Cyber Insurance Incident Response: Market tends towards commoditization
cyber-economics.com
cyber-economics.com
I know I can't insure my home if it doesn't meet basic fire-proofing standards. Does cyber security insurance work the same way?
However there will be written requirements into the policy on security expectations.
When the incident happens, there will be a post mortem review of whether the security best practices were implemented and how they contributed or hindered to the incident
The insurer will use that to either deny some coverage, increase premiums or worst case, advice that the policy will not be renewed.
The way requirements are handled is true for small or medium clients. I dont have experience with large firms but i would not expect those clients to be different.
(One does not go about winning business by asking new clients to submit to an audit prior to switching)
That being said, there may be audit requirements at renewals.
The client is given an output of our findings and what would be necessary for us to underwrite the policy.
Any cyber insurance company that does not do this is exposing themselves to outsized risk because they're writing policies based on incomplete data on their exposure.
It could seem like the PCI/NIST and others are akin to a building's electrical or fire code, which raises all boats, but it also concentrates overall portfolio risk in high-value assets with catastrophic failures. Like saying, "we only insure unsinkable ships certified by Titanic & Co., it's free money." Where instead of Titanic, with cyber the risk is only diversified over configurations of MSFT, AMZN, GOOG products and some linux kernels. Not a criticism, but as a security architect, it's the most interesting set of questions of all.
The insurance incentive to close ports is great, and super positive, perhaps how that risk gets managed on the back end is secret sauce.
For large companies the answer is a clear yes. At least we do this. It is not very complicated process, but depending on the IT/OT complexity it might take 1-2 weeks to gather the data since it usually requires the input from many stakeholders within the company.
What I'm always amazed by: companies think protection only when thinking about cyber. But that's not how an insurance thinks about. You have got to take into account what is at stake, too.
I've even begun seeing a trend towards tying coverage to use of continuous monitoring platforms, which I see becoming the norm within the next couple of years.
Basically, not only will they want to see where you are at before the policy is underwritten, they also will expect you maintain compliance and they can verify that compliance via CM.
In my opinion, use of CM would actually benefit the customer more than anything, as these policies are written in such a way I am skeptical they'll ever pay out (e.g., 100% compliance with something like NIST CSF is a pipe dream; you will always have some level of implementation snafus and oversights/negligence).
Or another thing I would look like is the controls that are implemented with the domain registrar itself (e.g., is two factor authentication enabled, principle of least privilege implemented, etc.).
Scoping your information system is one of the most important and difficult parts of cybersecurity. Many would not think that implementation of controls with their domain registrar would be in scope. But if you think of the reality, something like weak authentication in use by a domain registrar or lack of protection of data at rest/in transit is potentially just as risky any other service provider/your internal boundary. This is especially true if your product is quite literally dependent on the domain name resolving properly.
For example, it was fairly recent that NIST updated its guidance on requiring changing of passwords at a defined frequency.
In the case of DNSSEC, it is potentially a relevant and required control under, for example, NIST 800-53, revision 5.1, SC-21 [1]. That's why I mentioned that depending on the standard, it COULD be a requirement.
[1] https://csrc.nist.gov/Projects/risk-management/sp800-53-cont...
Edit: It is also still offered as a potential (arguably secure) practice under NIST SP 800-81-2.
Two other big industry-wide things that happened vis a vis DNSSEC:
1. All the mail providers banded together and came up with an alternate SMTP transport security standard, MTA-STS, that says explicitly that it exists because nobody wants to deploy DNSSEC.
2. The DNSSEC people and the browser/TLS people got together and proposed a DNSSEC stapling mechanism as a TLS extension. That stapling --- which Geoff Huston once wrote was an existentially important feature for DNSSEC, since DNSSEC queries routinely fail when made behind random CPE equipment that won't forward weird-looking DNS messages --- failed and was withdrawn.
There are basically no positive signals with respect to DNSSEC deployment. We're belaboring it; your comment isn't really about DNSSEC. I'm just saying: even if you're very, very diligent about security, it's unlikely that DNSSEC would be a high priority item. :)
One of the shortcomings of the article though, is that they don't address the price effect:
has the grouping of IR led to cheaper premiums with top carriers?
Are top carrier cyber policies effectively a "better deal" as a result of this gating?
Or is the margin even justified given the commoditization that is taking place at the top firms?
You know what the government did about this? They gave me free credit monitoring for a certain number of years. Enough critical information / infrastructure is online that heads should roll with each major breach.
There is apathy toward security on a large scale. There is apathy toward identity thievery. I grew out of the "death to capitalism" stage of my life decades ago but in this case it is obvious that money is protecting the big players.
But that document lists family members, past residences, perhaps previous crimes, etc.
Its the same document from high level people down to the janitor.
Its extremely useful from an intelligence perspective. Allows you to connect A LOT of dots.
It's not uncommon for government agencies to put their security manager in an at-will position for precisely this purpose. In other words, they have hired people for the purpose of having heads available to be cut so the people with authority are not at risk.
I am curious as to how this "limited collection" of IR firms adds to or drains from the overall security ecosystem.
On one hand, having a limited number of firms allows for seamless knowledge transfer, and upholds a somewhat high standard of service - kind of like a licensing regime.
On the other hand, I wonder if this cartel limits innovation and keeps new entrants with new ideas and better service from entering the fray.
Maybe its a bit of both?