It always concerns me when I read articles (this one is from CPO Magazine) that ends with the words: “…the time may soon come for greater oversight and regulation of this market”.
‘This’ market, this time, is the cyber insurance market. The real gist of the article is that you need to be careful to buy the right cyber policy for your needs but, of course, the language is quite a bit scarier than that.
‘Flaws’, ‘shortcomings’, and ’32% loss ratios’ pirouette throughout the article constantly hinting at shadiness in the design, sale, and claims handling of cyber policies.
But that’s not what concerns me about the article; those of us in the business are all too familiar with this kind of language and, to be fair, it isn’t always totally unfair.
But in the case of cyber, I think it somewhat is. Why only somewhat?
On one hand, cyber is still, relatively speaking, so new that no one yet really knows how it will perform. Or what people really want/need to buy, particularly as cloud continues to grow. Or how best to manage the risk. Or how to manage portfolios in an environment that changes more and faster than anything else we currently try to insure. Or how to deal with an environment that is both bigger and more interconnected and therefore more subject to both cat and systemic exposure than any other. A 32% single year loss ratio may yet prove to be horribly inadequate in the face of a major systemic event; and if that loss ratio is just a loss ratio – and includes no other costs – it is certainly not a loss ratio that supports any material cat exposure.
On the other hand, we can’t really complain when we persist in trying to deal with all the challenges cyber risk poses using a business model originally designed to deal with marine risks when boats never got much above walking speed. When the subject of the insurance now moves at the speed of light, it is no wonder articles need to be written telling buyers to be careful about what they buy.
So, this article is concerns me not because it’s unfair but because it’s fair – in so far as we in the insurance industry haven’t done enough to eliminate the deficiencies in what we do (and how we do it) that make us such an easy target for this kind of criticism.
Specifically, the buying and selling of a product/service designed to mitigate risk is an inevitably adversarial transaction in economic terms; both buyer and seller seek to optimize their relative positions in the face of significant uncertainty around almost everything to do with the transaction. How much risk is there here? How well is this risk managed? Will an insured event even occur? What could the consequences be? Will the insurer pay up? And so on…
These uncertainties (and others) have always existed in risk transfer; the current business model persists because risk transfer is still valuable, even after the process of transferring risk adds uncertainty and so reduces overall value. But I suspect the model may have been getting less effective as the pace of risk and change have accelerated.
Cyber though is something new; its challenges are so much more severe than older and better known risks that I am not sure it is manageable using the current insurance business model because I suspect the transfer process adds more uncertainty the more complex and dynamic the risk being transferred.
Interestingly, I don’t think cyber is alone in this regard; both new and old risks share the same problem, if for different reasons. This newest of risks, where too little is so far known because of its novelty (and where ‘knowing’ in actuarial terms may be impossible because of constant change and therefore constant novelty) and one of the oldest of risks – sexual misconduct, where too much is unknown because no one likes talking about the risk (amongst other things) – both show evidence of everyone involved being similarly frustrated by the risk transfer process because the level of uncertainty is similarly high for both transactions.
What concerns me though is that so much insure-tech investment seems to have been about making insurance buying a little quicker or easier, and insurance selling a little less expensive. I wonder whether such ‘enhancements’, which certainly reduce cost at the front end of the insurance transaction by reducing information exchange, end up adding more uncertainty and therefore cost at the back end than they save at the front end because, for anything but the simplest of risks, less information equals more uncertainty. And I doubt the relationship between increasing risk complexity/dynamism and increasing uncertainty is linear.
If we in insurance want to avoid the kind of criticism in this article, which we have all heard so often, we have to adapt our business model so the process of risk transfer and the transfer itself both reduce uncertainty – for both insurer and insured. While I am confident this is possible, the real challenge will be developing sufficient incentives for both sides of the transaction to get comfortable with a completely new process.
But, until we start looking at how to reduce uncertainty in the transfer process – for everyone’s sake – and which I think we must if we are going to successfully deal with the complexity, dynamism, and systemic and cat potential of cyber risk, journalists and most everyone outside insurance will continue to find insurance an easy target for criticism.
