3 ms·
Depends on the company. Mine (Coalition) does do scanning and ensuring basic metrics and protection are in place. For example, RDP ports must be closed, which
by dd82 5y ago
Depends on the company. Mine (Coalition) does do scanning and ensuring basic metrics and protection are in place. For example, RDP ports must be closed, which is an auto-decline.
The client is given an output of our findings and what would be necessary for us to underwrite the policy.
Any cyber insurance company that does not do this is exposing themselves to outsized risk because they're writing policies based on incomplete data on their exposure.
- motohagiography 5y agoNaive and perhaps pedantic question from me, does using scanning for monitoring not create an aggregated/correlated re-insurance risk? It could seem like the PCI/NIST and others are akin to a building's electrical or fire code, which raises all boats, but it also concentrates overall portfolio risk in high-value assets with catastrophic failures. Like saying, "we only insure unsinkable ships certified by Titanic & Co., it's free money." Where instead of Titanic, with cyber the risk is only diversified over configurations of MSFT, AMZN, GOOG products and some linux kernels. Not a criticism, but as a security architect, it's the most interesting set of questions of all. The insurance incentive to close ports is great, and super positive, perhaps how that risk gets managed on the back end is secret sauce.
- balgan 5y agoThere are multiple parts to the underwriting process (full disclosure I run the team that does data collection and security at Coalition where the op you're replying to works). Part of the data we collect is used for risk selection (do we want you on our book?) and then other piece is used for pricing and thats where technologies, providers and a lot of other things come in! Lmk if u have any questions!
- motohagiography 5y agoSuper cool of you to respond. You're solving one of the most interesting problems in security. I worked on a concept for modelling an SPV for an event driven ILS for cyber policies many years ago, and the barrier was the bond modelling people wanted a standardized risk model signed off by a university, which to me seemed like /dev/null for risk, and seemed to miss the point. I'm just excitable about that topic, it's probably not a useful public discussion, I'll certainly keep an eye to what you're doing for my institutional clients. Rooting for you.