by 2024 from 4.7% in 2019. According to the Reserve Bank of India’s (RBI’s) settlement data of select payment systems, Unified Payments Interface (UPI) crossed 1 billion transactions in volume by mid-October 2020. With major e-commerce platforms conducting their festive sales with discounts and offers, experts believe that the growth of digital transactions will receive a further boost. The way many devices like computers, mobile phones, security systems, televisions, wearables connected to the internet are rapidly increasing, undoubtedly increases vulnerability of an individual for a cyber-attack. As per a study titled, "India - Emerging Hotbed of IoT Opportunities by Zinnov, a 6 Product Structure for Cyber Insurance leading global management and strategy consulting firm, the number of connected devices will touch 2 Billion by 2021.In our increasingly connected world, the risk does not stop just because the systems are switched off. Also, it has been noticed that, there is an impactful increase in number of cybercrime targeting individuals. More than 90,000 case have been reported from 2012 till 2018. Out of 80% of them had intention of unlawful financial gain. In addition, it is believed that most of cyber frauds go unreported in India due to low level of consumer awareness, inadequate knowledge about recourse mechanisms and also because of individually insignificant losses (can be massive when looked at large). The use of social media has increased significantly in past few years across all classes in the society. Identity theft is a real threat to many social media users, as millions of online users use their personal information in order to get registered with one or more social media platforms. Such huge information with personal data of so many people is one of the easiest targets for many cyber criminals. In addition to phishing emails and texts, social media is growing to be a major source of account access related frauds. Cybercrimes on social media include impersonation where a fake account is used to groom a victim, eventually tricking them into handing over money or representing another person through a fake identity. This risk is compounded by the fact that awareness & investment in cyber security measures like use of anti-viruses, firewalls, etc is limited. There is little awareness around use of privacy measures available on social medial platforms (e.g. public vs private posting), phone security (e.g. use of passwords & biometrics), etc. Some of the ways financial fraud can be perpetrated is through phishing or spoofing attacks, malware or spyware, SIM swap (original SIM gets cloned and becomes invalid, and the duplicate SIM can be misused to access the user’s online bank account to transfer funds), credential stuffing (compromising devices and stealing data), man-in-the-middle attacks during online payments or transactions, identity theft, card cloners or readers at ATM machines and as simple as imposters calling up unsuspecting individuals and asking their personal banking details. The safety of bank accounts, and debit and credit card lies with the customer as well as the concerned bank. Taking the cognizance of the complaints related to unauthorized transactions, in July 2017, the RBI reviewed the criteria for determining customer liability in such cases and issued some directions. RBI has also set forth the situations to establish liability of a customer. 7 Product Structure for Cyber Insurance 4.2 Zero Liability of a customer 4.2.1 Contributory fraud/ negligence/ deficiency on the part of the bank, irrespective of whether or not the transaction is reported by the customer. 4.2.2 Third party breach where the deficiency lies neither with the bank nor with the customer but lies elsewhere in the system, and the customer notifies the bank within 3 working days of receiving the communication from the bank regarding the unauthorized transaction. 4.3 Limited Liability of a customer 4.3.1 Where loss is due to the negligence of the customer, e.g. payment credentials are shared, the customer shall bear the entire loss till the time unauthorized transaction is reported to the bank. Any loss after reporting of the unauthorised transaction shall be borne by bank. 4.3.2 In cases where the responsibility for the unauthorised electronic banking transaction lies neither with the bank nor with the customer, but lies elsewhere in the system and when there is a delay (of four to seven working days after receiving the communication from the bank) on the part of the customer in notifying the bank of such a transaction, the per transaction liability of the customer shall be limited to the transaction value or the amount ranging between INR 5,000 to INR 25,000 whichever is lower dependent upon the type of account. 4.3.3 Detailed directions are in RBI circular no. RBI/2017-18/15 dated July 6, 2017. It may be noted that Zero liability is not a carte blanche. Further, Cyber insurance addresses exposures beyond the situations described in RBI circular. 5. INDIVIDUAL CYBER INSURANCE COVER - SALIENT FEATURES Given below are the salient features of individual cyber insurance policy. a) Theft of funds – Provides protection in respect of theft of funds due to Cyber Incident or Hacking of insured’s Bank account, Credit/Debit card and/ or Mobile wallets by a Third Party. b) Identity Theft Cover – Provides protection in terms of Defence cost for claims made against insured by third / affected party due to identity theft fraud, provides expense to prosecute perpetrators and other transportation cost. 8 Product Structure for Cyber Insurance c) Social Media Cover / Personal Social Media- Provides protection in terms of Defence cost for claims made against insured by third / affected party due to hacked social media account of insured, provides expense to prosecute perpetrators and other transportation cost. d) Cyber Stalking / Bullying – Provides expenses to prosecute the stalker. e) Malware Cover / Data Restoration Cost – Provides coverage for data restoration cost due to malware. f) Phishing Cover – Provides protection in respect of financial losses as a result of phishing attack and provides expense to prosecute perpetrators. g) Unauthorised Online Transaction – Provides protection against fraudulent use of bank account, credit / debit card, e-wallet by third party to make online purchasing over internet. h) Email Spoofing - Provides protection in respect of financial losses as a result of spoofed email attack and provides expense to prosecute perpetrators. i) Media Liability Claims Cover – Provides coverage for defence costs in third party claims due to defamation or invasion of privacy due to Insured’s publication or broadcasting of any digital media content. j) Cyber Extortion Cover – Provides protection for extortion loss as a result of Cyber extortion threat and provides expense to prosecute perpetrators. k) Data Breach and Privacy Breach Cover – Provides indemnity for defence costs and damages in respect of claims lodged by a Third party against the Insured for Data Breach and or Privacy Breach. 6. GAPS IN THE CURRENT COVERS AND RECOMMENDATIONS FOR IMPROVEMENTS While the current offerings are addressing the requirements of individuals reasonably well, there are a few gaps which are listed below. Some of them relate to product features and the others to processes involved. It may not be possible to address all these gaps. But attempts can be made, in respect of some gaps, either to respond fully or partially. 9 Product Structure for Cyber Insurance S. No. Gaps Recommendations 1 Compulsory FIR in case of a Cyber incident is a must while filing a claim which becomes a hassle for an individual and creates distrust in their minds when claims are not settled because of the same FIR is a critical requirement to assess claims and hence can’t be fully dispensed with. However, for small claims upto INR 5000, Insurers may ask for E-Complaint lodged at the National Cyber Crime Reporting Portal. 2 Individuals are required to take due diligence, care and reasonable precautions to safeguard their identity/personal details while on web and claims are admissible only if the Individual is an innocent victim of the cyber fraud and Gross negligence is excluded from the coverage. This again creates a grey area in the coverage More explicit exclusion language could be used, e.g. - ‘Deliberate, criminal, fraudulent, dishonest or malicious act or omission of Insured Beneficiary’ Also, such exclusion should be triggered only when the said negligence has directly caused the loss 3 Definition of Cyber-attack states targeted intrusion into the Individual’s system which is mostly not the case. The attack is usually targeted to multiple web users/content users and the said condition again leaves the Individual uninsured. Insures could use “unauthorized access” language as suggested in the model policy form 4 Territory and Jurisdiction is restricted to India only in most of the policies. A number of syndicated frauds originate from outside India (e.g. phishing, ransomware, malware attacks), cyber insurance clauses may or may not be clear on the coverage in this regard. Insurers may offer options for Worldwide territory. Jurisdiction for claims settlement should be India 5 Unsolicited communications are also excluded from the scope of cover in many insurance policies while this is one of the major reasons of cyber related losses leaving the individual uninsured. Insurers could offer coverage for such losses 10 Product Structure for Cyber Insurance 6 Sim-jacking, card cloning, skimming coverage is not available currently in the market while the same is a major reason of loss in India. Insurers could offer coverage for such losses 7 Online shopping fraud like when the item that individual bought but not received the goods or sold, something that has left their custody but the payment is not received is not covered or only a very small coverage for the same is available Insurers could offer limited coverage for such losses for example: Non- delivery of goods ordered from merchant or non-receipt of premium while goods are delivered are prime- facie business risks and cannot be classified under cyber coverages unless resulting directly from cyber related events. 8 Bricking: Cyber insurance policies generally exclude coverage for damaged computer hardware. Bricking refers to a loss of use or functionality of hardware as a result of a cyber-event. While malicious software may be removed, hardware may also require replacement. Here, coverage provides for the cost to replace such affected hardware. Insurers could offer coverage for such losses 7. STANDARDISATION OF CYBER INSURANCE POLICIES- CHALLENGES & DIFFICULTIES a) Cyber threats are growing and are dynamic, cyber threat actors adopt new technologies faster and exploit it to their benefit, and hence cyber insurance as a risk transfer method should also be dynamic and continue to respond to latest developments. b) New legislation and regulations are in development and this may lead to requirement of new insurance solutions and services. c) Cyber experts, insurers and reinsurers are learning and trying to develop better understanding on exposures and insurance solutions. Policy wording, coverage and offerings are getting refined however, this is still a long journey. d) The user base is across all age groups, be it enthusiastic young kids & young adults who are on internet for school education and other social networking sites to explore internet services much aggressively; the professionals having much more dependence on internet for day to day business. Another set of 11 Product Structure for Cyber Insurance users are the elderly in form of parents and grandparents who have also joined the enthusiastic user segment. Each of these segment faces very different level of threats like Cyber bullying or Harassment, to Data theft or Malware attack to Digital theft of funds and Identity theft. This is a very wide spectrum to be addressed by a standard product and needs a flexible approach. e) Standardized wordings is not considered desirable from customer’s perspective. Flexibility allows for innovation and healthy competition, and not just price driven competition. f) Cyber insurance, being a new product, is supported by international reinsurers for the innovation, technical knowledge, product wording and various other services. Instead of a standardized wording they may prefer to use coverage and exclusions as per the latest development in the market. g) To increase penetration of the product various distribution channels have to be used and this will require flexible approach in coverage and services. It is good to allow market to explore, innovate and invest in the product proposition along with various risk management services. 7.1 Standardisation of the Cyber policy wordings for individuals may hamper the developments of this product in Indian market. It is important now to focus on popularizing the Cyber insurance product, make it easier for insurer to adapt the product as per the customer requirements and continue to enrich customer’s experience and protection. 7.2 Nevertheless, Insurers can build in certain minimum covers as a part of individual cyber insurance. The attached model policy wording can be considered by the insurance industry as a reference point to provide minimum basic coverage. 8. SUGGESTIONS TO POPULARISE INDIVIDUAL CYBER INSURANCE The following are some suggestions to popularise individual cyber insurance policy. a) Awareness Campaign: Awareness about the policy is currently low. Insurance industry should launch awareness campaign to educate consumers about their exposures and the insurance protection available to mitigate the losses. 12 Product Structure for Cyber Insurance b) Policy wording must be easy to understand and claim process must be easy to comprehend and implement. c) Dissemination of information about claim scenarios/ settlements without confidentiality breaches. d) Group policies, including affinity policies, may be encouraged as the reach of the message gets wider. e) Insurers may consider offering cyber insurance as a part of package policy like House Holders Package policy. Swiss Re’s global survey reveals that many would prefer to buy personal cyber insurance in combination with other products. f) It is better to offer a base version of the policy at an affordable premium and then give the customer an option to choose additional covers. 9. SUGGESTED DOS AND DON’TS FOR INDIVIDUAL CYBER INSURANCE POLICY BUYERS Do’s 1. Install Anti-Virus and Firewall in devices 2. Use a Virtual Private Network 3. Keep software and operating system updated 4. Keep hard-to-Guess Passwords or Passphrases, Password should have a Minimum of 10 Characters using uppercase letters, lowercase letters, numbers and Special Characters 5. Keep different passwords for different accounts. If one password gets hacked, your other accounts are not compromised 6. Use Privacy Settings On Social Media Sites to Restrict Access To Your Personal Information 7. Pay Attention to Phishing Traps in Email and watch for Telltale Signs of a Scam 8. Destroy Information Properly When It Is No Longer Needed 9. Be Aware of Your Surroundings When Printing, Copying, Faxing or Discussing Sensitive Information. 10. Lock your Computer and mobile phone when not in use. This Protects Data from Unauthorized Access and use 13 Product Structure for Cyber Insurance 11. Remember that wireless is inherently insecure. Avoid using public wi-fi Hotspots 12. Report all suspicious activity and cyber incidents 13. Check if the web site being visited is a trusted web site 14. Be extra careful during festival season 15. Always delete mail/ SMS from unknown sources 16. Use Multifactor Authentication (MFA) for email and online portal accounts Don’ts 1. Leave or share your sensitive information lying around or share to some one 2. Share or post any private or sensitive information, such as credit card numbers, passwords or other private information, to some one, on public sites, including social media sites 3. Click on links from an unknown or untrusted source 4. Respond to fake phone calls or emails requesting for confidential data 5. Install Unauthorized Programs on your computer 6. Leave devices unattended. Keep all mobile devices, such as laptops and cell phones physically secured 7. Share personal information with persons unless authenticity and required authority is confirmed 14 Product Structure for Cyber Insurance Personal Cyber Insurance Model Policy wordings Table of Contents Sl. No Particulars Page No. A PREAMBLE 15 B INSURING CLAUSE 15 i. Theft of Funds/ Financial Loss Cover 15 ii. Malware Decontamination Cover/ Data Restoration Cover 15 iii. Cyber Extortion Cover 15 iv. Cyber Stalking Cover 16 v. Identity Theft Cover 16 vi. Privacy Breach and Data Brach Cover 16 vii. Media Liability Cover 16 C DEFINITIONS 17 D GENERAL CONDITIONS 22 E SPECIAL CONDITIONS 25 F EXCLUSIONS 25 G DUTIES OF THE INSURED 27 H CLIAM REPORTING / PROCESS 28 I DEFENCE SETTLEMENT AND CLAIM COOPERATION 29 J GRIEVANCE REDRESSAL MECHANISM 29 15 Product Structure for Cyber Insurance A. PREAMBLE: Mr./Mrs./Ms. ____________________ (henceforth referred to as the “Insured”) has submitted a proposal and declaration. --------------------------------------------------- (henceforth referred to as “Insurer”), relies on the information furnished in the proposal and declaration for this Policy, or its preceding Policy of which this is a renewal. On such reliance and in consideration of the premium received, the Insurer hereby agrees to the following Terms and Conditions. These Terms and Conditions will be the basis for any claim or benefit under this Policy. B. INSURING CLAUSE: In consideration of the payment of the premium, the Insurer and the Insured agree as follows: i. Theft of Funds / Financial Loss Cover: The Insurer shall indemnify the Insured during the Period of Insurance or Discovery Period Any direct and pure financial loss sustained by the Insured: (i) as a result of a theft of funds due to an unauthorized access to Insured’s bank account, credit or debit card or mobile wallets by a third party, and (ii) as a consequence of Insured being a victim of cybercrime - including but not limited to phishing, email spoofing, Vishing/ Hacking/ Skimming/ Smishing / Card Cloning/SIM Jacking. ii. Malware Decontamination cover / Data Restoration Cover The Insurer shall indemnify the Insured during the Period of Insurance or Discovery Period any reasonable and necessary costs incurred by the involvement of an IT expert after a cybercrime to restore insured’s data or to decontaminate or clean insured’s personal device from malware. Costs shall include Bricking costs. iii. Cyber Extortion Cover The Insurer shall indemnify the Insured during the Period of Insurance or Discovery Period the Cyber Extortion Loss that the Insured incurs solely and directly as a result of a Cyber Extortion Threat first Discovered during the Period of insurance. As a condition for payment under this cover the Insured shall: 16 Product Structure for Cyber Insurance i. keep the terms and conditions of this Cyber Extortion Cover confidential, unless disclosure to law enforcement authorities is required; and ii. Take all reasonable steps to notify and cooperate with the appropriate law enforcement authorities; and iii. Take all reasonable steps (including the involvement of a security consultant with the Insurer’s prior written consent), to effectively mitigate the Cyber Extortion Loss. iv. Cyber Stalking Cover The Insurer shall indemnify the Insured during the Period of Insurance or Discovery Period if applicable Costs incurred by the Insured for prosecution of a criminal case against Third party under The Information Technology Act 2000 (No 21 of 2000), and or any other applicable law prevalent in India including the relevant provisions of Indian Penal code for Cyber Stalking the Insured. v. Identity Theft Cover The Insurer shall indemnify the Insured during the Period of Insurance or Discovery Period if applicable reasonable Defense Costs incurred as a result of any Claim by an Affected Person or an entity for Legal liability that directly results from the Identity Theft of the Insured by Cybercrime . vi. Data Breach and Privacy Breach Cover The Insurer shall indemnify the Insured during the Period of Insurance or the Discovery period if applicable, reasonable Defence Costs and Damages incurred by the Insured as a result of a Third Party claim for Data Breach and/or Privacy Breach. vii. Media Liability Cover The Insurer shall indemnify the Insured during the Period of Insurance or the Discovery period if applicable, reasonable Defence Costs and damages lodged by a Third party against the Insured for any unintentional defamation, breach of copyright, title, slogan, trademark, trade name, service mark, service name or domain name, or 17 Product Structure for Cyber Insurance breach or interference of privacy rights, resulting from Insured’s online media activities including media activities in social media. PROVIDED always that the liability of the Company shall in no case exceed the Limit of Liability stated against each item or in aggregate as stated in the schedule. C. DEFINITIONS In this Policy the following words in bold shall have the following meaning: 1. Affected Person: means any natural person who has been affected by the named insuring clauses. 2. Bricking costs refer to costs incurred to repair/ replace hardware, where loss or impairment of functionality of hardware is caused by a Cybercrime. Bricking costs shall also include costs for removal of malicious software. 3. Claim means any written demand, suit or civil legal proceeding. A Claim shall be deemed to be first made or commenced when the Insured first becomes aware of it. 4. Computer means any electronic magnetic, optical or other high-speed Data processing device or system which performs logical, arithmetic, and memory functions by manipulations of electronic, magnetic or optical impulses, and includes all input, output, processing, storage, Computer software, or communication facilities which are connected or related to the Computer in a Computer system or Computer network; 5. Computer Programs means a collection of instructions that describe a task, or set of tasks, to be carried out by a Computer System, including application software, operating systems, firmware and compilers. 6. Computer System means a device or collection of devices, including input and output support devices and excluding calculators which are not programmable and capable of being used in conjunction with external files, which contain Computer Programmes, electronic instructions, input Data and output Data, that performs logic, arithmetic, Data storage and retrieval, communication control and other functions; For avoidance of Doubt, Computer System shall include all kinds of digital devices. 18 Product Structure for Cyber Insurance 7. Cybercrime means an unauthorised intrusion into the Insured’s Computer System: which results in the transmission of unauthorised Data to the Insured’s Computer System or from the Insured’s Computer System to a Third Party’s Computer System that is designed to modify, alter, damage, destroy, delete, record or transmit information without authorisation, including Data that is self-replicating or self-propagating, or is designed to contaminate other Computer Programmes or legitimate Computer Data, consume Computer resources or in some fashion usurp the normal operation of a Computer System. 8. Cyber Stalking means the repeated use of electronic communications to harass or frighten someone. 9. Cyber Extortion Threat means threat by an extortionist to cause harm or damage to Insured’s data on Insured’s personal device in order to extract an extortion ransom by use of coercion. 10. Cyber Extortion Loss means: a) Reasonable and necessary fees, Costs and expenses incurred by or on behalf of the Insured with the prior written consent of the Insurer directly resulting from a Cyber Extortion Threat; b) Monies payable by the Insured with the prior written consent of the Insurer in order to resolve or terminate a Cyber Extortion Threat. 11. Credit card cloning is a technique whereby someone obtains an individual’s credit card details, copies them onto a bogus card and begins using the credit card. 12. Damages means the following, incurred as a result of a Claim: i. any amounts that an Insured shall be legally liable to pay to a Third Party in respect of judgments or arbitral awards rendered against an Insured; ii. monies payable by an Insured to a Third Party pursuant to a settlement agreement negotiated by the Insured with the prior written approval by the Insurer; or iii. Civil fines and penalties, Punitive or exemplary Damages where insurable by the law of this Policy and the jurisdiction in which the payment is to be made. Damages shall not include: i. The loss, offset or return of fees, commissions, royalties, bonuses or profits by the Insured or the Costs to re perform any services; ii. The Costs to comply with any order for, grant of or agreement to provide injunctive or other non-monetary relief; 19 Product Structure for Cyber Insurance iii. The Costs to design, upgrade, maintain, or improve a Computer System or Computer Programme, including correcting any deficiencies or problems; iv. Taxes v. Compensatory Costs. vi. Consequential Loss. vii. Cash Back/Reward points 13. Data means any electronic Data of a form readily usable by a Computer Programme. 14. Data Breach and Privacy Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to, personal data or confidential information transmitted, stored or otherwise processed on Insured’s personal devices 15. Data Protection Legislation means any Law or Regulation regulating the processing of personal information, including the Indian Data Privacy Act 2019, Indian Information Technology Act, 2000 and Information Technology,(reasonable security practices and procedures and sensitive personal Data or information) Rules, 2009/2011 or any amendments or modifications thereof, from time to time or any similar legislation. 16. Deductible means the amount as mentioned in the schedule that the Insurer deducts from the covered loss before effecting payment. 17. Defence Costs means reasonable and necessary legal fees, Costs and expenses incurred by or on behalf of the Insured, with the prior written consent of the Insurer, in relation to the investigation, response, defence, appeal or settlement of a Claim, including the Costs of attachment or similar bonds, provided the Insurer shall have no obligation to furnish such bonds. 18. Direct Financial Loss shall mean the loss of funds belonging to the Insured as a Consequence of the Insured being an innocent victim due to Cybercrime. 19. Discovery Period means the period commencing immediately after the expiry of the Period of Insurance, during which written notice may be given to the Insurer of a Claim arising from an insuring clause that has occurred prior to the expiry date of the Period of Insurance and only where Loss from such insuring clause is not partially nor wholly covered by any other insurance policy in force after the expiry date of the Policy. 20 Product Structure for Cyber Insurance 20. E-mail Spoofing means a forgery or a wrongful manipulation of an E-mail header so that the message appears to have originated from the actual source. 21. Financial Institution means any bank whose function or principle activities are regulated by the Indian financial regulatory bodies in the territories in which it operates. 22. Funds mean any cash, money currency owned by the Insured or held by a) A Financial Institution b) A Payment System Operator in an Electronic form on behalf of the Insured. 22. Hacking is an attempt to exploit a computer system or a private network inside a computer system. It is an unauthorised access to or control over computer network security systems for some illicit purpose. 23. Identity Theft means any fraudulent and Unauthorized Access to, usage, deletion or alteration of Insured’s Personal Data stored in the Insured’s Computer System 24. Insured means the Policy Holder named in the Policy schedule. 25. Insurer/ Company means ________________________________ 26. Insured’s Computer System means a Computer System the Insured leases, owns or operates and which is securely made available or accessible to the Insured for the sole purpose of storing and processing the Insured ‘s Data and which is not accessible for the general public. 27. Loss means a) Direct financial loss b) Damages c) Defence Costs d) Restoration Costs e) Cyber Extortion Loss f) Consultant Costs g) Any other amount the Insurer is liable to pay under the terms and conditions of this Policy 28. Malware means a Computer program received through SMS, File transfer, downloaded programs from internet or any other digital means by the Insured’s Computer System maliciously designed to infiltrate and damage Insured’s Computer System without Insured’s consent. 21 Product Structure for Cyber Insurance 29. Payment System Operator is an entity authorized by the Reserve Bank of India to set up and operate in India under the Payment and Settlement Systems Act, 2007 30. Phishing is the attempt to obtain sensitive information such as usernames, passwords, and credit card details (and sometimes, indirectly, money), often for malicious reasons, by masquerading as a trustworthy Entity in an electronic communication. 31. Personal Data shall mean any information or details such as bank details, photographs, name, location data etc. which are unique to an Individual and are stored in the Insured’s Computer System. 32. Policy Period: means the period mentioned in the schedule not exceeding 12 months. 33. Pollution means the discharge, dispersal, seepage, migration, release or escape of: a) any solid, liquid, gaseous, biological or thermal irritant or contaminant, including smoke, vapor, soot, fumes, acids, alkalis, chemicals, radiation and waste. Waste includes materials to be recycled, reconditioned or reclaimed; b) electromagnetic energy, radiation or fields; c) nuclear or other radiation. 34. Proposal Form means the written application or proposal for this Policy made by the Policyholder, including any document provided by the Policyholder in connection with such application or proposal which shall be incorporated in and form the basis of this Policy. 35. Regulator means any official or public body with responsibility to enforce Data Privacy Regulation 2019 or Authority empowered to adjudicate the disputes/complaints, including but not limited to any Controller of Certifying Authorities, Deputy Controller of Certifying Authorities, Assistant Controller of Certifying Authorities, adjudicating officer, Cyber Appellate Tribunal, appointed or constituted under the Indian Information Technology Act, 2000 read with Information Technology (Reasonable security practices and procedures and sensitive personal Data or information) Rules, 2011, or such other Regulator/adjudicating authority as may be designated/appointed, from time to time. 22 Product Structure for Cyber Insurance 36. Restoration Cost includes Reasonable and necessary Cost to technically restore, retrieve or reinstall Data or Computer Program damaged by entry of the Malware including the Cost of purchasing a Software License necessary to reproduce such Data or Computer Programs if so required to bring back to the position before occurrence of the incident excluding any improvement cost. 37. Skimming is a method used by identity thieves to capture information from a cardholder. Several approaches can be used by fraudsters to procure card information with the most advanced approach involving a small device called a skimmer. 38. Smishing is a portmanteau of "SMS" (short message services, better known as texting) and "phishing." When cybercriminals "phish," they send fraudulent emails that seek to trick the recipient into opening a malware-laden attachment or clicking on a malicious link. Smishing simply uses text messages instead of email. 39. Social Media means any forms of electronic communication (as apps and web sites for social networking and microblogging) through which users create online communities to share information, ideas, personal messages, and other content (as videos) 40. Third Party means any natural or legal person except the Insured 41. Vishing is an attempt where fraudsters try to seek personal information like Customer ID, Net Banking password, ATM PIN, OTP, Card expiry date, CVV etc. through a phone call. 42. Insured means the Policy Holder named in the Policy schedule. 43. Insurer means ----- General Insurance Company Limited 44. Unauthorized Access or Use means the improper access or use of the Insured’s Computer System by an unauthorized person acting in an unauthorized manner D. GENERAL CONDITIONS: 1. Limit of Liability: The Insurer’s liability to pay or indemnify under this contract for each and every Loss and for all Loss in the aggregate shall not exceed the Limit of Liability during the policy period 23 Product Structure for Cyber Insurance 2. Discharge of Insurer from Liability: The payment of any Loss and or any other amounts payable under this Policy to the Insured shall fully release the Insurer from the Insurer’s liability to make payment with respect to such Loss and all other amounts 3. Policy Renewal: The Insurer shall not be bound to accept any renewal premium nor give notice to the Insured that such renewal is due. No receipt for renewal premium is valid except on the official form issued by the Company. Under normal, circumstances renewal will not be refused except on the grounds of misrepresentation, fraud and non-disclosure of material facts or non- cooperation of the insured. 4. No Third Party Rights: Notwithstanding what is stated in any Law, this Policy is not intended to confer any rights or benefits on and or enforceable by any Third-Party other than an Insured and accordingly no Third Party shall acquire any rights in relation to or under this Policy nor can enforce any benefits or Claim under term of this contract against the Insurer. 5. Assignment: The Insured shall not be entitled to assign this Policy nor any interest or right under the Policy without the Insurer’s prior written consent 6. Contribution: If at the time of any loss or damage happening to any property hereby insured there be any other subsisting insurance or insurance whether effected by the Insured or by any other person or persons covering the same risk, the Insurer shall not be liable to pay or contribute more than its rateable proportion of such loss or liability. 7. Subrogation: The Insured and any claimant under this policy shall at the expense of the company do or concur in doing or permit to be done all such acts and things that may be necessary or reasonably required by the company for the purpose of enforcing any rights and remedies or obtaining relief or indemnity from other parties to which the company shall be or would become entitled or subrogated upon the company paying for or making good any loss or damage under this policy whether such acts and things shall be or become necessary or required before or after the insureds’ indemnification by the company. The Insurer reserves the right to recover amount due from any third party by virtue of Letter 24 Product Structure for Cyber Insurance of Subrogation post settlement of the claim. Any amount recoverable from any Third party shall be sum payable to the insurers post settlement of the claim. 8. Fraud: If any claim under this policy shall in any respect be fraudulent or if any fraudulent means or devices are used by the insured or anyone acting on the insureds’ behalf to obtain any benefit under this policy, all benefits and rights under this policy shall be forfeited and the policy will be null & void. 9. Misrepresentation: This policy shall be void in the event of mis-representation, mis-description or non-disclosure of any material particulars. 10. Cancellation: The Insurer may at any time, cancel this policy by giving seven (07/ 15) days’ notice in writing by registered post or by courier to the Insured at his last known address in which case the Company shall return to the insured a proportion of the last premium corresponding to the un-expired period of insurance. 11. Arbitration: If any dispute or difference shall arise as to the quantum to be paid under the policy (liability being otherwise admitted) such difference shall independently of all other questions be referred to decision of a sole arbitrator to be appointed in writing by the parties to or if they cannot agree upon a single arbitrator to be appointed in writing by the parties to or if they cannot agree upon a single arbitrator within 30 days of any party invoking arbitration the same shall be referred to a panel of three arbitrators, comprising of two arbitrators, one to be appointed by each of the parties to the dispute/difference and the third arbitrator to be appointed by such two arbitrators and arbitration shall be conducted under and in accordance with the provisions of the Arbitration and Conciliation Act, 1996. It is clearly agreed and understood that no difference or dispute shall be referable to arbitration as herein before provided, if the company has disputed or not accepted liability under or in respect of this policy. It is hereby expressly stipulated and declared that it shall be a condition precedent to any right of suit upon this policy that award by such arbitrator/arbitrators of the amount of the loss or damage shall be first obtained." 25 Product Structure for Cyber Insurance 12. Observance of Terms and Conditions: The premium payable under this policy shall be paid in advance. No receipt for premium shall be valid except on the official form/official website of the company. The due payment of premium and observance and fulfilment of the terms, conditions and endorsement of this policy by the insured shall be a condition precedent to any liability of the company to make any payment under this policy. No waiver of any terms, provisions, conditions and endorsement of this policy shall be valid unless made in writing and signed by an authorized official of the company. Any violations of terms & conditions will make the policy voidable at the option of the insurer depending on the degree of implication on the loss occurred, recovery prospects & investigation except in case of fraud & misrepresentation. E. SPECIAL CONDITIONS: 1. The debit card/ credit card involved must be blocked immediately within 24 hours after detection of the loss of money or loss of card, which ever happens earlier. 2. Any cashback/rewards if so credited to the concerned card holder’s account against misused transaction leading to loss of money, shall be reduced from the loss payable under the policy. 3. Insured should have a registered valid mobile number &e-mail id to receive SMS alerts/OTP from the bank. 4. This insurance shall not cover losses that can be received from a financial institution, payment wallet/service operator, ecommerce service provider or any such entity who has a primary responsibility to indemnify the insured. F. EXCLUSIONS: No coverage will be available under this Policy with respect to any Loss arising out of, based upon or attributable to: 1. Dishonest and Intentional mis-conduct: Any deliberate, criminal, fraudulent, dishonest or malicious act or omission; or intentional or willful violation of any duty, obligation, contract, law or regulation; by the Insured. Such acts should have directly caused the loss for the exclusion to apply. Provided, however, the Insurer shall advance Defense Costs until there is a) final decision of a court, arbitration panel or Regulator, or 26 Product Structure for Cyber Insurance b) a written admission which establishes such behavior. Following such finding the Insurer shall be entitled to repayment of any amount paid to or on behalf of the Insured under this Policy. 2. Bodily Injury: Any actual or alleged bodily injury, sickness, mental anguish or emotional distress or disturbance, disease or death of any person howsoever caused. 3. Property Damage: Any damage to or destruction of any property, including loss of use thereof. 4. Contractual Liability: Any liability under any contract, agreement, guarantee or warranty assumed or accepted by an Insured except to the extent that such liability would have attached to an Insured in the absence of such contract, agreement, guarantee or warranty; 5. Prior Acts Exclusion: Any Claim due to, arising out of or based upon or attributable to acts committed, attempted, or allegedly committed or attempted, prior to the inception of the coverage and known to the Insured 6. Intellectual Property Rights: Any actual or alleged plagiarism or infringement of any Trade Secrets, patents, trademarks, trade names, copyrights, licenses or any other form of intellectual property. 7. Trading: Any losses or liabilities connected with any types of purchase or sale transactions or other dealing in securities, commodities, derivatives, foreign or Federal Funds, currencies, foreign exchange, cryptocurrencies and the like. 8. Outage/Disturbance Loss: Losses due to the outage/disturbance of external networks (e.g. power, internet, cable & telecommunications) 9. Commercial, Political, Union or Religious Activities: Any kind of losses in connection to commercial, political or union activities, the exercise of a religious function/office and/or the membership in any club/association that is salaried and/or not for leisure. 27 Product Structure for Cyber Insurance h) Immoral/Obscene Services: Any losses in connection with racist, extremist, pornographic or other immoral/obscene services, statements or representations provided made or committed by the insured. i) Professional Services: Any loss or damage attributable to rendering or non-rendering of professional services j) Sharing/Divulging user id and password: Any sharing of divulging of id / password leading to loss of money/data. Any act of error and commission by insured causing over payment or transfer to a wrong bank account not intended to. k) Loss of Reputation/Goodwill l) Matters uninsurable by law. m) Prior/ Pending Litigation: Any legal proceedings which commenced prior to inception of this policy n) War & Terrorism Any actual, threatened or feared act of: a) war, invasion, act of foreign enemy, hostile operations (whether war has been declared or not), civil war, rebellion, revolution, insurrection, riot or civil commotion, military or usurped power or martial law, or b) Violence or other intended harm to human life or health or to property for political, religious or other ideological reason and for the purposes of intimidating, coercing or harming, in part or in whole, any government, population or segment of economy, except to the extent exclusively carried out through an actual Cybercrime. G. DUTIES OF THE INSURED: Insured shall take all reasonable measures to safeguard the Insured’s Computer System and Digital Devices and prevent the occurrence and to minimize the impact of any Cybercrime including but not limited to i. Updating Antivirus Software from time to time as per recommendations of the Antivirus Software provider. ii. Maintaining up-to-date patch-states of the OS, browser, E-Mail, other software programs iii. Maintaining back up of all valuable data stored in the Computer System in other storage media including external data media. 28 Product Structure for Cyber Insurance iv. Implementing best practices security e.g. password strength, regular changes of passwords, use of two-factor-authentication as recommended by Internet Service Provider, Social Media Service Provider, Financial Service Provider/Bank/Payment System Operator and/or Government/Authorities *Note: Waiver of conditions (i) to (iv) above may be considered by the Company at its discretion, in cases of hardship where it is proved to the satisfaction of the Company that under the circumstances in which the Insured was placed, it was not possible for the Insured to take reasonable measures to safeguard the Insured’s Computer System and Digital Devices and prevent the occurrence and to minimize the impact of any Cybercrime. H. CLAIM REPORTING/ PROCESS: On happening of any loss or damage the insured or Upon receipt of any Claim, the Insured shall, as soon as practicable, give notice in writing/e-mail from registered email id with insurer thereof to the Insurer within 7 days but in any event not later than 14 days after the end of the Period of Insurance or Discovery Period, if applicable; and if, during the Period of Insurance, the Insured becomes aware of any fact, event or circumstance which is likely to give rise to a Claim then the Insured shall give written notice thereof to the Insurer as soon as reasonably practicable and, in any event, during the Period of Insurance. If the Insured reports a Claim or facts that might give rise to a Claim to the Insurer, then the Insured shall give the Insurer such information and co-operation as it may reasonably require including but not limited to: a) Submission of fully completed and signed Claim form b) Copy of FIR/Complaint lodged with Police Authorities / cyber cell c) Copies of legal notice received from any Person/entity d) Copies of summons received from any court in respect of a suit filed by a party/entity e) Copies of correspondence with financial institutions with regard to any Loss f) Legal notice served on any Financial Institution and or case filed against Financial Institution for IT Theft Loss g) Copies of legal notice served on any Third Party for any Data breach or privacy breach h) Copies of criminal case filed against third party i) Copies of invoices for expenses covered under the policy for which indemnity is sought j) Proof to show that the Personal Data is the propriety information belonging to the Insured. k) Proof to show that Loss is incurred by the Insured. 29 Product Structure for Cyber Insurance Particulars of other applicable insurance, if any All notifications and all communications under this Policy must be in writing to the address mentioned in the Schedule I. DEFENCE SETTLEMENT AND CLAIM COOPERATION: Insurer shall be entitled to fully participate in the defence and at the negotiation stage of any settlement that is reasonably likely to involve or appear to involve. However, the right and duty to defend and contest the claim shall lie solely on the Insured. As condition precedent to liability under the policy, the Insured shall provide the Insurer at his own cost with all documentation, information, assistance, co-operation that may be requested and required towards, investigation, defence, settlement or appeal of a claim or circumstances. Insured shall take all reasonable steps to mitigate the loss in his capacity immediately within reasonable period of time. J. GRIEVANCE REDRESSAL MECHANISM: If you are dissatisfied with any service, please contact the Branch Manager / Regional Manager of the local office which has issued the policy. If the issues are not resolved to your satisfaction by the local office, please e-mail or write to: customercare@---- or address--------. If you are still not satisfied, you can approach the Insurance Ombudsman in the respective area for resolving the issue. The contact details of the Ombudsman offices are mentioned below. 30 Product Structure for Cyber Insurance Cyber Insurance Common Reference Framework 31 Product Structure for Cyber Insurance 1. INTRODUCTION 1.1. Humankind always faces risks from a multitude of elements, some of them unsettling, a few perplexing and a few more terrifying. However, Risk Management and Risk Transfer devices have always responded with effective solutions to manage risks and to mitigate their adverse consequences. The insurance industry has made a stellar contribution to progress with its agility in designing loss mitigation instruments. 1.2. The contribution of insurance industry is all the more profound, not just in loss mitigation, but in risk mitigation too. By its rigorous approach to risk analysis, risk evaluation, risk control, and risk reduction incentives, insurance has brought a significant awareness of risks and their consequences. 1.3. Particularly after Industrial Revolution, insurance industry has been ever receptive to the challenges of new exposures and has crafted many an innovative solution for loss mitigation. Not long ago, even an automobile was considered a dangerous chattel for the risks it posed to human safety. Third Party liability management has been one of the singular contributions that insurance industry can be proud of. Today, motor liability insurance policies are as ubiquitous as automobiles. 1.4. A similar threat has been wrought upon us by the Information Revolution. We live in a digital world today, and this world is teeming with innumerable risks of the known and unknown kind. While data is the new oil of the economy, just as oil could be inflammable and cause devastation, data, if not properly secured, could play havoc with the economy. 1.5. The proliferation of handheld devices, availability of internet access at affordable cost, increased computing power of mobiles, widening horizons of ecommerce, facilitation of payment gateways, the power of social media and its commercial possibilities and a multitude of such other factors are changing the way the world moves, works, sleeps, and conducts its business. 1.6. Now, not only execution, but even control functions are also done by digitally enabled machines. This has almost led to the subservience of mankind to machines. Every sphere of activity from manufacturing, finance, vehicular movement, aircraft navigation, distribution, weather prediction, education, health, and entertainment are dependent on a digital network of operations and control. The interdependence of these systems on each other amplifies the vulnerabilities. What makes cyber risks so potentially monstruous is the pervasive use of 32 Product Structure for Cyber Insurance technology in every activity which was hitherto performed and controlled by humans. Cyber risks refer to the potential exposures to harm or loss or emanating from usage of information technology or systems. 1.7. India has been quick to seize the opportunities the digital realm offers. It has emerged as an Information Technology powerhouse. India is also one of the largest markets in the world, particularly with its young demography. The emergence of ecommerce, entertainment and financial ecosystems are opening new vistas of opportunities and, unfortunately, new trenches of threats. 1.8. The threats emanate from the dangers posed by accidental and deliberate breaches in the cyber space, which need to be fathomed and controlled. 1.9. Concurrent with the development of technology and digitally enabled possibilities for growth, data protection is emerging as a key concern. Globally, data protection has acquired salience. Data privacy and the need to secure the data a person holds is now recognised as an important responsibility. In India too, particularly after the Hon. Supreme Court recognised right to privacy as a fundamental right, data protection has become a major anxiety. 1.10. The legal framework for cyber liability is also evolving. Every person, be it an individual or an entity, is expected to exercise a duty of care to secure the data that he comes to possess, and to ensure that access to such data is not gained by unauthorised users. Should there be a breach in this duty, a cyber liability could arise. Regardless of whether the breach resulted in a financial loss to the person whose data is compromised, a breach of duty in cyber could result in grave legal and financial consequences. Notification and credit monitoring responsibilities, fines and penalties, and numerous other provisions make the responsibility of those who hold data onerous. One could never know what could be deemed to be reasonable care, what kind of threats could one foresee, and what kind of preventive measures one could have in place. Further, with most of areas of business operations getting automated and interconnected, vulnerability to disruption from cyber-attacks and resultant losses has increased significantly. There is a clear and present danger in the cyber world that cries out for a solution. 1.11. As ever, the insurance industry has been responsive in addressing these needs. Insurance solutions are indeed available for the risks faced by corporates and individuals. Undeterred by the uncertainties surrounding the evolution of cyber liability, the insurance industry has been quick to design risk and loss mitigation solutions in the form of cyber insurance. Cyber insurance is a form of insurance designed to protect an insured against damages caused by cyber risks. Cyber insurance is also referred to as cyber risk insurance, Cyber liability insurance, or Cybersecurity insurance. 33 Product Structure for Cyber Insurance 1.12. But the coverage could be disparate, and the coverage terms could be onerous, which is understandable, given the shifting nature of the risk itself. The insurance industry is also impeded by lack of data on past losses, lack of clarity on the extent of their assumed risks under such coverage and other actuarial and underwriting challenges. Therefore, the exposures, the losses, and the coverage available to mitigate such losses need critical examination. Attempts also need to be made to develop a sound framework for loss assessment and mitigation, and to harmonise the efforts of the various risk carriers involved in this enterprise. 2. VARIOUS STATUTORY PROVISIONS ON INFORMATION AND CYBER SECURITY Overview of Cyber Laws in India & other countries India 2.1 There is always an element of risk involved in all online activities. But the way individuals use online services, such as storing credit card details on a retailer’s website or sharing sensitive personal data via an unprotected wireless network, or use of non-encrypted websites, they expose themselves to risks. 2.2 The cyber law ecosystem in India comprises Information Technology Act, 2000 (IT Act) that came into force on 17th October 2000 and its further amendments, proposed Personal Data protection Bill 2019, Indian Penal Code, Indian Evidence Act, Bankers’ Book Evidence Act, RBI Act and / or respective statute which may impact respective industry. An overview of the various laws is elaborated as follows – Information Technology Act, 2000 (IT Act) 2.3 When Information Technology Act 2000 was passed, India became the 12th country to enact cyber laws in accordance with UN-endorsed model law as the backbone of the cyber laws of different countries. Cyberlaw in India is not a separate legal framework. It is a combination of various laws. With the Computer and internet taking over every aspect of our life, there was a need for strong cyber laws. Cyber Laws provide legal recognition to electronic documents and a framework to support e-filing and e-commerce transactions and provides a legal framework to mitigate and check cybercrimes. 2.4 Information Technology Act, 2000 is India’s mother legislation regulating the use of computers, computer systems and computer networks as also data and 34 Product Structure for Cyber Insurance information in the electronic format. This legislation has touched varied aspects pertaining to electronic authentication, digital (electronic) signatures, cybercrimes and liability of network service providers. The primary objectives of the IT Act are as under: Granting legal recognition to all transactions done through electronic data exchange Legal recognition of books of accounts in electronic form Addressing Computer-related crimes and cyber offenses Protecting privacy and sensitive personal data The IT Act broadly covers the following entities within its ambit – Intermediaries Body Corporates The rules under IT Act applicable to above entities are – 2.5 The Information Technology (Intermediaries guidelines) Rules, 2011: These rules provide the rights and responsibilities of internet intermediaries in India. If the Internet intermediaries follow these rules and exercise proper cyber due diligence, they are entitled to a “safe harbour protection”. Otherwise, they are liable for various acts or omission occurring at their respective platforms once the matter has been brought to their notice. IT Act defines an intermediary as under: 2.6 Sec 2(W): “intermediary”, with respect to any particular electronic records, means any person who on behalf of another person receives, stores or transmits that record or provides any service with respect to that record and includes telecom service providers, network service providers, internet service providers, web- hosting service providers, search engines, online payment sites, online-auction sites, online-market places and cyber cafes. 2.7 The Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011: These rules, regarding sensitive personal data or information, are applicable to the body corporate or any person located within India. It basically, requires entities holding sensitive personal information of users to maintain certain specified security standards. Provisions relating to Offences & Penalties 35 Product Structure for Cyber Insurance Some of the provisions relating to penalties and offences which are relevant in the context of general insurance are given below – 2.8 Section 43: Penalty and compensation for damage to computer, computer system, etc.– If any person without permission of the owner or any other person who is in charge of a computer, computer system or computer network – a) accesses or secures access to such computer, computer system or computer network or computer resource; b) downloads, copies or extracts any data, computer data base or information from such computer, computer system or computer network including information or data held or stored in any removable storage medium; c) introduces or causes to be introduced any computer contaminant or computer virus into any computer, computer system or computer network; d) damages or causes to be damaged any computer, computer system or computer network, data, computer data base or any other programmes residing in such computer, computer system or computer network; e) disrupts or causes disruption of any computer, computer system or computer network; f) denies or causes the denial of access to any person authorised to access any computer, computer system or computer network by any means; g) provides any assistance to any person to facilitate access to a computer, computer system or computer network in contravention of the provisions of this Act, rules or regulations made thereunder; h) charges the services availed of by a person to the account of another person by tampering with or manipulating any computer, computer system, or computer network; i) destroys, deletes or alters any information residing in a computer resource or diminishes its value or utility or affects it injuriously by any means; j) steal, conceal, destroys or alters or causes any person to steal, conceal, destroy or alter any computer source code used for a computer resource with an intention to cause damage; 36 Product Structure for Cyber Insurance he shall be liable to pay damages by way of compensation to the person so affected. Section 43 A - Compensation for failure to protect data: 2.9 Where a body corporate, possessing, dealing or handling any sensitive personal data or information in a computer resource which it owns, controls or operates, is negligent in implementing and maintaining reasonable security practices and procedures and thereby causes wrongful loss or wrongful gain to any person, such body corporate shall be liable to pay damages by way of compensation to the person so affected. (“body corporate” means any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities) Section 66 - Computer related offenses: 2.10 If any person, dishonestly or fraudulently, does any act referred to in section 43 (as explained above a to j), he shall be punishable with imprisonment for a term which may extend to three years or with fine which may extend to five lakh rupees or with both. Explanation – For the purposes of this section - a) the word “dishonestly” shall have the meaning assigned to it in section 24 of the Indian Penal Code; b) the word “fraudulently” shall have the meaning assigned to it in section 25 of the Indian Penal Code. 2.11 Section 66 B - Whoever dishonestly received or retains any stolen computer resource or communication device knowing or having reason to believe the same to be stolen computer resource or communication device, shall be punished with imprisonment of either description for a term which may extend to three years or with fine which may extend to rupees one lakh or with both. 2.12 Section 66C - Whoever, fraudulently or dishonestly make use of the electronic signature, password or any other unique identification feature of any other person, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine with may extend to rupees one lakh. 37 Product Structure for Cyber Insurance 2.13 Section 66D - Whoever, by means for any communication device or computer resource cheats by personating, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to one lakh rupee. Some other relevant provisions are indicated below Section 66E - Punishment for violation of privacy Section 66 F - punishment (life imprisonment) for cyber terrorism Section 67 / 67A / 67B - punishment for publishing or transmitting obscene material in electronic form 2.14 Section 72 - punishment (maximum of 2 years of imprisonment with fine of Rs 1 lakh) for disclosure of material without the consent of the person concerned to any other person. 2.15 Section 72 A - punishment (maximum of 3 years of imprisonment with fine of Rs 5 lakhs) for disclosure of personal information in breach of lawful contract, to a third party Personal Data Protection Bill, 2019: 2.16 This bill is largely modelled on the EU’s General Data Protection Regulation (GDPR) and aims to protect the informational privacy of individuals by creating a preventive framework that regulates how businesses collect and use personal data. It is currently being examined by a Joint Parliamentary Committee in consultation with experts and stakeholders. 38 Product Structure for Cyber Insurance 2.17 The Bill proposes to protect "Personal Data" relating to the identity, characteristics trait, attribute of a natural person and "Sensitive Personal Data such as financial data, health data, official identifier, sex life, sexual orientation, biometric data, genetic data, transgender status, intersex status, caste or tribe, religious or political beliefs. The key stakeholders under the bill are:- Data Principal - the natural person to whom the personal data relates Data Fiduciary – any person, including the State, a company, any juristic entity or any individual who alone or in conjunction with others determines the purpose and means of processing of personal data; Data Processor – any person, including the State, a company, any juristic entity or any individual, who processes personal data on behalf of a data fiduciary; 2.18 Key provisions Any entity collecting or using personal data should obtain consent from data principal. Processing of personal data should be done only for “clear, 39 Product Structure for Cyber Insurance specific and lawful” purposes. Only that data which is necessary for such processing is to be collected from anyone. Processing of sensitive personal data should be based on “explicit consent” of the data principal. Critical personal data of Indian citizens should be processed in centers located within the country. Other personal data may be transferred outside the territory of India with some conditions. However, at least one copy of the data will need to be stored in India. In case of fiduciaries that are not present in India (e.g. Facebook, Google etc.), the law is applicable to one who carry out the business in India. The data fiduciary shall retain personal data only as long as may be reasonably necessary to satisfy the purpose for which it is processed. The right to be forgotten – It provides a data principal the right against the disclosure of their data when the processing of her personal data has become unlawful or unwanted. The right to confirmation and access allows individuals to find out what is being done with their data. Stringent norms for protecting the data of children, with a provision that companies be barred from certain types of data processing such as behavioral monitoring, tracking, targeted advertising and any other type of processing which is not in the best interest of the child. Every data fiduciary shall implement policies and measures to ensure that, managerial, organizational, business practices and technical systems are designed in a manner to anticipate, identify, and avoid harm to the data principal. The data fiduciary shall take reasonable steps to maintain transparency regarding its general practices related to processing personal data. Every data fiduciary and data processor shall undertake a review of its security safeguards periodically as may be specified and may take appropriate measures accordingly. The data fiduciary shall notify the Authority of any personal data breach relating to any personal data processed by the data fiduciary where such breach is likely to cause harm to any data principal. India does not have sector specific data protection legislation. But directives and guidelines are issued by sector regulators like RBI and IRDAI etc. While at present there is no central authority, The PDP Bill envisages the constitution of the Data Protection Authority of India (“DPAI”) for enforcement of its provisions. Data protection laws apply to businesses established in other jurisdictions also to the extent provided in the respective legislations. 40 Product Structure for Cyber Insurance 2.19 PDP Bill vs GDPR – Similarities & Divergences Similarities Divergences Includes extraterritorial applicability Broader scope of PDP Bill w.r.t definitions of PD & SPDI Functionally similar concept of relevant parties Introduction of consent managers Rights of data principals Vast difference in compliance requirements Privacy by design policy Extensive power to DPA under PDP Bill Security safeguards Age threshold for children and related compliances Similar responsibilities of Data Protection Officer NO SDF or registration of SDF under GDPR Non-EU controllers required to have a representative in EU Data transfer data localization No criminal penalty under GDPR Broad authority to Government under the PDP Bill Sandbox mechanism 2.20 Other laws The Indian Penal Code (as amended by the Information Technology Act) penalizes several cybercrimes. These include forgery of electronic records, cyber frauds, destroying electronic evidence, etc. Identity thefts and associated cyber frauds attract the Indian Penal Code (IPC), 1860 – these can be invoked along with the Information Technology Act of 2000. Relevant sections of IPC are: Section 463 - Forgery Section 464 - Making a False document Section 468 - Forgery for the purpose of cheating Section 469 - Reputation damage Section 471 - Using a forged document as genuine Digital Evidence is to be collected and proven in court as per the provisions of the Indian Evidence Act (as amended by the Information Technology Act). 41 Product Structure for Cyber Insurance In the case of bank records, the provisions of the Bankers’ Book Evidence Act (as amended by the Information Technology Act) are relevant. Investigation and adjudication of cybercrimes is done in accordance with the provisions of the Code of Criminal Procedure, Civil Procedure Code, and the Information Technology Act. The Information Technology Act also amended the Reserve Bank of India Act paving the way for digital payments. Consumer Protection Act 2019 also makes reference to disclosure of personal information under Sec 2(47) Unfair Trade Practice as under: (ix) disclosing to other person any personal information given in confidence by the consumer unless such disclosure is made in accordance with the provisions of any law for the time being in force. Right to privacy is a facet of right to life and personal liberty enshrined under Article 21 of the Indian constitution and has been recognized as fundamental right in the recent judicial pronouncement by the Supreme Court in Justice K.S Putthaswamy v. Union of India. Besides the primary laws dealing with cybercrimes as mentioned earlier, there are sector-specific regulations issued by regulators such as the Reserve Bank of India (RBI), the Insurance Regulatory and Development Authority of India Act 1999 (IRDAI),the Department of Telecommunication (DOT) and the Securities Exchange Board of India (SEBI), that mandate cybersecurity standards to be maintained by their regulated entities, such as banks, insurance companies, telecoms service providers and listed entities etc. 2.21 Other Countries Furnished below is the listing of the provisions in information and cyber security and / or respective statute which may impact respective industry. Region / Country Law European Union (EU) and the European Economic Area (EEA) General Data Protection Regulation (GDPR) USA Identity Theft Act (18 U.S.C. 1028) Access Device Fraud Act (18 U.S.C. 1029) 42 Product Structure for Cyber Insurance Computer Fraud and Abuse Act (18 U.S.C. 1030) Electronic Communications Protection Act (“ECPA”), Health Insurance Portability and Accountability Act (HIPAA) Gramm-Leach-Bliley Act, SEC Security Guidance Singapore Computer Misuse Act, Cybersecurity Act, Evidence Act, Enforcement of Personal Data Protection Commission (PDPC) Some of the above acts are elaborated as below: - European Union (EU) and the European Economic Area (EEA) The General Data Protection Regulation (GDPR) is a regulation on data protection and privacy for all individuals within the European Union (EU) and the European Economic Area (EEA). It also addresses the export of personal data outside the EU and EEA areas. This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data. The GDPR aims primarily to give control to individuals over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU. The GDPR not only applies to organizations located within the EU but also applies to organizations located outside of the EU if they offer goods or services to, or monitor the behavior of, EU data subjects. It applies to all companies processing and holding the personal data of data subjects residing in the European Union, regardless of the company’s location. The GDPR was approved and adopted by the EU Parliament in April 2016. The regulation took effect from May 2018. 2.22 Important provisions from GDPR: Personal Data: Only if a processing of data concerns personal data, this regulation applies. Personal data are any information which is related to an identified or identifiable natural person. Consent of data subject to use/process data: 43 Product Structure for Cyber Insurance Processing personal data is generally prohibited, unless it is expressly allowed by law, or the data subject has consented to the processing. Consent must be freely given, specific, informed and unambiguous. In order to obtain freely given consent, it must be given on a voluntary basis. The consent must be bound to one or several specified purposes which must then be sufficiently explained. Consent must be unambiguous, which means it requires either a statement or a clear affirmative act. The data subject shall have the right to withdraw his or her consent at any time. Processing of personal data: Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject, processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage. Data protection officer: The legal obligation to appoint a Data Protection Officer(DPO) is not the size of the company but the core processing activities which are defined as those essential to achieving the company’s goals. If these core activities consist of processing sensitive personal data on a large scale or a form of data processing which is particularly far reaching for the rights of the data subjects, the company has to appoint a DPO. The duties of a Data Protection Officer include: Working towards the compliance with all relevant data protection laws, monitoring specific processes, such as data protection impact assessments, increasing employee awareness for data protection and training them accordingly, as well as collaborating with the supervisory authorities. Direct marketing: The data subject always has the right to object the processing of personal data for direct marketing purposes. If the data subject objects, the controller has to stop the processing for marketing purposes. Encryption: The Regulation places the responsibility on the controller and the processor to implement appropriate technical and organizational measures to secure personal data. The GDPR deliberately does not define which specific technical and organizational measures are considered suitable in each 44 Product Structure for Cyber Insurance case, in order to accommodate individual factors. Encryption as a concept is explicitly mentioned as one possible technical and organizational measure to secure data. Privacy impact assessment: This refers to the obligation of the controller to conduct an impact assessment and to document it before starting the intended data processing. A data protection impact assessment must always be conducted when the processing could result in a high risk to the rights and freedoms of natural persons. Records of processing activities: GDPR obligates written documentation and overview of procedures by which personal data are processed. Records of processing activities must include significant information about data processing, including data categories, the group of data subjects, the purpose of the processing and the data recipients. This must be completely made available to authorities upon request. The right of access: The right of access includes information about the processing purposes, the categories of personal data processed, the recipients or categories of recipients, the planned duration of storage, information about the rights of the data subject. Information must be provided without undue delay but at latest within one month. Right to be forgotten: Personal data must be erased immediately where the data are no longer needed for their original processing purpose, or the data subject has withdrawn his consent and there is no other legal ground for processing, the data subject has objected and there are no overriding legitimate grounds for the processing. In addition, data must naturally be erased if the processing itself was against the law in the first place. Right to be informed: GDPR gives individuals a right to be informed about the collection and use of their personal data, which leads to a variety of information obligations by the controller. Where data is obtained directly, the person must be immediately informed. The right to be informed also includes information about the duration of storage, the rights of the data subject, the ability to withdraw consent, the right to lodge a complaint with the authorities and 45 Product Structure for Cyber Insurance whether the provision of personal data is a statutory or contractual requirement. In addition, the data subject must be informed of any automated decision-making activities. Penalties for non-compliance: Organizations can be fined up to 4% of annual global turnover for breaching GDPR or €20 Million. This is the maximum fine that can be imposed for the most serious infringements e.g. not having sufficient customer consent to process data or violating the core of Privacy by Design concepts. There is a tiered approach to fines e.g. a company can be fined 2% for not having their records in order not notifying the supervising authority and data subject about a breach or not conducting impact assessment. It is important to note that these rules apply to both controllers and processors. 2.23 United States of America Being at the forefront of computer technology and the country that developed what is today referred to as the Internet, the USA has been the global leader in developing laws relating to cybercrime. While there are a few federal regulations, all the fifty states are free to have their own legislative authorities and there is no such rule that laws should be uniform or consistent. Some of the relevant US laws are: Health Insurance Portability and Accountability Act (HIPAA): The HIPAA Privacy Rule provides federal protections for individually identifiable health information held by covered entities and their business associates and gives patients an array of rights with respect to that information. Gramm-Leach-Bliley Act: This Act requires financial institutions – companies offering consumers financial products or services like loans, financial or investment advice, or insurance etc. to explain their information-sharing practices to their customers and to safeguard sensitive data. Computer Fraud and Abuse Act (18 U.S.C. 1030), which addresses fraud and related activity in connection with computers. Securities and Exchange Commission (SEC): SEC issued guidance to help issuers determine whether they needed to disclose certain cyber- vulnerabilities, past cyber-attacks, and other cyber security matters. In the recent past, it released a report summarizing best practices for securities market participants, including public companies, to monitor, assess, and manage their cybersecurity risk. 46 Product Structure for Cyber Insurance California Consumer Privacy Act (CCPA): The California Consumer Privacy Act (CCPA) is a law that allows any California consumer to demand to see all the information a company has saved on them, as well as a full list of all the third parties that data is shared with. In addition, the California law allows consumers to sue companies if the privacy guidelines are violated, even if there is no breach. The law went into effect on January 1, 2020, but enforcement began on July 1. The CCPA includes two distinct categories of financial losses that could result from noncompliance: private right of action damages, either individually or as part of a class action, and regulatory fines and penalties. Federal Exchange Data Breach Notification Act of 2015: This bill requires a health insurance exchange to notify each individual whose personal information is known to have been acquired or accessed as a result of a breach of security of any system maintained by the exchange as soon as possible but not later than 60 days after discovery of the breach. A violation of this requirement is an unfair or deceptive act or practice under the Federal Trade Commission Act. Cybersecurity Information Sharing Act (CISA) 2015: It is enacted to create a voluntary cybersecurity information sharing process that will encourage public and private entities to share cyber threat information while protecting classified information, intelligence sources and methods, and privacy and civil liberties. Identity Theft Act (18 U.S.C. 1028), which addresses fraud and related activity in connection with identification documents, authentication features, and information and (18 U.S.C. 1028A) which addresses Aggravated Identity Theft. Access Device Fraud Act (18 U.S.C. 1029), which addresses fraud and related activity in connection with access devices. CAN-SPAM Act (18 U.S.C. 1037), which addresses fraud and related activity in connection with electronic mail. Communication Interference Act (18 U.S.C. 1362), which addresses interference to communication lines, stations, or systems. 2.24 Singapore The Computer Misuse Act: It provides for penalty for several cybercrimes including unauthorized access to computer material, unauthorized modification of computer material, unauthorized use / interception of computer service, unauthorized disclosure of access code etc. It also provides for enhanced 47 Product Structure for Cyber Insurance punishment for offences involving protected computers. The Criminal Procedure Code empowers a police officer to access a computer suspected of being used for criminal purposes. The Cybersecurity Act: regulates owners of critical information infrastructure and regulates to cybersecurity service providers. It also authorizes measures to prevent, manage and respond to cybersecurity threats and incidents. The Cybersecurity (Critical Information Infrastructure) Regulations 2018 is also related to this issue. The Evidence Act was amended in 2012, to do away with outdated and cumbersome requirements for admitting computer output as evidence, and to replace these with presumptions regarding the authenticity of electronic records. Enforcement of Personal Data Protection Commission (PDPC): to prevent the unauthorised disclosure of personal data. Bill to amend the PDPC in 2020 (to be confirmed): Fine minimum of SGD 1 million or 10% of turnover Notify PDPC within 3 days and individuals affected The organization must conduct assessment of suspected data breached 3. CRITICAL ISSUES INVOLVING LEGAL ASPECTS OF TRANSACTIONS IN CYBER SPACE 3.1 Cyber law becomes important because it touches almost all transactions and activities involving the computer and internet. Every action and reaction in cyberspace have some legal dimensions. 3.2 In today’s techno-savvy environment, the world is becoming more and more digitally sophisticated and so are the crimes. Internet was initially developed as a research and information sharing tool in a relatively unregulated environment. With the passage of time, it became more transactional with e-business, e- commerce, e-governance, and e-procurement etc. All legal issues related to internet crime are dealt with through cyber laws. As the number of internet users is continuously on the rise, the need for cyber laws and their application gathered great momentum. Some of the regular and well-known transactions in cyber space include: Online banking transactions/ Credit card & debit card transactions Ecommerce transactions Government forms/ returns in electronic form 48 Product Structure for Cyber Insurance Digital signatures Data of all kinds stored in electronic form by various organizations Electronic communication using email, phones, and SMS Share transactions in DMAT form Some of the critical issues involving legal aspects of transactions in cyber space are discussed below. Jurisdiction 3.3 One of the vexing issues in the law relating to cyber space is Jurisdiction. Jurisdiction essentially refers to the concept where the power to determine and hear a case is vested with an appropriate Court in a legal system. The main issue that clouds Cyber Space Jurisdiction is the fact that parties involved in a dispute can be placed across the globe and are connected only virtually. The internet does not recognize any geographical or jurisdictional boundaries, but the users of the internet remain in physical jurisdictions around the world and are thus, subject to laws that are independent of their presence on the internet. A single internet transaction may involve laws of the country in which the user resides or the laws of the country that apply where the server hosting the transaction is located or the laws of the country which apply to the person with whom the transaction takes place. Digital Payments 3.4 With the rise of digital payments, cybercrimes involving payment transactions in the online space have significantly increased and become complex. While the RBI has been active in requiring companies operating payment systems to build secure authentication and transaction security mechanisms (such as 2FA authentication, EMV chips, PCI DSS compliance and tokenization), given that these payment companies often offer real-time frictionless payments experiences to their consumers, it leaves less time for banks and other entities operating in the payment ecosystem to identify and respond to cyberthreats. Hence, there is an increased need to identify and develop cybersecurity standards commensurate with the nature of information assets handled by them, and the possible harm in the event of any cybersecurity attack, to ensure that these emerging risks are mitigated. Cyber Defamation 3.5 Cyber Defamation refers to publishing of false statement about an individual in cyberspace that can injure or demean the reputation of that individual. The ease of accessibility to and publication in online world has led to many cases of cyber 49 Product Structure for Cyber Insurance defamation because of abuse of digital platforms by unscrupulous internet users. Added to this is the speed of travel of the message. While a person can be made liable for defamation both under civil and criminal laws in India, the challenge in this matter would be to identify the persons intending harm, as that person may not reveal his real name and identity in the cyber world. Regulatory notification obligations 3.6 Cyber incidents can have repercussions both nationally and internationally. It is necessary that they are reported as soon as they are detected lest it might cause avoidable damage. Hence, there is a need for reporting them to appropriate authorities. In the Indian context, some provisions relating to reporting obligations are given below: 3.7 There is no specific requirement under the IT Act to inform the data subject of a cybersecurity incident. However, under the Intermediaries Guidelines, the intermediary is required to inform CERT-In of cybersecurity breaches. Further, specific types of cybersecurity incidents (target-scanning or probing of critical networks or systems, unauthorised access of an IT system and data, malicious code attacks, identity theft, spoofing, phishing, etc) have to be mandatorily reported to CERT-In by service providers, intermediaries, data centres and body corporates within a reasonable time of the occurrence of the incident to aid timely action.In addition, sector-specific regulators have their own reporting requirements. For instance, the RBI requires banks to comply with the Cyber Security Framework in Banks, which, inter alia, requires banks to report cybersecurity incidents to the RBI within two to six hours. 3.8 Also, of interest and relevance would be the notification requirements in developed jurisdictions. Notification requirements imposed in many jurisdictions worldwide related to the release of personal information is given in box below: 50 Product Structure for Cyber Insurance Box 2.2. Notification and disclosure requirements and related fines and penalties Data confidentiality breaches involving unauthorized access to personally identifiable information may be subject to notification and/or disclosure requirements (either to a regulator or to those affected) and fines and penalties in several countries: • In the United States, there are prompt notification requirements established at the state- level in all but three states as well as federal privacy requirements that require notification (to regulators and affected individuals) if health or financial information is stolen (Health Insurance Portability and Accountability Act and Graham-Leach-Bliley Act, respectively). The requirements in 36 states as well as the federal requirements related to health information allow for the respective authorities to impose penalties on organizations for the release of that information. In addition, regulatory actions can be brought by a number of federal and state agencies, including the Federal Trade Commission and state Attorney Generals (Allianz Global Corporate & Specialty, 2015). The US Securities and Exchange Commission (SEC) requires disclosure by public companies of cyber incidents, where an incident is "reasonably likely to have a material effect on the registrant's results of operations, liquidity, or financial condition" and where an incident is likely to "materially affect a registrant's products, services, relationships with customers or suppliers, or competitive conditions" (SEC, 2011). Data breach incidents could be included within the scope of this disclosure requirement although a number of significant breaches have not been disclosed by public companies (Tsukayama, 2016). • In the European Union, notification requirements are currently less prevalent although there are potential notification requirements in some sectors. The Payment Services Directive 2, for example, allows for the possibility of public ("payment service user") notification in cases where "an incident has or may have an impact on the financial interests of its payment service users". There are also notification requirements related to incidents that are operationally disruptive to critical services (see the section below on system malfunction). This will change as a result of the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data) which will come into effect in May 2018 and will include more generalized notification requirements. The GDPR will require prompt notification to the supervisor in cases where there is a risk to the "rights and freedoms of data subjects" (and to affected individuals if there is a high-risk) and will impose administrative fines in the case of breaches that are deemed intentional or involving negligence (Steptoe and Johnson LLP, 2016). • In Australia, Canada and Japan fines may be imposed although only in the context of non- cooperation with an investigation or non-compliance with a specific order (BakerHostetler, 2015) (although, in Australia, changes to privacy legislation will lead to broad notification requirements and the potential for penalties of up to AUD 1.8 million for "serious or repeated interferences with the privacy of an individual" to be imposed by federal courts (Lui, 2017)). In Japan, financial sector businesses are required to notify the supervisory authority of data breaches while companies in other sectors may be required to notify supervisory authorities, depending on the nature of the data breach, the type of data involved and the number of 51 Product Structure for Cyber Insurance data subjects affected, along with other relevant factors. In Singapore, the Personal Data Protection Act introduced requirements for the protection of personal data that is collected and fines of up to SGD 1 million can be imposed (Allianz Global Corporate & Specialty, 2015). An amendment to the Republic of Korea's Personal Information Protection Act allows for fines of up to KRW 100 million (and a prison sentence of up to ten years) (PwC, 2016). Mexico also imposes monetary penalties related to violations of the Ley Federal de Protecci6n de Datos Personales en Posesi6n de Particulares (Federal Law on the Protection of Personal Data held by Private Parties). Redressal for unauthorised cyber activity or failure to adequately protect systems and data 3.9 The IT Act makes statutory remedies available to persons affected. Section 43A of the IT Act expressly provides that whenever a body corporate possesses or deals with any sensitive personal data or information, and is negligent in maintaining reasonable security practices and procedures that in turn cause wrongful loss or wrongful gain to any person, the body corporate shall be liable to pay damages to the person affected. Therefore, the affected party may initiate a civil action against the negligent body corporate, making it liable to pay damages. 3.10 Other Legal aspects involved in certain cyber transactions a) It is easy to identify individuals in the real world, but very difficult identify and reach a cybercrime suspect as most forms of online identification are complicated as there are multiple layers between the suspect and the victim. While with the advancement of technology, it is now possible to reach a suspect with all the forensics, it is yet not easy to take and enforce action because of various issues including issues of jurisdiction. b) Many countries have cyber laws dealing with cybersecurity and cybercrimes. As provisions between laws of nations are not always the same and may contradict each other in some areas, there are bound to be issues with judicial outcomes for resolution of disputes in cyber transactions involving multiple jurisdictions. c) Legality of Bitcoins & other Crypto Currency - Bitcoin, as a medium of payment, has neither been authorized nor been regulated by any central authority in India. There are yet no Cryptocurrency regulation in India. 52 Product Structure for Cyber Insurance d) Sanctions - Recently the US and EU issued sanctions against Cyber Hacking Groups, complicating the situation for victims of such attacks. Sanctions may now apply not only to the parties directly involved, but also the facilitators. e) Fines and Penalties under GDPR and PDPB: Insurability of Fines and Penalties could become a moral issue and a matter of Public Policy This issue is particularly relevant in the context of insurance coverage. There is still ambiguity as to which penalties are payable, and which are not. 4. VARIOUS TYPES OF INCIDENTS INVOLVING CYBER SECURITY IN THE RECENT PAST AND POSSIBLE INSURANCE COVERAGE STRATEGIES FOR THOSE 4.1 Internet provides us with many tangible benefits- be it in communication, using search engines, doing financial transactions, availing online / web services, finding employment opportunities, finding life partner or even running entire businesses. Internet touches almost all aspects of our lives. However, it also makes individuals and enterprises, whether large or small, vulnerable to a wide range of threat actions from both internal and external threat actors. 4.2 A cybercrime is a crime involving computers and networks. This includes a wide range of activities, from illegally downloading music files to stealing money from online bank accounts etc. Cyber criminals are not always financially motivated. Cybercrimes include non-monetary offenses as well. It can include frauds such as job-related frauds, matrimonial frauds; stealing and misusing sensitive personal information (Aadhaar details, credit/debit card details, bank account credentials, etc.); defamation of an individual on social media, distribution of computer viruses etc. 4.3 New and powerful cyber-attacks are striking the internet at an alarming pace. A minor lapse in managing our digital lives can open the door to cyber criminals. Cyber criminals can steal our money or damage our reputation. According to a study by a leading industry research organization, 90% of all cyber-attacks are caused by human negligence. Therefore, cyber security awareness is important for everyone today. Over 313,000 cybersecurity incidents were reported in 2019 alone, according to the Indian Computer Emergency Response Team (CERT-In), the government agency responsible for tracking and responding to cybersecurity threats. 4.4 Whilst on the incidents involving cyber security, The CRO Forum (2016)* has developed a set of "incident type groups" that provides a useful categorisation of 53 Product Structure for Cyber Insurance the different types of losses that could be incurred as a result of cyber incidents. The CRO Forum was formed in 2004 to advance risk management practice in the insurance industry. The CRO Forum member companies are large multi-national insurance companies. The members are headquartered across the world with a concentration in Europe. 4.5 The categories of losses put forward by the CRO Forum are described in Table below: "Incident Type Group" (loss types) "Coverage Scope" Business interruption Interruption of operations Reimbursement of lost profits caused by a production interruption not originating from physical damage. Contingent business interruption (CBI) for non-physical damage Reimbursement of the lost profits for the observed company caused by related third parties (supplier, partner, provider, customer) production interruption not originating from physical damage. Data and software loss Costs of reconstitution and/or replacement and/or restoration and/or reproduction of data and/or software which have been lost, corrupted, stolen, deleted, or encrypted Financial theft and/or fraud Pure financial losses arising from cyber internal or external malicious activity designed to commit fraud, theft of money or theft of other financial assets (e.g. shares). It covers both pure financial losses suffered by the observed company or by related third parties as a result of proven wrongdoing by the observed company. Cyber ransom and extortion Costs of expert handling for a ransom and/or extortion incident combined with the amount of the ransom payment (e.g. access to data is locked until ransom is paid). Intellectual property theft Loss of value of an intellectual property asset, resulting in pure financial loss. Incident response costs Compensation for crisis management/remediation actions requiring internal or external expert costs but excluding regulatory and legal defence costs. Coverage includes: (i) IT investigation and forensic analysis, excluding those directly related to regulatory and legal defences costs; (ii) public relations and communications costs; (iii) remediation costs (e.g. costs to delete or cost to activate a "flooding" of the harmful contents published against an insured); (iv) notification costs. Breach of privacy [compensation] Compensation costs after leakage of private and/or sensitive data, including credit-watch services, but excluding incident response costs. 54 Product Structure for Cyber Insurance Network security/security failure [liability] Compensation costs for damages caused to third parties (supplier, partner, provider, customer) through the policyholder/observed company's IT network but excluding incident response costs. The policyholder/observed company may not have any damage but has been used as a vector or channel to reach a third party Reputational damage (excluding legal protection) Compensation for loss of profits due to a reduction of trade/clients because they lost confidence in the impacted company Regulatory & legal defence costs (excluding fines and penalties) A: Regulatory costs: compensation for costs incurred to the observed company or related third parties when responding to governmental or regulatory inquiries related to a cyber-attack (covers the legal, technical or IT forensic services directly related to regulatory inquiries but excludes Fines and Penalties). B: Legal defence costs: coverage for own defence costs incurred to the observed company or related third parties facing legal action in courts following a cyber-attack. Fine and penalties Compensation for fines and penalties imposed on the observed company. Insurance recoveries for these costs are provided only in jurisdictions where it is allowed. Communication and media [liability] Compensation costs due to misuse of communication media at the observed company resulting in defamation, libel, or slander of third parties including web-page defacement as well as patent/copyright infringement and trade secret misappropriation. Legal protection - Lawyer fees Costs of legal action brought by or against the policyholder including lawyer fees and costs in case of trial (e.g. identity theft, lawyer costs to prove the misuse of victim's identity). Assistance coverage - psychological support Products [liability] Assistance and psychological support to the victim after a cyber event leading to the circulation of prejudicial information on the policyholder without his/her consent. Compensation costs in case delivered products or operations by the observed company are defective or harmful resulting from a cyber event, excluding technical products or operations (Technology errors and omissions) and excluding Professional Services errors and omissions). Directors and officers (D&O) [liability] Compensation costs in case of claims made by a third party against the observed company directors and officers, including breach of trust or breach of duty resulting from cyber event. Technology errors and omissions (E&O) [liability] Compensation costs related to the failure in providing adequate technical service or technical products resulting from a cyber event. 55 Product Structure for Cyber Insurance Professional services errors and omissions (E&O)/Professional indemnity [liability] Compensation costs related to the failure in providing adequate professional services or products resulting from a cyber event, excluding technical services and products (Technology errors and omissions). Environmental damage Coverage scope: compensation costs after leakage of toxic and/or polluting products consecutive to a cyber event. Physical asset damage Losses (including business interruption and contingent business interruption) related to the destruction of physical property of the observed company due to a cyber event at this company Bodily injury and death Compensation costs for bodily injury or consecutive death through the wrong-doing or negligence of the observed company or related third parties (e.g. sensitive data leakage leading to suicide). 4.6 Indian enterprises whether big or small are rapidly moving to the digital realm. There have been several cyber-attacks reported in India and around the world in the recent past. Economic consequences of cyber-attack can be immense to business and result into reputational damage. 4.7 Appropriate covers under insurance policies can help mitigate losses resulting from the cyber-attacks. It may be noted that while of some these covers are available under traditional policies, stand-alone cyber insurance is becoming the ideal coverage instrument. Given below is the list of some of the incidents in the recent past with possible applicable covers. Note: Information available in public domain only is mentioned here. Company affected Description of the incident Appliable Insurance Covers Dr Lal Path Labs data leak (October 2020) Dr Lal Path Labs, one of the largest lab testing labs in India, kept the huge data of its patients on a public server unprotected for months. This has exposed the personal data of millions of patients in the public domain making it accessible to everyone last month. The lab testing giant serves around 70,000 patients a day. It was also among the few labs which got permission from 1) Defence costs and damages arising out of Privacy breach 2) Regulatory cost and fines 3) Consultant service cover including Forensics 4) Response cost incurred in making notifications to the affected person 5) Crisis Management Expenses Reference: https://www.the420.in/dr-lal- 56 Product Structure for Cyber Insurance apex health body ICMR to test Covid-19 patients pathlabs-data-leak-fine-of-rs-5- crore-can-be-imposed-as-millions- of-patients-at-risk/ Haldiram’s crucial data stolen (October 2020) According to the FIR lodged, the cyber-attack took place on the intervening night of October 12 and 13 and the hackers may have stolen "entire or substantial data" of the company which runs several restaurants and outlets. Hackers demanded INR 7.50 lakh to release information 1) Consultant services expenses including Forensics 2) Cyber extortion losses 3) Defence costs and damages arising out of data breach (in case if their client data has been stolen) 4) Response cost incurred in making notifications to the affected person Reference: https://www.business- standard.com/article/companies/ha ldiram-s-crucial-data-stolen- hackers-demand-rs-7-5-lakh-to- release-info-120101601338_1.html Amazon hack (May 2019) Amazon was the victim of a serious online attack by hackers who broke into about 100 seller accounts and funneled cash from loans or sales into their own bank accounts, according to a U.K. legal document. The hack took place between May 2018 and October 2018 Amazon found the accounts were likely compromised by phishing techniques that tricked sellers into giving up confidential login information. 1) Defence costs and damages due to Privacy and data breach 2) Consultant services expenses including Forensics 3) Response cost and Notification cost expenses including credit monitoring 4) Crisis management expenses Reference: https://www.financialexpress.com/i ndustry/technology/amazon-hit-by- extensive-fraud-as-hackers- siphon-funds-from-100-seller- accounts/ 57 Product Structure for Cyber Insurance Mondelez data breach (International - June 2017) A global malware incident impacted the company’s business. The malware affected a significant portion of the company’s global Windows- based applications and its sales, distribution and financial networks across the company The company also incurred incremental expenses of $7.1 million because of the incident Mondelez made a claim for the costs on its property insurance policy that, it said, provided cover for “physical loss or damage to electronic data, programs, or software, including physical loss or damage caused by the malicious introduction of a machine code or instruction This claim was repudiated based on ground that the policy did not include a cover for a hostile or warlike action initiated by a government or sovereign power or any state-funded actor/s. This was contested by Insured and the matter is in a court of law in USA. Reference: https://www.cybersecurity- insiders.com/mondelez-files-100m- claim-from-zurich-insurance-for- notpetya-cyber-attack/ British Airways (September 2018) On 6 September 2018, British Airways informed its customers that details from around 3,80,000 booking transactions had been stolen, including bank card numbers, expiry dates and cvv codes. It took the firm just one day to announce it had been hit by a cyber-attack between 21 August and 5 September. Soon afterwards, it was discovered the details were taken via a script designed to steal financial information by 'skimming' the payment page before it was submitted. Defence costs and damages arising out of privacy breach 1) Consultant services expenses including Forensics 2) Crisis Response cost, credit monitoring expenses, notification cost to affected customers 3) Insurable Fines and Penalties 4) Regulatory costs Reference: https://www.pinsentmasons.com/o 58 Product Structure for Cyber Insurance Loosely translated, it appears that the hackers placed themselves in a position to read all of the data coming into BA’s booking system, including customer’s names, addresses, dates of birth, bank details and critically their CVV numbers. (According to the Payment Card Industry Data Security Standard (PCI DSS), which applies to companies accepting credit card information, storing CVV information is not allowed to be held on any company’s data base as they are considered as such a vulnerable piece of information. Not only will British Airways face the bill for making good on all their customers potential losses, but they could also face a large fine. The latest GDPR regulations allows for a fine of up to 4% of worldwide turnover, and for a company that had turnover of £12 billion in 2017, this fine could be more than £480m) ut-law/news/british-airways-fined- 20m-over-gdpr-breach Big Basket user data for sale online (October 2020) India’s top online grocer Big basket has suffered a potential data breach resulting in personal information of over 20 Mn customers being allegedly sold on the dark web. 1) Defence costs and damages arising out of privacy breach 2) Consultant services expenses including Forensics 3) Notification cost. credit monitoring expenses, response cost 4) Crisis management expenses 59 Product Structure for Cyber Insurance Reference: https://indianexpress.com/article/e xplained/explained-how-big-is-the- bigbasket-data-breach-7026688/ Unacademy learns lesson about security (May 2020) Breach dates to January, hacker claims to have access to entire the database. Unacademy, one of the most popular online educational platforms in India, has suffered a major security breach that led to the exposure of data of around 20 million of its subscribers. 1) Defence costs and damages arising out of privacy breach 2) Notification cost, credit monitoring expenses, response cost 3) Consultant service cover including Forensics 4) Crisis management expenses Reference: https://www.theweek.in/news/sci- tech/2020/05/07/unacademy- hacked-data-of-20-mn-users-up- for-sale.html Local search provider JustDial exposes data of 10 crore users (April 2019) More than 10 crore users of local search service Justdial in India have been potentially affected by the data leaks, including their names, email ids, mobile number, gender, date of birth and so on were reportedly made public. 1) Defence costs and damages arising out of privacy breach 2) Notification cost, credit monitoring expenses, response cost 3) Consultant service cover including Forensics 4) Crisis management expenses Reference: https://www.timesnownews.com/bu siness- economy/companies/article/justdial -data-breach-affects-more-than- 10-crore-users/402297 Dr. Reddy's Laboratories Ltd. (October 26, 2020) Indian pharmaceutical company Dr. Reddy Laboratories reported a cyber-attack about a week after the company was granted permission to begin its final 1) Defence costs and damages arising out of Privacy breach 2) Regulatory cost and fines 3) Consultant service cover including Forensics 60 Product Structure for Cyber Insurance stage trials for a Russian COVID-19 vaccine. In a statement to the National Stock Exchange of India, the company said it had isolated all data centers services and took required preventive actions. 4) Response cost incurred in making notifications to relevant authorities Reference: https://www.scmagazine.com/hom e/security-news/dr-reddy-labs- discloses-cyberattack-soon-after- getting-ok-for-final-covid-vaccine- trial/ Mega Mumbai power outage (October 2020) A malware attack is suspected to be the reason behind Mumbai's power outage last month. The case is being probed by the state's cyber department and the final report is awaited. 1) Consultant service cover including Forensics 2) Business interruption losses Reference: https://www.indiatoday.in/india/stor y/mumbai-power-outage-malware- attack-1742538-2020-11-20 5. CYBER LIABILITY INSURANCE COVERS AVAILABLE IN INDIAN MARKET AND IN OTHER DEVELOPED JURISDICTIONS Cyber Insurance in India 5.1 Cyber insurance market in India and abroad is growing but it is still quite small compared to other insurance lines of business. Only a small fraction of cyber losses is currently insured. Still the demand for cyber coverage remains limited. Many companies be it in service industry or manufacturing industry do not yet appreciate the full extent of cyber risk, or they assume that traditional insurance lines will protect them. Others like financial institutions recognize the risk but see cyber insurance coverage as too narrow or ambiguous to guarantee adequate recovery at their hour of need. 5.2 Insurance companies on the other hand, are treading cautiously, expanding their offerings at a conservative pace. Most cyber insurers offer small coverage limits and high deductibles, and they may limit coverage in areas like business interruption, because cyber risk is difficult to estimate and price accurately. Further, there is too little actuarial data to draw upon. The risks at play evolve continuously based on unpredictable changes in digital technology itself, the radically changing patterns of technological use, hacker/perpetrators’ capabilities / intentions etc. 61 Product Structure for Cyber Insurance 5.3 These and other challenges of covering cyber risk are well-known in the insurance world globally. Internationally and in India, Insurers, insureds, and governments have worked steadily and incrementally to address them. Consequently, more cyber insurance coverage is being sold each year—including policies specifically created for cyber risk (known as “standalone” cyber coverage), as well as some traditional lines, like property and casualty insurance, that are revised to include cyber alongside other risks (adding a “cyber endorsement” to a broader policy). Synopsis of Covers Available in Indian Market 5.4 Cyber insurance can be offered as a stand-alone product and as an add-on coverage to traditional lines of business. It can include coverage for both first party and third-party liabilities. Most insurers provide insurance solutions with appropriate endorsements and add on services as well and some insurers also offer their products through coinsurance and reinsurance with other insures due to capacity constraints. The standard coverages currently available and normally offered in India in a stand-alone cyber insurance policy can be summarised as below: First party Coverage Third Party Liability Coverage Coverage for other services Business interruption losses Cyber Extortion Theft of funds/ Loss of funds Data restoration costs Privacy and Data Breach Liability including Customer notification and Credit Monitoring Network Security Claims Cover Multimedia / Media Liability Cover Regulatory / Data administrative inquiry and insurable fines and penalties E-payment Contractual Damages Defence Costs Crisis management cover including public relations costs Consultant Services Cover As indicated, coverage for losses due to cyber incidents can be categorized by differentiating between losses borne as a direct result of the incident (first party coverage) and losses incurred as a result of litigation by alleged injured parties (third 62 Product Structure for Cyber Insurance party coverage) and coverage for other services. As policy wordings vary from insurer to insurer, only major generic coverage features, exclusions and extensions are discussed here. 5.5 . COVERAGE: 5.5.1 First Party Coverage: a) Business interruption: Coverage is offered for business interruption loss (loss of net profits) as a result of a Cyber-attack that causes total or partial unavailability of the company’s computer system which are in direct control of the insured. Coverage for such loss of profit is subject to waiting periods (in hours or days) as agreed in the policy. Further, costs incurred to restore the Company’s Computer System to the same level of functionality which existed immediately prior to such event and the costs to retrieve or reinstall Data or Computer Programmes are also offered. Also, the costs associated with continuing to run the insured’s business, including payroll expenses, as well as the costs associated with reducing the impact of the income loss (generally referred to as extra expenses) are also covered. Proof of loss is required by the insurer to quantify the losses claimed by the insured. In some instances, a forensic accountant may be called upon to perform a more thorough analysis to substantiate the extent of loss. b) Cyber Extortion: Coverage is offered for Cyber Extortion Loss that the Insured incurs solely and directly as a result of a Cyber Extortion Threat. Such loss is triggered when a hacker breaks into computer system and threatens to commit a wicked act like damaging the data, introducing a virus, initiating a denial of service attack, or releasing confidential data unless the insured pays a specified sum. Coverage typically extends to any extortion payment that the company has to make and expenses incurred while responding to the demand. Cyber extortion can take various forms, but ransomware is by far the most common variant. Ransom ware is a type of malicious software that, when launched within a computer (usually from an e-mail opened by an unsuspecting employee), encrypts data or locks access to critical applications. An anonymous demand for payment then overlays the computer screen demanding payment, usually in bitcoin or any other currency—a form of 63 Product Structure for Cyber Insurance electronic currency that is difficult to trace—in exchange for the decryption key. Other forms of cyber extortion include denial-of-service attacks that disrupt networks until payment is made, or threats to disclose customer data or other confidential information unless a specific demand is met. Possible losses could be forensic cost, cost of consultant to negotiate with fraudsters and extortion money. c) Theft of Funds/ Loss of Funds Cover: Coverage is offered for IT Theft Loss caused due to Funds wrongfully or erroneously paid by the Insured as a direct result of hacker’s intrusion into the Company’s Computer System which results in fraudulent and unauthorised deletion or alteration of Data contained in the Insured’s Computer System. As a result of tampering within the insured computer systems, the insured ends up becoming inadvertent victim of fraudulent, dishonest, or malicious payment instructions and fund transfers. This coverage could also extend to include loss sustained due to unauthorised communication triggered by insured’s computer system to financial institutions, suppliers or such other third parties that lead to fraudulent fund transfers or financial transactions. d) Data Restoration Costs: Coverage is offered to technically restore, retrieve or reinstall Data or Computer Programmes, including the cost of purchasing a software licence necessary to reproduce such Data or Computer Programmes which would have got lost or impacted during a cyber-attack incident. 5.5.2 Third Party Liability Coverage: a) Privacy and Data Breach Liability including customer notification and credit monitoring costs: Coverage is offered for Damages and Defence Costs for a claim made against the Insured by any affected person or a client resulting from a privacy beach or a data breach for which the Insured is legally liable. Sensitive, personal, or confidential third-party data that resides with the Insured could get compromised due to a cyber-event and could lead to third party claims for damages. Data breaches are characterized by (1) loss, theft, or unauthorized disclosure of personally identifiable information (PII) in company’s care, custody, and control; (2) damage to data stored in the company’s computer systems belonging to a third party; (3) transmission of 64 Product Structure for Cyber Insurance malicious code or denial of service to a third party's computer system; (4) failure to timely disclose a data breach; (5) failure of the company to comply with its privacy policy prohibiting disclosure or sharing of PII; and (6) failure to administer an identity theft program required by governmental regulation or to take necessary actions to prevent identity theft. In addition, this clause covers the cost of defending claims associated with each of these circumstances. Insured could also incur substantial Response costs that may include (i) notification expenses towards the affected third parties and regulators in such an event (ii) credit monitoring services for a defined period - these include the monitoring of one's credit history for a specified period for to detect any suspicious activity or unauthorized charges. It also may provide special alerts when there are noticeable changes to one's credit history (iii) cost of identifying and preserving relevant Data on the Company’s Computer System b) Network Security Claims Cover: Coverage is offered for Damages and Defence Costs arising from Third Party Claim against an Insured for any actual or alleged act, error or omission of the Insured as a result of which a Cyber Attack would have occurred. It covers claims against company for negligent acts, errors or omissions that result in a denial of service attack, unauthorized access, introduction of a virus, or other security breach of the Insured’s computer system. This clause also offers cover for claims alleging company’s failure to protect sensitive data stored in company’s computer system. c) Multimedia / Media Liability Cover: Coverage is offered for damages and Defence Costs arising from Third Party Claim made against an Insured for Media liability in context of Insured’s publication or broadcasting of any digital media content. This clause offers cover for lawsuits against company for acts like libel, slander, defamation, and copyright infringement, invasion of privacy or domain name infringement. These acts are covered only if they result from company’s publication of electronic data on the Internet. d) Regulatory / Data administrative inquiry and insurable fines and penalties: Coverage is offered for insurable fines and penalties and defence Costs arising from a Claim by a Regulator made against an Insured which arises out of a Data Breach or Privacy Breach. 65 Product Structure for Cyber Insurance It covers the costs of dealing with privacy regulatory authorities / agencies (which oversee data breach laws and regulations), including the costs of hiring lawyers to consult with regulators during investigations and the payment of regulatory fines and penalties (insurable by law) that are levied against the insured (as a result of the breach). Data breaches typically involve customers residing in multiple countries and because each country has its own unique set of laws and rules, regulatory defence and penalties coverage is especially valuable given the need for company to deal with multiple sets of regulators. e) E-payment Contractual Damages: Coverage is offered for Damages, Contractual Damages/Penalties and Defence costs arising from a Claim made against an Insured by a E-Payment Service Provider alleging a negligent breach of any published Payment Card Industry Data Security Standards that the Insured is required to comply with. Companies engaging into contract with payment service providers may face serious actions from such service providers when the Insured fails to comply with payment card industry related regulations. Such losses could include defence costs, claim investigation costs, court awards and contractual penalties. f) Defence Costs: Coverage is offered for expenses including the cost of hiring a lawyer, court fees, investigations, gathering facts, filing legal paperwork, and other related costs that the Insured may incur to defend itself from legal claims made by third parties like customers and regulators. 5.6 Services offered: a) Crisis management cover including public relations costs: Coverage is offered for Public Relation Expenses incurred by the Insured to prevent or reduce the effects of negative publicity caused due to a cyber-attack event. This provides cover for costs incurred for hiring a public relations consultant for managing the marketing and public relations for the Insured to protect their reputation following a cyber-attack event. b) Consultant Services Cover: Coverage is offered for consultant costs incurred by the Insured: 66 Product Structure for Cyber Insurance to prove the amount and the extent of a covered Loss and to investigate the source of such Loss and adequate steps to mitigate it. To prove that the Insured on the ground of facts reasonably suspects a Privacy Breach, Cyber Attack or Business Interruption Event, to investigate if and to what extend such Privacy Breach, Cyber Attack or Business Interruption Event has taken place, the causes of such event and how it can be mitigated. IT and forensic expert costs incurred to investigate cyber-attack related events are covered. Such costs are integral to the policy coverage as cyber claims are quite complex and significant IT and forensic efforts are required to manage and quantify the effect and extent of a cyber loss. 5.7 EXTENSIONS: 5.7.1 Cover for Cyber Terrorism - Coverage for claims emanating from or perpetrated by cyber terrorists: Cyberterrorism is the use of the Internet to conduct violent acts that result in, or threaten, loss of life or significant bodily harm, in order to achieve political or ideological gains through threat or intimidation. Companies could become victims of such disruptive Internet activities and incur first party and third-party losses. 5.7.2 Reward Expenses: Reward Expenses offered by the Insurer for information that leads to the arrest and conviction of any individual(s) committing or trying to commit any illegal act. This extension offers cover for the amount that an Insured pays to an Informant for information not otherwise available which leads to the arrest and conviction of persons responsible for a Cyber-attack, Fraudulent Access or Transmission, or a Threat. 5.7.3 Psychological Support expenses: This extension covers all reasonable expenses for any trauma or distress caused to a stakeholder of the Insured because of a cyber-attack. Cyber situations can potentially cause psychological distress to the persons involved in the crisis. This extension offers cover for counseling expenses incurred by such affected parties. 5.7.4 PCI DSS Assessment cover / E-payment Cost: Coverage for any written demand received by an Insured from a Card Association or Acquiring Bank imposing assessment costs. Company’s negligent breach of published card industry regulations may be exposed to claims by E-Payment Service Provider 67 Product Structure for Cyber Insurance for damages. Losses could include defence cost, contractual penalties, and court awards. 5.7.5 Social Engineering coverage: Comprehensive cover for loss arising from impersonation of critical stakeholders that are acted upon based on good faith by the insured. Companies could become victims of third party’s fraudulent electronic payment communications as fraudulent or dishonest impersonation of a company’s Director, CEO, CFO. This may result into direct loss of funds. 5.8 MAJOR EXCLUSIONS: 5.8.1 Dishonest or Deliberate Wilful conduct Any fraudulent, dishonest activity, willful violation, breach of law done by the insured stands excluded from scope of coverage. This exclusion could be amended to include defence cost coverage for innocent insured and could also contain final adjudication clause. 5.8.1 Contingent Business Interruption This clause excludes any business interruption loss resulting from damage to the computer system of a service provider or a supplier on which the insured depends. 5.8.2 External Infrastructure Failure This clause excludes any claims arising due to any electrical or mechanical failure of infrastructure including any electrical power interruption, surge , brown out , black out , failure of telephone lines , data transmission lines , any satellite failure or any other telecom / network infrastructure which are not under the control of the insured / the outsource service provider. 5.8.3 Bodily Injury and Property Damage This clause excludes any actual or alleged bodily injury, sickness, mental anguish or emotional distress or disturbance, disease or death of any person howsoever caused or damage to or destruction of any tangible property, including loss of use thereof. As the control and operation of physical assets becomes increasingly managed by computers that are themselves interconnected, cyber-attack on automation / operational technologies could cause property damage and bodily injury related losses. Such losses are 68 Product Structure for Cyber Insurance excluded from cyber policy as the Property and casualty policies are expected to address coverage for bodily injury and property damage. Insurers may consider extending the coverage by amending the definition of Bodily Injury to include mental anguish, mental injury, emotional distress resulting from a Privacy Breach or Media Wrongful Act. 5.8.4 War, terrorism, Invasion, riot, or insurrection This clause excludes coverage for loss from acts of war, terrorism, invasion, and/or insurrection. Since the repercussions of state-sponsored, political, and ideological cyber-attacks could be too vast and across industries, coverage for such events is excluded. For ex. NotPetya exposed a serious ambiguity in how insurance policies treat state-sponsored cyber incidents. Some property and casualty insurers declined to pay NotPetya-related claims, invoking their war exclusions. However, recently there is coverage available for “cyberterrorism” or “electronic terrorism”, but Cyber war still stays as a common exclusion. 5.8.5 Monetary and Trading losses The theft of money, trading losses or securities are typically excluded from a cyber-policy. 5.8.6 Prior act Cyber policies typically exclude any cyber incidents which existed prior to the insurance policy commencement. 5.8.7 Unauthorized collection of data and Unsolicited Communication This clause excludes any unlawful or unauthorized collection of data and distribution of unsolicited correspondence or communications (whether in physical or electronic form), wiretapping, audio or video recordings or telephone marketing. 5.8.8 Contractual Liability/ Assumed liability The policy excludes any liability under any contract, agreement, guarantee or warranty assumed or accepted by an Insured except to the extent that such liability would have attached to an Insured in the absence of such contract, agreement, guarantee or warranty 69 Product Structure for Cyber Insurance Study on the Cyber Insurance in other Jurisdictions including USA 5.9 The USA is the largest market and is estimated to account for the 90% of the Global standalone Cyber premium. It has been the main contributor behind the growth of cyber premium. The impressive growth rates in their cyber markets have been driven by several factors like; Data breach legislation was progressively enforced in almost all the states in the USA ( Alabama and South Dakota are the only ones without a statute ) Mandatory Data Breach disclosure law was first signed in 2002 in California making firms legally obliged to notify affected parties in the event of data breach. Similar legislations were subsequently enforced in other states between 2005 to 2016. A rising awareness on Cyber threats involving large corporations targeted by hacking groups like Sony in 2011, Target in 2014, E-Bay in 2014 and Yahoo breaches of 2013-14 disclosed in 2016 etc. 5.10 The U.S. market is much more developed than its European counterpart, partly because the U.S. have had reporting requirements for cyber-attacks in place for several years with relatively heavy fines for violations. These regulations have considerably increased the awareness of cyber risk and increased the demand especially for liability (third party) cyber coverage. The U.S. market is thus mainly dominated by third party coverage, whereas in Europe focus more on first party coverage. However, GDPR in the EU has become an important driver in the development of the European cyber insurance market. On a comparison of the policy coverage in India with the global policy offerings, it is observed that the following covers which are available globally, are not available in India currently in the normal course or offered by few insurers selectively. The reasons are not difficult to understand as cyber insurance is in a nascent stage in India. 5.10.1 Bricking costs: Cyber products usually cover costs to replace / restore / recreate data and software that have been destroyed, corrupted or damaged and not the Computer System itself (computer, server, mobile phones, Industrial control systems, etc.) using / storing such data or software. Purpose of this extension is to cover replacement costs for such equipment that is rendered useless for its intended purpose because of a Security Incident or a System Failure (“bricking”). 70 Product Structure for Cyber Insurance 5.10.2 Coverage for Hardware Betterment costs: These include digital asset replacement costs the insured incurs due to the alteration, modification, deletion, denial of access to, damage, corruption or destruction of digital assets. Hardware betterment expenses include increased memory capacity or processing speed necessary to install more secured IT system standard technological advances. These may be necessary to prevent the re-occurrence of alteration, modification, deletion, denial of access to, damage, corruption or destruction of digital assets caused by a cyber-attack. 5.10.3 Crypto Currency Payments: Cyber Extortion loss which provides coverage for payment in Digital Currency including Crypto Currency particularly for payment in respect of extortion payments. As on date, there is no clarity on the legality of crypto currency payments in India. 5.10.4 Consumer Redress Fund: This provides coverage for payment which the Insured is legally required to pay, or has agreed to pay by way of settlement, to establish a fund for the payment of consumer claims. This may include fines and penalties which the insured’s customer may be required to pay because of a security incident or data breach attributable to the insured. 5.10.5 Contingent Business Interruption: The objective here is reduce the impact of the events outside the control of Insured. It covers business interruption loss and expenses incurred as a result of an interruption, degradation of service or unplanned suspension of a supplier / receiver Computer System. It creates exposure to third party IT systems which are commonly used as entry point for cyber-attacks. The cyber contingent business interruption risk of an insured single company is characterised by the exposure and the information security level of the relevant provider of IT services or of the suppliers of goods. There are insured organisations which represent a higher exposure than others by virtue of their industry sector. For example, there is an above average dependence on IT services by retailers, financial institutions, and IT service providers themselves, as well as by organisations active in the tourism, hospitality, logistics and transportation industries. Given the complexity as well as the loss potential of the exposure, providing cyber Contingent Business Interruption coverage is unlikely to be offered as a standard offering on the market. As there is limited expertise and capacity available in this space currently, this is offered by a few insurers very selectively. 5.10.6 System/ Technical failure: This provides coverage for business interruption caused by Unintentional / Unplanned outage of computer systems. Unexpected 71 Product Structure for Cyber Insurance technical failure of the Company’s Computer System which causes a loss, destruction or modification of Data or Computer Programmes is covered. Technical failure includes failures in power supply, but only if the power supply is under direct operational control of the Insured; over and undervoltage and electrostatic build-up and static electricity. 5.10.7 Carve-back for Bodily Injury and Property Damage (BIPD) exclusion: Cyber insurance policies exclude any actual or alleged bodily injury, sickness, disease or death of any person and any damage to or destruction of any tangible property, including loss of use thereof. With absolute cyber exclusions under other policies becoming increasingly common, there is a need to cover cyber incident triggered bodily injury and property losses, so that they do not fall in a no man’s land. Value Added services It may be noted that insurers may not offer all services, mentioned below, free of cost and some of them may attract a fee – separately or built in as a part of premium. 5.10.8 Vulnerability scan: Services are provided to remotely scan a business’s internet-facing infrastructure to identify vulnerabilities that are open to potential exploitation by cyber criminals. The scanning service helps detect and prioritises hidden risks and provides a detailed view of a company’s vulnerability status so they can better track, understand, and works towards fixing them. 5.10.9 Proactive shunning and training: Before initiating an attack, criminals often conduct reconnaissance to confirm an IP address is a viable target. Shunning prevents these communications from reaching a network, reducing the risk of an attack. If a network is already compromised, shunning can also prevent communication back to the criminal’s servers, effectively disarming malware. Web-based training is also made available to proactively reduce the single largest cybersecurity risk to an organisation: human error. 5.10.10 Cyber-security information portal: This Portal provides online access to a centralized hub of educational and technical cybersecurity information that can help assist in the prevention of a breach. Resources include training tips, cyber news and articles, cyber risk assessments and a variety of valuable tools and calculator. 5.10.11 Simulation Exercises: How the insured would respond, should a cyber-attack take place? These exercises help test efficacy of the incident response in the event of a cyber-attack. 72 Product Structure for Cyber Insurance 6 RECOMMENDATION OF THE SCOPE OF THE CYBER LIABILITY INSURANCE COVERS FOR THE PRESENT CONTEXT AND FOR THE MEDIUM TERM Introduction: 6.1 The changes in the cyber risk landscape entails continuous study of the cyber insurance covers to ensure that they respond adequately. While Cyber insurance offerings in India compare well, on many parameters, with that are available globally, enhancement of scope of coverage is always work in progress. As the Indian industry gathers more experience, it can move further to offer covers or services not offered currently. 6.2 Any risk to an individual or an organization, accidental or malicious, arising from a loss, failure, or misuse of its own or a third party’s information technology systems - this may lead to physical and non-physical losses. Physical Loss: e.g.: Property damage, Bodily Injury Non-physical Loss: e.g.: Loss of data, non-damage business interruption, extortion, fraud. 6.3 These losses are mitigated by Cyber specific and Standard first and third party covers. Further cyber covers are offered as a part of bundled policies or as Cyber extensions within other classes. Standalone Cyber products: Coverage for losses due to cyber incidents can be categorized by differentiating between losses borne as a direct result of the incident (First party coverage), and losses incurred as a result of litigation by alleged injured parties (Third party coverage). It also provides coverage for other services. 73 Product Structure for Cyber Insurance Bundled Products: Cyber covers combined with other lines such as Errors & Omissions Insurance (E&O) and Crime Insurance. Cyber Extensions: built-in extensions, endorsements, and exclusions carved- back in standard products. Evolution of Cyber in medium term 6.4 There is significant uncertainty in the market on covers to be bought, appropriate limit purchase, and taking right deductible. Attacks on establishments are increasing and every year new cyber incidents are carried out on specific targeted industries. During NotPetya and WannaCry, healthcare, logistics, and manufacturing establishments were targeted, during Covid-19 pharma companies and schools were targeted. Coverages are evolving, more and more demands would evolve in medium term based on new discoveries about these incidents. All these demand that cyber insurance underwriting teams invest more in cyber knowledge to build expertise to properly develop and manage their portfolio. 6.5 It is worth noting that cyber insurance is only a part of the service that insurance companies provide. Many other services are also offered during the life cycle of the policy which help the insured in better understanding of the risk leading to prevention and mitigation of losses. These are necessary for both small and large clients, even though the scale varies, as a part of complete solution. Indicative examples are given below. Some of the services may be free and others invite some fee. Examples of Cyber insurance panel of services 74 Product Structure for Cyber Insurance Recommendations for enhancement of scope of the cover for the present context and in the medium term 6.6 Cyber risks are not static. Therefore, cyber insurance covers cannot be static. It is necessary that as the market evolves in response to the emerging needs, the scope of the cyber policy needs to be enhanced. Cyber insurance being much reinsurance dependent at present, the breadth of the coverage enhancement, the pace of addition and pricing depend upon the perception of reinsurers/insurers about the claims experience and exposures including accumulation exposures in this space in India and globally. Yet, evolutionary hiccups should not deter the insurance industry in keeping pace with technology and the challenges it unfolds. The following steps and covers are recommended to facilitate the development of a resilient and robust cyber space, both in the short and medium term. Present Context: 6.7 Addressing Silent Cyber: Insurers may place this matter high on the agenda and address this problem sooner than later. In simple words, it is when the policy explicitly does not exclude Pre-bind Cybersecurity assessment & scoring Cybersecurity technical audits and recommendations Cyber training for insureds Post-bind Call center with dedicated triage Legal / PR / Crisis management advice Forensic experts End customer notification ID / Credit monitoring 75 Product Structure for Cyber Insurance or include coverage. This is also known as “unintended” or “non-affirmative” cyber coverage. Cyber exposure is a concern for all underwriters. Cyber affirmative and silent covers are scattered in many different products beyond Standalone ones. Cyber risk permeates all classes of insurance without boundaries of industries. A cyber event can trigger losses across various lines of insurance – property damage and business interruption resulting from computer systems failure / virus under property insurance, siphoning money through phishing under crime insurance, product liability / recalls from security vulnerabilities under product liability / recall insurance, breach of contract / negligence claims under E&O insurance and for managerial negligence under D&O insurance (FedEx case). 6.8 Insurance cover may respond in one of following 2 ways: Affirmative cover: Covered through cyber specific policies for the coverage as mentioned above. Non-affirmative cover: Policy explicitly does not exclude or include coverage. This is also known as “unintended” or “non-affirmative” cyber coverage. 6.9 When cyber insurance was introduced in the 1990s, the focus was on covering data breach exposures in response to regulations framed by authorities in USA and Europe. Later, with business operations getting more digital and owing to spread of all-pervasive influence of information technology, insurers started 76 Product Structure for Cyber Insurance offering wider coverage. But there was not much foresight about the seepage of silent coverage in other lines of insurance like property, marine and general liability insurance etc. Many property and liability insurance policies were designed when cyber wasn’t perceived as a major risk. These policies often did not explicitly mention cyber coverage. While the insurance fraternity debated this issue as a part of regular review of operations, albeit at a low volume, the devastating NotPetya attack and other high-profile cyber security events, in the recent past, have placed the issue high on the agenda for the insurance industry. 6.10 Having recognized the need to avoid assumption of unintended exposures / losses Insurance Regulators have also expressed concerns about lack of certainty in Policy coverage and inadequate risk assessment, in response market has engaged a clarification process. PRA (Prudential Regulation Authority, UK) was first to express concerns in 2019: “All insurers should have action plans to reduce the unintended exposure which can be caused by non-affirmative cyber cover” Lloyd’s responded in a staged approach addressing all (re)insurance classes in 4 phases (January 2020 July 2021) and LMA (Lloyd’s Market Association) panels subsequently issued Cyber clarification clauses: “Lloyd’s underwriters are required to ensure that all policies affirm or exclude cyber cover”. Most large insurers have also issued Cyber endorsements to their P&C products. 6.11 It is necessary to address this issue and ensure that all policies either affirm or exclude cyber cover leaving no scope for vagaries of future interpretations. Listed below are some of the common exclusions in the market which take away the cover Insurance: NMA 2914; NMA 2915; CL380; NMA 2981; NMA2982 … Reinsurance: NMA 2912; NMA 2928; IT clarification agreement … NMA 2914, NMA 2915 excludes non-physical loss only, CL 380: excludes physical and non-physical loss Most of these clauses have been drafted in the early 2000’s and are not capturing the most recent developments of Cyber risks 77 Product Structure for Cyber Insurance As an attempt to clear these issues, new clauses are being drafted for various markets: property (LMA, IUA), engineering (IMIA), aviation (AICG), etc. Comprehensive Solutions: 6.12 Insurers must work towards offering comprehensive solutions rather than mere loss mitigation products, not only as a customer friendly initiative but also as a good risk mitigation measure. The bouquet of services has been discussed earlier in the chapter. Clarity relating to some payments: 6.13 Insurers should strive to bring clarity to coverage on fines and penalties which remains unclear at this moment as discussed below. It is now well known that GDPR has exacerbated exposure to regulatory fines and question of insurability. It is found that in many EU countries, such fines are not seen as insurable since contrary to public policy. Source: DLA Piper 78 Product Structure for Cyber Insurance Bricking costs: 6.14 Cyber products usually cover costs to replace / restore / recreate data and software that have been destroyed, corrupted or damaged and not the Computer System itself (computer, server, mobile phones, Industrial control systems, etc.) using / storing such data or software. Purpose of this extension is to cover replacement costs for such equipment that is rendered useless for its intended purpose. Removal of Reference to Targeted intrusion: 6.15 Targeted intrusion refers to intrusion by the attackers to identify a target and then infiltrate the target’s network to achieve their objectives. Some of the policies currently cover only targeted intrusion into the computer system which is mostly not the case. The attack is usually targeted to multiple web users/content users and the said condition again leaves a gap in the coverage. Given the need for this cover, insurers may remove reference to targeted intrusion and extend cover as long as it is unauthorised. Bodily injury and Property Damage (BIPD): 6.16 Cyber insurance policies exclude any actual or alleged bodily injury, sickness, disease or death of any person howsoever caused Property Damage and any damage to or destruction of any tangible property, including loss of use thereof. With absolute cyber exclusions under other policies becoming increasingly common, there is a need to cover cyber incident triggered bodily injury and property losses, so that they do not fall in a no man’s land. Contingent Business Interruption: 6.17 It covers business interruption loss and expenses incurred as a result of an interruption, degradation of service or unplanned suspension of a supplier / receiver Computer System. It creates exposure to third party IT systems which are commonly used as entry point for cyber-attacks. The cyber contingent business interruption risk of an insured single company is characterised by the exposure and the information security level of the relevant provider of IT services or of the suppliers of goods. There are insured organisations which represent a higher exposure than others by virtue of their industry sector. For example, there is an above average dependence on IT services by retailers, financial institutions, and IT service providers themselves, as well as by organisations active in the tourism, hospitality, logistics and transportation industries. 79 Product Structure for Cyber Insurance Given the complexity as well as the loss potential of the exposures, Cyber Contingent Business Interruption coverage is being provided on a very limited scale currently Medium Term: Cyber Reputation loss: 6.18 Covers loss of net profit that a company is prevented from earning due to damage to company’s reputation caused by a Cyber-attack. Most of the policies currently offer coverage for mitigation and crisis management expenses to preserve reputation / image of the insured. The widened extension can also cover business interruption loss as a direct consequence of a reputational damage. In this context, it may be noted that lack of clear measurement of impact of reputation damage on income makes loss assessment/ adjustment challenging. Coverage for Hardware Betterment costs: 6.19 These include digital asset replacement costs the insured incurs due to the alteration, modification, deletion, denial of access to, damage, corruption or destruction of digital assets. Hardware betterment expenses include increased memory capacity or processing speed necessary to install more secured IT system standard technological advances. These may be necessary to prevent the re-occurrence of alteration, modification, deletion, denial of access to, damage, corruption or destruction of digital assets caused by a security event. Voluntary shutdown: 6.20 Following a cyber-attack, particularly manufacturing companies may have to temporarily shut down/ isolate some of their facilities when they are on the same network to take required preventive actions after the detection of the cyber-attack. This in fact may help avoid spread of the loss. 7 CHALLENGES IN DEVELOPING STANDARD COVERAGES, EXCLUSIONS, AND OPTIONAL EXTENSIONS FOR VARIOUS CATEGORIES 7.1 Cyber liability insurance in India is still evolving and the current ecosystem allows it to innovate and bring solutions to the market with agility. As the cyber insurance market evolves, some amount of convergence would emerge among players on best practices and this section of the report will help provide a point of reference to underwriting, claims, reinsurance, services, sales and other practitioners operating across the cyber insurance segment in India. Coverage aspects, 80 Product Structure for Cyber Insurance extensions and exclusions have been extensively discussed in earlier paras. Other relevant matters are as under. Underwriting and Pricing Methodology 7.2 Cyber Risk Insurance is different from other Insurance coverage as there is no standard scoring systems or actuarial tables for rate making. Cyber risk is a relatively new concept, and data on security breaches and losses either do not exist or exist only in miniscule quantity. The issue is further exacerbated by the reluctance of organizations to disclose details of their security breaches as it could lead to loss of market share, loss of reputation and so forth. Modelling Cyber risk is inherently extremely challenging due to lack of available and standardized cyber incident data, and the continuously and rapidly changing nature of risks. 7.3 Available data on cyber risk underwriting is at a very nascent stage because of which standardized and established strategy for pricing and assessment is still far- fetched as the actuaries do not have the data sets of the standard that they are used to working with. 7.4 The need of the hour is that all the Insurers capture the data in similar to facilitate more efficient data transfer between the industry participants (client to broker to insurer to reinsurer) which will facilitate anonymous data sharing mechanism for the benefit of the entire market. 7.5 As per Institute and Faculty of Actuaries, Cyber is an Evolving risk. There are many factors are many factors involved which in turn result into many attacks as highlighted in the Figure below with examples. 81 Product Structure for Cyber Insurance (Institute of Faculty of Actuaries – Cyber Pricing) 7.6 Meanwhile, insurers rely on certain common underwriting practices to evaluate cyber exposures for each insured on a case specific basis. 1) Scale, Scope and Type of Insured’s operations a. Turnover, Employee strength, geographical spread b. Type of services/business/products offered – Industry specific cyber threat vectors c. Level of Outsourcing and partners involved 2) Nature of data held by the insured and the security framework around it a. Data protection and Privacy policy followed by the Insured b. Compliance with ISO, GDPR and other data protection guidelines laid across geographies c. Data access (firewalls, access restrictions, etc.) and recovery plans (data back- up and recovery framework) – IT and Network security plans 3) Understand the technology framework of the insured including the level of inter- connected ness and related vulnerabilities a. Operations Technology layout and framework (extent of Inter- connectedness) b. Operations Technology data back-up and recovery plans 4) Crisis management and Resilience plans – Business Continuity plan, Crisis Management plan 82 Product Structure for Cyber Insurance 5) Past Cyber incidents – Type and extent of loss incurred, and remedial measures undertaken Insurers could also undertake further assessment measures like: Cyber scanning tools and reports that offer a view of potential cyber vulnerabilities of the Insured and cyber risk grading Detailed security risk assessment through in-house or third-party cyber security agencies Tabletop discussion with the Insured to get an in-depth view from the Insured Claims Response and Management 7.7 The liability linked to cyber exposure can have devastating effect on the businesses. As much as it is important to have robust systems in place to avoid cyber incident, it is all the more important to have effective system in place to respond and manage the situation when a cyber-incident occurs. 7.8 As companies rely more heavily on their IT systems, the business interruption associated disruption becomes even more substantial and detrimental. At the same time, ransom- ware attacks are increasing in sophistication and are even infiltrating backup systems. The costs and expenses associated with a cyber-incident can be categorized into four segments. Assistance and Emergency Measures Restoration Costs and Additional Expenses Liability Coverage Loss of Turnover and Increase in costs Identification, assessment, and containment of security event (IT forensics). Provision of legal assistance (data breach of confidentiality). Provision of crisis management or communication assistance. Restoring the IT system to its state prior to the claim. Maintaining operability of the IT system. Preparing the claim. Preventing or mitigating a liability exposure/detecting and controlling any improper use of personal data (data breach). Communication strategy. Notification to the authority or to individuals (data breach). Ransom. Defence costs and damages arising out of claims made by third parties: A security event. A breach of confidentiality of personal data. Defamation, damage to reputation, breach of intellectual property, violation of privacy, etc. Business interruption. Extra expenses. 83 Product Structure for Cyber Insurance Defence costs resulting from an investigation by a regulator. Regulatory fines by national authorities for data protection rights violations, such as the GDPR. 7.9 Considering the complex nature of cyber claims, it is common for Insurers and Insureds to appoint Claims/Incident Response Consultants who could offer Incident response, legal and IT forensic services for the Insured. Such consultants could also assist in ransom-ware claim management. Industry Wise Cyber Exposures 7.10 The advancements in technology and its usage have connected people, businesses and organisations in India and brought them closer, leading to economic progress. However, these advancements come with critical vulnerabilities which can be exploited by those who are experts in misusing technology for economic gains. As corporate systems get more interconnected, another significant factor the industry is grappling with is the increasing number of breaches and sophisticated cyberattacks. 7.11 India was ranked among the top five countries to be affected by cybercrime, according to a 22 October report by online security firm “Symantec Corp”. In September 2020, the Ministry of Electronics, and Information Technology (MeITY) told the Parliament that Indian citizens, commercial and legal entities faced almost 7 lakh cyber-attacks till August this year. A PwC study estimates that the cyber security market in India will be defined by three key sectors—banking and financial services industry (BFSI), information technology (IT) and information technology enabled services (ITeS), and government. These sectors will constitute 68% of the cyber market share. 7.12 Reports published by several leading analysts and consulting firms clearly indicate that while all sectors are observing significantly increased cyber risk; banking and finance, public/government, professional services, information and technology and related industries and healthcare and pharma clearly stand out in terms of incidents. 84 Product Structure for Cyber Insurance Source: 2019 Verizon Data Breach Investigations Report (DBIR) This is also evident in business disruption caused due to such incidents or breaches in terms of perceived risk in these industries. We discuss below a few industries with unique characteristics and exposures to better understand the nature of cyber risk in the market: 85 Product Structure for Cyber Insurance a. Healthcare: 7.13 The rapid digitization of the healthcare industry has led to a huge increase in the number of ransomwares, malware and targeted attacks, which puts confidential patient data like personal details, medical history and financial information at risk. The healthcare systems are emerging as an attractive industry for hackers to target with each stolen medical record. During the past years, cyber- attacks on healthcare services have resulted in the loss of hundred thousand of Personal Identifiable Information (PII) and Personal Health Information (PHI) data and resulted in disruption of critical care services. 7.14 Implications of cyber-attacks on healthcare across a wide spectrum are critical PII and PHI data loss of VVIPs and HNIs globally could lead to a significant financial and political control by organized cyber-crime syndicates and states sponsoring them. The populated geographies like India can become a rich source of medical research data by virtue of the sheer size of the sample. Advanced attacks like ransomware can cause major operation disruption by holding critical data and assets to ransom. There is financial and brand reputation loss to the healthcare provider in terms of regulatory fees and mistrust. Healthcare organizations saw a significant increase in malware or bot attacks, with socially engineered threats and Distributed Denial of Service (DDoS) attacks steadily growing, as well. b. IT and Telecoms: 7.15 Cyber-attacks are increasingly targeting the technology and telecom sector. The complexity of a tech company’s risks depends on the type of products and services the company provides. Some companies may be required to store large amounts of sensitive data, while other companies need only maintain smaller amounts of information on their customers. Still, any stored data is a vulnerability, and any security incident can result in negative press, a potential stock devaluation and an overall lack of trust in the company holding or servicing your data. 7.16 Telecom and network service providers, Cloud storage providers, Cloud computing services, Developers of cyber security software, or a file-sharing solution provider, are often the targets of cyber-attacks. The damage such attacks can inflict go far beyond the cost of recovering compromised data. As these companies are often a gateway into multiple businesses, the ultimate aim of direct cyber-attacks is to access the core infrastructure of a telecom or technology 86 Product Structure for Cyber Insurance company. Companies may suffer huge losses in terms of Third-party clams for privacy breach, Ransom ware, Business interruption, regulatory investigation and fines and penalties. In case of a cyber-incident, they may also need to assess, aid, and resolve any impact to corporate client systems and data exposed. c. Banking and Financial Services (BFS): 7.17 Due to the high value of financial data, cybercriminals are increasingly targeting customer banking credentials when carrying out attacks. An International Monetary Fund (IMF) study suggests that the average annual potential losses from cyber-attacks could be nearly 9% of banks global net income i.e. around $100 billion. And in cases where the attacks were severe, the loss estimate could range from $270 billion to $350 billion. In rarest of the rare cases, the average potential loss could be as high as half of a bank’s net income, which could put the entire banking and financial sector in jeopardy. 7.18 As more banks implement mobile banking applications, new vulnerabilities for cybercriminals to target are introduced to the network. Banking apps can be exploited from both the client-side or the server-side, making them difficult to secure. This means that banks must be able to ensure that data is secure when it is being accessed from a customer device as well as when it is stored on bank servers. Cybercriminals also attempt to target bank’s third-party vendors (software vendors, banking equipment vendors, customer service vendors). Vendors have access to critical banking data but often lack stringent security policies, making them a prime target for threat actors. 7.19 According to Cyber Risk Services at Deloitte, hackers from various countries attempted over 40,000 cyber-attacks on India’s Information Technology infrastructure and banking sector over five days in the last week of June 2020. Malware has long been a threat to the banking sector. By infecting vulnerable end- user devices with malware, cybercriminals are able to gain access to entire banking networks and steal critical user data. With malware becoming easier than ever to obtain, this threat has grown in recent years as in 2019, it was responsible for 75% of all data breaches in the banking sector. In addition to malware attacks, phishing attacks i.e. communications, such as emails, calls, or texts, that impersonate company officials in order to trick customers or employees into sharing information is another common risk. d. Manufacturing: 7.20 Given its focus on innovation and an increasing reliance on connected products, the manufacturing industry is also vulnerable to cyber risks. As the 87 Product Structure for Cyber Insurance manufacturing industry is undergoing industrialization by leveraging IoT, digitization, cloud computing services for their productivity enhancement, resource management, and creating cost efficiencies is more vulnerable to cyber-attacks. According to Quick Heal, a cybersecurity firm the Indian manufacturing sector faced 27.56% of total cybersecurity attacks in the 1st quarter of 2019. 7.21 Given the highly connected environments manufacturers work in, and the pace of technological change they face, cyber risk is a top-of-mind industry issue. In fact, nearly half of the executives surveyed by consulting firm Deloitte lacked the confidence that they are protected from external threats, and it is increasingly important for organizations to assess their organization’s risk profile and preparedness in the event of a breach or cyberattack. 7.22 Apart from the loss of revenues/market credibility and the operational disruption caused by successful cyber-attacks, they will also now be hit with heavy financial penalties imposed by regulatory bodies for every security breach. 7.23 Manufacturers with inadequate cybersecurity also risk their intellectual properties (IP) such as new technologies/products, confidential designs/formulas, and manufacturing processes being compromised by outside actors and internal threats. These IPs can then be sold to potential buyers, including competitors, or heavily advertised across the Dark Web. The exposures get compounded for organisations that are listed or are operating in more litigious jurisdictions. CYBER SOLUTIONS FOR MSME SEGMENT 7.24 In 2019, 43% of all cyber-attacks worldwide were aimed at SME’s. MSMEs in India face the same threat and trend. Hacker’s target them because of their less sophisticated IT security infrastructure Data security council of India is committed to promote cyber security awareness among these sectors. Such incidents can result from a wide range of causes, including hackers, malware/virus, malicious insiders, lost or stolen laptops and employee error. 7.25 Lack of awareness, complex policy structure and wording, affordability and underwriting requirements are key barriers to increase cyber insurance penetration in this segment. Shared industry awareness programs, simplification of product constructs and underwriting processes and competitive pricing can aid secure digital adoption for MSMEs in India and help unlock the market potential for insurers. 88 Product Structure for Cyber Insurance 7.26 At the minimum, it is necessary to offer to MSME sector coverages that include first party coverage, third party coverage and coverage for other services as mentioned in Chapter 4. A digital first approach providing self-service solution for MSMEs and insurance intermediaries, automated rules-based underwriting and claims and service model would help the industry serve this segment and improve reach and affordability. Due to low awareness on exposures and required security measures, challenges in this segment cannot be addressed through cyber insurance alone. For any initiatives relating to MSME sector, to begin with it is a good idea for the insurers to take the definition for MSMEs as defined by the Government of India. 7.27 Normally, the coverage terms for MSMEs are broadly similar to those offered to other corporate customers. However, considering the vulnerability of the MSMEs who might not be having highly sophisticated control systems to prevent cyber incidents, insurance industry should ensure that coverage terms do not become too stringent and also make efforts to demystify cyber coverage through initiatives such as dissemination of information on coverage provisions, safety standards and by incentivizing adoption of possible safeguards. Coverage for MSMEs should facilitate a quick resumption of business after an incident, by offering all allied recovery services as a bouquet. An ecosystem approach involving insurers, cyber risk consultants and solution providers, insure-tech companies, industry bodies, financial institutions and digital platforms can help accelerate awareness and adoption While policy wording and coverages are important, it is education and supportive ecosystem which matters most for spread of cyber insurance culture in MSME sector. Standardisation of Cyber Insurance Policies: 7.28 The review of the market suggests that cyber insurance segment is still in nascent stages and being closely linked to rapid evolution of technology. The risk profiling and industry coverage needs are expected to change over the next few years. A few aspects that would impact cyber insurance offering by insurers and reinsurers in the market are: 7.29 Ever-evolving cyber threat landscape: Cyber-attacks have an inherent volatility as they keep evolving over time, which limits the value of historical experience and undermines the exposure’s predictability. As a result, existing cyber threats keep mutating, while new ones are continually arising. As companies 89 Product Structure for Cyber Insurance adapt to one type of attack, threat actors keep coming up with new techniques, targets, and points of entry to exploit. New legislation and regulations are in development and this may lead to requirement of new insurance solutions. 7.30 Digital adoption by industries yet to peak: While digital adoption and technology adoption across industries has accelerated in the last few years, several industries & corporates are still investing and evolving. It means that the business and operations models, technology infrastructure and services are yet to hit a point where risks are well understood. For example, Industry 4.0 as a theme in manufacturing is expected to see a huge boost once 5G telecom infrastructure is launched in India which may transform businesses but also significantly shift cyber risk profile. 7.31 Lack of historical loss data: Cyber insurance is a relatively new line of insurance and hence there is lack of historical data with insurers, which makes it difficult to build the predictive models that can help assess probability of loss. There is also no comprehensive, centralized source of information about cyber events for insurers to refer. In addition, a large percentage of cyber losses aren’t even acknowledged to outsiders especially cyber events such as denial of service attacks, ransomware, and theft of intellectual property are often kept under wraps. In view of the foregoing, insurers need to frequently adapt and change their policy wordings, question sets, and underwriting approaches in order to ensure that they are best serving their customers while managing their exposures prudently. Insures also need to adapt based on risk evolution in domestic as well as international markets and reinsurance policies & capacities available. 7.32 Cyber insurance, being a new product, is supported by international reinsurers for the innovation, technical knowledge, product wording and various other services. Instead of a standardized wording they may prefer to use coverage and exclusions as per the latest developments in the market. 7.33 The standardisation of cyber insurance in its nascence may impede innovation and adaptation to evolving industry needs. It may lead to price-based competition instead of being agile and contextual to client needs. Nonetheless, there are certain aspects of cyber insurance that require a consensus and Common Reference Framework to bring about clarity in coverage. Some of the issues that need to be addressed are listed below: a. Computer System: Some policies contain a provision that coverage is provided to those systems which are provided by the company for exclusive and secure usage for the purpose of its business. This may deny coverage 90 Product Structure for Cyber Insurance when employees use their own computers while working from home which is more prevalent now, in the post Covid19 world. Given the compulsion for and encouragement given to employees to work from home, it is necessary to include their own devices too. So also, other devices, tablets, mobile phones etc. which are used for official purposes, albeit with required safeguards. It is necessary to provide coverage for all these aspects explicitly b. Regulatory fines and penalties Coverage: Cyber insurance policies provide cover for fines and penalties "to the extent insurable by law" i.e. the law applicable to the policy and the jurisdiction in which the payment is to be made. Ambiguity in this matter arises because the issue of insurability is normally not directly addressed in the statute or in the regulatory provisions, the one known exception being the UK Financial Conduct Authority’s prohibition of insurance payments to reimburse the cost of financial penalties it imposes. Further, there are jurisdiction related issues – some favorable to allowing such coverage and others and others not. One way to address this issue is to identify the kind of fines payable and confirm coverage under favorable jurisdiction. c. Intentional Acts exclusion: Cyber policies exclude coverage for Dishonest or Improper Conduct of employees, however this could be modified to make it applicable only for Key personnel of a company i.e. Chief Executive Officer, Chief Financial Officer, Chief Risk Officer, General Counsel, Head of IT department, Head of HR department, Data Protection Officer and Chief Compliance Officer or any other Person in a functionally equivalent position. Further, insurers can advance Defence Costs until there is i. a final decision of a court, arbitration panel or Regulator, or ii. a written admission d. Bodily Injury and Property Damage Exclusion: Cyber policies exclude coverage for claims arising out of “bodily injury” and “property damage” as these would find coverage under casualty, property, and marine policies. However, coverage for claims alleging mental anguish, mental injury, shock, emotional distress, and humiliation are carved back, as claimants may cite these injuries as damages stemming from a cyber incident. With absolute cyber exclusions under other policies becoming common, there is an urgent need to consider covering cyber incident triggered bodily injury and property losses, so that they do not fall in no man’s land e. War, Terrorism, Invasion, or Insurrection Exclusion: All cyber policies exclude coverage for loss from acts of war, terrorism, invasion, and/or insurrection. The exclusions are often written expansively and given the 91 Product Structure for Cyber Insurance proliferation of state-sponsored, political, and ideological cyber-attacks, could exclude coverage for most security breaches. However, insurers could modify these exclusions to carve out coverage for “cyberterrorism” or “electronic terrorism” f. Failure to maintain minimum security standards: Some cyber policies exclude coverage for claims based upon the insured’s failure to maintain minimum security standards. While the wording varies from insurer to insurer, and at times they are placed as recommendatory measures, this exclusion may deny coverage, sometimes in unexpected ways. If this exclusion is tied to the standards mentioned in the proposal from, policyholders need to be careful to accurately complete cyber insurance proposal form and ensure compliance with the security standards mentioned therein are maintained throughout the policy period. But, to avoid the risk of any wrong application of this exclusion, it is desirable to consider specifying that this exclusion applies only when the failure is material to a cyber loss. g. Changes in the risk: If material changes in the risk are not informed to insurers, policy rights may get prejudiced. There may be changes in the fund transfer protocol, changes in the business continuity planning and access control for remote access. It is necessary to seek continuity of coverage by informing insurers about the changes lest coverage gets impacted adversely. Need for this notification to insurers has become more pronounced after Covid 19 lockdown when work from home has become a norm and other processes also had to undergo significant change. While the insurers concern to ensure that the risk underwritten and the risk subsisting at the time of loss are the same is understandable, the notification of risk changes should not be so onerous as to deprive the insured of a claim even when such changes are not material to the loss. 8 OTHER MATTERS OF RELEVANCE 8.1 Remote Working: The New Normal: Even before the pandemic, there was a slow, but gradual shift of the workspace from the office to home. The pandemic has propelled this shift to a new reality, which could continue to be a permanent feature of the future of work. With many employees around the globe working remotely, steps need to be taken for bolstering IT security in the home office: Some of the suggested measures are: keeping software up to date 92 Product Structure for Cyber Insurance activating virus protection and firewalls being increasingly cautious about sharing personal data Making sure web browsers are up to date keeping passwords safe and changing them regularly protecting confidential emails with encryption Only downloading data from trusted sources making regular backups turning off voice-activated smart devices and covering webcams when not in use making clear distinctions between devices and information for business and personal use and not transferring work between the two identifying all participants in online sessions Logging out when devices are no longer in use and keeping them secure following security practices for printing and handling confidential documents being careful with suspicious e-mails or attachments 8.2 Accumulation Issues: Cyber loss exposures emanate in many ways - i. Economic loss: Damage to systems/property; Notification costs; Remediation costs to investigate & remedy breach ii. Liability exposures: Damages by customers, vendors, business partners triggered by errors & omissions or failure to protect data For primary insurance companies the risk accumulation within their portfolio of Cyber Policies may expose them to accumulation risk and higher financial losses. A single event generating a widespread impact on thousands of businesses at once is another distinct possibility. For example, a single malware attack could breach multiple client network at one point. The major cyber accumulation risk scenarios are essentially man-made and in addition to the malware attacks and attempted data breaches, technical failures can also have devastating consequences. Hence, it is essential for an insurance company to actively identify, quantify, model, manage and control cyber accumulation risk. a) Accumulation Scenarios: Ransomware and malware attacks in the recent past have affected businesses causing huge economic losses. These attacks proved to be globally contagious, infecting organizations across multiple countries & geographies. 93 Product Structure for Cyber Insurance It is evident that in cyber a significant accumulation potential on a global scale arises from shared software or hardware vulnerabilities, the disruption/outage of central IT services, and attacks on critical infrastructure, such as power supply or telecommunications networks – including the internet. Each of these events may cause various types of financial losses to thousands of companies, and hence poses a major accumulation loss potential. b) Challenges in accumulation control: Tracking the accumulation exposure in traditional property class of business has matured with modelling tools available for measuring earthquake and flood exposures. With cyber risks, the contours of systemic accumulation are not as clear. Accumulation in Cyber Insurance is also a function of the Cyber Insurance coverages provided. Cyber risk is clearly systemic – it is spread through interconnectivity: the internet, communications, and internal and external networks. These connections are neither obvious nor easily tracked. Following are the main challenges faced – Identifying dependencies among the risks, defining the different scenarios, and assessing severity of a single event affecting many risks that are affected The frequency and severity of cyber events as well as their interdependence are not easy to establish, making it difficult to assess potential aggregation of losses as new and unforeseen attack patterns emerge constantly Lack of awareness of potential cyber losses Hidden cyber exposure within existing coverages Quantification approaches for cyber accumulation risk: As cyber insurance in India is still in a nascent stage, the common approach of quantification of accumulation is the aggregation of full policy limits in the portfolio. This is a very conservative and restrictive approach. In developed cyber insurance markets, insurers are relying on deterministic scenario analyses to quantify the risk. Realistic Disaster Scenario (RDS) modeling for bottom-up measurement of exposure on an event basis is becoming part of cyber framework. The probabilistic modelling of scenario events is considered ideal to assess potential cyber losses, but their development is in early stages. 94 Product Structure for Cyber Insurance To address this problem, insurers should closely work with reinsurance companies and modelling firms to develop a cyber risk framework. 8.3 Cooperation between various agencies: Considering the pervasive nature of cyber risks, it is desirable that there be cooperation between insurance industry and other technical bodies like CERT- in (part of Ministry of Electronics and Information Technology and a nodal agency to deal with cyber security threats like hacking and phishing also responsible for strengthening security-related defence of the Indian Internet domain) and professional bodies like FICCI (which plays an important role in formulation of economic and finance policies), CII (works to create and sustain an environment conducive to the development of India, partnering industry, Government and civil society, through advisory and consultative processes.) and NASSCOM (trade association of Indian Information Technology (IT) and Business Process Outsourcing (BPO) companies.) etc. This can help understand the changes that are taking place globally with potential impact on Indian market and facilitate exchange of ideas and information on cyber security, economic, finance policies and Insurance. Moreover, this shall provide a consolidated domain with current trend of industry practices, current trends in terms of hacks including proactive steps for loss prevention, impactful solutions developed by various companies and challenges faced in executing the same. This would also provide a common platform to harmonise current industry practices, to glean current trends and to promote proactive measures for loss prevention. Insures can consider sharing amongst themselves information on incidents without breaching confidentiality norms. 8.4 Cyber Literacy and Education Index: India occupies 45th position in this index which measure the population’s cybersecurity knowledge as well as the ways that countries can enhance that knowledge through education and training. It may be a good idea for the insurance industry to work with concerned authorities and organisations to promote cyber literacy. 8.5 Developing an enabling cyber insurance ecosystem: Given the complexities surrounding the technology space, cyber insurance is expected to not only act as a loss mitigation mechanism, but also as a risk mitigation device. Expertise needs to be developed on the morphing challenges technology presents and the threats confronting technology deployment. These include developing a risk evaluation framework, promoting risk improvement 95 Product Structure for Cyber Insurance measures, incentivizing establishment of safeguards, immediately responding to incidents, recovery, forensic audit and a host of other services that require considerable expertise and knowledge. The insurance industry should collaborate within itself, and with other stakeholders in developing a robust ecosystem of experts and professionals who are equipped to confront the formidable disruptions the threat actors heap on society and to provide mitigation. Insurance industry should act as a facilitator for the growth and development of technology without disruptions. To this end, the industry should identify and benchmark reliable service providers to address each area of specialized response. Insurance industry should also promote sound loss assessment standards and practices.
Research the source law
This record is not yet linked to a specific provision. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source laws