logo

A Cyber Insurance Backstop

ID: 1f8a097e-1922-5626-a970-4220c33783d7

STIX ID: report--1f8a097e-1922-5626-a970-4220c33783d7

Feed Name: Schneier on Security

Date Published: 2024-02-28

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

This article analyzes the concept of a federal cyber insurance backstop to cover catastrophic, state-backed cyber incidents, using Merck’s NotPetya-related litigation as a case study and comparing potential models to TRIA/TRIP, NFIP, and the UK’s Pool Re. It details insurers’ expanding exclusions (e.g., Lloyd’s, Chubb), the difficulties of attribution and defining trigger thresholds, and the risk of moral hazard without baseline security requirements. The piece reviews ongoing U.S. policy efforts (Treasury FIO RFC, National Cybersecurity Strategy) and argues that any backstop should be informed by robust empirical evidence on effective security controls, potentially derived from insurer claims data, CIRCIA-driven reporting, or a Bureau for Cyber Statistics, before implementation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.