Live data from Hacker News

Big Companies Thought Insurance Covered a Cyberattack

nytimes.com

1–10 of 91 posts

Re: Big Companies Thought Insurance Covered a Cyberattack

#2
If you are a large target many actors will be looking for your weaknesses. One bad actor will eventually find it, or just trick your employees to give them access.

Companies should make a solid effort to prevent the possibility, but I'm torn on what ramifications should be.

Re: Big Companies Thought Insurance Covered a Cyberattack

#4
post #2

If you are a large target many actors will be looking for your weaknesses. One bad actor will eventually find it, or just trick your employees to give them access. Companies should make a solid effort to prevent the possibility, but I'm torn on what ramifications should be.

> One bad actor will eventually find it, or just trick your employees to give them access.

or do what the Russians do and use kompromat

Re: Big Companies Thought Insurance Covered a Cyberattack

#5
post #2

If you are a large target many actors will be looking for your weaknesses. One bad actor will eventually find it, or just trick your employees to give them access. Companies should make a solid effort to prevent the possibility, but I'm torn on what ramifications should be.

> One bad actor will eventually find it, or just trick your employees to give them access. or do what the Russians do and use kompromat

What is "kompromat"?

Re: Big Companies Thought Insurance Covered a Cyberattack

#6

It might actually be a good thing in the long term as insurance companies may require 3rd party audits and that you comply with basic security practices.

It might well kill the use of open source and small-company software in business, in that the developers/management behind said code can't pay insurance companies to say that their code will pass audit. Microsoft and Oracle will pass with flying colors, of course.

Re: Big Companies Thought Insurance Covered a Cyberattack

#7
This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"?

On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the attack may not have been state sponsored, the insurance is certainly worthless.

Re: Big Companies Thought Insurance Covered a Cyberattack

#8

Earlier quoted context omitted.

> One bad actor will eventually find it, or just trick your employees to give them access. or do what the Russians do and use kompromat

What is "kompromat"?

It's where you do your dirty laundry.

Re: Big Companies Thought Insurance Covered a Cyberattack

#10

Earlier quoted context omitted.

> One bad actor will eventually find it, or just trick your employees to give them access. or do what the Russians do and use kompromat

What is "kompromat"?

It's leverage over an individual--whether that's secrets that might be released, financial problems, or whatever.
Post reply on HN