Skip to main content

Lindy Cameron at BIBA Conference 2023

CEO of the NCSC spoke at the British Insurance Brokers' Association (BIBA) 2023 Conference in Manchester.
Lindy Cameron, NCSC CEO speaking at BIBA Conference 2023
Lindy Cameron, NCSC CEO speaking at BIBA Conference 2023

Lindy Cameron spoke to insurance professionals at the British Insurance Brokers' Association (BIBA) 2023 Conference today, where she urged the insurance industry to work together to make the cyber insurance market as mature and effective as possible.

She highlighted the fact that the cyber insurance is currently one of the few market-based levers for incentivising organisation to implement security controls and cyber resilience measures.

Lindy acknowledged that insurance companies operate in a market where the default position is to compete, rather than collaborate. But she urged the insurance industry to collaborate with government and with each other to develop a more sophisticated, better priced market, that helps manage the risk of cyber attacks, while reducing the harm caused by those attacks on the UK.

The full speech can be seen below.

Hello. Thank you for that introduction and for inviting me to speak to you today.

I am delighted to be back here in Manchester. Heron House in Albert Square, which is the north-west home to NCSC and GCHQ, is less than a mile from here.

Our new offices, in the heart of Manchester, offer us the ideal location to collaborate with industry and academia and to tap into existing talent in Greater Manchester’s thriving technology ecosystem.

I know that colleagues from Government Digital Services, Department for Education and the Department for Science Information and Technology are equally delighted to be in such a vibrant and diverse city.

It reminds me of the buzz that we had in Belfast a few weeks ago when we hosted our CYBERUK conference there.

For those of you who came to CYBERUK, you’ll have heard me talk about the importance of being resilient to all threats, whether they come from nation states or cyber criminals.

I want to repeat that message here today.

We operate in an uncertain world where our adversaries range from the unsophisticated but effective cyber criminals operating in their bedrooms, to the full-throated might of sophisticated hostile states.

But whatever the scenario, each of us has a responsibility address the gaps in our defences.

For the cyber insurance industry, this includes raising the minimum standards you expect of your customers, being realistic about the risks that your customers face, better data sharing, and better transparency during incidents.

We in the NCSC continues to do everything we can to make the UK as unattractive a target as possible for cyber criminals, while responding to complex nationally significant incidents.

So, I’m pleased to say that we are making significant progress in bolstering UK resilience…stopping hundreds of thousands of attacks upstream, while helping UK organisations prepare and defend against threats downstream.

Despite those efforts, the collective resilience-building effort must continue.

We’d like businesses of every size must take responsibility for their own cyber security.

They can’t afford to ignore cyber risks, and recklessly leave their digital back door open to cyber criminals.

We continue to see far too many incidents arising because of poor cyber hygiene rather than sophisticated attack techniques.

At CYBERUK, we announced that the latest cyber breaches survey from the Department for Science, Innovation and Technology showed that in 2022, nearly a third, 32% of all businesses and nearly a quarter of charities reported a cyber incident. The numbers are almost double for medium and large businesses.

That is a really significant impact on the business sector.

The disruption caused by these attacks is not just inconvenience – it is also financial. And again not just for the businesses – for their supply chain, for their customers.

It has massive implications for businesses and for you in the insurance industry, especially if risk and resilience are not managed effectively.

When it comes to protecting ourselves from cyber attacks, risk and resilience must be seen through the lens of the attackers’ motivations and where most damage will be felt.

What I see a lot of is that people are obsessed with the possibility of ‘nation-state cyber wars’. The reality is that most state attackers prefer not to be discovered. They are interested in stealing information for espionage purposes. In fact, most of the damage is likely to be caused by cyber criminals.

That’s why it is important to ‘raise the floor’ of resilience to cyber crime. By raising cyber security standards, individuals and businesses will also be increasing resilience to sophisticated actors.

We want to make it difficult, time-consuming, and tedious for criminals and scammers to operate, especially here in the UK. We want the UK to be the safest place to live and work online. We want the criminals’ frustration to be a deterrent to would-be attackers.

Clearly, there are certain organisations and sectors of greater interest to state actors.

In his speech at CYBERUK in Belfast, Oliver Dowden, the now Deputy Prime Minister warned of the threat to the UK’s Critical National Infrastructure from Russian-aligned groups sympathetic to Putin’s invasion of Ukraine.

While we don’t think that these groups currently have the capability to cause widespread damage to our infrastructure, the motivations and behaviours of these actors make the situation particularly concerning.

That is why the NCSC issued an official alert to operators of our critical national infrastructure.

We needed to highlight the risks they face and provide them with actionable advice to defend themselves and the country against such attacks.

How insurance companies deal with cyber attacks conducted, enabled or back by hostile states continues to be a lively debate.

It was reported in March, that Lloyd’s will require insurers to include exemptions that would prevent policies paying out if a major attack is judged to be “state-backed.”

I know opponents of the exemptions say that the policy threatens to scare off companies buying the insurance at all.

That is something that concerns me.

I'm not going to get into whether government should step in and cover losses in the event of a destructive cyber attack by a state actor, but I do welcome a more informed conversation on the reality of state activity, the potential impact, and what can be done to build the resilience of the UK as a whole.

Because, as I see it, we - the NCSC and the insurance industry - have a shared interest in developing a much more sophisticated, a much better priced market, that helps manage the risk of cyber attacks, while reducing the harm caused by attacks on the UK.

Most organisational risks, such as financial or legal, have a cyber component to them.

So it’s really important that businesses look at cyber security as an integral part of their organisational risk management.

For the cyber insurance industry, there is an added incentive to ensure that your customers make better, more informed decisions about their overall cyber security requirements and their resilience.

This will deepen their understanding of the coverage and value of insurance on the market and help them choose the cyber insurance policy that is right for their business.

It might also mean that you're not paying out for avoidable claims.

We’d like to see the correlation between customer implementing good cyber security and your bottom line. It seems obvious on a micro level.

An aspirational cyber culture where clients focus on ensuring better resilience, and therefore reducing high premiums that can deter new customers.

On a macro level, the cyber insurance industry can be a force for good in making the UK the safest country in the world to do business.

Prosperity and economic security go hand in hand.

Cyber insurance is currently one of the few market-based levers for incentivising organisation to implement security controls and resilience measures.

We don’t believe this should be done by regulation. We think the market has a really key role.

We know that organisations who implement the NCSC’s Cyber Essentials controls are 80% less likely to make a claim on cyber insurance than organisations that don't have Cyber Essentials certification.

It is a clear demonstration that getting fundamental cyber security controls right, can make a measurable difference to resilience, and the pay-outs that insurers must make.

But, this message is not getting through.

It has been said that only 200,000 of the 2.7 million businesses in the UK with a website, buy stand-alone cyber insurance policies.

I’d love to believe that this was because it was covered as part of their wider business insurance. But I don’t believe this is the case.

This is partly due to a basic lack of understanding about cyber security. But the insurance industry also has a key role to blay here.

A disjointed approach to adopting minimum cyber standards is compounding the problem.

We all know that to get car insurance, you need (amongst other things) a driving license; tax; MOT; and a commitment that you have not modified your vehicle in some dodgy way that will make it more unsafe.

So what is the equivalent benchmark for cyber insurance? At the moment, there are no minimum protections that organisations must have before they are issued a cyber insurance policy. Yet we know from the Cyber Essentials data that those would really help.

Surely the time has come for the insurance industry to agree appropriate cyber certification requirements as pre-requisite for taking out a policy.

From our perspective, embedding cyber certification into the underwriting processes would provide organisations, regardless of size and revenue, with greater confidence that they have done everything that can to meet the insurance policy threshold.

We think that such certification will raise the bar across the economy and reduce the markets exposure to avoidable, but costly claims.

That’s why my team working are with the cyber insurance industry is pushing for a more collaborative approach on this matter, so I hope that you will join me in supporting their efforts to reduce individual approaches and focus on collective action to raise the bar.

If the UK is to respond to the threats we face, we need to continue to evolve our understand of the scale and impact of incidents. Data is key to this, and insurers are in a unique position to help build this understanding.

As insurers, you hold a wealth of data and information that could be used to better understand the threat landscape, which could be used to build risk-based pricing models that incentivise the market.

However, the lack of aggregated data sharing across the industry on the scale and impact of incidents is hampering the maturity of the market and the models on which cyber insurance is priced.

I recognise that aggregated insurance data is a valuable commodity in determining price variation. From a commercial standpoint, there is an understandable nervousness of handing competitive advantage to newcomers.

This makes sharing data difficult for you. However, I urge you to collaborate with us and with each other to make best use of aggregated data, in order to help us understand the true scale and impact of cyber incidents.

We in the NCSC are certainly committed to working with insurers to build a trusted basis on which to share anonymised data, improve the collective understanding, and use this to better defend against the threats that you and we are seeing.

We want to incentivise data sharing without skewing the market.

On the issue of transparency, there is a real issue about organisations being more open about cyber attacks that they have experienced, particularly ransomware attacks.

That is linked to my point about aggregated data. Because we are not confident that we are seeing the full picture.

Every “hushed up” case that is not shared or fully investigated makes other attacks more likely because no-one can learn from them.

In fact, you will see that the National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO) are publishing a joint blog post tomorrow that encourages victims to report incidents and to seek support to help deal with the fallout effectively.

My Deputy Director for Incident Management, Eleanor Fairford, who co-authored the blog with Mihaela Jembei, Director of Regulatory Cyber at the ICO. She puts it very succinctly. She says that keeping a cyber attack secret helps nobody except the perpetrators.

By responding openly and sharing information, organisations can help mitigate the risk to their operations and reputation, as well breaking the cycle of crime to prevent others from falling victim.

So, if there is one thing I hope you take away from today, it that there is lots we can do together.

Let’s work together to make the cyber insurance market as mature and effective as possible, by focussing on the risks that UK organisations actually face on a daily basis.

Cyber criminals will likely have a more devastating impact on your customers than the threat posed by hostile state actors. We will worry about that.

We need you to raise the baseline of resilience across the whole economy, from the bottom up…from the smallest businesses to the largest.

We want people to be more transparent following an incident and share data to help us and you identify the type and scale of threats that businesses are facing on an everyday basis and work out what to do about it.

The NCSC and the rest of government stand ready to work with you to deliver this.

Thank you for your time and attention today.

Published

Date of speech

Location

Manchester