- Only 15 percent of potential information asset losses are covered by insurance; almost 60 percent of total physical asset values are protected
- 38 percent of EMEA businesses have suffered a cyber loss in last 24 months, averaging $3.3m per loss
- Only 30 percent of businesses in EMEA are “fully aware” of legal and economic consequences of EU General Data Protection Regulation (GDPR)
London (October 16, 2017) – The 2017 EMEA Cyber Risk Transfer Comparison Report, released today by Aon in collaboration with the Ponemon Institute, a leading research firm on privacy, data protection and information security, found that organizations recognize the growing value of technology and data assets relative to historical tangible assets, though they are spending four times more budget on insurance for Property, Plant and Equipment (PP&E) risks.
“Our goal is to compare the financial statement impact of tangible property and network risk exposure,” said Dr. Larry Ponemon. “A better understanding of the relative financial statement impact will assist organizations in allocating resources and determining the appropriate amount of risk transfer resources to allocate to the mitigation of network risk exposures.”
The report found that while 38 percent of businesses surveyed confirmed they have experienced a cyber loss in the past 24 months, only 15 percent of their probable maximum loss (PML) is covered by insurance. This is in stark contrast to the policy limits purchased against physical assets like Property, Plant and Equipment, where around 60 percent of their PML is typically covered. The report also shows that the impact of business disruption to information assets is 50 percent greater than to PP&E *.
Vanessa Leemans, Chief Operating Officer for Global Cyber Insurance Solutions at Aon commented: "This study compared the relative insurance protection of certain tangible versus intangible assets. We found that most organizations spend much more on fire insurance premiums than on cyber insurance, despite stating in their publicly disclosed documents that a majority of the organization’s value is attributed to intangible assets.”
The report also found that only 30 percent of businesses are “fully aware” of the legal and economic consequences of European Union General Data Protection Regulation (GDPR). GDPR comes into effect on 25th May 2018, and introduces a 72-hour notification for all personal data breaches – except those unlikely to pose a risk to individuals. Fines for non-compliance with the GDPR will increase to as much as €20m or 4 percent of an organization’s global turnover (whichever is highest). Insurance carriers are starting to see an increase in demand for cyber coverage as cyber exposure awareness becomes an enterprise-wide issue.
Vanessa Leemans concluded: “With 65 percent of EMEA organizations expecting their cyber risk exposure to increase over the next two years, cyber risk needs to be approached at an enterprise-wide level in order to achieve cyber resilience. This should include enterprise-wide education, assessment and quantification, preventive risk management, incident response plan, as well as cyber insurance.
To download a copy of the Aon/Ponemon Institute 2017 EMEA Cyber Risk Transfer Report, please visit our website.
Notes to Editors:
The Aon/Ponemon Institute 2017 EMEA Cyber Risk Transfer Report is based on a survey of over 500 individuals in Europe, the Middle East and Africa involved in their company’s cyber risk management as well as enterprise risk management activities. 35 percent of respondents are in finance, treasury and accounting and 25 percent in risk management. Corporate compliance/audit accounted for 17 percent of respondents and general management nine percent of respondents.
* On average, the total value of PP&E, including all fixed assets plus Supervisory Control and Data Acquisition (SCADA) and industrial control systems is approximately $932m for the companies represented in this research. The report calculates an average total value of information assets, which includes customer records, employee records, financial reports, analytical data, source code, models methods and other intellectual property, of $1,092m.
Aon plc (NYSE:AON) is a leading global professional services firm providing a broad range of risk, retirement and health solutions. Our 50,000 colleagues in 120 countries empower results for clients by using proprietary data and analytics to deliver insights that reduce volatility and improve performance.
Aon Media Contact:
Senior Director, External Communciations EMEA
+44 (0)20 7086 0347