Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations

6/13/2016
12:50 PM
Sean Martin
Sean Martin
Slideshows
Connect Directly
LinkedIn
RSS
E-Mail
50%
50%

12 Tips for Securing Cyber Insurance Coverage

As cyber insurance grows more available and popular it is also becoming increasingly complex and confusing. Our slideshow offers guidelines on how to get insurance, get decent coverage, and avoid limitations in coverage.
Previous
1 of 13
Next

Image Source: imsmartin/Mimecast

Image Source: imsmartin/Mimecast

Cyber Liability Insurance, or cyber insurance, can help protect your organization from the financial ramifications of a successful attack on your data systems, which might include the theft of customer data from your servers. There’s still a lot of confusion around what’s required to get coverage, what it takes to get good rates, and what it takes to ensure a claim will be paid. Some might question whether or not a claim will even be paid given some policies may not be up to snuff when it comes to covering some events such as email attacks.

It’s possible that all of this confusion is introducing some risk to both sides of the bargaining table – insurer and insured. The good news is that the focus on risk is good for all, as it is forcing organizations to look at their risk in light of their use of technology and tech-connected partnerships, thereby raising the cybersecurity posture across the board.

Note: imsmartin would like to thank Thomas Conway, Principal, Ernst & Young LLP, William Dixon vice president, Stroz Friedberg, Howard Miller of LBW Insurance’s Tech Secure division, and Mimecast for their research.

 

Sean Martin is an information security veteran of nearly 25 years and a four-term CISSP with articles published globally covering security management, cloud computing, enterprise mobility, governance, risk, and compliance—with a focus on specialized industries such as ... View Full Bio
 

Recommended Reading:

Previous
1 of 13
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
roxychan
50%
50%
roxychan,
User Rank: Apprentice
4/10/2017 | 10:31:28 AM
192.168.1.1
Thanks for the help.
Pascal_Millaire
50%
50%
Pascal_Millaire,
User Rank: Author
3/15/2017 | 9:18:55 AM
Cyber insurance tips
All pertinent points. On the regulatory fines issue, it is also important to note that policy language may state that regulatory fines are payable "where permissible by law" however in some cases your jurisdiction may not allow for the payment, which renders the coverage moot.
Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Google's new See No Evil policy......
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-33347
PUBLISHED: 2021-06-18
An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag management module. If you log in to the background by means of weak password, the storage XSS vulnerability can occur.
CVE-2021-33576
PUBLISHED: 2021-06-18
An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk.
CVE-2021-33577
PUBLISHED: 2021-06-18
An issue was discovered in Cleo LexiCom 5.5.0.0. The requirement for the sender of an AS2 message to identify themselves (via encryption and signing of the message) can be bypassed by changing the Content-Type of the message to text/plain.
CVE-2021-32536
PUBLISHED: 2021-06-18
The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaScript without privilege and thus perform reflected XSS attacks.
CVE-2021-21669
PUBLISHED: 2021-06-18
Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.