April 28, 2014

Taleen Ananian:, 202.778.4993
Robyn Ziegler:, 847.212.6231

Zurich Insurance Group and Atlantic Council Release New Recommendations from Pioneering Report on Cyber Risk, Shocks, and Resilience

Sector-Specific Recommendations for Automotive, Construction, Healthcare, Information Technology, Large and Small/Mid-sized Businesses and Governments to Help Risk Managers Prepare for Future Cyber Shocks and Help Prevent a Cyber-Subprime Meltdown

DENVER – Zurich Insurance Group and the international think tank, Atlantic Council, today released new risk management specific insights – including recommendations – from its pioneering new report on cyber risk, shocks, and resilience. As the Internet increasingly connects with real life and permeates all facets of society, it can be a source of global shocks for which risk managers, corporate executives, board directors, and government officials might not be prepared.

The industry specific insights from today’s news conference – held at the RIMS 2014 annual conference and exhibition for risk managers – will help to prepare risk managers to address these cyber shocks of tomorrow and become more resilient and possibly prevent what could be called a cyber sub-prime meltdown.

“To protect the integrity and reliability of cyberspace and the bottom line for businesses, governments, the private sector and civil society must work closely together,” said Dan Riordan, CEO Zurich Global Corporate North America. “We need a clear plan of what to do in the case of an event – both at the individual company level and also holistically and hopefully this report becomes a catalyst for developing such a plan.”

Recommendations for managing risk include some combination of the following actions depending on their sector-specific factors.

    • Shifting from protection to resilience;
    • Improving basic cyber security;
    • Embracing new technology but carefully managing the risks;
    • Implementing incident response and business continuity planning;
    • Focusing on interconnection risks;
    • Pushing out the risk horizon and looking beyond their four walls; and
    • Practicing board level risk management

The report – Risk Nexus: Beyond Data Breaches: Global Interconnections of Cyber Risk is the result of a year-long study by the Atlantic Council and Zurich on interrelated cyber hazards and underlying risks and was designed to better prepare governments and businesses for the cyber shocks of the future.

As the Internet increasingly connects with real life and permeates all facets of society, cyber attacks can affect interdependent systems like electrical grids and global logistics systems. Through a combination of stable technology and dedicated technicians, the Internet has been resilient to attacks on a day-to-day basis, creating an extended period of reliability. Yet, as we approach nearly absolute dependence on the Internet, cyber attacks of the future can and will affect globally interconnected systems.

“The recent Heartbleed vulnerability demonstrates the main message of the report,” according to report author Jason Healey, who serves as director of the Atlantic Council’s Cyber Statecraft Initiative. “The Internet is so complex and tightly coupled to the real world, it turns out we were all gravely exposed to a cyber risk in an obscure technology that few understand and we didn’t see coming. This time it was just passwords, but what happens once the internet is connected to the electrical grid or driverless cars?”

Read the full report hereRead the industry segment reports here.

For more information or to speak with our experts, please contact the Atlantic Council at or Zurich at


The Atlantic Council is a nonpartisan organization that promotes constructive US leadership and engagement in international affairs based on the central role of the Atlantic community in meeting today’s global challenges. For more information, please visit and follow us on Twitter @AtlanticCouncil.

Zurich Insurance Group (Zurich) is a leading multi-line insurer that serves its customers in global and local markets. With more than 55,000 employees, it provides a wide range of general insurance and life insurance products and services. Zurich’s customers include individuals, small businesses, and mid-sized and large companies, including multinational corporations, in more than 170 countries. The Group is headquartered in Zurich, Switzerland, where it was founded in 1872. The holding company, Zurich Insurance Group Ltd (ZURN), is listed on the SIX Swiss Exchange and has a level I American Depositary Receipt (ZURVY) program, which is traded over-the-counter on OTCQX. Further information about Zurich is available at

In North America, Zurich is a leading commercial property-casualty insurance provider serving the global corporate, large corporate, middle market, specialties and programs sectors. Life insurance offered in the United States is issued by Zurich American Life Insurance Company, an Illinois domestic life insurance company. For more information about the products and services it offers and people Zurich employs around the world go to 2012 marked Zurich’s 100 year anniversary of insuring America and the success of its customers, shareholders and employees.

Related Experts: Jason Healey