We’re all familiar with home and auto insurance, but cyber security insurance? It’s vital to have if you’re a mid-size or above company looking to mitigate risk. In this episode of Cyber Security Inside, Malcolm Harkins joins Tom and Camille again to unpack it all. Now the Chief Security and Trust Officer at Epiphany Systems, Malcolm’s over thirty-year career in the tech industry, gives him a unique perspective on the various facets to consider, so you definitely don’t want to miss it.
We cover:
What cyber insurance is and who might need it
How cyber insurance compares to other forms of insurance, such as home insurance or pet insurance
The kinds of expenses usually covered by cyber insurance
Whether or not cyber insurance providers employ requirements or stipulations
Why companies might or might not choose to report a compromise to the authorities and self-insure instead
... and more!
Tune in for some next-level insight.
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
Here are some key take-aways:
In essence, cyber insurance is like any other form of insurance - it offers a method to pay premiums and mitigate some of the potential financial impacts of either a business interruption, a lawsuit, or expenditures specifically related to a cyber event.
There are various clauses with different conditions that appear in these insurance policies, depending upon what you're trying to insure against, be it ransomware attacks, business interruption, etc.
Some of these clauses can also reduce coverage depending on factors like whether or not you patch the system, whether the antivirus was up to date, etc.
Typically the kinds of businesses that have cyber insurance policies are mid-size and above.
Companies with large market caps may opt for a level of self-insurance as a form of risk mitigation.
Compromises rarely get reported to law enforcement, whether it’s because it’s a nuisance or because a company wants to maintain control over its liability.
But the main hope is that, like with other forms of insurance, safety standards and hygiene will ultimately be raised by cyber insurance.
Some interesting quotes from today’s episode:
“A company might want to maintain control over the investigation in order to limit their liability, and stay in control of the investigation versus having law enforcement come in with an unknown set of motivations and start doing things or seizing systems or collecting evidence that could disrupt the business.”
“Being vulnerable doesn't mean you're exploitable.”
“What we need to be able to start doing is start focusing on where we're exploitable, and not just where we're vulnerable; that will allow us to turn the dial on risk more efficiently, as well as more effectively.”
“If I'm worried about a compromise, and data theft, a redundant system doesn't stop data theft.”
“I think they [cyber insurance providers] will help push some level of hygiene and corrective action at the broad level.”
“There's a lot of connective tissue. And without understanding that connective tissue and that exploit path, you're going to be focused on the wrong thing. You're going to say, I'm going to patch all these things, I'm gonna do all the things. And you're still going to have a connection and a pivot point. Because you can't eliminate risk.”
“And I think people need to start thinking about digital extortion, well beyond just the typical unlocking of your system.”
“There's evidence that the insurance industry has made a tremendous amount of impact on improving safety on things. So I'm hopeful that that will occur.”