...
Skip to content

Cloud-based tools change risk profiles

Software as a service offerings are proliferating in the insurance sector, providing insurers, brokers and others with access to a growing array of tools and capabilities, but ease of use also comes with some restrictions, according to industry sources.

Along with the growing universe of capabilities, companies using software as a service products have an increased reliance on connectivity, security concerns and potential limitations on flexibility, they say.

From external data sets to analytics, evolving machine learning, artificial intelligence and security capabilities, software as a service users are obtaining and accessing a variety of services via web-based platforms.

Software as a service is technology/infrastructure that lives in a cloud environment, as opposed to being deployed and hosted on-site.

“Historically, you might have purchased software or even infrastructure that you would install or host in your own data center,” said Nick Graf, assistant vice president for information security in Las Vegas with CNA Financial Corp.’s specialty insurance organization.

CNA recently announced a partnership with Opaq Networks Inc. to offer the security services to CNA cyber insurance customers.

Opaq offers a security technology product as a service aimed primarily at small and mediumsize enterprises that is accessed online. It provides an online managed firewall that can be accessed by individual users online, or with the addition of a hardware appliance used to secure an entire location, such as an office, said Casey Corcoran, chief information security officer in Baltimore for Opaq.

“It makes a great deal of sense as far as risk management goes,” Mr. Graf said. “If we can make recommendations or offer services that help our insureds reduce the likelihood or severity of a claim, that’s beneficial to everyone.” 

Opaq is also working with PSA Insurance & Financial Services, which has included the online firewall with its Cyber On policy launched in June in what Mike Volk, PSA’s vice president for cyber risk solutions, called a “small business-specific initiative” aimed at firms with fewer than 50 employees or less than $15 million in annual revenue, such as a small association, he said.

The abundance of software as a service offerings has led insurers to exist in a “multicloud” environment, said Mark McLaughlin, global insurance director for IBM in Chicago, which brings challenges such as maintaining interoperability.

There are “lots of different data sources you can fold into this, and many are offered as a service,” Mr. McLaughlin said.

“Providers are offering all manner of better data, better visuals” and better interpretation of visual data, he said.

Insurers and other organizations are “getting some mix of services from different cloud providers and having to operate across those various services from various providers,” he said, which can be challenging.

IBM data services range from simple storage to analytics, machine learning and other capabilities, Mr. McLaughlin said. Maintaining security across operations that may utilize multiple vendors and internal systems can be challenging, he said.

Software as a service can allow small and medium-size companies to access and utilize technology in a more cost-effective way, industry sources say, but still requires critical participation from users as well.

“You still have to set the security levels and the configurable items,” such as access controls, said Stacy Scott, managing director for cyber risk in Dallas with Kroll LLC, a wholly owned affiliate of Duff & Phelps LLC.

“You as the customer still must see that security is managed in an appropriate and reasonable way,” she said.

Users of software as a service, Mr. Graf said, must remain “mindful of what responsibilities you do still have.”

Software as a service does, however, provide tools to help companies cope with the ever-expanding list of technology issues such as security and data storage, which are costly and difficult to manage, Ms. Scott said.

“I think it’s something that should be considered,” said Marie Carr, principal of global growth strategy and U.S. financial services practice in Chicago for PwC, also known as PricewaterhouseCoopers. “Anyone who’s looking to grow, this should be in your consideration set.”

Offerings in the software as a service space have been proliferating, she said.

There was $4.15 billion of global insurance technology investment in 2018, according to a recent report from PwC, with 28 investments of $30 million or more.

Ms. Carr said that using software as a service can allow insurers and other users to trial new technologies before becoming fully invested but cautioned that users should make sure such capabilities can grow and scale with the user’s growth plans.

Another concern is the increased reliance on connectivity, according to Mr. Graf.

“As you move more and more resources, software, infrastructure to the cloud, that connection becomes your pipeline to these services,” he said.

A loss of an online connection could impair business operations, although this is becoming less of an issue as high-speed access becomes more widely available, he added.

There also can be a lower degree of customization available with such services, he said, as opposed to when a company hosts technology internally, such as with security configurations and user settings.