EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
Related Services
-
EY-Parthenon Financial Services Strategy Consulting can help create value for banking and capital markets, wealth and asset management, and insurance firms.
Read more
But regulation only partly explains why resilience is a focal point for CROs. The fundamental goal of keeping the business up and running properly in support of customers is every bit as important. While this is an objective for regulators, the reputational risk is significant for those firms that fail to meet basic customer obligations. Further, with customers expecting insurers to deliver the same rich, personalized experiences and anytime-anywhere access to critical services that businesses in other sectors provide, resilience is a baseline for growth.
When it comes to potential disruptions, cyber attacks top the list: 66% of respondents to our latest survey this year, up from 53% last year, said cyber threats will require the most attention in the next 12 months. That increase is a function of intersecting risks. Consider how CROs must ensure the business is protected and prepared for increasing cyber attacks that originate from geopolitical tensions and armed conflicts.
Third-party risks may also increase vulnerabilities to cyber attacks. Resilience is a critical consideration here, too, as more carriers rely on ecosystems to enrich service offerings, promote innovation and expand distribution. Regulators are also focused on the resilience implications of increased connectivity across the industry.
The same is true of technology risk: insurers can’t allow major systems implementations that replace legacy systems or cloud migrations to disrupt the business. This is an increasing concern with ongoing digitization of claims processing, increased automation in underwriting, the widespread use of cloud infrastructure and connectivity with third-party data sources. Failures of any component in increasingly complex IT environments can directly impact customers, raising the risk of operational breakdowns, reputational hits and penalties for non-compliance.
Because of these dynamics, increased operational resilience is now widely viewed as a target outcome – a key goal in setting strategies and tactics to manage many other types of risks. That helps explain why CROs are acting on multiple fronts to enhance resilience.