As the growth of AI and other technologies diversify data center models, cyber underwriters need to adapt their cybersecurity risk management strategies.

Data centers have expanded from on-premises to public cloud and edge computing deployments, with some dedicated to single enterprise users and others are co-located, serving multiple tenants. First-party and third-party cyber exposures vary among these different models. With data centers forming the backbone of the digital economy, the stakes are high. Regardless of the data center model, cyber underwriters should look closely at how cybersecurity and insurance programs can work together to address the next frontier of risk.

The popularity of multi-tenant and outsourced data center models leaves a significant margin for error in mitigating cyber risks. Effective management of cyber risks in these data centers types therefore is less dependent on the physical location of a data center and more reliant on clear understanding of, and compliance with, a shared responsibility model. Clarity is essential for cybersecurity teams as well as cyber underwriters.

The following table summarizes key exposures and risk profiles for different data center operating models. Risks vary somewhat across these categories, but virtually all of them require trust and dependency on operators and vendors.

Delineating responsibilities

Across data center types, providers and customers each have responsibility for cybersecurity. These vary but have important delineations for each party.

For example, in a public cloud environment, the provider is responsible for security in the underlying infrastructure, facilities, hypervisors and core networking. Customers of the public cloud are responsible for securing their data, operating systems, application code, network traffic, identity and access management (IAM), and configuration of the cloud services they use.

In colocation data centers, providers are responsible for owning and managing the multi-tenant facility and its physical infrastructure – power supply, cooling systems, and physical security. Tenants, or customers, own and manage their servers, operating systems, software and application-layer security within their racks or cages in the colocation facility.

Managed hosting of data centers shifts more lower-level management responsibility to the provider. This includes the operating system and platform, while the customer is responsible for applications and data.

These delineations are critical to underwriters’ assessment of cyber risk and exposure. A shared responsibility model also is key in allocating the liability and claims that arise from cyber issues. Operational control in a shared responsibility model, paired with robust segmentation across both physical sites and data, serves as a main source of mitigation for ransomware and operational risks.

Identifying exposure areas

Cyber underwriters assessing data center risks in a shared responsibility model have at least seven categories of concern and expectations for addressing each one. These categories include:

Segmentation. How is the segmentation for tenants and the system designed and tested? Ideally, each customer’s environment is segmented and failure testing occurs regularly.

Access and patching. What governance is in place for privileged access, patching and vulnerability management? Full access governance with high patching cadences, and vulnerability management through scanning, penetration testing and incident response exercises are preferred.

Ransomware. How are ransomware preparedness and data backup structured? Underwriters look for data immutability, isolation and testing, with backups stored in a separate location.

Incident response (IR). What are the insured’s incident response and escalation capabilities for multi-customer events? Preferred practices include strong IR capabilities and logging of downtime.

Operations technology (OT) security. How are OT systems secured and isolated from information technology (IT) networks? Underwriters are looking for isolation, with the OT environment on a different network unconnected to the IT environment.

Uptime tiering. Is the data center certified by the Uptime Institute, or designed to an Uptime Institute tier? Cyber underwriters usually accept data center risks with Tier II (limited redundancy) or greater uptime tiers. Tier I (basic) features a single distribution path with no redundancy, which typically leads to the longest amount of annual downtime.

Contractual terms. How is cyber liability allocated contractually with customers? Data centers typically set the terms in their contracts, using hold-harmless clauses and limitations of liability.

It is incumbent on cyber underwriters, data center operators and their customers to understand their shared responsibility for mitigating cyber risks. A thorough review of the cyber risk management programs, including cybersecurity practices, governance and incident response, is critical to evaluate and fix vulnerabilities. Organizational resilience depends on doing so.

 

Meet the Author

Headshot of Maria Long

Maria Long

Chief Underwriting Officer, Resilience

Maria Long is Chief Underwriting Officer for Resilience, where she holds global responsibility for underwriting strategy, policy, and risk assessment. Long has nearly 20 years of experience in insurance including in cyber risk management program design and leadership, and underwriting leadership with a strong focus on holistic risk mitigation. Her thoughtful approach to the sustainability and performance of insurance products has been a consistent trait throughout her career.

Maria is an active volunteer in organizations that support women, including as a leadership advisory board member of International Women’s Cyber Alliance and as an advisory board member of the University of New Haven’s Women in Leadership Program. Additionally, she is a member of Aphinia, an invitation-only networking organization of senior cybersecurity executives.

News Type

PLUS Blog

Business Line

Cyber Liability, Professional Liability

Contribute to

PLUS Blog

Contribute your thoughts to the PLUS Membership consisting of 45,000+ Professional Liability Practitioners.

Related Podcasts

Related Articles