Live data from Hacker News

Big Companies Thought Insurance Covered a Cyberattack

nytimes.com

11–20 of 91 posts

Re: Big Companies Thought Insurance Covered a Cyberattack

#11

Earlier quoted context omitted.

> One bad actor will eventually find it, or just trick your employees to give them access. or do what the Russians do and use kompromat

What is "kompromat"?

Materials for compromising someone. Blackmail material.

Re: Big Companies Thought Insurance Covered a Cyberattack

#12
Wow, this is huge. If cyber insurance doesn't cover cyber attacks, then what does it cover? Having seen the process for cyber insurance paying out for an intrusion, I'd be super concerned if I were a CSO/Chief Risk Officer and there's a chance the cyber insurance wouldn't cover you.

Re: Big Companies Thought Insurance Covered a Cyberattack

#13
post #6

It might actually be a good thing in the long term as insurance companies may require 3rd party audits and that you comply with basic security practices.

It might well kill the use of open source and small-company software in business, in that the developers/management behind said code can't pay insurance companies to say that their code will pass audit. Microsoft and Oracle will pass with flying colors, of course.

It could just as well lead to better support models for contributions to fix and audit open source.

The open source model is benefiting too many businesses to just up and throw it out.

Re: Big Companies Thought Insurance Covered a Cyberattack

#14
post #7

This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…

> On one hand, how are insurers supposed to properly cost...

That's more or less the core competency of insurance providers...

Re: Big Companies Thought Insurance Covered a Cyberattack

#15
post #6

It might actually be a good thing in the long term as insurance companies may require 3rd party audits and that you comply with basic security practices.

It might well kill the use of open source and small-company software in business, in that the developers/management behind said code can't pay insurance companies to say that their code will pass audit. Microsoft and Oracle will pass with flying colors, of course.

Doubt it, there are a lot of PCI Compliant businesses that get audited with open source software in their systems. I'm sure they have a node_modules somewhere on their build server.

When you have an attack that moves from your servers to your desktop computers, you have a network issue, which would be covered in an audit to verify you properly segment your network instead of having it in one large broadcast domain.

Re: Big Companies Thought Insurance Covered a Cyberattack

#16
post #7

This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…

> how are insurers supposed to properly cost and be able to provide payouts

This is what insurance companies do..

Re: Big Companies Thought Insurance Covered a Cyberattack

#17

Wow, this is huge. If cyber insurance doesn't cover cyber attacks, then what does it cover? Having seen the process for cyber insurance paying out for an intrusion, I'd be super concerned if I were a CSO/Chief Risk Officer and there's a chance the cyber insurance wouldn't cover you.

Seems a very odd strategy for cyber-insurance companies to take... If I were a large company insured by Zurich right now, I would definitely be reconsidering giving them my money.

Re: Big Companies Thought Insurance Covered a Cyberattack

#18
Most insurers require customers to limit their risk in all kinds of ways.

I’m curious if there are cyber mitigation’s that are out there, such as mandatory two factor authentication, requiring up to date software and OSes or other measures. It seems like any insurance company would Be highly Interested in forcing these best practices.

Re: Big Companies Thought Insurance Covered a Cyberattack

#19
post #7

This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…

> On one hand, how are insurers supposed to properly cost... That's more or less the core competency of insurance providers...

Well, no argument there, but I wrote more words in that sentence that you cut off.

My point is, that a "cyber attack" is poorly constrained, compared to something like a fire or a flood... a company only has so many assets, valued at $X that are liable to be burned to the ground or ruined by a flood, and these constraints can be modeled and adjusted for. Perhaps I am mistaken, I don't see a cyberattack as being analagous to anything else in the insurance industry.

Re: Big Companies Thought Insurance Covered a Cyberattack

#20
post #7

This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…

This hinges on the US assigning attribution, and to be fair, the US probably has a better idea than an insurance company.

If the FBI publicly arrests some teenager or former employee related to a company hack, and the insurance tries to use a cyberwarfare exception, then we can go grab the pitchforks.

Both sides of this are going to get tested though: does the US actually have a definition for cyberwarfare and is that the same as what's in the insurance contract? Do countries have to publicly declare cyberwar (but not necessarily regular war) on other countries for this clause to be valid? What due diligence do companies have to do to prove they weren't part of a cyberwarfare hack?

This headline is misleading though. Big Companies know what's in those contracts. Maybe this is a kick in the pants for more scrutiny of those contracts to strike things like cyberwarfare.

Post reply on HN