Abstract
Business disruption from cyber-attacks is a recognized and growing concern, yet the uptake of cyber insurance has been substantially lower than expected. This study aimed to identify what factors may be influencing perceptions and uptake of cyber insurance. In-depth interviews were conducted with two stakeholder groups: those responsible for making cybersecurity decisions within businesses, and those involved in marketing cybersecurity products and/or services including cyber insurance. Thematic analysis generated five themes from the data: High complexity of company-level decision making, Security investment trade-off, Lack of risk data and immaturity of cyber insurance, Mistrust of insurers, and Compliance legislation as a driver for cyber insurance adoption. The results highlight the importance of recognizing that internal organizational decision making involves a complex eco-system which can make the process of obtaining and renewing cyber insurance an effortful process. Legislation may facilitate insurance uptake, but several external factors represent key barriers. There is a need for clearer policy wording, improved processes for cyber risk assessment, improved trust in insurers and lower policy premiums.
Original language | English |
---|---|
Title of host publication | EuroUSEC 2022 |
Subtitle of host publication | The 2022 European Symposium on Usable Security |
Place of Publication | New York, US |
Publisher | ACM |
Pages | 151-159 |
Number of pages | 9 |
ISBN (Electronic) | 9781450397001 |
ISBN (Print) | 9781450397001 |
DOIs | |
Publication status | Published - 29 Sept 2022 |
Event | EuroUSEC 2022: 2022 European Symposium on Usable Security - Karlsruhe, Germany Duration: 29 Sept 2022 → 30 Sept 2022 https://eurousec2022.secuso.org/ |
Publication series
Name | ACM International Conference Proceeding Series |
---|
Conference
Conference | EuroUSEC 2022 |
---|---|
Country/Territory | Germany |
City | Karlsruhe |
Period | 29/09/22 → 30/09/22 |
Internet address |
Keywords
- cyber insurance
- cybersecurity
- policy
- qualitative methods
- risk assessment