Cybersecurity professionals are likely familiar with “black swan” events: rare, unpredictable incidents that occur without warning and are nearly impossible to prepare for. A “gray rhino” is the black swan’s converse: a predictable threat that can be easily managed by taking the proper steps. But there is also a third, lesser-known type of event called a “gray swan.”
Gray swan incidents are foreseeable, but organizations nonetheless struggle to handle them adequately. Data breaches and ransomware attacks fall into this category. Companies are highly likely to experience these scenarios — financial institutions identified $1.2 billion in payments related to ransomware attacks in 2021, according to the U.S. Treasury Department, and in 2022 ransomware attacks on industrial organizations increased by 87% compared with 2021. Despite the frequency of these incidents, many organizations still falter when they happen to them.
Some organizations may feel they have their arms around gray swan data breaches and ransomware attacks, but while 2022 saw a leveling off of ransomware attacks, they are unfortunately back on the rise. The number of ransomware attacks in June increased 221% compared with the same month last year, according to a report from NCC Group. Furthermore, the average cost of a data breach reached an all-time high in 2023 of $4.45 million, according to an IBM Security report. While London-based insurance brokerage Howden Broking Group Ltd. reported that cyber insurance rates dropped about 10% in June, it estimates that premiums could exceed $50 billion by 2030.
Any lull in ransomware attacks or data breaches is temporary, as hackers will find new avenues for exploiting information technology security. That means executive leadership and IT leaders must recognize that the frequency of cyberattacks, and the expense of ransomware attacks are expected to continue to increase.
How should organizations plan for this? Even businesses that take steps to enhance cybersecurity, handle data more responsibly, hire forensics experts and purchase insurance coverage can fall into the trap of being underprepared. The following recommendations can help enterprises assess their preparedness and become operationally resilient in the face of ransomware attacks and other gray swan events.
Evaluate insurance
While having cyber insurance is an important step in mitigating the risk of cyberattacks, organizations may be operating under the misapprehension that their coverage is enough. Swiss Reinsurance Co. Ltd. estimates that half of organizations have some form of cyber policy, but fewer than 20% of those have enough coverage to meet the average ransomware demand.
Many current cyber risk models rely on exposed record counts to estimate losses, which does not accurately reflect the real-world costs and losses businesses suffer when crippled by ransomware attacks. To better understand breach scenarios and their accompanying costs, including the costs of ransomware attacks, business interruption and property damage, organizations need to look beyond the traditional models. To do so, they should continuously evaluate third-party models and software, while understanding the importance of adequate data inputs for any model. The adage of “garbage in, garbage out” continues to hold true for many current cyber loss quantification models. Further, organizations should conduct tabletop scenario analysis with key stakeholders from operations, IT and finance to understand the impact across the business from critical system disruption.
Understand scope, definitions
Leaders also need to evaluate their cyber insurance policies and fully understand the scope of their coverage and definitions of key terms. Some organizations make the mistake of treating cyber insurance like an “off-the-shelf” purchase. Instead, buyers should know their risk exposure and negotiate terms accordingly.
Enterprise leaders should also prepare for a world where cyber insurance doesn’t exist in its current form. Insurers are scrutinizing cyber hygiene, and companies that fall short may face higher premiums or may not be able to obtain coverage at all.
While we may continue to see some fluctuation in pricing, cyber insurance costs are high and difficult to control. As government frameworks around best practices evolve, fines and penalties for privacy violations could further elevate costs. An increasing and dangerous trend is that some organizations are deciding to forego cyber insurance. Some companies have determined that the costs are too high relative to what insurers can provide.
There has also been discussion of potential government regulation against paying ransoms demanded in ransomware attacks, which would significantly change the landscape of coverage. Whether modulated by government regulation or by market factors, the cyber insurance sector is likely to evolve and look very different over the next five to 10 years, and organizations should be prepared.
Focus on resilience
To navigate these shifts, enterprises should focus on operational resilience, not just IT resilience. When a data breach occurs, companies can find themselves in one of two situations: uncertain panic or ready to take decisive action. An organizational playbook that reflects the reality that breaches are inevitable can help companies move quickly, work decisively and proceed calmly when they occur.
Here are a few practices organizations can follow to make the difference between effective breach response and scrambling:
- Expect the breach. Hackers are always finding loopholes even in resilient IT environments. Have a playbook ready that outlines in detail the steps your organization will follow when it experiences a breach. When a computer doesn’t turn on, who does what? Without a playbook, there could be five people who think they have the same role to play, leading to delays and further damage. A playbook should outline who’s in charge of which tasks and who needs to be alerted — including relevant government agencies — as well as provide guidelines for command and control during the crisis.
- Practice makes perfect. Tapping the right stakeholders to respond to a breach is crucial. Key players outside of the IT/cyber suite include finance, legal, operations and human resources. It is important to regularly assemble this group for tabletop practice exercises to prepare for an incident. True operational resilience requires practice to eliminate gaps in stakeholder behavior and make executing the playbook second nature. Regular rehearsals create alignment so the whole organization can focus on minimizing the damage from a breach.
- Refresh your cyber resilience. Operational resilience requires a cyber plan that includes governance, communications, protocol and reporting. Companies should have a roadmap for implementing this cyber program throughout their organization and for evaluating their cyber capabilities against those of their respective industry and peers. Finally, with the cyber landscape changing frequently, your cyber response plans will frequently need to be refreshed to keep up with risk and business changes. Organizations should have a system for ongoing maintenance to ensure their response plans are up to date.
Ransomware and other cyber threats are a significant and predictable risk for organizations — in other words, they are the gray swans. Although gray swan threats are identifiable in advance, many organizations lack the expertise to effectively address them. Any historical or forthcoming trend of declining ransomware attacks is unlikely to last. When there is a lull in cyberattack activity, companies should take proactive steps to prepare for potential major incidents, including evaluating cyber insurance and bolstering operational resilience.
Mark Millard is a New York-based partner at BDO USA P.C., where he leads the firm’s risk advisory group. He can be reached at [email protected]