General Information & Client Service
  • Americas: +1.212.553.1653
  • Asia: +852.3551.3077
  • China: +86.10.6319.6580
  • EMEA: +44.20.7772.5454
  • Japan: +81.3.5408.4100
Media Relations
  • New York: +1.212.553.0376
  • London: +44.20.7772.5456
  • Hong Kong: +852.3758.1350
  • Tokyo: +813.5408.4110
  • Sydney: +61.2.9270.8141
  • Mexico City: +001.888.779.5833
  • Buenos Aires: +0800.666.3506
  • São Paulo: +0800.891.2518
January 30, 2019

PRA published a letter that presents the key themes that emerged from its survey on cyber insurance underwriting risk. This letter from Anna Sweeney, Director of Insurance Supervision, is addressed to the Chief Executives of specialist general insurance firms.

In July 2017, PRA had published the supervisory statement SS4/17 on cyber insurance underwriting risk. SS4/17 set out the PRA expectations for insurers on the prudent management of cyber underwriting risk in the areas of actively managing non-affirmative cyber risk; setting clearly defined cyber strategies and risk appetites that are agreed by the board; building and continuously developing insurer cyber expertise. In May 2018, and after discussing with industry associations and Lloyd’s, PRA conducted a follow-up survey involving firms of varying size. This letter provides feedback on the key themes that emerged from firms’ responses and describes areas inn which the PRA thinks that firms can do more to ensure the prudent management of cyber risk exposures.

The survey results suggest that although some work has been done, more ground needs to be covered by firms especially in relation to non-affirmative cyber risk management, risk appetite, and strategy. Having reviewed the responses of firms, PRA also believes that the expectations set out in SS4/17 are relevant and valid. SS4/17 set out the PRA expectations that firms should:

  • Robustly assess and effectively manage their insurance products with specific consideration to non-affirmative cyber risk exposure
  • Monitor their aggregate cyber underwriting exposure and conduct underwriting risk stress tests that explicitly consider the potential for loss aggregation (in case of firms writing affirmative cyber products)
  • Consider cyber underwriting risk stress tests with consideration given to loss aggregation at extreme return periods (up to 1 in 200 years)

In the letter, PRA states that the responsibility is on firms to progress their work and fully align with the expectations set out in SS4/17. In relation to the expectation that firms reduce the unintended exposure to non-affirmative cyber risk, insurers should develop an action plan by the first half of 2019, with clear milestones and dates by which action will be taken. Supervisors may ask to review this plan and subsequent progress toward it. Over the rest of the year, PRA plans to undertake the following steps:

  • Provide further, targeted feedback to surveyed firms by arranging meetings with individual surveyed firms by the end of the first quarter of 2019
  • Coordinate with Lloyd’s to agree any follow-up actions in relation to Lloyd’s managing agents
  • Carry out sample deep-dive reviews to other firms (not necessarily those in the initial sample) in second half of 2019 to assess how these firms are meeting the expectations set out in SS4/17

 

Related Links

Keywords: Europe, UK, Insurance, Cyber Risk, Underwriting Risk, SS4/17, PRA

Related Insights
News

OFR Adopts Data Collection Rule on Centrally Cleared Repo Transactions

OFR adopted a final rule to establish a data collection covering centrally cleared funding transactions in the U.S. repurchase agreement (repo) market.

February 20, 2019 WebPage Regulatory News
News

FHFA Finalizes Rule on Federal Home Loan Bank Capital Requirements

FHFA published, in Federal Register, the final rule to adopt, as its own, portions of the regulations of the Federal Housing Finance Board pertaining to the capital requirements for the Federal Home Loan Banks.

February 20, 2019 WebPage Regulatory News
News

SRB Publishes Framework for Performing Valuations in Resolution

The framework provides independent valuers and the general public with an indication of the expectations of SRB on the principles and methodologies for valuation reports, as set out in the legal framework.

February 19, 2019 WebPage Regulatory News
News

US Agencies Extend Consultation Period for the Proposed SA-CCR

US Agencies (FDIC, FED, and OCC) extended the comment period for a proposed rule to update their standards for how firms measure counterparty credit risk posed by derivative contracts.

February 18, 2019 WebPage Regulatory News
News

FED Extends Consultation Period for Stress Testing Rule

FED has published in the Federal Register a notice proposing amendments to the company run and supervisory stress test rules.

February 15, 2019 WebPage Regulatory News
News

EBA Single Rulebook Q&A: Third Update for February 2019

EBA published answers to two questions under the Single Rulebook question and answer (Q&A) updates for this week.

February 15, 2019 WebPage Regulatory News
News

SEC Proposes Rule on Risk Mitigation Techniques for Uncleared SBS

SEC proposed a rule that would require the application of specific risk-mitigation techniques to portfolios of security-based swaps (SBS) that are not submitted for clearing.

February 15, 2019 WebPage Regulatory News
News

FSB Report Examines Financial Stability Implications of Fintech

FSB published a report that assesses fintech-related market developments and their potential implications for financial stability.

February 14, 2019 WebPage Regulatory News
News

US Agencies Amend Regulatory Capital Rule to Allow Phase-In for CECL

US Agencies (FDIC, FED, and OCC) adopted the final rule to address changes to credit loss accounting under the U.S. generally accepted accounting principles; this includes banking organizations’ implementation of the current expected credit losses (CECL) methodology.

February 14, 2019 WebPage Regulatory News
News

FASB Proposes Taxonomy Improvements for the Credit Losses Standard

FASB proposed the taxonomy improvements for the proposed Accounting Standards Updates on Targeted Transition Relief for Topic 326 (Financial Instruments—Credit Losses) and Topic 805 (on Business Combinations—Revenue from Contracts with Customers).

February 14, 2019 WebPage Regulatory News
RESULTS 1 - 10 OF 2617