Overview - ISO/IEC 27102:2019 (cyber-insurance)
ISO/IEC 27102:2019 provides guidelines for using cyber‑insurance as a risk‑treatment option within an organization’s information security risk management framework. The standard explains how to evaluate purchasing cyber‑insurance, how cyber‑insurance can help manage the impact of a cyber‑incident, and how to share relevant data with insurers. It also describes how an ISMS (information security management system), for example one aligned to ISO/IEC 27001, can be leveraged to support underwriting, monitoring and claims. The guidance is applicable to organizations of all sizes and sectors.
Key topics and technical focus
- Cyber‑insurance fundamentals: definitions, purpose and typical policy forms (stand‑alone policies or endorsements).
- Cyber‑risk and insurable losses: categories of loss commonly covered - e.g., data breaches, business interruption, cyber‑extortion, incident response costs, legal/regulatory fines, contractual penalties, and systems damage.
- Risk management integration: how cyber‑insurance fits into the risk treatment process and complements technical and organizational controls.
- Underwriting and risk assessment: information collection needs for insurers, assessment of inherent cyber‑risk, controls assessment and review of prior losses to support underwriting decisions.
- ISMS role and evidence: how ISMS documentation, planning, operation, performance evaluation and improvement activities can be used to demonstrate controls, meet policy conditions and streamline information sharing with insurers.
- Operational issues: supplier risk, silent/non‑affirmative coverage in other policies, policy exclusions, coverage limits, and use of third‑party vendors (forensics, legal, PR) in incident response.
- Privacy and data sharing considerations: guidance on sharing sensitive information with insurers while using an ISMS to manage confidentiality and compliance.
Practical applications and users
Who benefits:
- CISOs, risk managers and security leaders evaluating cyber‑insurance as part of their risk treatment strategy.
- Insurance brokers and underwriters seeking structured information for underwriting and monitoring.
- Legal, compliance and procurement teams assessing policy obligations and contractual exposure.
- Incident response teams coordinating claims, forensics and recovery funding.
Typical uses:
- Preparing underwriting dossiers using ISMS artifacts.
- Aligning contract terms and controls with insurer requirements.
- Designing incident response plans that maximize recoverable costs.
- Demonstrating ongoing risk management maturity to reduce premiums or exclusions.
Related standards
- ISO/IEC 27000 (vocabulary and overview) - cited normative reference.
- ISO/IEC 27001 - ISMS requirements referenced for leveraging management systems in support of cyber‑insurance.
- Other ISO/IEC 27000 family guidance (e.g., 27002) for specific controls and implementation practices.
Use ISO/IEC 27102:2019 to inform buying decisions, improve insurer communications and ensure your ISMS supports robust cyber‑insurance outcomes.