3 ms·
No disagreements there. What's a better answer though? No one wants to do it, most non-tech people don't understand it, yet the standards and procedures need to
by bojo 3y ago
No disagreements there. What's a better answer though? No one wants to do it, most non-tech people don't understand it, yet the standards and procedures need to improve to reduce the attack surface area - especially for businesses which support critical infrastructure.
- konschubert 3y agoYou could legally mandate companies to insure themselves against cybersecurity risks. It's really an interesting idea: https://www.cato.org/sites/cato.org/files/serials/files/regulation/2013/3/v36n1-10.pdf https://www.cato.org/sites/cato.org/files/serials/files/regu... This creates a "market for effective practices", because companies that follow good security practices would get cheaper insurance. But it would allow insurances and companies to figure out dynamically what is cost effective and what isn't. There would be lots of financial incentive to figure out what protects you effectively and what is just security theatre.
- Veserv 3y agoMost companys already do. Unfortunately for the insurance companys their actuarial tables are backwards looking and cyberattacking is one of the fastest growing industrys. The smart insurance companys are all getting out of cybersecurity insurance because the premiums on the policys they wrote 10 years ago when the average attack cost $1,000 to remediate do not look so good when the average attack now costs $100,000 to $1,000,000 to remediate. Since the expected probability of a successful attack in any given year that requires payout is approaching 100% these days the insurance needs to be priced something like 10x-100x the prevailing prices to be survivable. Eventually it will shake out once the cyberattacking industry becomes mature because at that point backwards looking projections make sense. Until that time, we are in for a wild ride.