Risk

3/23/2017
10:30 AM
Pascal Millaire
Pascal Millaire
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
0%
100%

5 Ways CISOs Could Work Better with Their Cyber Insurers

Risk management has become increasingly important, making it crucial companies have good relationships with their insurance company.

Cybersecurity risk management is undergoing one of the most important shifts in recent memory — but this shift is not being driven by the information security industry. Cyber insurance is emerging as a critical new risk management tool for companies and, according to Fitch, it's the fastest-growing segment in property/casualty insurance. But what does this mean for information security professionals?

Corporate clients and insurance brokers from Allianz recently rated cyberrisk as the third most important corporate peril, above fire, natural catastrophes, and even macroeconomic developments. Too often, CISOs and information security teams have cursory engagement with their cyber insurer. This is bad for the CISO, bad for their insurer, and bad for the cyber resilience of the company.

Forty percent of information security professionals don't fully understand the "characteristics and limits of the company's cyber insurance coverage," according to a study conducted by SANS, and only 14% of insurance broker respondents thought that CISOs fully understand and value the insurance.

Here are five ways CISOs should start engaging with their corporate risk managers, brokers, and insurance carriers today.

1. Understand what cyber insurance coverage your company already has purchased.
Coverage for cyberrisk is complicated because it can be purchased by itself or embedded into other insurance lines such as property, general liability, and crime policies. Knowing what is and isn't covered is an important first step and will often require engagement with the risk management department and the company's broker.

Many companies have notification requirements to get their insurer involved in case of a breach. At worst, information security departments should be aware of the policy and its requirements. At best, insurers should have seen a large number of breaches and can be a tremendous resource working through everything from coordinating vendors to offering advice and mobilizing response teams.

2. Get involved with risk managers in the cyber insurance purchase process and in insurance renewals.
Engaging with the information security organization can lead to better premiums by allowing the company to display the security culture that exists in the organization. A top-three broker reported that two airlines with similar cybersecurity postures achieved a 30% differential in the cyber insurance pricing, attributed to the confidence projected by an engaged cybersecurity team in the purchase process and the "culture of security" presented by the CISO.

CISOs are an important party in the insurer selection process. For example, a Fortune 2000 technology company was using a leading managed security services provider to oversee its cybersecurity. However, the vendor was not on the insurer's incident response panel. This meant that in the event of a breach, the company would not be reimbursed for the additional breach response costs incurred with the managed security provider. Without engagement from the CISO, the company could have purchased a policy that prohibited their most trusted security partner from responding in a breach, which had the potential to slow down the speed of response in a crisis.

3. Proactively provide information in the underwriting process.
Providing security information to an insurer is often misunderstood as a game of "gotchas," but it's important to tell them everything. Insurers want to avoid bad risks so they will be on the lookout for practices that they deem risky and providing more information will enable more carriers to quote insurance. Think of it like an auction of a piece of property. You want as many bidders as possible, but providing only piecemeal information creates uncertainty and lowers participation.

Research sponsored by Advisen shows that insurance brokers are frustrated by divergent and sometimes conflicting expectations from underwriters. Cyber underwriting is an evolving discipline that's slowly improving as the industry matures and adopts new data modeling and software tools to make better risk decisions. In the meantime, engaging proactively in the underwriting process and having patience for the questions that insurers are asking is an important step.

4. Security personnel should engage in a transparent dialogue about what security they don't currently have.
It makes sense that an insurer covering the costs of a data breach wishes to provide incentives to companies to purchase leading data loss prevention software to protect that sensitive data. Similarly, if a company is insuring against ransomware, which is almost exclusively delivered via email, the implementation of email security filtering could be subsidized by the carrier. Companies should understand that their insurer can be a real partner in creating a more resilient cybersecurity program.

Carriers will often include free, trial, or discounted cybersecurity services to their clients, but this requires engagement from the information security team. Looking for security awareness training for employees? In some cases, insurers will pay for services from a cybersecurity organization. 

5. Security professionals should openly share prior breaches with their insurers.
It's better for a company to illustrate its awareness of its breach history, the lessons learned, and plans to deal with future events. Too frequently, insurance carriers witness risk managers and information security leaders meeting for the first time in an underwriting meeting. To make matters worse, sometimes it's the insurer informing the risk manager of previous breaches that he or she was not aware of. This doesn't inspire confidence in the insurer, who could be on the hook for tens of millions of dollars in the event of a claim. Security professionals should be deeply engaged with risk management and insurance buyers.

Security professionals should not see insurers or underwriters as an unwelcome intrusion, second-guessing a company's security protocols, but rather as a partner protecting the firm's assets, sometimes with tens of millions of dollars of the insurer's money on the line. It's time for CISOs and insurers to take one step closer and embrace each other in a united front against cybercrime.

Related Content:

Pascal Millaire is Vice President at Symantec Corporation, the world's largest cybersecurity company, and General Manager of the company's Cyber Insurance Group. In that role, he is responsible for creating new underwriting, actuarial, and catastrophe modeling products that ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-15583
PUBLISHED: 2019-03-25
Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
CVE-2017-7340
PUBLISHED: 2019-03-25
A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.
CVE-2014-9187
PUBLISHED: 2019-03-25
Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules, which could lead to possible remote code execution or denial of service. Honeywell strongly encourages and recomme...
CVE-2014-9189
PUBLISHED: 2019-03-25
Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules that could lead to possible remote code execution, dynamic memory corruption, or denial of service. Honeywell...
CVE-2019-10044
PUBLISHED: 2019-03-25
Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters e...