Keynote speech by Peter Hacker, Founder & Director, Distinction.Global

State-sponsored hostile cyber activity presents a challenge not only for targeted households and firms but also for re/insurers who assume some of the associated risks, either through affirmative policies or as part of traditional property and casualty insurance. Losses linked to wars are generally not insurable, but attributing cyberattacks to nation states is difficult. Even if the technical characteristics of an incident have all the hallmarks of a particular perpetrator, proving they acted under the control or direction of a sovereign state is hard. Efforts by the re/insurance industry to align policy language with modern cybersecurity threats and create greater contract clarity are laudable, not least to avoid any reputational damage surrounding disputed coverage after an event. But contract certainty is not the same as legal certainty, and attribution will continue to be the subject of intense legal arguments, both in domestic and international courts.
Panel discussion

Matt Prevost (on screen), Senior Vice President, Chubb; Simon Dejung, Chief Underwriting Officer Cyber Reinsurance, SCOR; Peter Hacker, Founder & Director, Distinction.Global; Helga Munger, Senior Claims Manager, Munich Re; Tom Johansmeyer, Head of Property Claim Services (PCS), Verisk; Chuck Jainchill, Cyber Product Development Leader, AIG
To expand the cyber insurance market sustainably, new risk-absorbing capital will be needed to match the ballooning growth in exposures. Fundamental to that is robust contract design that gives re/insurers and prospective capital investors comfort that the assumed risks are manageable. Arguably, contract wordings failed to keep pace with risk exposure during the soft underwriting market of 2015–2019. The panel debated recent market initiatives to refine policy language and how far they are likely to deliver increased legal certainty over coverage.
Various proposals put forward by market practitioners offer improvements to contract templates, not least the increased precision over the nature of assets protected and the types of attack to which the policy will respond. However, the different terminology used for ostensibly similar concepts could be confusing. Moreover, the new policy terms would likely still face legal challenges in the event of a major cyber incident, especially over the definition of critical infrastructure, what amounts to a major detrimental impact and attributing any hostile attack to a particular nation state.
Beyond exclusions and endorsements, other product innovation will also be important. This includes further developments in excess-of-loss cyber reinsurance and industry loss warrants that allow capital providers with different risk appetites to participate, thereby boosting overall capacity in the market.