S&P Global Research & Insights
October 25, 2022
Cyber Risks and Credit Trends
Cyberthreats are no longer an emerging risk — they need to be an embedded part of an issuer's overall risk management profile, updated continuously as threats, insurance markets, and geopolitics evolve.
Cyberthreats are no longer an emerging risk — they need to be an embedded part of an entity's overall risk management profile, updated as threats evolve. While companies recognize cybersecurity is a higher priority today, roughly 40% still don't have a chief information security officer (CISO). While that may in part be a function of a company's size or complexity, for those that do have CISOs, one-quarter remain on the job for just one year. The situation may be worse in many local governments, which often have fewer resources to compete for talent with the private sector and may outsource all IT needs.
This underscores the challenge facing corporate, government, and not-for-profit debt issuers: rising cybersecurity incidents, higher costs to combat them, and an imbalance in the executive and risk management experience needed to manage them properly. In an ever-more-connected world, the risk of systemic attacks resulting in damaging financial and reputational consequences keeps increasing. How insurers respond to this risk may also have far-reaching consequences, particularly should they move to exclude systemic attacks from claims.

Key Takeaways
- Cyber risk is a credit risk. S&P Global Ratings took just over 50 negative credit-rating actions in a recent 10-month span attributed to risk management, culture, and oversight — a small subset due to cyberattacks. Where cybersecurity is weak, overall risk management tends to be weaker, potentially resulting in lower ratings than peers with similar financial metrics.
- Response time matters. Rating actions following cyberattacks tend to occur where response time significantly lagged the attacker's initial entry — the more time attackers have within systems, the more damage they can do.
- Third-party vendor management is critical. An entity's security position may only be as strong as its weakest vendor. Strong vendor management policies are essential for limiting credit impacts.
- Cyber insurance is evolving. The rise of ransomware and state-sponsored attacks is reshaping the cyber insurance market. Court cases following NotPetya insurance claims are leading to changes that could negatively affect policyholders expecting a payout.
- Systemic risks are growing. As cyber warfare and espionage become more commonplace, risks to issuers increase, particularly if insurance policies won't pay. The greatest risks remain the "unknown unknowns."

The Evolving Threat Landscape
Risks of cyberattacks continue to evolve, and entities must adapt to keep pace with cyber threat trends. While data breaches, ransom demands, and distributed denial-of-service attacks have had limited impacts on ratings to date, the sufficiency of capital and liquidity will surely be tested for some. These trends could have significant credit implications, particularly if issuers fail to adopt proper risk management.
If we view a company's cyber defenses as lagging or below expectations, we could lower our rating to capture this risk — we incorporate cyber defenses into our view of an issuer's overall risk management, which we consider a governance factor in our analysis. In a recent 10-month span, we recorded just over 50 negative credit rating actions — a downgrade and/or a negative revision in outlook or CreditWatch placement — across rated corporate, financial institution, infrastructure, insurance, international and U.S. public finance, and sovereign issuers attributed to risk management, culture, and oversight, a small subset due to cyberattacks.

Third-Party Vendor Risk
Strong vendor management policies are critical to limit credit impacts. We expect issuers to have third-party vendor management policies as part of their overall risk framework — an entity's security position may only be as strong as that of its weakest vendors. S&P Global Ratings evaluates how issuers mitigate third-party vendor risk as part of our overall risk management assessment, looking for comprehensive vendor due diligence, contractual security requirements and service-level agreements, ongoing monitoring of vendor security posture, incident response coordination with vendors, and data access controls and encryption standards.
Cyber Warfare And State-Sponsored Attacks
As cyber warfare and espionage become more commonplace, risks to issuers increase, particularly if cyber insurance policies won't pay. Given the motivation and resources of state-sponsored adversaries, attacks are increasingly likely to breach cyber defenses — making an entity's ability to respond and recover, and the transfer of risk away from insurers toward issuers, critical to credit quality. Rating actions following cyberattacks tend to occur where response time significantly lagged the attacker's initial entry; higher education providers and research companies, in particular, are attractive targets for corporate espionage from sovereign-backed attackers.
The Cyber Insurance Market
Cyber insurance continues to evolve. Beyond investing in their own defenses, organizations can consider partial risk transfer through insurance — but the rise of ransomware has affected the industry as a whole, while attacks that spill into the cyber realm from other fields of conflict can wreak collateral havoc, resulting in both claims and higher coverage costs. A $1.4 billion court ruling against ACE American in January 2022 underscored the need to clarify war exclusions in cyber policies.
Related Research
See "Cyber Risk In A New Era: The Rocky Road to a Mature Cyber Insurance Market," published July 26, 2022, for more on the evolving cyber insurance landscape.

Implications for policyholders and insurers
There are implications for both sides of the market. Policyholders need to understand the risk of "silent cyber" — where policies neither explicitly include nor exclude cyberattack coverage — as well as cyber warfare exclusions through force majeure clauses, both of which could mean a policy fails to reimburse costs a policyholder might expect. For insurers, strict underwriting and precisely worded policies are key to the sustainable development of cyber insurance, especially given it is the fastest-growing subsector of the insurance market. This is highlighted by concerns about the contractual treatment of cyber warfare in the wake of the Russia-Ukraine conflict; there may be movement toward excluding systemic attacks from insured claims, though stricter underwriting may also mean more denials of coverage or more costly policies — potentially leaving issuers exposed without sufficient liquidity to deal with the aftermath of an attack.
Cybersecurity As A Governance Priority
Cybersecurity must be an embedded part of an entity's risk management framework. The extent of these risks, and the impact they have already had, make cybersecurity a policy issue at the highest levels of both the public and private sectors — lawmakers are moving toward a more systematic approach to mitigating cyber risk, from global data privacy regulation to executive orders, to regulators aiming to develop and enforce greater disclosure of cybersecurity incidents.

Conclusion
Cyberthreats have moved beyond a specialized aspect of risk to a near-ubiquitous priority that must be integrated into risk management frameworks. The greatest risks are the unknown unknowns — for many years, this described the cybersecurity space entirely; as cyber defenses mature, unforeseen events are more likely to arise from poor modeling of potential risks than from a total absence of foresight. Issuers should frequently update their policies and practices to address changes in the cyberthreat landscape: cybersecurity can't be the sole responsibility of the IT department or the CISO. Without proper risk management — protecting against an attack and preparing for the response and recovery that follows one — financial losses can compound and reputational damage runs high. Cyberattacks have already led to rating changes across corporates, financial institutions, and U.S. public finance, and as cyber threats multiply, we expect this trend to continue.
The views expressed are those of the authors and do not necessarily reflect the opinions of S&P Global.