兰德-承保灾难性网络风险(英)-2025_86页_1mb
报告摘要
Cyber Risk Insurance Analysis Report Summary
Key Findings
- The private cyber insurance market effectively manages attritional cyber losses but struggles with catastrophic losses due to high correlation risk and limited underwriting capacity.
- Attritional cyber events (e.g., data breaches, IT outages) satisfy most insurability criteria, while catastrophic events (e.g., attacks on critical infrastructure) do not.
- Current market limitations include limited coverage for war/infrastructure events, price premiums exceeding expected losses due to capital costs, and low policy adoption rates.
Proposed Solutions
- A federal Cyber Risk Insurance Program (CRIP) with two reinsurance towers:
- Tower 1: Covers war, terrorism, and infrastructure cyber events (10% co-pay, high public sector share)
- Tower 2: Covers other insured losses (20-30% co-pay, private sector bears most risk)
- Ex post data collection mechanisms to inform future cybersecurity standards and improve program design.
Recommendations
- Establish clearer criteria for classifying unexpected cyber incidents as acts of war or terrorism.
- Implement mandatory cyber hygiene standards through enhanced data collection efforts.
- Evaluate the banning of ransomware payments carefully, balancing political and empirical considerations.
- Monitor adoption rates and capacity constraints to improve program accessibility, especially for small/medium enterprises.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载