K&R insurance and the art of confidentiality.
The world’s worst icebreaker
There are those in the insurance community who seem faintly ashamed to work in an industry so often mischaracterised as dull. In these poor souls, the niggling and entirely unfair sense of professional inadequacy tends to surface as bouts of self-aggrandisement at social gatherings. I prefer to treat it as a social litmus test. If, during casual introductions, “I’m an insurance broker” is met with a blank stare and a hasty change of subject, I quietly conclude that the person who asked is, well, rather uninteresting themselves, and woefully in thrall to the stereotype. Anyway, who needs more friends at our age?
Which brings me to a barbecue during the recent heatwave. Whether it was the sun, the wine, or some potent combination of the two, the insurance manager of a large, listed company, plainly rattled by a lull in conversation, blurted out: “We’ve just done our kidnap and ransom renewal!” Cue a ripple of coy glances in my direction and a volley of excited questions in theirs. The audience, tragically, had taken the bait.
I don’t know this person, and I’ll observe the usual protocols of discretion. I simply chuckled to myself, wondered who the underwriter was, and whether I might offer a quiet wording review at some later point. I did tell you I don’t need friends.
Why we whisper
I have been broking Security Risks (K&R) insurance since 2012, and the importance of confidentiality was drummed into me from day one. Policies sat in siloed systems, assured names were masked, and correspondence and billing were handled to avoid any explicit reference to the product. We were just as emphatic with clients, because these policies ordinarily contain a confidentiality condition requiring knowledge of the policy to be restricted, often ‘as far as reasonably possible.’
The logic is simple. If the cover becomes widely known, it may influence a would-be perpetrator’s perception of the target and the potential availability of funds, increasing the risk to employees and their families. Nobody wants that: not the client, not the broker, not the insurer. Confidentiality clauses also reduce the risk of an inside job by keeping the circle as tight as possible.
Could you just confirm I’m covered?
A few years ago, I took a call from a very polite gentleman who introduced himself as a sub-contractor to one of my clients. He wanted to be added to their policy and given the 24/7 incident hotline, just in case. I happened to know that this client had a sizeable contractor population around the world.
Despite his pleas of “can you just confirm I’m covered?”, I explained that I couldn’t comment on the client’s insurance arrangements, or indeed on their absence, and promptly called my contact. It turned out a well-meaning, policy-aware HR director had encouraged him to get in touch. We agreed it was a confidentiality issue, and I hurried off to explain it to the underwriter, who kindly accepted our apologies and confirmed cover was in place.
There’s a wider lesson in that call. You can reassure staff that measures are in place for their security and safety, which is a genuine duty-of-care point, without ever specifying an insurance policy. A carefully crafted statement can answer most questions without compromising confidentiality.
The need-to-know
Keeping the circle tight is one thing. Deciding who belongs inside it is another. Within the limits imposed by the confidentiality condition, who inside an organisation needs to know?
It’s a common frustration for policyholders, and it ties directly to their crisis-management infrastructure. The right list varies with the size, sophistication and structure of the group in question, but the common thread is this: the people responsible for handling a crisis need to understand that the policy exists and how it works. In practice, that can mean the C-suite, risk and insurance managers, general counsel, security directors, HR leaders, regional directors and crisis-communications specialists.
The point is that when a serious incident occurs, those dealing with it can reach for the policy without delay. It follows that the policy quietly forces clients to examine their internal notification processes and whether they’re built for crisis response. That, I’d argue, is a good thing – it moves the conversation from risk transfer towards risk mitigation, capacity-building and resilience.
Cautionary tales
Over the years, I’ve heard about rather more egregious breaches. The overzealous client who uploaded the entire suite of policy documents to the ‘employee benefits’ page of the intranet, then sent a smug, company-wide email announcing it. The security director who, during a get-to-know-you session in his first week, cheerfully informed 300 assembled staff that they were all covered against kidnap for ransom and extortion.
Every one of these, however excruciating, must be judged in context and shared with insurers straight away so it can be resolved. The lesson – be transparent with your underwriter, and discreet with everyone else.
One of my favourite clients was the anxious father of a daughter setting off on her gap year. The lucky lady had planned something akin to a world tour, joyfully wandering through territories her poor dad had never heard of, and a few he had and rather wished he hadn’t.
We put the cover in place, and during onboarding I explained the confidentiality point. Yes, she would know about it too and have the number: that all made sense. No mentioning it to fellow backpackers, tuk-tuk drivers, Machu Picchu guides or the smoking-area crowd in a Bogotá bar.
“And her mother,” he asked, “should I tell her?”
I paused.
“Senior leadership,” I said, “is best kept informed of these things.”
What triggers a K&R insurance claim?
More than you might expect. Comprehensive policies can be triggered by the unexplained disappearance of an insured person – no confirmation of a kidnap required. Malicious or violent threats alone can activate crisis support, with no ransom demand needed. Active assailant incidents, home invasion, and stalking can all be covered by extensions to the coverage. Policies can be extended to cover evacuations linked to security crises and geopolitical developments The policy has evolved well beyond its name.
Is kidnap and ransom insurance only for high risk travel?
No. While K&R insurance is frequently associated with travel to high risk destinations, it covers a broad range of critical security incidents, both at home and abroad. Evacuation support, crisis response, reputational protection, and business continuity are all part of the Security Risks toolkit, making it a far more versatile product that its origins suggest.
Who needs K&R insurance?
Any organisation or individual with exposure in environments where personal security risks are elevated. This includes companies and organisations with staff travelling to high-risk regions, executives who may be targets for extortion or stalking, and businesses operating in sectors that attract a higher threat profile. Regardless of travel destinations or office locations, organisations who recognise their duty of care towards and consider crisis management a key corporate governance priority should be considering Security Risks insurance.