Skip to main content
United States flag An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Show

FFIEC Issues Joint Statement on Cyber Insurance and Its Potential Role in Risk Management Programs

April 2018
FFIEC Issues Joint Statement on Cyber Insurance and Its Potential Role in Risk Management Programs

The Federal Financial Institutions Examination Council (FFIEC) members today issued a joint statement to describe matters that financial institutions should consider if they are determining whether to use cyber insurance as a component of their risk management programs.

The FFIEC members do not require financial institutions to maintain cyber insurance. The evolving cyber insurance market and the shifting cyber threat landscape may, however, prompt financial institutions to consider whether cyber insurance would be an effective part of their overall risk management programs. 

The joint statement notes that cyber attacks are increasing in volume and sophistication and that traditional general liability insurance policies may not provide effective coverage for all potential exposures caused by cyber events. Cyber insurance could offset financial losses from a variety of exposures—including data breaches resulting in the loss of confidential information—that may not be covered by more traditional insurance policies. Financial institution management should assess the scope of coverage of current insurance and consider how cyber insurance may fit into the institution’s overall risk management framework.

As with any insurance coverage, cyber insurance does not diminish the importance of a sound control environment. Rather, cyber insurance may be a component of a broader risk management strategy that includes identifying, measuring, mitigating, and monitoring cyber risk exposure.

http://www.ffiec.gov.


Statement: Joint Statement on Cyber Insurance and Its Potential Role in Risk Management Programs

AgencyContact NamePhone
CFPBSam Gilford202.435.7673
FDICLaJuan Williams-Young202.898.3876
FRBEric Kollig202.452.2955
NCUABen Hardaway703.518.6333
OCCStephanie Collins202.649.6870
SLCJim Kurtzke202.728.5733

 

Last modified on