Listen to this episode

Don't Get Cybersecurity Insurance (Until You Listen to this Podcast)!

0:001:15:58

Recorded May 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this episode of Encrypted Ambition, Erin and Blake welcome Craig to discuss cybersecurity insurance and why businesses need it. Craig explains that insurers have raised the bar at the time of recording because of ransomware payouts, and now require proof of multi-factor authentication, customized policies and procedures, security risk assessments, and penetration tests before issuing coverage.

Blake notes that many businesses lack device inventories, system security plans, or network diagrams. The hosts discuss different forms of MFA, with Craig arguing that SMS text codes are unsafe and favoring authenticator apps paired with hardware tokens. Blake reads examples from a real vendor security questionnaire that larger companies use to vet suppliers. Craig recounts a case where a client lost nearly three quarters of a million dollars to wire fraud after an IT worker's phished credentials, saying MFA would have stopped it. The panel warns that lying on insurance applications can void claims, and Erin argues that compliance is an investment offering competitive advantage rather than a sunk cost.

Worth remembering

Key takeaways

  1. Craig says multi-factor authentication is the number one thing cybersecurity insurance providers look for, because it adds an effective extra layer beyond passwords.
    “So MFA is really the, the number one thing that cybersecurity insurance is looking for.”
  2. Craig warns that SMS text message codes can be defeated through SIM swap attacks and recommends authenticator apps with hardware tokens instead.
    “So this is why we do not recommend SMS for an authentication method.”
  3. Insurance companies want customized policies with supporting evidence that they are actually followed, not generic documents downloaded from the internet, Craig explains.
    “they don't want you to go on the internet and just go download policies and then just stick them in a folder that you're not going to read”
  4. Craig warns that answering the insurer's questions dishonestly may get coverage issued, but the claim will be denied at the time of a breach.
    “At the time of a breach, if you don't have all of your evidence and proof that you've answered all those questions truthfully”
  5. Craig recounts a client who lost almost three quarters of a million dollars to wire fraud after phished credentials, saying MFA would have blocked the hackers.
    “It would have avoided, it was almost three quarters of a million dollars that they lost due to wire fraud.”
  6. Blake and Craig describe vendor security questionnaires of four to six hundred questions that larger companies use to vet suppliers before doing business.
    “They're going to hit you with, what's called a vendor security questionnaire, or VSQ sometimes four or five, 600 questions of all this deep due diligence”
  7. Erin argues cybersecurity compliance is not a sunk cost but a competitive advantage that puts businesses ahead when pursuing contracts and insurance.
    “Cyber security is not a sunk cost. It does not have to be a sunk cost.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Hackers aren't going anywhere, any time soon, so a lot of companies are (wisely!) looking into cyberinsurance.

However, not all companies know what they need to do to get cyberinsurance, or they try to use it as a replacement for ACTUAL cybersecurity. On today's podcast, we discuss the right (and wrong) ways to get cyberinsurance for your business.

Hosts: Craig, Blake and Erin

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.