Featured Product

    EIOPA Chair Speaks on Implications of Cyber Risk for Insurance Sector

    February 26, 2019

    While speaking at the Third Annual Fintech and Regulation Conference in Brussels, the EIOPA Chair Gabriel Bernardino discussed what EIOPA is doing and what should be done to cope with the challenges posed by cyber risk at a global level. He opines that these risks affect the insurance sector on two levels: the first involves the security of the insurance business and the second relates to the role of insurance in covering and managing cyber risk.

    Mr. Bernardino believes that a well-developed cyber insurance market can help to raise awareness of businesses to the risks and losses that can result from cyber-attacks; to share knowledge of good cyber risk management practices; to encourage risk reduction investment by establishing risk-based premiums; and to facilitate responses to, and recovery from, cyber-attacks. The future demand for coverage of this kind will depend, to a large extent, on both the frequency of high-profile cyber incidents and legislative developments in relation to personal data protection. In this context, the implementation of the data protection regulation in EU may lead to a significant growth in cyber risk insurance, with estimates suggesting that there may be parity between the EU and U.S. markets in coming years. Although coverage of cyber risk by insurers is still in its infancy, most of the market is concentrated in the United States. Growth in this market, however, has been significant, with the current forecasts suggesting that premiums may reach USD 20 billion in 2025.

    He added that EIOPA has been monitoring developments in the cyber insurance market for some time. Last year, EIOPA published a report titled "Understanding cyber insurance" based on a structured dialog with insurance companies across Europe. Through this dialog, EIOPA identified a number of issues relevant to the cyber insurance market in Europe. It was found that the cyber insurance industry expects a gradual increase in demand for insurance, mainly driven by new regulation, the increase in cyber risk related incidents, increased awareness of risks, and the increased frequency and severity of cyber attacks. Regulation may be welcomed by the industry in a moderate fashion, as it could help to address some of the identified challenges.

    He also added that EIOPA took into account its work and these findings in the development of our supervisory convergence plan for 2018–2019. In this plan, cyber risk is identified as a priority under the supervision of emerging risks. As part of the activities in this field, EIOPA will develop guidelines regarding Information & Communication Technologies (ICT), security and governance, including cyber resilience, and will further develop supervisory practices that seek to assess information system resilience, cyber risk vulnerability, and the insurance industry’s use of big data. EIOPA will also look into an efficient way of carrying out stress tests on the resilience of the insurance sector to cyber-attacks. It is clear that cyber insurance affects countries worldwide, not just in Europe. Issues related to cyber security and cyber risk are, therefore, one of the three priorities of the EU-U.S. Insurance Project, in which EIOPA plays a leading role. He concluded that "This is a universal challenge! Everyone has to contribute to meet this challenge!"

     

    Related Link: Speech (PDF)

    Keywords: Europe, EU, Insurance, Cyber Risk, Regtech, Stress Testing, Guidelines, EIOPA

    Featured Experts
    Related Articles
    News

    BIS Examines Use of Big Data and Machine Learning at Central Banks

    BIS published a paper that provides an overview on the use of big data and machine learning in the central bank community.

    March 04, 2021 WebPage Regulatory News
    News

    APRA Finalizes Reporting Standard for Operational Risk Requirements

    APRA finalized the reporting standard ARS 115.0 on capital adequacy with respect to the standardized measurement approach to operational risk for authorized deposit-taking institutions in Australia.

    March 03, 2021 WebPage Regulatory News
    News

    ECB Publishes Guide for Determining Penalties for Regulatory Breaches

    ECB published a guide that outlines the principles and methods for calculating the penalties for regulatory breaches of prudential requirements by banks.

    March 02, 2021 WebPage Regulatory News
    News

    MAS Sets Out Good Practices to Manage Operational Risks Amid COVID

    MAS and The Association of Banks in Singapore (ABS) jointly issued a paper that sets out good practices for the management of operational and other risks stemming from new work arrangements adopted by financial institutions amid the COVID-19 pandemic.

    March 02, 2021 WebPage Regulatory News
    News

    ACPR Announces New Data Collection Application for Banks and Insurers

    ACPR announced that a new data collection application, called DLPP (Datalake for Prudential), for collecting banking and insurance prudential data will go into production on April 12, 2021.

    March 02, 2021 WebPage Regulatory News
    News

    BCB Maintains CCyB at 0%, Initiates First Cycle of Regulatory Sandbox

    BCB announced that the Financial Stability Committee decided to maintain the countercyclical capital buffer (CCyB) for Brazil at 0%, at least until the end of 2021.

    March 02, 2021 WebPage Regulatory News
    News

    EIOPA Launches Study on Non-Life Underwriting Risk in Internal Models

    EIOPA has launched a European-wide comparative study on non-life underwriting risk in internal models, also kicking-off of the data collection phase.

    March 01, 2021 WebPage Regulatory News
    News

    SRB Publishes Overview of Resolution Tools Available in Banking Union

    SRB published an overview of the resolution tools available in the Banking Union and their impact on a bank’s ability to maintain continuity of access to financial market infrastructure services in resolution.

    March 01, 2021 WebPage Regulatory News
    News

    EBA Consults on Pillar 3 Disclosure Standards for ESG Risks Under CRR

    EBA is consulting on the implementing technical standards for Pillar 3 disclosures on environmental, social, and governance (ESG) risks, as set out in requirements under Article 449a of the Capital Requirements Regulation (CRR).

    March 01, 2021 WebPage Regulatory News
    News

    ESAs Issue Advice on KPIs on Sustainability for Nonfinancial Reporting

    ESAs Issue Advice on KPIs on Sustainability for Nonfinancial Reporting

    March 01, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 6655