We're live. Thanks for continuing to join me today. This is the panel on cyber risks at the first annual, hopefully annual, Bank of America U.S. Insurtech Conference. We're broadcasting live from One Bryant Park here at the Bank of America headquarters in New York City. I'm happy to be back in the office, and this is a really great panel here on cyber risks. We have three companies who are going to be participating in our panel, and all of them are at very different stages of who they are as companies and what they do. I'll let them introduce their companies a little bit, but we have Tracie Grella, who is the Global Head of Cyber Risk at AIG. She's a 25-year AIG veteran, formerly the head of professional liability at AIG. Welcome, Tracie. Thank you for coming. We have Phil Edmundson, who is the founder and CEO of cyber specialty underwriter, Corvus. He's got a long tenure in the insurance industry. His business, William Gallagher. He sold it to AJ Gallagher. He's an early-stage tech investor in the Insurtech area with CoverWallet and Verifly. We have Josh MacDonald. He's the chief underwriter at cyber specialist Elpha Secure. He's been underwriting cyber claims for Chubb, for Beazley. Really, it's a great panel. Thank you all three for coming. We're going to try, I guess, to do this in a little bit of alphabetical order, I guess. Tracie, why don't you begin and tell us a little about what you're doing at AIG, and then we'll go on to each of you, and then I'll start asking some questions. Okay. Thanks, Josh. Thank you for having me here today. I'm Tracie Grella. I'm the Global Head of Cyber Risk at AIG, and in my role, I'm responsible for managing cyber insurance and the cyber exposure across all of our product lines at AIG. We're not only focused on the cyber insurance products we sell, but also the cyber risk that we have in other products such as property and casualty and all of the other lines of AIG. We're closely managing that risk and working with our clients to better understand their exposure, taking data that we have from all the claims activity we have over the last few years, and developing insights that we share with our clients to help them improve their cybersecurity risk. We've also been using a lot of external data in cyber underwriting. We use that data to help our clients identify vulnerabilities that are on their network or malware that's on their network that gives rise to losses under the policy. We work with them proactively to help them improve their security in that way, to improve their risk profile. We've been writing cyber insurance for over 20 years. We're a leading carrier in over 50 countries around the world. The cyber market is definitely dynamic. It's a time of transition. We're playing an instrumental role, the insurance industry is, in helping improve the security of all organizations. Thank you. Phil, tell us a little about what you're doing at Corvus. Hey, thanks, Josh. It's a pleasure to be here with you and the other panelists. I'm the CEO and founder of Corvus Insurance. We're an Insurtech company that broadly uses new types of data to predict and prevent commercial insurance claims and to deliver value to our stakeholders. Our stakeholders are our risk capital partners, our internal underwriters, our brokers, and of course, the policyholders. While we work in a number of commercial insurance areas, cyber insurance is the most elegant expression of our overall market thesis. Here we use our proprietary software to ascertain insights into the IT security of organizations that we consider for our cyber insurance products. We not only execute on that on our digital platform that we call the CrowBar, but we also use that to deliver IT recommendations, IT security recommendations to our policyholders and alerts, so that when bad things happen in the middle of the year, SolarWinds, Microsoft Exchange, our policyholders know what they can do to prevent vulnerabilities from being exploited because we understand the same view of their organizations that the cybercriminals hold. Love this conversation. Great panelists. Thanks for inviting me. Josh, tell us about Elpha Secure and what you're doing in the market. Sure. Thanks. Happy to be on the panel. I appreciate the invitation. ElphaSecure is a new MGA, cyber Insurtech space. We came around in response to what's really been happening in the cyber space for the past couple of years. I'm sure the audience is aware of how the cyber risk transfer market is evolving and responding to the past year by now mandating insureds have proper security hygiene in order to be insurable. At ElphaSecure, we took that to the next level by actually embedding a full suite of risk mitigation software into the risk transfer product. We have built a solution over the past couple of years to deliver the necessary tools for a small business to mitigate cyber threats. Tools such as multi-factor authentication, EDR, VPN, and patching. Also the resilience should an incident occur. Off-site encrypted cloud backups, security operations center, and incident response. We deliver all of these tools to the insured at bind, giving the insured a full end-to-end solution for all of their cybersecurity and insurance needs. Think of Elpha really as Progressive Snapshot for auto, but we're also putting seat belts, airbags, and brakes in the car. Fantastic. I have a bunch of questions, and you don't have to get the answers right. This isn't a quiz. This is more explain to people the market scale and how it works. The first question is how big do we think the market is currently? I guess measured in premium, although that may not be the right way to think about it. How big could the market potentially be if everybody who needed cyber risk bought it? How should we think about it for municipalities and small businesses who might not be even aware that they need it right now? Can you sort of scale up the market, Tracie, for us to give a sense of what we're talking about here? Yeah. There are lots of estimates about the size of this market. It's a little difficult to determine the actual size because of the way cyber exposure is embedded in multiple products. It's not consistently captured across all industries and across all companies the same way. Some companies may purchase some cyber risk in property or other lines. There's basic cyber insurance. There's BOP policies that include cyber. We haven't really had an accurate measurement of what that number is. But it's in the billions based on all the different estimates that we have. It is a robust market, and there are offerings that apply to all size organizations. Small organizations can get package policies with their cyber in it. A lot of the services, some that were just being mentioned, you might find going towards small companies. Larger companies, there's products available that's more customized, and can be a little bit more robust for larger companies. The market is pretty robust and able to address different size entities, different industries. The actual size on the number is something that there's been different estimates on. More markets have been regularly coming in, and at one point we had about 200 markets offering cyber insurance. It is a robust and vibrant market. I'm going to keep going through questions, although if somebody feels like something's open-ended and wants to just pipe in, you can interrupt me. The more information we get, the better. Can we talk a little about structuring, I guess? Some risks are small, and a underwriter can take the whole risk themselves. Other risks are large and require syndication. I guess there's two things I want to know a little about that market. Maybe, Phil, you can give us a bit about the syndicated market versus the whole market. The big question I guess people are wondering is, whenever I hear there's a big loss in the cyber market that we assume is probably part of the syndicated market, is everybody on that loss? Is underwriting a tool where in the big syndicated deals, some companies are on, some companies are off? Can you talk about how, I guess, structure a little bit to understand what's going on? Josh, I'll give that a try, and then I'll connect that to your first question as well, because I think there's some more interesting color there. You're right. Organizations are buying more insurance, and frequently they need to use multiple insurers. Many insurers are reducing the amount of limit that they want to expose for any individual organization. Those are typically stacked up horizontally, frequently with the broadest coverage at the bottom, and sometimes with restrictions on coverage as you go up a tower of insurance, but not always. How that integrates into the earlier question, sure, we all read these estimates, maybe the U.S. market's $4 billion, maybe double that globally. Great growth potential. The interesting thing to me is how the growth is taking place. Not only are prices going up, premium rates going up, that's driving growth, but demand is growing because organizations have much more awareness of cyber risk, and as Tracie said, there's lots of cyber insurance available. They're buying more than they did before, and they're also requiring each other to buy more. Frequently, organizations are required to buy certain types of liability insurance before a third party will do business with them. That could be a landlord-tenant relationship or a contractor-subcontractor relationship. Those requirements for cyber insurance didn't even exist five years ago, and now they're increasing. There's a second driver. The third driver is, let's face it, commercial insurance doesn't usually get to be a board-level conversation. What board of directors isn't talking about cyber risk today? They all are. Their brokers will generally get dragged into the meeting and try to explain why do we buy $5 million of insurance today? Oftentimes the next question is, "How much does 10 cost, and how much is 20?" The attention that's being paid to cyber risk is causing organizations to buy more insurance because there's frequently an uncertain answer to that question, how much is enough? It's a lot of things driving the growth in the market, and one way to answer that are these horizontal towers of placement. For the smaller companies, I guess there's more risk selection. Two things I want to know is, one is when there are large losses, is everybody on them? To the extent to which the market, I guess, is the market bigger for these large conglomerates and large corporations buying cyber or is it bigger for the many small entities who are buying little bits of protection each? All carriers have. There's a number of different underwriting processes. We even mentioned some of the things that we were doing as we opened up. Carriers have different appetites right now and are targeting different types of business, whether it's small or large, or industry-based or control-based, what they're looking for. There will be many towers where not every company is on. There's so much capacity in the market. There's many large losses that large incumbent carriers are not on those. You're not going to see that when there's a large tower, that every carrier is participating, because there are so many markets that are available, and because each market is looking for different type of risks and focusing their portfolio in different ways. Yeah. To piggyback on what Tracie just said, there are some carriers whose strategy is only to place the primary and then maybe first or second excess, and then some other carriers' strategy is to only place high excess placements. Yeah, to piggyback what you said, there are plenty of large losses where half of the major carriers are probably not even on the loss. In terms of market right now, I guess this is to Josh. I wonder to some extent, is the stage the market's in right now at a stage where most players or some players are looking just to break even and learn about the depth that's necessary to become a great player? Are we at the stage where everyone's trying to make money? Is the whole industry in startup stage where the goal is just to be relevant? I think there is some partial merit to this view, really dependent on the carrier. Up until, I'd say, the past two years, most carriers were actually making money, and pretty good money at that in cyber, despite the relative infancy. There were ebbs and flows of profitability between major accounts and middle market and then various industry classes. By and large, those dynamics were manageable from a profitability perspective. Of course, there were some outliers who made some bad bets that didn't make money, but I believe that was the exception and not really the rule. Really, that all changed in the past two years with the rise in ransomware. Middle market accounts, which were historically a growth class, quickly became unprofitable. The problem is, none of the carriers had the data to predict that quick turn, and that's one of the issues with cyber risk, right? It evolves and changes quickly. Unfortunately, to compound the problem, what we saw in the past five years was traditional incumbent carriers trying to achieve really aggressive new business goals while competing with unsustainable rates in the marketplace. Not dissimilar to many lines across P&C, cyber was just the last line to get there. Most incumbent carriers at this point have largely taken new business goals off the table this year and will be growing on rate alone while using their data to credit their books, putting them, I believe, in a better position to return to profitability as opposed to newer entrants. Certainly, the carriers with the vast amounts of data will be in a better position to inform their underwriting and pricing moving forward and de-risk their book as much as possible. I think that the view that you proposed has considerably more merit moving forward than it did historically. Just to make a note, if you're listening to this webcast, you're probably accessing through the Veracast web system, where although we're virtual and not live, it's possible for you to ask questions as well. You can type questions into the screen. I can ask them, I do welcome your questions. I got plenty of them, but if you have questions for me, please send them in and I can relay those questions. The opposite claims are up due to ransomware. There might be some nervousness. I've often wondered what a real worst-case scenario is for maybe a cyber CAT event for the industry. I'm always worried about fat tails and things being priced, but escaping the perception. Tracie, to your estimation, is there something that I should think of as a cyber CAT event where the industry understands that this is a major risk looming out there and is paying a price for that outcome? The big concern for cyber insurers is systemic risk, that's what we've been focused on from the beginning, is measuring the risk. A lot of work goes into accumulation modeling, and scenario development around the type of catastrophic events that we can have. Some of them could be a cloud failure, some type of vendor that is well relied on in the industry that might have a vulnerability or some type of failure. All the carriers are working on developing those scenarios, sharing those scenarios, and developing that modeling. The industry recently formed a consortium with a few carriers that are in that consortium now, and hopefully more will be joining. One of the things that we're working on in that consortium is working together around modeling systemic risk and improving the data collection around that. We bring in suppliers, some of the key suppliers, like key cloud companies and others that are major aggregators, so that we can better understand how they're managing their risk, what they see as the potential, and make sure that we're working with our insureds to capture the right data to measure that. That's an area of focus. It does need to continue to move forward and develop. There are some efforts for the industry to work together to share all of our knowledge there, to better model out that risk. Yeah. I think just to add to that, Josh, as an industry, we definitely need better data and more granular data. We need to be able to have a full understanding of our insured security posture, like down to the endpoint. That enables us to properly underwrite, and as important, that data enables the CAT models, as Tracie mentioned, to more accurately measure those fat tails. Ultimately, that enables the industry to properly price the risk. When you think about NotPetya, probably the closest we've come to a CAT, that easily could've been avoided for most companies if they had a proper patching cadence in place, as Microsoft had released that patch for about three months prior to the event. Having insight into an insured's patching cadence, just as an example, beyond the paper application, is critical. If you're behind the firewall and it can see what their actual patching cadence is, then we can actually underwrite to that better. We'll have a more exact underwriting science than what currently exists. Josh, this is really still a big challenge for the industry. Most of us, I'm assuming on the panel, and others in this field, look to a variety of third-party CAT modeling companies. If you use multiple models, you'll find, at least we have, and we've heard from other competitors, that you get very different results from these different modeling tools. I think it's fair to say there's not a consensus yet around what is the most likely catastrophe. Even if you can narrow it down that way, how do we model this? Some of the interesting developments to look forward to are whether or not we see risk capital segmenting the risk and looking at this the way that the risk capital market looks at a Florida windstorm and says, "Well, the very top catastrophic risk is something that we can pass off to insurance-linked securities markets or other forms of capital," as more and more tools, the tools we use, and I think that Josh and Tracie use, are able to score risk at the individual account level so that we can put together portfolios that are able to be at least partially securitized in risk transfer. I guess these answers sort of are getting to my next question a little bit. If we look at this as a 20-year sort of line of business that was truly in its infancy 20 years ago, what were the initial data and variables that the industry was relying on early on in the process? What are contemporary variables and information that you're looking for, and what will be, as things are developing, the emerging possibilities of things that are within the realm of knowable that are going to help refine the underwriting for the next generation of products that are being sold? I guess, Josh, why don't we start with you on that one? Or actually, Phil, actually. Sorry. Phil, why don't you start there, and, of course, Josh come in, and Tracie. What is the data we're looking at? What was it? What is it? What will it be? The insurance industry, over the course of my career, I've seen several new products emerge and get broad acceptance, and this is obviously one of those. The cyber risk started as an outgrowth of professional liability at companies like AIG and Lloyd's of London, Chubb, other early pioneers who tried to use the smartest people in our business to build models for it. As Josh said earlier, for the most of this history, that model has led to an overpricing of risk, a market that was not rational and produced above-average profits until the last couple of years. We're all focused on accumulation and catastrophe. I think it's going to take some time for that to shake out. I've spent my whole career at the intersection of technology and insurance, and I'll use an example from another part of that career. I've worked in the biotech sector in the '80s and '90s. At the beginning, when biotech companies first started to bring drugs into clinical trials, commercial insurers charged $1,000 per clinical trial subject for a $5 million insurance policy. Today, they charge about $10. What happened there is at the beginning, there was a lot of fear and a lot of uncertainty and a lack of track record that led to an overpricing or overcaution in pricing risk because everybody was afraid of biotech. Don't you remember? We used to have headlines about unmanageable fears of altering DNA. Then we all got used to it, and things settled down. It'll be interesting to see if cyber follows that same pattern or not. Right now, we've gone down a path where initially, the industry overpriced risk. Now the cybercriminals have taken the upper hand, we'll have to find a new equilibrium here in the coming years. I don't think it's going to be months. It's going to be years before it settles. Then to understand the claims side of the equation. In the past decade or so, or maybe five years, maybe some more, some of the more notable events have been the Equifax data hack, the Kohl's data hack, the Colonial Pipeline hack. There was a combination of data privacy thievery. There was ransomware. Can we talk about a little bit, Josh, about the claims for merely having private data stolen versus having a ransomware attack? There was, this past year, a large insurer was in a major ransomware attack that cost a lot of money. Some of the claims are very different size. They reference different situations. What does the claims history look like to help us understand what's at risk and try and come up with an understanding for the industry about what protections we're looking at? Yeah, sure. The Equifax incident, even in contrast to what we were seeing in the news with ransomware, was still a massive loss. The drivers of that loss were different. Notification and credit monitoring expenses and then forensics to determine the root cause and scope is what really drove that loss. As opposed to ransomware, which does require a heavy forensic response. It's usually the resulting ransom and business interruption that drives the loss. Before ransomware, as akin to the Equifax breach, personal information aggregation was the biggest exposure when underwriting to cyber risk. It was relatively easy to quantify the exposure to a certain degree. What are the number of records? These could be credit card numbers, Social Security numbers, et cetera. While PII breaches can and do still occur, technology and controls have advanced to a degree where organizations can largely scope these exposures out of their risk profile. What's difficult to price in this current loss environment is the unknown associated with ransomware. How much are the hackers going to demand? Can clients recover and restore in an efficient manner to avoid a lengthy business interruption? The good thing is, as we speak, all carriers are accumulating the data that will help better inform their underwriting questions and processes and pricing in response to ransomware. That's really the evolution that we've seen from one threat being massive PII aggregation, which we still see, to sort of the unknowns that we're facing with ransomware right now. Is the rise in ransomware an outgrowth of crypto? Can ransomware exist without crypto? Well, it's a tough question. I think a lot of fingers are being pointed in that direction, and I think that there is certainly a degree of blame to be associated with crypto, but it's not all on the hands of crypto. There's certainly certain aspects that regulators can do with crypto, making it less transparent and easier to track criminals and therefore easier to get the funds back and/or prosecute those criminals. There are other things that go into it, such as poor cybersecurity hygiene. As long as we implement a baseline of cybersecurity for companies that are doing business on the Internet, that would prevent a lot of ransomware claims on its own. There's a lot of different factors that go into it, but crypto certainly does play its part. I'm gonna pause for a second, just we have some questions from the audience. I have more questions, but I'll ask some of theirs. Can you make some comments about cyber reinsurance? Seems like that's much harder to price. Do you guys have any thoughts about the reinsurance markets for the audience? Anyone can answer. I can't comment on pricing of the reinsurance market, the reinsurance market is certainly an important piece of the market for cyber. Many carriers are using reinsurance, again, to reduce that systemic risk exposure, so we're spreading the risk out. That is an important piece. There is a lot of startup companies coming in and offering cyber insurance, so they're reliant on reinsurance as well. It is a critical piece of the market. The reinsurers are asking questions about systemic risk and how carriers are managing that, how we're collecting data, the data that we're capturing. They'll have the influence on that as well, what they see as important from a systemic standpoint. Yeah, I think Tracie hit the nail on the head here. They really fear the aggregation. Capacity is starting to become tight and will probably be tight for a while to come. A lot of large primary carriers do rely heavily on quota share reinsurance. That pressure supply, I think, will really start to increase and continue for quite some time. The second question is: while prices are up due to claims currently, have terms and conditions changed as well? Can insurers buy the product they want? Is it available on the market or you can't even get, at this point, the amount of protection or the product you're looking for? Well, there are certainly exceptions, there has been some tightening on terms, not as broadly as there has been on pricing. Certainly, what not everyone realizes, I think, is that there's a lot of levers inside a cyber insurance policy. It's much more complex than most other types of commercial insurance policies. We're certainly seeing some of those knobs being turned down in some classes of risk and companies that perhaps fail their IT security scan tests or tools that we all use now, you may see some restrictions, but broad coverage is still available. A lot of the restrictions that are being introduced in the market are really incentives to help organizations improve their security. You might see restrictions, but if a company can improve their security, we're giving guidance about the type of controls that need to be in place. We're working with our clients to get those controls in place. We're identifying through scans and other data sources, we're identifying vulnerabilities and weaknesses. When organizations can clean those up, then they will see more broad cover. For those that can't or aren't investing now or something, we hear a lot that this is a plan, but it does take time, and it'll be over the next couple of months, the next year. There will be restrictions on cover. When I think about ransomware, it triggers in my head as an insurance guy that it somewhat relates to the old kidnap and ransom policies. There was part of that which was the payment and protection for the buyer to pay those claims and get back their loved ones or whatever. There was also a component of that a lot of these specialists had black ops, former military personnel who would work to remediate the claim after payment and get the ransom back. To what extent are the claims departments for cyber risk underwriters involved in trying to minimize claims through remediation, through trying to, I guess, find who the villains are in this whole story and get the money back over time as a way of minimizing their own costs? I guess I'll go to Tracie on that one. Okay. There are a number of external vendors that are involved in this process. The claims department is certainly involved, but there are ransomware negotiators or providers of cryptocurrency, that holds cryptocurrency wallets. The clients, the ransomware negotiators are working with law enforcement. The law firms are working with law enforcement. There's a number of parties that are involved, and then you have the forensic firms as well, and then there's others. The claims department is involved with working with these various vendors and certainly working with the insured through this matter and helping to give advice on how to recover in the most cost-effective way. Definitely a number of experts have to come and be involved in this type of negotiation and discussion. I think the latest news or latest big story was the JBS meat processing plant. Without betraying my own ignorance, I imagine it doesn't sound like the bedrock of cybersecurity, that target might have been able to be hackable before. It wasn't like a momentary letting down of the guard. I just imagine there's a lot of hackable businesses out there. Are we at the trough of cybersecurity hygiene right now? As we go forward, is hygiene going to get a lot better and it's going to be harder to hack into various targets? Or is this kind of like code and semiconductors and Moore's law, that as time goes on, while silicon wafers get cheaper and thinner, the amount of code is doubling, so we're kind of running in place? Will the hackers get more sophisticated at the same pace that cyber hygiene is improving, we're going to be at this equilibrium for the foreseeable future? Phil, I guess I'll go with you on that question. Josh, that is a great question, I think you got to the most difficult part at the end there is, will the cyber hackers, the cyber criminals, continue to grow in sophistication? Will they be able to continue to hide under the protection of certain governments or in other ways elude law enforcement? They will need to amp up their game because so much is being spent on cybersecurity. Not just because we recommend it to our policyholders, but organizations are doing this and investing broadly, maybe not all of them, but broadly into cybersecurity. I'm sure one of your colleagues that covers the cybersecurity software market could talk about that at great length. Big challenges there and a lot of uncertainty about how the cyber criminals will be able to continue to stay steps ahead of the cybersecurity industry and those of us who underwrite the risk. Josh, I'd jump in there and say that I think the rule of thumb going to JBS is that any company can be hacked. That has been proven many times over. You think about it, the NSA, Mandiant, military agencies, and the biggest banks have all been compromised, and they have the best cybersecurity in the world. Privy to JBS's network security, it is known that manufacturing is a vulnerable class with outdated operational technology and a high dependency on uptime. Their control is going to be best in class, when you have the power of a state-sponsored actor breaking down your door, very few companies stand a chance at prevention. In the context of ransomware, it's how resilient is a company when they're hacked? Could JBS recover their data quickly to avoid a substantial interruption to their operations? Did they have a business continuity plan in place? To your point that the hacks are still making news, making them appear infrequent, but I would estimate that probably less than 1% of hacking incidents actually make the news. Hackers are taking every opportunity they can right now because, as you said, security hygiene is only going to improve across the board. Governments are demanding better hygiene. Industry groups are demanding better hygiene. Insurance carriers are now demanding better hygiene. Once the baseline of cybersecurity hygiene improves, because it was very low before, especially in the middle market to small, even a modest improvement across the board, I think will make a significant impact. I guess, something that Phil said does sound quite a relationship between cyber hackers and state sponsorship. To what extent are there going to be successful cyber hackers without the protection and funding of a state as a bad actor being a funder of this sort of villainy and whatnot? Are many of these cyber hackers truly independent and just villains for their own purposes, or is this necessarily tied to international peace disruption? I guess, I'll leave it up to you. We're kind of out of order. I matched who was going to get the questions. Anyone can answer just because it doesn't matter so much. What is the linkage? We're going to go talk about terrorism a little bit. We're going to talk about Biden a little bit. It can go anywhere. You guys can take wherever you want. Yeah. Josh, we rely on the reports from the FBI and other law enforcement agencies to answer that question. That certainly points out the fact that in many cases, if not state-sponsored, there are state defenders of these attacks. Honestly, most of the events that we respond to, the party on the other side may have a code name, but they are otherwise pretty opaque and are mostly successful at staying that way. After September 11th, 2001, the insurance industry got gummed up because no one really knew how to price it, really knew how to take the risk of a terrorist event becoming a property CAT destruction for a lot of small risks, large and small, and the federal government responded with TRIA as an umbrella of protection that allowed the insurance industry to continue to underwrite without having to contemplate. There's been no real claim under TRIA. I guess it's worked or it hasn't worked, but it's not really been tested. As we think about the ability of some of these cyber hackers to potentially create mass havoc, where does criminality end and terrorism begin? Does the TRIA cover cyber attacks? Do we need a TRIA for cyber attacks? Where are we right now? What do we have to contemplate? What fears should the government be assuaging with protection for the private market? Phil looks like he's ready to answer, I'm just going to give it to him. Anyone can pipe in. Yeah, it's a great question, Josh. My understanding is TRIA does not preclude cyber events from its definition of terrorism. However, the definition of what is an act of terrorism has not been put to the test under TRIA, there's a lot of different scenarios that could play out here where we have cyber criminals who, as I just said, are so opaque in their source and where there's not clarity around the motivations of their government sponsors, defenders, or colleagues. I think what would be most helpful to the commercial insurance industry is clarity from the Treasury Department around when TRIA might respond to a large cyber event, rather than the need for new legislation. All right. The final question, I guess for today, involves Mr. Biden and Mr. Putin. At their recent summit, Biden, I guess, drew a red line around 16 different sectors that the United States would not stand for any cyber hack disruptions, I guess Mr. Biden believed that was within Mr. Putin's ability to limit the amount of cyber hacks. When we think about how business is priced, should the cost of buying cyber insurance on those 16 areas go down? Because presumably they're under the explicit protection of the United States government in terms of prompting an international incident if something should happen. Does that mean everything else is suddenly fair game, and the price of the remaining sectors that were not specifically named, suddenly maybe should go up in value because the United States has less of an aggressive view on what would be the response if something were to happen to those areas? My gut reaction to that would be no. Even if you scope Russia out, there are still several other state actors that would have no problem targeting those entities. I don't think any insurance carrier would be prudent to place their pricing based on that loose agreement, if it even was an agreement as opposed to a directive. If something changes, we always look at our portfolio based on different segments, where attacks are coming from, who they're against, and what the potential loss could be. We would address that. You'd have to see that change, and it does seem like it would be unlikely based, the agreement that Josh was saying. Agreed. I have one question coming through here. In a lot of different types of policies, acts of war are excluded. If there is a cyber claim that was paid, and that later it's determined to be the act of a foreign government who was actually the instigator of that attack, is that claim a claim that could be subrogated or could be to the government or whatnot? Is a attack by a foreign government a payable event, or is that somehow excluded in how the business is underwritten today? Typically, under the cyber insurance policy, there's not an exclusion for actors. The actor who conducts the attack, where the actions took place, that in itself is not an exclusion. You do need to look at the war exclusion and other exclusions in the policy. In the cyber marketplace, war exclusions were addressed years ago to make sure. We know that many attacks come from state actors and state-sponsored actors. In a cyber policy, that has been considered as a war exclusion, and there was some language that was removed. When you look at other insurance policies in the market, the war exclusion may be more robust and not written with cyber attacks in mind. Those who are concerned about having a cyber attack that might result in a property damage or some type of bodily injury, they are going to have a more strict war exclusion in those policies typically. Thank you all for your time today. We are at the end of the session. I do appreciate you all joining in. If anyone has any questions for any of the participants, you can email me those questions and I can certainly pass them on to you. It's truly been interesting, and obviously, this is a topic that is constantly evolving. The best of luck to all three of you. We'll continue the dialogue and learn more from each other as time goes on. Thanks for having us. Thanks, Chad. Have a great day. Yeah. Let's avoid those claims. All the best. Bye.
Loading workspace