Risk
3/24/2017
02:15 PM
Kelly Sheridan
Kelly Sheridan
Slideshows
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Intro to Cyber Insurance: 7 Questions to Ask

Buying a cyber insurance policy can be complex and difficult. Make sure you're asking these questions as you navigate the process.
Previous
1 of 8
Next

(Image: Panchenko Vladimir via Shutterstock)

(Image: Panchenko Vladimir via Shutterstock)

Cyber insurance is a growing field putting business and security leaders to the test as they navigate the often tricky process of researching and purchasing policies. Technology is quickly changing, and so is risk.

Insurance for cybersecurity is different from other types of insurance because the nature of threats is constantly changing. A hurricane doesn't change intensity because a building code changes, but cybercriminals will change their strategies as technology and risk evolve.

"New trends like BYOD, [and] IoT make tech strategy change all the time," says Portnox CEO Ofer Amitai. "It's really a problem for businesses to assess their policies and terms. Technology is so dynamic. It's difficult to say what's going on; what's their risk." 

These changes make it harder for underwriters and companies to stay abreast of the landscape. During the tricky process of buying cyber insurance, you'll ask and answer questions about your company, security posture, and other factors to determine which policy is best for you, and how much coverage you should buy. 

It's worth noting the research process is changing for businesses as the marketplace gets more competitive, notes David Bradford, chief strategy officer and director of strategic partner development at Advisen. Because insurers are fighting to underwrite the same businesses, they're making the purchasing process less burdensome for clients.

That said, insurance remains a tricky field to navigate, especially for companies new to it.

Here, Bradford and Amitai share questions businesses frequently ask -- and those they should be asking -- in researching insurance. Keep these in mind as you ponder which policy will work best for you.

[Bradford will give a presentation called Cyber Insurance 101 during Interop ITX, May 15-19, at the MGM Grand in Las Vegas. To learn more about his presentation, other Interop security tracks, or to register click on the live links.]

 

Kelly Sheridan is Associate Editor at Dark Reading. She started her career in business tech journalism at Insurance & Technology and most recently reported for InformationWeek, where she covered Microsoft and business IT. Sheridan earned her BA at Villanova University. View Full Bio

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
AndyJ008
50%
50%
AndyJ008,
User Rank: Apprentice
7/15/2017 | 11:20:24 PM
Service
Great article! I like the idea that this insurance will be a less hassle and less work. The only thing that I can think is how about the services. I know for myself when I bought my insurance from JS Downey Insurance Services, the thing I look is there services and of course affordablity would come next. But if there will no changes about the  Services and reliablity I think this would be great for us as a Consumer.  
ross007
50%
50%
ross007,
User Rank: Apprentice
4/9/2017 | 10:41:57 AM
Crazy Bulk
exertion you put into your online journal great insurance 
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
3/27/2017 | 10:29:55 PM
Risk assessments and coverage
Risk audits are par for the course for cyber insurance for mid- to large-size enterprises.  Small businesses are often only asked to fill out a questionnaire.

As for the different types of coverage, it's important to keep in mind that not every policy has all of the things mentioned (e.g., forensics), but they certainly are common.

And there are many more things "cyber insurance" can cover -- including offline data losses (such as a physical loss).  Indeed, it's not so much "data breach insurance" as it is "data loss/data compromise" insurance -- and MORE.  Another option, for instance, may be content injury liability -- such as when a hacker takes over a company's Twitter account or what-have-you and smears the company somehow.

And more.  Often, companies just have to ask their carrier or broker and/or explain what they are looking for.  (Of course, a company's staff has got to be innovative, imaginative, and experienced to intuit most of the cyber/data-related liabilities you might need covered.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
3/27/2017 | 10:20:55 PM
Re: business secure
@James: There are SO many different types of cyber insurance products out there.  Moreover, a lot of SMEs don't know all of their options simply because they don't think to ask.

Conversely, of course, large enterprises have a bit more leeway to negotiate exactly what they want with insurers -- and they certainly do, given the particularized needs each faces.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/27/2017 | 3:13:12 PM
insurers are fighting
"... Because insurers are fighting to underwrite the same businesses, they're making the purchasing process less burdensome for clients."

This is a good point. They are not going to make it simple then companies would understand where they waste their money, it will be quite complex that nobody would understand.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/27/2017 | 3:09:54 PM
Re: business secure
Yes, quite informative, I like reading it. 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/27/2017 | 2:30:04 PM
Re: business secure
"... it should be treated as an add-on to good security and compliance ..."

 I agree. Insurance would be like outsourcing responsibilities to third party and not paying attention too much.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/27/2017 | 2:27:57 PM
Re: business secure
 " ... one-size-fits-all product ..."

I agree, it would not be but that is how insurance companies will be making profit that moves the industry to a wrong direction. 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/27/2017 | 2:25:59 PM
Cyber insurance?
I do not like the idea that we have moved to a point that we need insurance on cyber security. Anytime insurance companies involved things get very complex and expensive for regular people and business.

 
Maggy2020
50%
50%
Maggy2020,
User Rank: Apprentice
3/27/2017 | 12:39:49 AM
Re: business secure
Very interesting...thanks
Page 1 / 2   >   >>
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Tell the sysadmin that we have a situation.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] Assessing Cybersecurity Risk
[Strategic Security Report] Assessing Cybersecurity Risk
As cyber attackers become more sophisticated and enterprise defenses become more complex, many enterprises are faced with a complicated question: what is the risk of an IT security breach? This report delivers insight on how today's enterprises evaluate the risks they face. This report also offers a look at security professionals' concerns about a wide variety of threats, including cloud security, mobile security, and the Internet of Things.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.