Cyber insurance is an odd product. It is not that expensive for what you get, but all insurance companies that sell it have extensive screening processes to ensure a companies IT infrastructure is well protected before they will cover you.
Such standards are good for the IT industry, but many IT experts are offended by being required to go through more such testing after they have been through ePCI , HIPA, Sar-Ox and other industry, government mandated certification processes.
While each process is great for its focused scope, cyber insurance screening can get into the nuts and bolts of a network in ways the others have not.
Another set of eyes is always good when the insurance company has potentially huge pay outs on the line.
Discussion on:
Top
Rated
Rated
Interesting post.
Edited by Hates Idiots
Updated - 21st Aug
Just
In
In
Spot on.
Edited by Hates Idiots
Updated - 24th Aug
Show:
+2
Votes
Interesting post.
Posted by Hates Idiots
Updated - 21st Aug
+1
Vote
Thanks, as always
You always have such specific, insightful comments. I really appreciate it,
Heather
Heather
Posted by Heather Clancy
21st Aug
+1
Vote
Cutting corners on data security
Heather, cyber insurance makes sense but certainly isnt a replacement or excuse for cutting corners on data security. I suspect that the insurance companies who offer these policies perform stringent due diligence to make sure a company has appropriate security mechanisms in place. Likewise, a more secure IT environment is likely to result in a lower premium. Making data unreadable if it is stolen by using encryption is another form of insurance protection. @Socialtis @Vormetric
Posted by SocialTIS
23rd Aug
0
Votes
Spot on.
You are very correct when you say "perform stringent due diligence" and " a more secure IT environment is likely to result in a lower premium."
Chubbs review made ePCI compliance look like childs play.
We were told they would not secure a weak network because companies could not afford the premiums.
It is a much more comprehensive security standard you must meet.
Chubbs review made ePCI compliance look like childs play.
We were told they would not secure a weak network because companies could not afford the premiums.
It is a much more comprehensive security standard you must meet.
Posted by Hates Idiots
Updated - 24th Aug