Cyber-attacks now a days have become a major obstacle for corporate governance. Corporate subsistence in the current scenario is dependent on its cyber risk management strategy. Data security in the digital world is no longer the responsibility of the IT division alone. Indeed, it’s the responsibility of the top management as a part of risk management and risk transfer mechanism.

Every director is needed to have a concrete awareness of the foundations of cyber security to transform India digitally by incorporating technology into corporate governance. Cyber insurance is one of the risk transfer mechanisms in the digital world. This article primarily focusses on the relationship between cyber insurance and corporate governance.

Introduction

Cyber risk has evolved over the long term, ensuring that more threats will persist than ever before. The majority of us identify corporate governance with company operations including financial integrity, hiring processes, legal and regulatory assurance, and corporate strategy. However, because of the growing importance and complexity of cybersecurity challenges, it is now required to be a major component of an overarching corporate governance framework. There is mounting evidence that the boards are lagging in terms of prioritising cybersecurity as critical governance problem. Traditionally, cyber security has been following the bottom-up approach which is the biggest threat in the current scenario as according to that the IT department of a company is responsible for protection of data.

As per the study conducted by (Singh and Upreti, 2021) unlike other countries, India has been dozing off when it comes to cyber risks posed to well-known companies. It is necessary to protect not just the public from data exploitation, but also organisations from external hacking attacks, that is why it is a significant issue in corporate governance. If a company is subjected to a cyber-attack, it may face several consequences, including the disclosure of confidential information, the destruction of data, and the loss of credibility. With the progress of technology, the sorts of cyber hazards are becoming more sophisticated, making it imperative for businesses to have cybersecurity strategies and have their data covered through cyber insurance.

Related Studies

The expected loss due to cyber-attacks uses collective risk modelling; computing the net premium that cyber insurers will charge to indemnify losses from a cyber-attack; computing the average loss data for each malicious attack using gamma and exponential distribution, and suggesting either cyber insurance or self-insurance, or self-protection, as a strategy for organisations to minimise losses (Mukhopadhyay et. al, 2017). According to the study conducted by (Bartolini et. al, 2019) cyber-insurance is regarded as the most effective way to prevent financial losses brought on by security breaches in information technology infrastructures and practises. (Cortez and Dekker, 2022) illustrates that the companies’ underinvestment in cybersecurity solutions can be explained in part by knowledge asymmetries and the resulting agency issues between management and other corporate stakeholders. Signs of the potentially tense management-shareholder relationship regarding companies’ cybersecurity procedures include high-profile class action lawsuits brought when companies discovered privacy infringements and regulatory agencies imposed heavy fines. (Miller, 2018) elaborated that due to the frequency and size of data breaches and information theft, cybersecurity is becoming essential. Cybersecurity insurance will help the market find a solution to corporate data theft by aligning incentives for companies to keep up a strong suite of data protection measures. (Kane and Goldstein, 2017) in their study finds that in addition to running the serious risk of failing to provide a necessary oversight, the boards that fail to adequately address the growing cybersecurity threat and oversee the development of effective cybersecurity policies and programmes with accompanying corporate governance may also be in violation of the expanding body of cyber regulations.

Global Data Breaches

Data thefts have increased significantly across the world over the past few years. They have damaged enterprises to the tune of millions of dollars, affecting businesses and organisations of all shapes, sizes, and industries.

Table 1: Details of Global Data Breaches

YearName of the CompanyDetails of Breach
2011SonyPersonal information of 77 million members was compromised.
2013Target110 million clients’ personal and financial data, as well as the banking information were stolen.
2013AdobeAdobe acknowledged that extremely sensitive information of 2.9 million accounts was hacked.
2014SonyA computer worm targeted Sony Pictures Entertainment. 100 terabytes of data, including a significant amount of sensitive information of 47,000 employees was stolen by the “Guardians of Peace.”
2014YahooCyber-attack compromised 500 million user accounts.
2015Adult Friend FinderDating site witnessed its first attack where sensitive information of 4 million accounts was made public on a forum only accessible on Tor.
2016Adult Friend Finder400 million accounts were hacked during the second attack on this dating site.
2016UberHackers stole the personal information of 57 million Uber users and drivers, a significant cybersecurity breach at the company.
2017EquifaxVictim of a cyber-attack over a period of months that included the personal information of 143 million clients as well as 200,000 credit card numbers.
2018Marriott hotels500 million guests’ personal information, including financial information, was exposed at the Marriott-owned Starwood hotel group.
2021Air India4.5 million customers’ personal information was stolen because of a sophisticated hacking attempt on SITA, the operator of Air India’s passenger service system.
2022NvidiaVictim of a ransomware attack. Employee login passwords and confidential company data are among the data that was pilfered.
2022MicrosoftHacking incident in a security blog post. The cybercriminal group even posted a 37 GB file that contained the source code of more than 250 Microsoft projects.
2022Apple Inc. and Meta Platforms Inc.Hackers posing as law enforcement officers received user data from Apple Inc. and Meta Platforms Inc., the parent company of Facebook in response to the fake “emergency data demands”.
2022Cash AppData breach that affected 8.2 million users and was caused by a former employee.
2022OpenSeaNFTs worth $1.7 million were allegedly taken from OpenSea customers during a phishing scam.
2022TwitterTwitter has acknowledged that the platform’s zero-day vulnerability, which was first identified in January 2022, allowed for the theft of 5.4 million accounts’ phone numbers and email addresses.
2022Tata PowerA cyber-attack on Tata Power’s IT infrastructure, which affected some of its systems. Hive, a ransomware gang, allegedly exposed a packet of crucial data from Tata Power servers on the dark web.

Role of Board in Cyber Security

A company’s competitiveness in the future may depend on how it responds to the effects of digitization. The board of directors may, in the future, play a significant role in helping the company adjust to shifting strategic contexts (Bankewitz et. al, 2016). It is crucial to protect any information of the businesses that manage a significant amount of sensitive consumer data. A cyber insurance coverage can be useful in this situation. (Landefeld et.al, 2015) discussed that the risk associated with cybersecurity will continue to grow, and the boards of publicly traded companies will need to exercise more control.

“Cybersecurity and cyber risk have become corporate governance issues. The board plays an inimitable role in governance; therefore, it is the responsibility of the board to receive the apt cybersecurity metrics for monitoring and detection on a regular basis.”

Cyber security and cyber risk are the priority agendas of the boardroom. Recent high-profile data breaches, including cyber risk events at global giants have caused many corporate crises. Cybersecurity and cyber risk have become corporate governance issues. The board plays an inimitable role in governance; therefore, it is the responsibility of the board to receive the apt cybersecurity metrics for monitoring and detection on a regular basis. The board’s desire to understand cyber threats that exist within the company and externally. The prospective roles and responsibilities of the corporate executives and the board of directors, as well as the concerns and obstacles for cyber security governance, are discussed in the study (Thuraisingham, 2019). The board should recognise cyber threats affecting the industry and certified protections. Training and awareness sessions must be organised at all levels in the company so that employees are proficient to maintain cyber hygiene. The board of directors may not have the technical proficiency to understand the intricacies of cybersecurity. However, individually, collectively, and with the help of technical experts, they must continue to find techniques to strengthen their cybersecurity efforts. (Trautman and Altenbaumer-Price, 2011) emphasise that to generate the necessary IT knowledge, each Governance and Nominating Committee must consult its current inventory of director skill sets.

As part of good corporate governance, directors are responsible for protecting shareholders, employees, and stakeholders from potential legal issues arising from cyber risks. Uday Kotak Committee on Corporate Governance, 2017 proposed that “The board of directors shall define the role and responsibility of the Risk Management Committee and may delegate monitoring and reviewing of the risk management plan to the committee and such other functions as it may deem fit. Such function shall specifically cover cyber security.” While no director can anticipate whether or not a data breach will occur, cyber insurance can assist to mitigate the impact if the worst happens. This type of unplanned, catastrophic expense is frequently ignored and not factored into a company’s budget. With cyber assaults and data breaches on the rise with no end in sight, the expenses of reacting to these disasters should be budgeted ahead of time rather than depleting balance sheet assets that could have been covered by insurance money.

Need for Cyber Insurance

Cyber risk is an emerging dynamic and difficult-to-quantify risk category (Eling and Zhu, 2018). Cyber risk insurance helps to minimize losses to a company, but it is not a replacement for a company’s cybersecurity strategy. Cybersecurity experts believe that the type of insurance a company is eligible for depends on its cybersecurity efforts. (Talesh 2017) demonstrated theoretical frameworks that how, in the context of cyber insurance, insurers move far beyond risk pooling and spreading to serve as compliance managers for businesses dealing with cyber security concerns. Because companies are still unprepared for cyber threats and do not comply with privacy rules, insurance sector assistance in this area is critical. All insurers first assess the strength of a company’s cybersecurity position before issuing a policy. The board of directors need to understand potential cyber threats in order to evaluate and implement appropriate plans. They must understand the legal and regulatory implications associated with cyber risk, cyber security and privacy.

“The legal and regulatory environment is evolving rapidly around the world, and the boards need to keep up with new laws, law enforcement and regulatory agencies at various levels.”

The legal and regulatory environment is evolving rapidly around the world, and the boards need to keep up with new laws, law enforcement and regulatory agencies at various levels. By managing claims after a cyberattack, companies can minimize losses and resume normal operations, but risks cannot be ruled out, so companies buy insurance to further mitigate losses. Directors can also review their own liability insurance policies in the event of a cyber breach. In case of data breach, immediate order for inspection against the board and company have been passed leaving no distinction between the director and manager of the IT department. For this reason, it is best for the board and companies to proactively investigate how cyber insurance can help manage cyber risk, rather than revealing cybersecurity gaps in the event of a security failure. Purchasing the right cyber insurance plays a key role in protecting a company’s bottom line, instead of spending millions of rupees as cost of damage that may have been insured.

Evaluation of Cyber Insurance

Solutions focused solely on detecting and eliminating security risks are unlikely to result in a secure cyberspace Pal et. al (2014). Once a company is prepared to buy cyber insurance, it’s far more critical to cautiously compare the plethora of cyber insurance alternatives from different angles. A company has to determine the amount of insurance required and the level of risk the business can afford. Once a need is identified, a business must determine how much it can afford out of pocket before it can pay any cyber claims. Experienced and knowledgeable cyber insurance professionals can help the company to evaluate coverage options and determine which coverage is best as cyber insurance policies are not standard policies and vary widely in terms of coverage. (Nishanka, 2016) highlights that the processes for securing the data in various forms of insurance should be made possible in the insurance industry as the market demands this sort of insurance evaluation.

Cyber Insurance in India

Cyber insurance is a type of insurance that protects policyholders from the potential consequences of cyberattacks. Cyber insurance is essential in India with the surge in online fraud cases involving malware and phishing emails. During the Covid-19 outbreak, these cases saw a quantum leap since an increase in digital payments also saw an increase in digital fraud. Although the cyber insurance market is expanding in India as well as internationally, it remains tiny in comparison to other insurance lines of business. Many companies, whether in the service or manufacturing industries, are unaware of the entire magnitude of cyber risk or believe that regular insurance lines would cover them. Others, such as financial organisations, are aware of the threat but believe that cyber insurance coverage is too limited or unclear to ensure appropriate recovery in their time of need. Insurance firms, on the other hand, are stepping carefully and gradually expanding their services.

Conclusion

Corporate governance has undergone a revolutionary change due to issues such as increased regulatory oversight, more dynamic and enthusiastic leadership, and increasingly sophisticated environment. Cybersecurity could be the only major factor that has redesigned corporate governance in decades. Business operations can become unstable because of a cyberattack and security breach. The business interruption has a negative effect on the company’s financial profitability. A data breach incident that results in the disclosure of confidential data has a negative effect on the company’s reputation and may also cause current and potential customers to be reluctant to do business with the impacted company because they lack confidence in the security of their confidential data. An incident involving a data breach could also lead to regulatory attention from the authorities, which could lead to fines and penalties. As a result, cyberattacks and data breaches have a variety of repercussions that are not just confined to the company computer systems. (Miller, 2019) concludes by arguing that a mandatory nationwide adoption of cyber insurance coverage will motivate companies to adopt proactive cybersecurity policies.

Cybersecurity has always been a never-ending exercise, but the pace of change is accelerating. Unfortunately, there is not yet enough clarity about the practical advice that corporate leaders can implement from the beginning to ensure the cyber security of data of the company. However, if cybersecurity is considered as a business problem and is not isolated as a technical problem that IT professionals solve using technical tools, the chances of success are much higher. All board obligations are governance obligations, including cybersecurity. Due to high level of cybersecurity risk and lack of knowledge compared to other areas of governance, today’s board of directors needs to pay particular attention to cybersecurity governance obligations.


References

  • Bankewitz M., Aberg C. and Teuchert C. (2016) Digitalization and Boards of Directors: A New Era of Corporate Governance?, Business and Management Research, volume 5, No. 2, pp. 58-69
  • Bartolini D. N., Benavente-Peces C. and Ahrens A. (2019) Using Risk Assessments to Assess Insurability in the Context of Cyber Insurance E-Business and Telecommunications. Communications in Computer and Information Science, volume 990. pp. 337–345
  • Cortez E. K. and Dekker M. (2022) A Corporate Governance Approach to Cybersecurity Risk Disclosure, European Journal of Risk Regulation, first view, pp. 1-23 DOI: https://doi.org/10.1017/err.2022.10
  • Eling M. and Zhu J. (2018) Which Insurers Write Cyber Insurance? Evidence from the U.S. Property and Casualty Insurance Industry Journal of Insurance Issues, 2018, 41 (1), pp. 22–56
  • Kane A. T. & Goldstein P. A. (2017) Cybersecurity Is Not a Product, It’s a Process: Financial Service Regulators Hold Insurance Company Boards Responsible for Cybersecurity, 4 Emory Corporate Governance & Accountability Review, volume 4, pp. 353-362
  • Landefeld S. M., Mejia L. R., and Handy A. C. (2015) “Board Tools for Oversight of Cybersecurity Risk” volume 23, Number 3, pp. 1-9
  • Miller L. (2018) Cybersecurity Insurance: Incentive Alignment Solution to Weak Corporate Data Protection Available at SSRN: https://ssrn.com/abstract=3113771 or http://dx.doi.org/10.2139/ssrn.3113771
  • Miller L. (2019) Cyber Insurance: An incentive alignment solution to corporate cyber- Insecurity, Journal of Law & Cyber Warfare, Vol. 7, No. 2, pp. 147-182
  • Mukhopadhyay A., Chatterjee S., Bagchi K. K., Kirs P. J. and Shukla G. K. (2017) Cyber Risk Assessment and Mitigation (CRAM) Framework Using Logit and Probit Models for Cyber Insurance Inf Syst Front 21, 997–1018. https://doi.org/10.1007/s10796-017-9808-5
  • Nishanka A. K. (2016) Evaluating Cyber Infrastructure for Cyber-Insurance in the Corporate World: An Analytical Focus available at SSRN: https://ssrn.com/abstract=2864383
  • Pal R., Golubchik L., Psounis K. and Hui P. (2014) Will cyber-insurance improve network security? A market analysis, IEEE INFOCOM 2014 - IEEE Conference on Computer Communications, pp. 235-243
  • Singh S. and Upreti V. (2021) Corporate Governance and Cyber Security, International Journal of Law Management & Humanities, volume 4, pp. 2808-2821
  • Talesh S. A. (2017) Data Breach, Privacy, and Cyber Insurance: How Insurance Companies Act as “Compliance Managers” for Businesses, Law & Social Inquiry, available at https://doi.org/10.1111/lsi.12303
  • Thuraisingham B. (2019) Cyber Security and Data Governance Roles and Responsibilities at the C-Level and the Board, IEEE International Conference on Intelligence and Security Informatics (ISI), pp. 231-236, doi: 10.1109/ISI.2019.8823534
  • Trautman L. J. and Altenbaumer-Price K. (2011) The Board’s Responsibility for Information Technology Governance, Journal of Computer & Information Law, volume 28, pp. 313-341

Author may be reached at: gunjank_cs@yahoo.com and eboard@icai.in