3 ms·
At coalition, we scan the infra when deciding to make an automated quote or do a secondary manual review. So being able to have data about what the possible in
by dd82 5y ago
At coalition, we scan the infra when deciding to make an automated quote or do a secondary manual review. So being able to have data about what the possible insured actually has in terms of hardware and practices (MFA, backups, etc) is very valuable. When we decline, the applicant gets the reasons why for the decline, and they're free to re-apply after implementing fixes and good practices.
We're not demanding perfect security. We do ask for good practices and evaluate risk from there. Security does not need to be expensive, but many places see it as second or third tier priority until shit hits the fan, and _that_ is where it gets prohibitively expensive. Penny wise, pound foolish.
- Root_Denied 5y agoThis is where I've been predicting the insurance side of cybersec going for a while. You have some baseline required security for the premium that offers X coverage, and you can reduce the premium or increase the coverage if you can prove Y standards have been met. Get a list of approved 3rd party auditors/pentesting companies, have them certify what level your company is at, apply appropriate discount. Insurance costs are a language that businesses speak fluently, so I think this has a higher chance of moving the needle on cybersecurity standards and have them actually be implemented across the board.