Jon Bateman, Steve Feldstein
{
"authors": [
"Jon Bateman"
],
"type": "legacyinthemedia",
"centerAffiliationAll": "dc",
"centers": [
"Carnegie Endowment for International Peace"
],
"collections": [],
"englishNewsletterAll": "ctw",
"nonEnglishNewsletterAll": "",
"primaryCenter": "Carnegie Endowment for International Peace",
"programAffiliation": "TIA",
"programs": [
"Technology and International Affairs"
],
"projects": [],
"regions": [
"Iran"
],
"topics": [
"Technology"
]
}Source: Getty
Does Your Cyber Insurance Cover a State-Sponsored Attack?
Modern businesses face a level of cyber risk that vastly exceeds the protections they can rely on from either insurance or government relief. To address this shortfall, business leaders must work with insurers and policymakers to devise practical, long-term solutions.
Source: Harvard Business Review
In 2017, Merck lost an& eye-popping $1.3 billion when it got caught in the crossfire of a Russian cyberattack targeting Ukraine. The event, later dubbed NotPetya, was the largest cyberattack in history, costing $10 billion worldwide — economic damage akin to a medium-sized hurricane, or a small war. Western governments vowed to hold Russia accountable, yet none stepped forward to support the companies that were hit by the attack.
Insurance was more helpful — to a point. The insurance industry sells policies specifically designed for cyber incidents, but their scope and scale remain limited. Cyber insurance paid for just 3% of NotPetya’s global damage, leading some NotPetya victims to turn to other insurance policies with more ambiguous terms. For example, Merck invoked property and casualty policies that covered all manner of hazards without explicitly mentioning cyber incidents. These policies had so-called “war exclusions,” which barred coverage for damages due to “hostile or warlike actions” by governments or their agents. Many insurers cited these clauses to push back on the claims, triggering high-stakes legal battles that continue to this day.
This article was originally published in the Harvard Business Review.
About the Author
Senior Fellow and Co-Director, Technology and International Affairs Program
Jon Bateman is a senior fellow and co-director of the Technology and International Affairs Program at the Carnegie Endowment for International Peace.
- Are All Wars Now Drone Wars?Q&A
- The Most Likely Outcomes of Trump’s Order Targeting State AI LawsQ&A
- +1
Jon Bateman, Anton Leicht, Alasdair Phillips-Robins, …
Recent Work
Carnegie does not take institutional positions on public policy issues; the views represented herein are those of the author(s) and do not necessarily reflect the views of Carnegie, its staff, or its trustees.
More Work from Carnegie Europe
- Europe Should Not Let Nuclear Nonproliferation DieCommentary
Amid uncertainty caused by the Iran war, the global drive for nonproliferation has stalled. With Europe diplomatically marginalized and countries reassessing their nuclear options, efforts to curb the spread of nuclear weapons risk becoming irrelevant.
Jane Darby Menton
- Ecological Statecraft in the Midst of War: Water, Regeneration, and the Future of Gulf SecurityPaper
The U.S.-Iran war has crossed a dangerous threshold: water infrastructure in the Gulf is now a target. Ecological statecraft is no longer peripheral to security, it's part of its foundations.
Olivia Lazard, Ali Bin Shahid
- The Fog of AI WarCommentary
In Ukraine, Gaza, and Iran, AI warfare has come to dominate, with barely any oversight or accountability. Europe must lead the charge on the responsible use of new military technologies.
Raluca Csernatoni
- Taking the Pulse: Can NATO Survive the Iran War?Commentary
Donald Trump has repeatedly bashed NATO and European allies, threatening to annex Canada and Greenland and deploring their lack of enthusiasm for his war of choice in Iran. Is this latest round of abuse the final straw?
Rym Momtaz, ed.
- Europe and the Arab Gulf Must Come TogetherCommentary
The war in Iran proves the United States is now a destabilizing actor for Europe and the Arab Gulf. From protect their economies and energy supplies to safeguarding their territorial integrity, both regions have much to gain from forming a new kind of partnership together.
Rym Momtaz