CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • Cybersecurity & Resilience

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

AIG

Mark Camillo, Head of Cyber, EMEA

Behind the numbers - understanding cyber losses

Cybercrime is a fast growing, global business. 80 percent of global businesses suffer from a cyber breach each year and total damage to the global economy could reach $400 billion in 2017. Understanding the causes of cyber loss is critical to how businesses can think about both the prevention of attacks and the cure should they occur. Major data breaches and more recently, audacious Distributed Denial of Service (DDoS) attacks exploiting the Internet of Things (IoT), are the types of cyber intrusion that are most likely to capture headlines. But it is cyber extortion and ransomware that is one of the fastest growing cybercrimes, a trend that is captured by AIG EMEA cyber claims statistics from the period between 2013 through to September 2016.

Encryption ransomware extortion claims accounted for 16 percent of claims during that period, with a further 4 percent of claims relating to other cyber extortions.

Paying the price

People are sometimes surprised at how small some of the ransom demands are. Nevertheless, given the high frequency of attacks, extortion is a lucrative and relatively straightforward way of accessing ‘fast cash’ for cyber criminals. Malicious actors are thought to have generated around $325million in revenue over the past three years by using the CryptoWall code, according to research by the Cyber Threat Alliance, while the Cryptolocker gang made over $30million in 2015 using relatively simple ransomware. An explosion in different types of ransomware deployed in 2016 suggests that this form of cyberattack is only going to become more frequent.

Despite the growing risk of a cyberattack, a surprising number of companies are unprepared to deal with the threat


In the cases of cyber extortion, claims severity depends on the type of organisation, the level of business interruption caused and need for forensic investigation and system restoration. Ransom demands typically remain small. For example, one online retailer was subject to a DDoS attack, which resulted in their website being inaccessible or experiencing reduced performance. Prior to the attack they received an online message claiming that their website protection was extremely low and it would be taken offline unless a payment of £3,000 was made. Further ransom demands of £500 were made during the attack.

Largescale DDoS attacks are also a rising concern, up 138 percent year-on-year, according to Akamai’s latest State of the Internet/Security Report. In October 2016, a massive DDoS attack hit servers at domain name system provider Dyn, resulting in widespread disruption. The DDoS involved a botnet coordinated through tens of millions of connected devices including surveillance cameras, webcams, smart thermostats and even baby monitors infected with the Mirai malware.

For those affected by ransomware or DDoSattacks, business interruption (BI) costs are highest during peak trading periods. Half of the respondents to one recent survey revealed that they could lose over $100,000 per hour during critical periods – even if the initial ransom demand is low.

While business interruption currently accounts for just four percent of AIG EMEA cyber claims (with a further four percent of claims falling under system failure/outage), BI cyber claims are expected to increase in frequency and severity in the future. Rapid breach response is one way of mitigating the potential impact.

Regulation to drive data breach claims

Perhaps unsurprisingly, the majority of cyber claims currently emanate from industries that are required to notify customers if sensitive data has been compromised. But from 2018, under the General Data Protection Regulation (GDPR), all companies based in the EU and those based outside of the EU who process EU citizens’ data will be required to report a breach within 72 hours of it occurring – if that is feasible. There will be significant fines for those firms that have failed to protect data adequately. A company can be fined up to two percent of their global annual turnover for not having records in order, failing to notify the supervisory authority about a breach or failing to conduct impact assessments. Infringements that are more serious could merit a four percent fine.

It is anticipated the new data protection rules and headline-hitting data breach exposés will continue to drive greater demand for cyber cover. However, despite the growing risk of a cyberattack, a surprising number of companies are unprepared to deal with the threat. From our experience of working with companies – large and small – that have suffered from some sort of data breach, it is clear that it is not just being a victim of a breach that can cause damage to businesses, but also how a breach is handled. Many organisations are dealing with cyber claims for the first time and, even if they have the resources required to respond, they often do not know how to deploy them. Insurance plays a key role in not just offsetting costs when a cyber event happens, but also preventing an attack in the first place, and responding correctly to reduce damage when cyber security fails.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://cyber-security-and-resilience.cioapplicationseurope.com/leadership-perspective/behind-the-numbers-understanding-cyber-losses-nid-42.html