Live data from Hacker News

Big Companies Thought Insurance Covered a Cyberattack

nytimes.com

31–40 of 91 posts

Re: Big Companies Thought Insurance Covered a Cyberattack

#31
post #2

If you are a large target many actors will be looking for your weaknesses. One bad actor will eventually find it, or just trick your employees to give them access. Companies should make a solid effort to prevent the possibility, but I'm torn on what ramifications should be.

> Companies should make a solid effort to prevent the possibility

Isn't this what they do and then hedge the risk by covering their potential losses with insurance?

If companies are not doing a good enough job with security, why does the cyber insurance not cost more? Priced properly, companies can choose between buying more coverage versus throwing more money at the "security problem."

Re: Big Companies Thought Insurance Covered a Cyberattack

#32
its pretty spectacular what major insurance does not cover in the digital context.

For example, I work as an automotive engine mechanic for a small chain of midwestern shops. Recently we had a Tesla owner drive in for servicing a recalled suspension control arm. We were approved to do the work by Tesla and had the parts shipped directly from California. once the work was completed, we informed the customer in the waiting room, who immediately took it upon himself to "auto-pilot" the car out of the garage while it was still on the lift.

The car happily obliged, and backed itself off a lift six and a half feet to the ground in a pretty spectacular display. No one was hurt thankfully, however our shop insurance refused coverage for our damaged lift, and the Tesla owners auto insurance refused coverage as well because he was technically not driving the car at the time. The customer had to pay out of pocket for repairing his car, as well as our lift.

Re: Big Companies Thought Insurance Covered a Cyberattack

#33
post #7

This is messy. On one hand, how are insurers supposed to properly cost and be able to provide payouts for a "cyberattack", which might be anything from "our company website was DDoSed for 30 minutes and we lost 50 customers" to "our production lines were shut down and our company ground to a halt for two weeks"? On the other hand, if insurers know they can invoke a cyberwarfare clause and deny a claim, even if the at…

IMO this feels like the whole point of insurance. You could restate this as "how are insurers supposed to cost and provide payouts for fires in the factory? It could be anything from a tiny, contained garbage can fire to the whole place going up in a blaze! [0]" Or chemicals in the case of TSMC [1]. Or blackouts at Samsung [2]. Any of this could have been industrial espionage on the same scale as a state-sponsored cyberattack. This is the domain of actuaries.

Of course, they're neither required nor obligated to provide such cover.

[0] https://www.extremetech.com/computing/166775-ram-pricewatch-...

[1] https://asia.nikkei.com/Business/Companies/TSMC-takes-550m-h...

[2] https://www.anandtech.com/show/12535/power-outage-at-samsung...

Re: Big Companies Thought Insurance Covered a Cyberattack

#34

It might actually be a good thing in the long term as insurance companies may require 3rd party audits and that you comply with basic security practices.

More like in the short term. A friend of mine just got a job at a SF startup for that. They're a consultancy which evaluates computer security for insurance companies, before they insure a business. She used to work on AI for intrusion detection, so they're hiring serious people for this.

There are specialty insurance companies which cover specific risks and know how to evaluate them. The classic is The Hartford Steam Boiler Insurance Company.[1] They were the first insurance company willing to insure steam boilers. About half their employees are boiler inspectors. When they started, in 1866, nobody else would touch that business.

They inspect before they insure. Typically, they send inspectors and provide the boiler owner with a to-do list. Then they come back to see if everything was fixed. Only then does HSB write a policy. Their policies give them the right to come in at any time and inspect. Which, randomly, they do.

Boring old Hartford Steam Boiler is expanding into computer systems insurance.[2] But they are not as hard-ass about inspections as they are with boilers, unfortunately. They know how to keep boilers from blowing up. Computer security isn't there yet.

[1] https://www.munichre.com/HSB/about-hsb/index.html

[2] https://www.munichre.com/HSB/cyber-insurance/index.html

Re: Big Companies Thought Insurance Covered a Cyberattack

#35
post #19

Earlier quoted context omitted.

> On one hand, how are insurers supposed to properly cost... That's more or less the core competency of insurance providers...

Well, no argument there, but I wrote more words in that sentence that you cut off. My point is, that a "cyber attack" is poorly constrained, compared to something like a fire or a flood... a company only has so many assets, valued at $X that are liable to be burned to the ground or ruined by a flood, and these constraints can be modeled and adjusted for. Perhaps I am mistaken, I don't see a cyberattack as being anala…

>> compared to something like a fire or a flood

Those are not easy things. People litigate the difference between fire and flood damage all the time. (Putting out a fire normally involves lots of water.) Sometimes flooding in building X even causes a fire in building Y. Is that covered by "fire" or "flood" insurance? The difference between various cyber attacks isn't substantively more complicated than any of the traditional insured risks. The issue is that insurers haven't invested in the experts needed to properly assess those risks. That is their problem to solve, not the customer's.

Re: Big Companies Thought Insurance Covered a Cyberattack

#36
post #32

its pretty spectacular what major insurance does not cover in the digital context. For example, I work as an automotive engine mechanic for a small chain of midwestern shops. Recently we had a Tesla owner drive in for servicing a recalled suspension control arm. We were approved to do the work by Tesla and had the parts shipped directly from California. once the work was completed, we informed the customer in the wai…

auto-pilot requires the driver to be in the vehicle, i'm guessing this was the summon feature activated from their app? what a complete waste

Re: Big Companies Thought Insurance Covered a Cyberattack

#37

Most insurers require customers to limit their risk in all kinds of ways. I’m curious if there are cyber mitigation’s that are out there, such as mandatory two factor authentication, requiring up to date software and OSes or other measures. It seems like any insurance company would Be highly Interested in forcing these best practices.

Mandatory snake oil

Re: Big Companies Thought Insurance Covered a Cyberattack

#38
post #19

Earlier quoted context omitted.

> On one hand, how are insurers supposed to properly cost... That's more or less the core competency of insurance providers...

Well, no argument there, but I wrote more words in that sentence that you cut off. My point is, that a "cyber attack" is poorly constrained, compared to something like a fire or a flood... a company only has so many assets, valued at $X that are liable to be burned to the ground or ruined by a flood, and these constraints can be modeled and adjusted for. Perhaps I am mistaken, I don't see a cyberattack as being anala…

Maybe I'm misunderstanding but aren't a fire and a cyberattack both capped at 100% of the value of the company? If the fire takes out the whole place, or a cyberattack empties out an equivalent amount from their bank accounts, the difference feels immaterial.

Re: Big Companies Thought Insurance Covered a Cyberattack

#39
post #19

Earlier quoted context omitted.

Well, no argument there, but I wrote more words in that sentence that you cut off. My point is, that a "cyber attack" is poorly constrained, compared to something like a fire or a flood... a company only has so many assets, valued at $X that are liable to be burned to the ground or ruined by a flood, and these constraints can be modeled and adjusted for. Perhaps I am mistaken, I don't see a cyberattack as being anala…

>> compared to something like a fire or a flood Those are not easy things. People litigate the difference between fire and flood damage all the time. (Putting out a fire normally involves lots of water.) Sometimes flooding in building X even causes a fire in building Y. Is that covered by "fire" or "flood" insurance? The difference between various cyber attacks isn't substantively more complicated than any of the tra…

Agreed with everything you said, though 'its their problem to solve' should they decide to offer cyberattack coverage and sell it, otherwise it is the customers.

Re: Big Companies Thought Insurance Covered a Cyberattack

#40
post #32

its pretty spectacular what major insurance does not cover in the digital context. For example, I work as an automotive engine mechanic for a small chain of midwestern shops. Recently we had a Tesla owner drive in for servicing a recalled suspension control arm. We were approved to do the work by Tesla and had the parts shipped directly from California. once the work was completed, we informed the customer in the wai…

> The customer had to pay out of pocket for repairing his car, as well as our lift.

Given the level of dangerous stupidity they displayed, that seems like a decent enough outcome.

Post reply on HN