WannaCry provides latest glimpse at nightmare cyber aggregation potential

By Chad Hemenway on May 18, 2017

CHICAGO—The WannaCry ransomware attack will likely be a manageable loss event for the insurance industry, but the event offers a new perspective on potential aggregation.

Though the worm known as WannaCry spread rapidly to about 150 countries starting May 12, the number of network computers infected and held for ransom is actually a small percentage of all possible global endpoints, according to Pascal Millaire, vice president and general manager at Symantec.

Millaire gave an impromptu presentation on WannaCry during lunch at Advisen’s Cyber Risk Insights Conference here.

“This may not be as bad as one might have thought,” he said. “This is a relatively good-news story.”

Scott Stransky, assistant vice president and principal scientist of research and modeling at AIR Worldwide, said he doesn’t “see losses adding to extreme amounts.”

Because the worm had a kill switch, WannaCry was stopped before it heavily affected the US, which buys more cyber insurance coverage than any other country by far. WannaCry was also poorly designed, Millaire said. In fact, the hackers didn’t automate payments, making it difficult to track who has forked over the ransom demand of $300 in bitcoin. Also, WannaCry took advantage of a vulnerability in older versions of Windows, for which Microsoft had issued a patch even for the no-longer-supported Windows XP.

But that doesn’t mean WannaCry is not important because it provides valuable insight into the insurance industry’s aggregation nightmares, Millaire said.

READ THE FULL STORY

This story in an excerpt of the original. The content originally appeared in Cyber Front Page News.
To read the full story, you must be a subscriber. If you are a subscriber, check your email for Cyber Front Page News on May 18, 2017.

Chad Hemenway is Managing Editor of Advisen News. He has more than 15 years of journalist experience at a variety of online, daily, and weekly publications. He has covered P&C insurance news since 2007, and he has experience writing about all P&C lines as well as regulation and litigation. Chad won a Jesse H. Neal Award for Best Single Article in 2014 for his coverage of the insurance implications of traumatic brain injuries and Best News Coverage in 2013 for coverage of Superstorm Sandy. Contact Chad at 212.897.4824 or [email protected].