Bashe Attack Global Infection by Contagious Malware 2
Total Page:16
File Type:pdf, Size:1020Kb
CyRiM Report 2019 Bashe attack Global infection by contagious malware 2 About CyRiM About Cambridge Centre for Risk Studies Cyber risks are emerging risk with new complexities that The Centre for Risk Studies is a world leading centre for call for insurers and risk managers to jointly develop the study of the management of economic and societal innovative solutions and tools, and enhance awareness risks. The Centre’s focus is the analysis, assessment, and underwriting expertise. and mitigation of global vulnerabilities for the The Cyber Risk Management (CyRiM) project is led by advancement of political, business, and individual NTU-IRFRC in collaboration with industry partners and decision makers. academic experts. CyRiM is a pre-competitive research project that aims to foster an efficient cyber risk The Centre provides frameworks for recognizing, insurance market place through engaging industry and assessing, and managing the impacts of systemic academic experts guided by government and policy level threats. The research programme is concerned with research. The CyRiM project will help Singapore to catastrophes and how their impacts ripple across an become an industry centre of excellence on cyber risk increasingly connected world with consequent effects on and grow the cyber risk insurance market by promoting the international economy, financial markets, firms in the both the demand and the supply of insurance coverage. financial sectors, and global corporations. To test research outputs and guide new research agendas, the For more information about CyRiM please visit Centre engages with the business community, http://irfrc.ntu.edu.sg/Research/cyrim/Pages/Home.aspx government policy makers, regulators, and industry bodies. CyRiM disclaimer Cambridge Centre for Risk Studies disclaimer This report has been co-produced by Lloyd's, Aon Centre This report describes a hypothetical scenario developed for Innovation and Analytics, MSIG, SCOR TransRe and as a stress test for risk management purposes. It is not a CyRiM for general information purposes only. This does prediction. The Cambridge Centre for Risk Studies not reflect the views of the Nanyang Technological develops hypothetical scenarios for use in improving University of Singapore Insurance Risk and Finance business resilience to shocks. These are contingency Research Centre and additionally does not necessarily scenarios used for ‘what-if’ studies and do not constitute reflect the views of any of CyRiM partners. While care forecasts of what is likely to happen. has been taken in gathering the data and preparing the report and the information herein, Lloyd's, CyRiM, the The views contained in this report are entirely those of Nanyang Technological University of Singapore the research team of the Cambridge Centre for Risk Insurance Risk and Finance Research Centre and the Studies, and do not imply any endorsement of these Cambridge Centre for Risk Studies do not make any views by the organisations supporting the research, or representations or warranties as to its accuracy or our consultants and collaborators. The results of the completeness and expressly excludes to the maximum research presented in this report are for information extent permitted by law all those that might otherwise be purposes only. This report is not intended to provide a implied. Lloyd's, Aon Centre for Innovation and Analytics, sufficient basis on which to make an investment decision. MSIG, SCOR TransRe the Nanyang Technological , , The Centre is not liable for any loss or damage arising University of Singapore Insurance Risk and Finance from its use. Any commercial use will require a license Research Centre, CyRiM and the Cambridge Centre for agreement with the Cambridge Centre for Risk Studies. Risk Studies accept no responsibility or liability for any loss or damage of any nature occasioned to any person Copyright © 2019 by Cambridge Centre for Risk Studies as a result of acting or refraining from acting as a result of, or in reliance on, any statement, fact, figure or expression of opinion or belief contained in this report. This report does not constitute advice of any kind. © 2019 All rights reserved Bashe attack – Global infection by contagious malware 3 Key contacts Insurance industry interviews and consultation − Mark Lynch, AON Centre for Innovation and Analytics Trevor Maynard − Alessandro Lezzi, Beazley Head of Innovation, Lloyd’s − Giles Stockton, Brit [email protected] − Nick Barter, Chaucer − Ian Pollard, Delta Insurance Shaun Wang − Matt Harrison, Hiscox Project Lead, CyRiM − David Singh, MS Amlin [email protected] − John Brice, MSIG − Joel Pridmore, Munich Re Syndicate Singapore For general enquiries about this report and Lloyd’s − Tim Allen, RenaissanceRe work on emerging risks, please contact − Sebastien Heon, SCOR [email protected] − Grace Lim, TransRe − Rhett Hewitt, TransRe Cambridge Centre for Risk Studies Lloyd’s project team Global Infection by Contagious Malware Scenario − Dr Trevor Maynard, Innovation Research Project Team − Angela Kelly, Commercial − Simon Ruffle, Director of Research and Innovation − Dr Keith Smith, Innovation − Dr Jennifer Daffron, Research Associate − Pavlos Spyropoulos, Commercial − Dr Andrew Coburn, Director of Advisory Board − Anna Bordon, Innovation − Jennifer Copic, Research Associate − Ronald Chua, Commercial − Timothy Douglas, Research Assistant − Linda Miller, Marketing and Communications − Eireann Leverett, Senior Risk Researcher − Elaine Quek, Marketing and Communications − Olivia Majumdar, Editor − Kieran Quigley, Marketing and Communications − Kelly Quantrill, Research Assistant − Flemmich Webb, Speech and Studies − Andrew Smith, Research Assistant − Emma Watkins, Risk Aggregation − Simon Sherriff, Risk Aggregation Cambridge Centre for Risk Studies Research Team − James Bourdeau, Research Assistant Lloyd’s Market Association − Oliver Carpenter, Research Assistant − Mel Goddard, Market Liaison & Underwriting Director − Tamara Evan, Research Assistant − Tony Elwood, Senior Executive, Underwriting − Ken Deng, Research Assistant − Gary Budinger, Senior Executive, Finance and Risk − Arjun Mahalingam, Research Assistant − Professor Danny Ralph, Academic Director Nanyang Technological University – Insurance Risk and − Kayla Strong, Research Assistant Finance Research Centre (NTU-IRFRC) − Dr Michelle Tuveson, Executive Director The Centre is established at the Nanyang Business School (NBS), Nanyang Technological University, Report Citation: Singapore. It aims to promote insurance and insurance related risk research in the Asia Pacific. It is seen as a Cambridge Centre for Risk Studies, Lloyd’s of London key foundation to establishing dialogue between the and Nanyang Technological University, Bashe attack: industry, regulators and institutions, and sharing critical Global infection by contagious malware, 2019 knowledge to facilitate the growing role of the insurance industry in the economic development of the region. Or Further thanks go to the remaining cyber experts that Daffron, J., Ruffle, S., Andrew, C., Copic, J., Quantrill, K., wish to remain anonymous. Smith. A., Leverett, E., Cambridge Centre for Risk Studies, Bashe Attack: Global Infection by Contagious Malware, 2019 Bashe attack – Global infection by contagious malware 4 Contents About CyRiM ......................................................................................................................................................................... 5 Executive summary ............................................................................................................................................................... 6 1. Introduction to the scenario ............................................................................................................................................ 10 2. Bashe attack: global infection by contagious malware scenario .................................................................................... 12 3. Scenario variants ............................................................................................................................................................ 18 4. Direct impacts on the economy ...................................................................................................................................... 23 5. Global and regional economic losses ............................................................................................................................. 28 6. The growing cyber insurance market .............................................................................................................................. 35 7. Insurance industry loss estimation .................................................................................................................................. 41 8. Conclusions .................................................................................................................................................................... 50 References .......................................................................................................................................................................... 52 Annex A: Global cybercrime ............................................................................................................................................... 60 Annex B: Cyber scenario selection ....................................................................................................................................