Listen to this episode

Petronella Technology Group Podcast 12-08-20

0:0056:01

Recorded December 2020. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig Petronella of Petronella Technology Group interviews Matt Holcomb of Biltmore Insurance Services, an insurance professional with more than twenty years of experience, about cyber insurance and related security topics. Holcomb explains that cyber coverage is sold a la carte rather than bundled, that buyers should look at coverages rather than price alone, and that standalone cyber policies are often recommended.

He describes how carriers scrutinize applications and company websites, how coverage limits are tied to revenue, and how umbrella and excess policies work. He argues that insurers verify answers after an incident and may deny claims when applicants said yes to security questions without documentation. Petronella discusses the Cybersecurity Maturity Model Certification and the DoD Interim Rule requiring NIST 800-171 compliance, noting at the time of recording a November 30 deadline for uploading self-assessment scores, and warns about possible False Claims Act consequences. The conversation also covers wire transfer fraud, AI voice cloning scams, breaches at Target and Home Depot, security awareness training, and how working from home during COVID is changing security needs and insurance policies.

Worth remembering

Key takeaways

  1. Matt Holcomb explains that cyber coverage is a la carte, so shoppers should verify what a policy includes rather than assume everything is bundled together.
    “You may have cyber insurance, but there could be things like money wiring. Any of this stuff may not be covered as a secondary that you have to ask for.”
  2. Price should not be the deciding factor when buying cyber insurance, because coverage gaps only become visible when a claim is filed.
    “Make sure you're looking at the coverages because the last thing you want to do is find out what coverage you have when it comes time to claim.”
  3. Carriers review a company's website during underwriting, so Matt Holcomb advises removing descriptions of services the business no longer performs.
    “if there's something on your website that you don't do anymore, take it off.”
  4. Matt Holcomb says carriers tie available coverage limits to company size, so a small business asking for limits far above its revenue will be turned down.
    “Nobody's going to touch that. Because they don't even have enough money. They're not even worth that.”
  5. Matt Holcomb warns that insurers may not verify application answers until a claim, when they will demand documentation and can deny coverage if proof is missing.
    “The insurance company's not going to check until there's a claim. And at that point, they're going to go back and say that you said you had security here.”
  6. Matt Holcomb relays Secret Service guidance that wire fraud victims have roughly three to four days to contact their bank before stolen funds leave the country.
    “if you have a situation where you do a wire transfer, you have about three to four days to get in touch with the bank to stop it.”
  7. Craig Petronella describes, at the time of recording, a DoD Interim Rule requiring defense contractors to upload NIST 800-171 self-assessment evidence by November 30.
    “We need you to upload all this by November 30. So there's this vast scramble.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Petronella Technology Group Podcast 12-08-20 with Craig Petronella of Petronella Cybersecurity and Digital Forensics and Matt Holcomb of Biltmore Insurance Services on Cybersecurity Insurance. In this episode, Craig Petronella and Matt Holcomb discuss various cybercrimes such as phishing, business email compromise, wire fraud, ransomware, malware. Learn how a $100 keylogger malware caused Target, Home Depot, Michael's, Sony and others to get hacked. The time is now to create and update your policies, procedures and security controls. Security awareness training, security risk assessments, penetration testing, and continuous security monitoring are essential. Learn how the new CMMC may impact cybersecurity requirements and how vendors are now assessing the your risk. Learn what your business needs to show supporting evidence of to ensure that you qualify for cybersecurity insurance and cybercrime insurance as well as what to look for.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.