Cyber Insurance Companies Demand Greater Risk Management Policies

Share post:

Cyber insurance companies are demanding greater risk management strategies from organizations interested in purchasing cyber insurance.

“Insurers want to know there is an organized and proactive effort to manage cybersecurity risk,” said Travis Wong, VP of risk engineering and security services at cyber insurance provider Resilience.

These risk management strategies include multi-factor authentication (MFA), backup, incident response plan, patching and cyber awareness training for employees.

While listing costs both before and after a cyberattack could be costly for both insurers and customers, both parties may get caught up in trying to fix the situation, overlooking other vulnerabilities that could lead to other costly problems.

“Theft of credentials either through phishing or unprotected assets exposed publicly on the internet remains the predominant approach for cybercriminals to launch an attack,” said Jack Kudale, founder and CEO of Cowbell Cyber.

Once companies already have a good security system and are ready to take the steps to meet security requirements, they can conclude a deal with a cyber insurance company.

Apart from the security requirements, many companies find it difficult to get cyber insurance because of the high costs.

According to the NetDiligence Cyber Claims Study 2021 report, the average cost to the insurer for a cyber incident is $145,000 for small and medium-sized businesses and $10 million for large businesses, with ransomware mitigation costs even higher at $256,000 and $16.6 million respectively.

The sources for this piece include an article in CIODIVE.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways