Demystifying Cyber Insurance Strategies for Security Executive
Document Type
Article
Publication Date
2025
Digital Object Identifier (DOI)
https://www.jstor.org/stable/48860771
Abstract
Security executives, including Chief Information Security Officers (CISOs), are responsible for ensuring their organizations are protected against cyber threats. In the event that a data or network breach in their carefully constructed cyber defenses occurs, their responsibility becomes the mitigation of the impact. Cyber insurance offers a key new and novel tool in the mitigation of a cyber threat. In this research, we expose the resources and four Executive Evaluation of Cyber Insurance Carrier Processes (EECICP) cyber insurers employ. We then identify four recommendations for evaluating and choosing among potential cyber insurer partners. Finally, we take an evidence-based approach to evaluate these recommendations when deciding to establish a strategic partnership with a cyber insurance carrier. We identify two novel aspects of cyber insurance—cyber underwriting and cyber claims handling—that cyber executives must understand. Our findings suggest that only by gaining clarity and fit in these areas are security executives able to make a choice of a carrier that maximizes their organization’s overall resilience to an attack.
Was this content written or created while at USF?
Yes
Citation / Publisher Attribution
Journal of Insurance Issues, v. 48, No. 2, p. 136-162
Scholar Commons Citation
Daniel, Clinton; Crabtree, Dalton; Biedova, Olga; and Mullarkey, Matthew T., "Demystifying Cyber Insurance Strategies for Security Executive" (2025). School of Information Systems and Management Faculty Publications. 74.
https://digitalcommons.usf.edu/qmb_facpub/74
