Cyber Insurance Blog

The Limits of Risk Transfer in Cyber Risk Management

From cloud platforms and managed service providers to payroll companies, marketing agencies, and software developers, third-party vendors have become integral to your clients’ operations.

That reliance raises this important question: If a vendor causes a cyber incident, who is actually responsible?

Many of your clients likely believe a vendor contract or the vendor’s Cyber Insurance policy transfers the risk away from their organization. But cyber risk transfer rarely works that cleanly.

Jim Whetstone, ProWriters’ director of National Brokerage Partnerships, answered some common questions about risk transfer as a part of cyber risk management.

Watch the video of the discussion below, then read on for more information that can support a productive conversation with your clients about the relationship between contracts, Cyber Insurance, and vendor risk.

Cyber Risk Transfer Defines Responsibility But Doesn’t Eliminate Risk

When your clients hear the phrase “cyber risk transfer,” they may assume someone else is now responsible if a cyber incident occurs.

Whetstone offers a more practical definition: “Risk transfer doesn’t completely eliminate exposure. It simply helps define who is going to be responsible for what, and how those losses are going to be funded when something goes wrong.”

Contracts establish which party is responsible for certain losses and obligations. Cyber Liability Insurance provides the financial resources and specialized expertise needed to respond when something goes wrong. Most organizations use both.

A vendor contract may require a technology provider to carry Cyber Insurance, maintain certain security standards, and indemnify the client for specific losses. Those provisions are important, but they don’t erase your client’s exposure if an incident disrupts operations, triggers regulatory scrutiny, or damages customer trust.

Outsourcing Services Doesn’t Outsource Liability

Cyber risk expert sits with businesswoman at table, pointing out suspicious internet activity on three computer monitors.Imagine one of your business clients hires a digital marketing agency to manage its CRM platform, which contains thousands of customer records. Months later, that agency experiences a data breach.

Your client will no doubt call you with questions:

  • The vendor caused the breach. Doesn’t its insurance cover this?
  • We’re named as an additional insured. Doesn’t that protect us?
  • If the vendor is responsible, what role does our own Cyber Insurance play?

If they’re asking these questions for the first time after a breach takes place, the conversation has come too late.

“You can outsource the service,” says Whetstone, “but not the liability.” His observation captures why contractual risk transfer is only one part of cyber risk management.

A vendor may bear contractual responsibility, but your client may still face business interruption, regulatory scrutiny, breach response costs, and difficult questions about how and when losses will be covered.

Brokers can serve their clients significantly by addressing these issues during coverage reviews. That’s the time clients can still review vendor contracts, evaluate insurance requirements, and identify potential coverage gaps.

The Critical Importance of Vendor Contracts

Well-written vendor contracts typically address:

  • Indemnification
  • Insurance requirements
  • Incident response obligations
  • Security expectations
  • Limits of liability

Organizations should also consider established guidance for managing third-party cyber risk when reviewing vendor relationships.

Requiring vendors to carry Cyber Insurance also provides a financial backstop for those contractual obligations. A vendor may agree to accept responsibility in a contract, but if it lacks financial resources to fulfill that obligation, the agreement may offer less protection than your client expects.

One simple question can help uncover valuable information: “Have you reviewed your vendor contracts alongside your Cyber Insurance?”

That conversation can bring to light gaps that would otherwise remain hidden until after a loss.

Additional Insured Doesn’t Mean Fully Protected

One misconception you’ll likely encounter is the belief that being named as an additional insured on a vendor’s Cyber policy solves the problem.

Additional insured status can provide meaningful protection in certain circumstances, but it also has limitations:

  • Coverage may apply only under specific conditions.
  • Policy limits may be shared with the vendor and its other customers.
  • Coverage disputes may not become apparent until a claim occurs.
  • Your client has little control over how another company’s insurer handles the claim or manages the response.

For all these reasons, your clients should view additional insured status as one layer of protection, not a replacement for a stand-alone Cyber Insurance policy.

What Your Client’s Cyber Policy Provides That Vendor Contracts Can’t

Although clients sometimes think of Cyber Liability Insurance simply as a way to pay covered losses, its value goes well beyond reimbursement.

Whetstone explains that contracts and Cyber Insurance “serve complementary purposes.” Contracts establish responsibility, while Cyber provides “the financial resources and the expertise needed to respond when something does go wrong.”

That expertise often includes:

  • Breach counsel
  • Digital forensic investigators
  • Incident response specialists
  • Crisis communications professionals

Maintaining a stand-alone Cyber policy also gives clients dedicated policy limits and direct access to those resources. If they rely solely on a vendor’s insurance, many of those decisions may be driven by another organization and another insurer.

Contracts answer who is responsible. Insurance answers how the response will be funded.

Your client’s own policy gives them greater control over that response.

Have a Conversation To Help Your Clients Connect the Dots

When discussing Cyber coverage with your clients, ask them:

  • Which third parties support your most critical business functions?
  • Which vendors have access to your sensitive information?
  • Do your vendor contracts clearly address cyber incidents?
  • Do those vendors carry Cyber Insurance?
  • Does your Cyber policy respond to vendor-related events?
  • If a vendor experiences a breach tomorrow, are you confident you know what happens next?

Questions like these help clients understand how vendor contracts, Cyber Liability Insurance, and operational risk all fit together.

ProWriters Helps You Turn Better Conversations Into Better Cyber Coverage

Cyber Liability Insurance broker sits at a conference table with three of his clients, discussing their policy needs.Contractual risk transfer remains one of the most important dimensions of cyber risk management.

Strong vendor agreements establish responsibilities, set expectations, and improve preparedness before an incident occurs. They don’t eliminate your clients’ exposure. As Whetstone notes, contracts and Cyber Insurance should be viewed as “part of a coordinated strategy.”

Helping clients understand how those pieces fit together positions you as an adviser who helps organizations make informed decisions about cyber risk before a claim ever occurs.

Having the right Cyber Insurance markets and comparison tools at the ready makes those conversations even more valuable.

Our Digital IQ Comparative Rate Platform makes researching, quoting, and selling the Cyber Insurance policies your clients need faster and easier. Find out more, and register to get started as a ProWriters broker today.

Subscribe to Our Monthly Newsletter!

    Retail vs. Wholesale Brokerage

    Experts Weigh In

    Get the eBook