Earlier quoted context omitted.
> One bad actor will eventually find it, or just trick your employees to give them access. or do what the Russians do and use kompromat
What is "kompromat"?
Big Companies Thought Insurance Covered a Cyberattack
11–20 of 91 posts
Re: Big Companies Thought Insurance Covered a Cyberattack
#12Re: Big Companies Thought Insurance Covered a Cyberattack
#13It might actually be a good thing in the long term as insurance companies may require 3rd party audits and that you comply with basic security practices.
It might well kill the use of open source and small-company software in business, in that the developers/management behind said code can't pay insurance companies to say that their code will pass audit. Microsoft and Oracle will pass with flying colors, of course.
The open source model is benefiting too many businesses to just up and throw it out.
Re: Big Companies Thought Insurance Covered a Cyberattack
#14This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…
That's more or less the core competency of insurance providers...
Re: Big Companies Thought Insurance Covered a Cyberattack
#15It might actually be a good thing in the long term as insurance companies may require 3rd party audits and that you comply with basic security practices.
It might well kill the use of open source and small-company software in business, in that the developers/management behind said code can't pay insurance companies to say that their code will pass audit. Microsoft and Oracle will pass with flying colors, of course.
When you have an attack that moves from your servers to your desktop computers, you have a network issue, which would be covered in an audit to verify you properly segment your network instead of having it in one large broadcast domain.
Re: Big Companies Thought Insurance Covered a Cyberattack
#16This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…
This is what insurance companies do..
Re: Big Companies Thought Insurance Covered a Cyberattack
#17Wow, this is huge. If cyber insurance doesn't cover cyber attacks, then what does it cover? Having seen the process for cyber insurance paying out for an intrusion, I'd be super concerned if I were a CSO/Chief Risk Officer and there's a chance the cyber insurance wouldn't cover you.
Re: Big Companies Thought Insurance Covered a Cyberattack
#18I’m curious if there are cyber mitigation’s that are out there, such as mandatory two factor authentication, requiring up to date software and OSes or other measures. It seems like any insurance company would Be highly Interested in forcing these best practices.
Re: Big Companies Thought Insurance Covered a Cyberattack
#19This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…
> On one hand, how are insurers supposed to properly cost... That's more or less the core competency of insurance providers...
My point is, that a "cyber attack" is poorly constrained, compared to something like a fire or a flood... a company only has so many assets, valued at $X that are liable to be burned to the ground or ruined by a flood, and these constraints can be modeled and adjusted for. Perhaps I am mistaken, I don't see a cyberattack as being analagous to anything else in the insurance industry.
Re: Big Companies Thought Insurance Covered a Cyberattack
#20This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…
If the FBI publicly arrests some teenager or former employee related to a company hack, and the insurance tries to use a cyberwarfare exception, then we can go grab the pitchforks.
Both sides of this are going to get tested though: does the US actually have a definition for cyberwarfare and is that the same as what's in the insurance contract? Do countries have to publicly declare cyberwar (but not necessarily regular war) on other countries for this clause to be valid? What due diligence do companies have to do to prove they weren't part of a cyberwarfare hack?
This headline is misleading though. Big Companies know what's in those contracts. Maybe this is a kick in the pants for more scrutiny of those contracts to strike things like cyberwarfare.