Artificial Intelligence (AI) has already started to revolutionize the world of Cyberinsurance and it seems that law firms are having to adapt to this new reality. It appears that AI has greatly assisted insurers in assessing risk and reducing errors during the application process. However, the rapid advancement of AI is developing into an insurance risk itself. As such, law firms may need to secure specific insurance if they are using AI. Further details can be accessed here.
There have been frequent instances where law firms have provided incorrect responses to cybersecurity application questions knowingly or otherwise. This has resulted in risk assessments which don’t reflect the actual scenario. AI, with its capability to sift through numerous resources, can now form a more realistic picture of the insurer’s risk. It can corroborate the given answers with resources like online reviews, SEC filings, social media, and more, leading to accurate risk assessments.
AI’s detection capabilities have also advanced significantly. Now, AI can detect previous data breaches with great precision, making transparency paramount. Moreover, recent developments have seen AI achieve a 77% accuracy rate in detecting fraudulent insurance claims.
The rise in ransomware attacks, with the average ransomware payment almost doubling from $812,000 in 2022 to over $1.54 million in 2023, underlines the critical role of Cyberinsurance. The recovery cost from a ransomware attack averages at $1.82 million as reported by Sophos. This escalating cost has led to stricter qualifications for policy and increased premiums.
Notably, the exclusion of coverage due to failure to maintain cybersecurity standards has become common in policies. A common measure being enforced to improve security is multi-factor authentication (MFA). Insurance companies may also demand regular cybersecurity awareness training and conformance to a specific timeline for applying security patches to qualify for coverage.
Law firms should be aware of the various exclusions that insurance companies may deploy. For example, a “prior acts exclusion” could apply for cases before a set retroactive date or the policy’s start. Possible solutions to this problem include an extended discovery period covering claims from prior to the policy’s start date.
Finally, one of the more contentious issues is the question of whether a nation-state cyber-attack could be regarded as an act of war. A recent New Jersey court ruling confirmed that policy language referring to “acts of war” applied only to traditional warfare forms and not cyberattacks.