Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

3/26/2019
04:15 PM
100%
0%

Insurers Collaborate on Cybersecurity Ratings

A group of insurers will base rates and terms on whether customers purchase technology that has earned a stamp of approval.

It's in the best interest of insurance companies to have their customers protected from cybersecurity losses. That, in a nutshell, is why a number of global insurers are collaborating on a rating system for cybersecurity products.

According to The Wall Street Journal, Marsh & McLennan, a professional services company specializing in risk and insurance, will evaluate enterprise cybersecurity technology in a program called "Cyber Catalyst." The article states, "Marsh will collate scores from participating insurers, which will individually size up the offerings, and identify the products and services considered effective in reducing cyber risk."

Companies that choose security products from among the approved selection may find themselves qualified for improved insurance terms and conditions. Insurers already signed up to participate include Allianz SE, AXA SA, Axis Capital Holdings Ltd, Beazley PLC, CFC Underwriting Ltd., Munich Re, Sompo International, and Zurich Insurance Group AG.

Read more here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
EdwardThirlwall
50%
50%
EdwardThirlwall,
User Rank: Moderator
4/12/2019 | 12:22:03 AM
Pros and cons
We know that we have reached a critical phase of digital attacks when insurance policies now cover cybersecurity losses too. What a time to be alive to be able to weigh in on the pros and cons of technological advances and how much will we stand to gain or lose in the long run.
RyanSepe
100%
0%
RyanSepe,
User Rank: Ninja
3/27/2019 | 9:32:00 AM
Collaborate on Realistic Policies
Its great that insurance companies are starting to collaborate around Cyber Security, but what I think is most pertinent between insurance companies and the companies they "protect" is ensuring that in the case of a breach or incident they cannot use the fine print to dodge coverage. I understand that some are prerequisites to ensure the company is making a best effort to be secure and avoid damage but some line items are just vague clauses that allow for wiggle room.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/13/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11749
PUBLISHED: 2020-07-13
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.
CVE-2020-5766
PUBLISHED: 2020-07-13
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.
CVE-2020-15689
PUBLISHED: 2020-07-13
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.
CVE-2019-4591
PUBLISHED: 2020-07-13
IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451.
CVE-2019-20907
PUBLISHED: 2020-07-13
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.