Live data from Hacker News

Big Companies Thought Insurance Covered a Cyberattack

nytimes.com

21–30 of 91 posts

Re: Big Companies Thought Insurance Covered a Cyberattack

#21
post #7

This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…

Insurers are under no obligation to offer policies which cover cyber attacks, and can even explicitly exempt them in their policies.

However, in this case:

> Mondelez said in a statement that while its business had recovered quickly from the attack, Zurich Insurance was responsible for honoring an insurance policy that explicitly covers cyber events.

Re: Big Companies Thought Insurance Covered a Cyberattack

#22

Earlier quoted context omitted.

> One bad actor will eventually find it, or just trick your employees to give them access. or do what the Russians do and use kompromat

What is "kompromat"?

If you want a great fictional interpretation (I don't know how accurate it is): https://en.wikipedia.org/wiki/The_Americans_(2013_TV_series)

Re: Big Companies Thought Insurance Covered a Cyberattack

#23

It might actually be a good thing in the long term as insurance companies may require 3rd party audits and that you comply with basic security practices.

But do audits show compliance with basic security practices, or compliance with PCI DSS and other standards which may be orthogonal to security?

Re: Big Companies Thought Insurance Covered a Cyberattack

#24
post #7

This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…

[deleted]

Re: Big Companies Thought Insurance Covered a Cyberattack

#25
Sounds like a big "out" is claiming an attack was an act of war. But very few nations declare war nowadays. They have "police actions" or "peacekeeping missions.

Maybe telling these companies "no war was declared, so you must pay out" would be a good thing.

Insurance companies are powerful lobbyists both in the traditional K street sense, and the soft power sense.

(For the soft power sense, picture a major insurance company telling a nation state their state owned businesses can self insure moving forward, since the business cannot handle the risks they generate.)

Re: Big Companies Thought Insurance Covered a Cyberattack

#26
post #19

Earlier quoted context omitted.

> On one hand, how are insurers supposed to properly cost... That's more or less the core competency of insurance providers...

Well, no argument there, but I wrote more words in that sentence that you cut off. My point is, that a "cyber attack" is poorly constrained, compared to something like a fire or a flood... a company only has so many assets, valued at $X that are liable to be burned to the ground or ruined by a flood, and these constraints can be modeled and adjusted for. Perhaps I am mistaken, I don't see a cyberattack as being anala…

If it's so hard to model then why are these insurance companies offering "cyberinsurance" in the first place?

Re: Big Companies Thought Insurance Covered a Cyberattack

#27

It might actually be a good thing in the long term as insurance companies may require 3rd party audits and that you comply with basic security practices.

But do audits show compliance with basic security practices, or compliance with PCI DSS and other standards which may be orthogonal to security?

In this case it would be the insurance company who requests the audit, so there would be incentives to ensure that the audits are meaningfully preventative.

Re: Big Companies Thought Insurance Covered a Cyberattack

#28
how can in insurance company declare a state of cyberwar, or any other war in general. I thought that was exclusively a government function.

By extension could we deny coverage when a bunch of crackheads raid someones home, simply chalking one up to the war on drugs?

Re: Big Companies Thought Insurance Covered a Cyberattack

#29
post #19

Earlier quoted context omitted.

> On one hand, how are insurers supposed to properly cost... That's more or less the core competency of insurance providers...

Well, no argument there, but I wrote more words in that sentence that you cut off. My point is, that a "cyber attack" is poorly constrained, compared to something like a fire or a flood... a company only has so many assets, valued at $X that are liable to be burned to the ground or ruined by a flood, and these constraints can be modeled and adjusted for. Perhaps I am mistaken, I don't see a cyberattack as being anala…

perhaps riot or vandalism [acts of civil disobedience]

Re: Big Companies Thought Insurance Covered a Cyberattack

#30
Similar to not relying on cyberinsurance when things go awry, the field as a whole is in an interesting shape where on one hand there is a dearth of skilled employees (1 million globally supposedly, according to reports), and on the other hand companies that do not want to train IT works with the necessary cybersecurity skillsets to fill the gap, and in turn rely less and less on the red herring of cyberinsurance. Talking to my colleagues who are looking to break in, even after taking training/seminars, which can be quite pricey, employers will tend to hire for junior roles at best.
Post reply on HN