The CrowdStrike outage has exposed the difficulties of modelling cyber risk

By Bernice Han

Insurers are probably breathing a little easier after July 19. On that day, millions of corporate devices crashed when CrowdStrike, a cybersecurity business, bungled a routine software update for the Microsoft Windows operating system.

The dreaded “blue screen of death” – synonymous with a Windows system failure – paralysed at least 8.5 million computers, according to Microsoft.

Airlines, hotels, factories, supermarkets, banks and other major corporations were locked out for hours as they waited for CrowdStrike to identify and fix the problem.


Estimates vary as to insured losses from the biggest IT outage on record.

Verisk’s property claim services unit designated the outage a global cyber catastrophe loss event. The risk assessment business tells Insurance News insured losses are anticipated to surpass its $US250 million threshold for such a designation, which includes affirmative and non-affirmative cyber losses.

Ratings agency AM Best’s initial loss estimates suggest a range of $US500 million to $US1.5 billion.

Michael Lagomarsino, the agency’s senior director, tells Insurance News the event “appears to be manageable” for affirmative cyber writers, particularly since they are coming off strong operating results in recent years.

“Actions taken around tightening policy language and terms and conditions, as well as an overall improvement in the cybersecurity hygiene of insureds over time, place the industry in a solid position to absorb any negative impacts,” he says.

But he warns it is still early days and the agency will be watching for more information.

He says the CrowdStrike event is “exactly the kind of aggregation risk that the industry is worried about and serves as another example why this is such a dynamic market and why clients … [and] insurers need to be on top of emerging issues.”

The July 19 outage has forced the industry to again ask if it is ready for a catastrophic cyber episode. And is it even possible to be fully prepared?

Wotton + Kearney’s Kieran Doyle believes the CrowdStrike event is about more than just cyber readiness.

“A lot of focus is rightly put onto preparing for cyber risks,” Mr Doyle, the law firm’s head of cyber and technology, tells Insurance News. “However, it certainly is a wake-up call for other forms of systemic risk that can be just as impactful.”

The outage has laid bare the challenges facing the insurance industry as it tries to stay up to speed with a fast-changing cyber risk landscape.

Attacks from bad actors are not the only cyber perils that could spark a digital blackout and widespread business disruption. Human errors, as shown by the CrowdStrike coding flaw, are just as menacing.

A report last October from Gallagher Re proved remarkably prescient. The biggest problem for the industry, according to the paper, was it had never experienced a cyber catastrophe.

“Because there has never been a truly systemic cyber disaster, there is no universally accepted definition for what might cause one and what form it might take … and no industry consensus on modelling the risks,” it said.

The most likely cause of a systemic cyber event would be an accident, an unintended consequence of a smaller event or a combination of two apparently unconnected events, the report said.

It went on to say: “For an event to threaten the system, it either has to knock out one of the internet’s crucial pieces of centralised infrastructure or go uncontrollably viral. A prolonged cloud outage is the first of the two most common suggestions – for example, the failure of Amazon Web Services or Microsoft Azure – rendering huge swathes of the business world inoperable.”

The University of Melbourne’s Michael Davern, a professor of accounting and business information systems, says the July 19 outage was more an “inevitable” event than a predictable one. “It was inevitable and we get complacent at times because we forget that inevitable but unpredictable things will happen,” he tells Insurance News.

“It’s like floods. Say we had a 100-year flood event last year; it could still happen again this year. It is inevitable and we’re playing a long-run game here as an insurer.”

The way businesses were caught off guard, with no back-up plans to resume operations quickly, says a lot about their risk management, and cyber insurers will be taking note.

“Everyone’s blindsided by it because prevention, while it is generally a lot cheaper than the cure, is expensive when you’re trying to make money in the short term,” Professor Davern says. “Some insurance contracts are going to get reviewed a little bit more closely in terms of the interconnections between businesses and the risk of the dependencies that exist, because we are so tightly connected in every respect.”

The Gallagher Re report says cyber is inherently difficult to model and price.

Professor Davern says that is, in part, down to the nature of the economy. “With cyber risk, the interconnectedness of companies and the constantly changing technologies mean it’s not even clear what variables should be tracked by the modellers.

“So historical data is often not useful in forecasting what future cyber risk looks like, and that’s the problem. And even if the data is available, it’s going to be out of date very quickly because technology is moving so rapidly.”

“It was inevitable and we get complacent at times because we forget that inevitable but unpredictable things will happen.”
Professor Michael Davern

Still, it’s possible for insurers to mitigate their cyber exposure.

“If I’m an insurer, I’d be focusing a lot on what are the mitigants that client is putting in place to help minimise the risk, because that’s the bit that you can see, that’s the bit that you can control,” Professor Davern says. “As the insurer, I want to see the client doing as much as they possibly can to reduce the risk. This obviously directly reduces my risk as insurer.

“Indirectly, it also helps, as the more the client is investing in mitigants, the more cognisant of the potential consequences, the better their awareness, attention and management of the risk becomes.”

Gill Collins, head of cyber at Marsh McLennan Pacific, says the CrowdStrike outage serves as a reminder for the industry to keep on top of developing threats and trends. Most organisations have third-party suppliers to support their operations, and this is particularly the case with IT essentials such as cloud storage and virus protection software.

“So it can be a really vulnerable penetration point by criminals,” she tells Insurance News.

“Any outage in externally sourced technology can have a really significant impact.”

Marsh has been warning clients about supply chain risks including cyber disruptions, so the CrowdStrike outage did not come as a surprise to the global broker.

“We have talked about this type of cyber supply chain risk,” Ms Collins says.

“We’ve been putting it front and centre for the past two years as something that needs to be thought about and solved by executives and directors who are overseeing and managing cybersecurity.”

She says more than 500 Marsh clients globally, including in Australia, were affected by the July 19 outage.

“I guess what I’ve been really impressed with is how resilient a lot of the organisations that were impacted were and how quickly they did get back to business as usual,” Ms Collins says.

“The next outage is obviously coming It could be tomorrow, it could be next year. How businesses prepare is important.”
Professor Sanjoy Paul

She says Marsh undertakes third-party reviews as part of its work for clients. And few clients have made claims under their cyber policies, because they resumed operations “very quickly and didn’t suffer very significant business interruptions. That was certainly the case in Australia for us. And the thing with cyber insurance, it’s a bespoke product. Each organisation purchases cyber insurance to cover what they want to cover.”

Wotton + Kearney’s Mr Doyle says whether insurers cover events such as the CrowdStrike outage will depend on their risk appetite.

For him, the message post-July 19 is clear. “I think the biggest takeaway for insurers is being prepared for and modelling systemic risks.

“Of course, insurers have been modelling what I would call a ‘cyber catastrophe’ for quite some time and while there have been some notable examples of systemic cyber events such as … Solarwinds … we have not seen an incident with such a large surface of collateral damage since NotPetya in 2017.”

He says the CrowdStrike incident shows how connected the world is, and is “perhaps a wake-up call for business continuity planning”.

It’s a view shared by Sanjoy Paul, an associate professor in operations and supply chain management at University of Technology Sydney Business School.

“We can’t avoid such outages, but how we manage it is important,” he tells Insurance News. “Back-up plans need to be updated regularly.”

He says businesses should consider switching to other operating systems to maintain activities.

“The next outage is obviously coming,” he says. “It could be tomorrow, it could be next year. How businesses prepare is important.

“Have an appropriate recovery plan, prepare well and respond quickly.”